14 ms·
Centralised DoH is bad for privacy
- ssalka 7y agoFor the uninitiated, what is DoH and what is its relation to DNS? I can see this is comes from a DNS-focused blog, but a little background info on the subject would really improve the quality of the article.
- ssalka 7y agoClicked more links; it's "DNS over HTTPS". Acronyms getting crazy these days
- mchristen 7y agoThe article includes a summary of what DoH is at the top and also has links to more information. Not sure what else could be done before the article is about DoH itself.
- bpt3 7y agoIt's standard practice to define acronyms prior to first use, such as DNS over HTTPS (DoH), rather than assuming people have a priori knowledge or that they'll click on the right links in the content to figure it out.
- michaelt 7y agoI think you meant to say Domain Name System (DNS) over Hypertext Transport Protocol with Secure Socket Layer (SSL) (HTTPS) (DoH)
- cabaalis 7y agoFrom my understanding, it uses HTTPS to perform dns lookups. This has the benefit of encrypting your dns lookups so that people reading packets can't read them. However, your pc and the DOH provider still can read/store/analyze/sell your dns lookups. Your isp is probably selling your dns lookup data. So do you trust cloudflare more than your isp? The primary issue is that this bypasses the normal dns mechanisms built into your local network. No more blocking sites using DNS. Presumably, ad block in your browser will still work. But things like pi-hole will suffer.
- ocdtrekkie 7y agoAs a note, I believe Pi-hole is implementing the Canary domain to automatically disable Firefox's DoH support: https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli... Though one wonders if ISPs and countries can use the same strategy to mitigate any benefit of Firefox's strategy here.
- sybercecurity 7y agoNot only that, but get ready to hear some more: DoH - DNS over HTTP(S) DoT - DNS over TLS. Often meaning DTLS ADD - Applications doing DNS, where the application is sending DNS queries instead of asking the OS resolver. Usually implied to be HTTPS as well.
- craftyguy 7y agoIt's right there in the article... which you read... right? > DNS over HTTPS meanwhile encrypts DNS queries going over the network, which means that no one between you and the DoH server can see your DNS queries or modify the DNS responses.
- neogodless 7y agoForgive my ignorance, but I searched the article and the internet (https://www.google.com/search?client=firefox-b-1-d&q=doh https://www.google.com/search?client=firefox-b-1-d&q=doh) and I could not figure it out. Shoot - I just remembered. "DNS over HTTPS" - it does put this in the description of "what DoH does", it's a little hard to find. There is a pattern that is popular to use a phrase and then abbreviate it, i.e. "DNS Over HTTPS (DoH)" which is perfect for this sort of scenario. By pairing them, the users that search for "DoH" will find it next to the phrase very early in the page. It's not a great idea to bury the full phrase somewhere on the page, and omit the abbreviation next to it.
- judge2020 7y agoA solution here is like what Chrome is doing - a DoH upgrade list that only uses it when your OS/router specifies a service that also provides DoH[0]. https://github.com/chromium/chromium/blob/711b1ba2735f8af4bd6359c6292e1875412df74f/net/dns/dns_util.cc#L146-L217 https://github.com/chromium/chromium/blob/711b1ba2735f8af4bd...
- ocdtrekkie 7y agoThis is a significant improvement over what Mozilla is doing, but still retains a big issue: It doesn't account for network requests sent outside the browser. I'd far rather these developers focus on getting DNS-over-HTTPS support built directly into operating systems and then properly using the OS's network stack.
- sp332 7y agoThis is still very experimental. I think doing the experiments in applications makes more sense than potentially breaking every network request on the system at once.
- srbby 7y agoSo, let's be clear about this--if Chrome detects your DNS server is on one those lists, it will automatically switch to using DoH with the same provider?
- rasz 7y agoin reality Chrome will(used to last time I looked into this) use DoH/hardcoded Google dns server when for example queried domain doesnt have A record. https://www.reddit.com/r/vivaldibrowser/comments/a23071/how_private_is_vivaldi/eav4buq/ https://www.reddit.com/r/vivaldibrowser/comments/a23071/how_... https://techdows.com/2018/12/vivaldi-2-2-lets-you-disable-google-dns-service-that-fixes-navigation-errors-privacy.html https://techdows.com/2018/12/vivaldi-2-2-lets-you-disable-go...
- judge2020 7y agoSpectrum still takes over NXDOMAIN and points it to a Yahoo search page when using their DNS, meaning you now have exposed the browser to all of the oath trackers and pushed it to AdChoices, meaning targeted ads. Not every DNS provider/ISP does this, but when you have one that does, it's probably a net positive to instead beam it to CF which makes guarantees about logging and gets audited[0]. 0: https://1.1.1.1/dns/#explanation https://1.1.1.1/dns/#explanation
- jannes 7y agoDoes this apply even when you are not using Spectrum's DNS? I.e. do they modify the DNS responses of other DNS providers? I am not a customer of theirs, nor have I been a customer of an ISP that engages in such practice. As a EU citizen I am much more concerned about sending my data to a US company which I am not a customer of. ("if it's free, you are the product") At least my ISP is subject to European regulation and I'm paying them to provide the service.
- judge2020 7y agoIt does only happen with their default DNS servers, and their router interface (at least on newer routers) makes it easy to change DNS, but the users Mozilla is targeting by making it the default likely don't know how to change DNS or why they would want to do so.
- deftnerd 7y agoI moved recently and let my ex keep my network gear and went with the default Spectrum cable modem and WiFi access point. The new modems not have user-facing access pages to check connection status and signal levels. Additionally the bundled WiFi access point let you change everything you want except for the DNS settings your routers local DHCP pushes out. They are actively forcing users to use their DNS unless you buy your own equipment. Its too bad because its actually a pretty decent WiFi router (1+ Gbps AC, 4 gigabit ports, no crashes with excessive usage, etc)
- 7y ago
- deleted 7y ago[deleted]
- ocdtrekkie 7y agoI was accused of having a hidden agenda and then blocked by the Senior Director of Browser Engineering at Mozilla for suggesting that building DoH into Firefox and bypassing the OS network stack was a significant concern. This person expressed some bizarre lack of understanding of how DNS works, how OSes work, etc. for such a position, as they seemed to suggest that the only way Mozilla could impact DNS requests is at the browser level, and that implementing it at the OS level wouldn't protect people from ISPs snooping? Not only will Firefox's approach cause significant breakage, but the fact that it doesn't protect non-browser traffic means users may mistakenly be protected when they are not. Mozilla may be putting lives at risk here, and what's truly irritating, is that Mozilla's said engineering director, didn't seem to realize Mozilla could've built something that integrates with the operating systems' network stack properly. Mozilla should've invested in improving DoH support at the OS-level or built a VPN client, again, that worked at the OS level to protect all DNS requests and/or network traffic, rather than trying to shoehorn in a way to redirect your DNS queries to their partner into your existing install. I have nothing inherently against Cloudflare, but Cloudflare should not want to be associated with this bad hack solution to DoH, and Mozilla should rethink implementing it.
- bpt3 7y agoCan you elaborate on how performing DNS lookups over HTTPS is putting lives at risk and what significant breakage will occur with this approach? Also, I would argue that the most effective way for an organization that maintains a popular browser to impact DNS requests is at the browser level.
- muraiki 7y ago> Can you elaborate on how performing DNS lookups over HTTPS is putting lives at risk The article touches on this.
- bpt3 7y agoUnder the "DoH for oppressive regimes" section? Either way, I would welcome confirmation and/or elaboration on how DoH makes things worse than the status quo, not worse than a theoretical ideal that doesn't exist.
- clubm8 7y agoOk but if I don't want to use DOH then what? I'd previously used Cloudflare's DNS because I trusted it more than my ISP. Is disabling DoH going to enhance my privacy? What action items can I take away from this article? I see a lot of writing about how DoH is back, but rarely do I see the writers lay out a specific solution.
- the8472 7y agoRun an iterative resolver somewhere, then connect to it either via DoT or some VPN (wireguard, openvpn...) from your router or the OS stub resolver. Depending on your threat model you could also run the iterative resolver locally.
- mr__y 7y agoTo extend your idea, if that "resolver located somewhere" would be shared by more than one user then mapping a dns query to a specific user/IP would be much harder, hence further improving the privacy
- the8472 7y agoThen you're back to where they have to trust the operator. The purpose of this exercise is to reduce the number of parties that have to be trusted, not increase them. Ideally iterative resolver - autheoritative nameserver traffic would also be encrypted, then we wouldn't have to "hide in the herd" (as much).
- mr__y 7y agoI get the "trust the operator problem", I was thinking about sharing this for several devices I own or possibly with family assuming that "trust the operator" would not be an issue then, while increasing privacy a bit by disabling the ability to match a DNS query to specific user/IP. If this was to be shared publicly then of course you are right and this not only solves nothing but makes it worse as it introduces another node to be "trusted"
- 7y ago
- kijin 7y agoI've said this before and I'll say it again. If you don't like the fact that DoH is centralized in the hands of Cloudflare, all you have to do is offer a competing service. Especially if you're a DNS company in the first place. It's your domain of expertise. Build something. Ship it. Once there are a number of alternatives, Mozilla et al. will have no reason to insist on using a single provider. Right now, for a lot of people in a lot of countries, a choice to use any resolver that isn't controlled by their ISP/government is a step in the right direction. So please stop trying to drag down other people who are doing their best to make progress. If you don't like the direction that they're headed, build an alternative, write an RFC, or do whatever you can to show us how you think it should be done instead. Show us the code or GTFO.
- trisiak 7y agoThe main point of the article is not that CF is evil and is now getting all your DNS data; it is that CloudFlare gets that data AND none of those that had access to it already are going to lose it after you migrate to DoH.
- briffle 7y agoThat is not true. Several middlemen are now going to not be able to see your data. Most people that used public resolvers were sending plain text UDP queries over their ISP. This could be redirected, hijacked, etc. If you had a connection that wanted you to use their filtering software, they could/would block outgoing port 53. That is not possible with DoH, they can no longer see what domain you are querying. They may be able to block 1.1.1.1, but as more places get DoH, it will be harder to block using other DNS providers.
- Spivak 7y agoThat’s not really the issue. The hard problem isn’t making a bunch of DoH competitors but getting OS level support so that browsers can drop their own logic. An app running on the system needs to be able ask the OS for an encrypted DNS lookup or where it should perform such a lookup and get be able to decide what to do when it can’t. The UI needs to be there to accept DoT or DoH networks from DHCP on trusted network profiles but the a user-chosen default on untrusted networks.
- eloff 7y agoIt's bad for privacy in theory because you centralize DNS requests through Cloudflare. In practice ISPs are almost universally reprehensible in how they collect, track, and sell your data. Cloudflare on the other hand has a great reputation for respecting user privacy and they do thrid-party audits on a regular basis so you can have peace of mind about it. Encrypting your DNS requests so your ISP (and other hops on the Internet) can't snoop on it is a huge privacy win. I'd much rather trust Cloudflare than my ISP. Doubly so when I'm out of the house or traveling abroad. Practice > theory. Every time.
- DavideNL 7y ago> In practice ISPs are the almost universally reprehensible in how they collect, track, and sell your data ... in your country. For me it's the other way around; i'd rather trust my ISP because privacy laws in my country/EU are much better vs the US. I interpret the move by Mozilla as hostile in regards of privacy, and i can't understand why EU politics don't intervene when a US company starts hijacking all Firefox users DNS requests (opt-out instead of opt-in.)
- the8472 7y ago> and i can't understand why EU politics don't intervene Maybe it is as simple as nobody having filed a complaint with a data protection agency yet.
- jannes 7y agoInteresting question... How would I file a complaint against Mozilla? Their privacy policy is only available in English and lists Mozilla Corporation in Mountain View as the legal entity. They probably don't conduct many business activities in the EU. However, it looks like they are providing a website for "data subject access requests" which means they might fall under EU regulation as it sounds like a GDPR compliance thing. https://app.onetrust.com/app/#/webform/4ba08202-2ede-4934-a89e-f0b0870f95f0 https://app.onetrust.com/app/#/webform/4ba08202-2ede-4934-a8...
- mfer 7y ago
- mfer 7y agoFor reference, Mozilla negotiated an agreement with Cloudflare around this. It's different from Cloudflare normal policies. You can read it at https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/firefox/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
- the8472 7y agoDoes the agreement have teeth? Is it even enforceable in the face of NSLs? > We also commit to documenting any government request to block access in our semi-annual transparency report, unless legally prohibited from doing so. I guess it is not.
- MrRadar 7y agoMozilla is only rolling out DoH to users in the US whose ISPs would already be subject to NSLs. Presumably they will wait until non-US DoH providers are available before rolling it out elsewhere.
- captn3m0 7y agoMozilla is not yet ready to even talk to non-US DoH providers as of now (I've tried, Quad9 tried from what I've heard, and I'm sure many others did). Till this changes, Mozilla DoH rollout will be US-only.
- the8472 7y agoEven then the question remains whether that agreement has any teeth.
- Illniyar 7y agoWhat about etc/hosts ?
- StreamBright 7y agoChrome ignores it. https://stackoverflow.com/questions/42636711/google-chrome-ignoring-hosts-file https://stackoverflow.com/questions/42636711/google-chrome-i...
- swiley 7y agoetc/hosts doesn't scale, it came first and was replaced with DNS when we had scaling problems.
- Illniyar 7y agoWhile that might be true many people still use the hosts file today to override dns resolution.
- dagenix 7y ago> And for actual privacy on untrusted networks, nothing beats a VPN, except possibly not using hostile networks. Except that using a VPN then funnels _all_ of your traffic through a single server which is ideally placed to monitor your browsing activity. And, VPN providers tend to be quite hard to evaluate for their trustworthiness.
- rocqua 7y agoYou can always run your own trusted VPN, either at home or at a rented box.
- rasz 7y agoVPN providers also mysteriously tend to be mostly China owned.
- Jonnax 7y agoGo to AWS make an EC2 instance. Configure it as a VPN. It's simple to do.
- samantohermes 7y agoRiseup VPN is good, and doesn't need an account.
- bryanlarsen 7y agoCannot Mozilla reasonably say that currently there's only one acceptable DoH provider; it hopes to vet more soon and once there are more than one it will select the default provider through some reasonable algorithm (random, perhaps).
- mukti 7y agoI suppose its good that DoH is addressing the privacy issues with DNS, but I think I agree with the point this article is making overall. If its only one vector of privacy, making it a default this early on (less than a year old?) seems a bit presumptuous. If someone is looking for your DNS traffic, but you're using DoH; they'll likely find what they're looking for using another method. In my opinion, this kind of goes against what I would expect a browser to do as well. I don't like the idea that it just bypasses the OS settings. I understand that there are guidelines for enterprise users, and people who want to disable it; but I feel that a prompt when they globally enable the setting isn't enough. Most average users will probably just click "Yes" on the dialog that asks if they want it enabled. The idea of DoH seems like a good one, but I would prefer if they figured out a better way to implement it. Probably a huge majority of people are just using their ISP's DNS servers, but I don't know that pointing them to Cloudflare's DoH implementation is necessarily better.
- Santosh83 7y agoIn a hypothetical Internet of the future where almost all websites and web-apps are also served from a handful of huge cloud providers, would DoH not increase privacy since now ISPs (and potentially some govts) will have a very hard time figuring out which site or app you are visiting?
- Forge36 7y agoIs it possible for me to run my own DoH at home? I can setup a DNS server, however I can't find any details on how I can get a full DNS copy which avoids the specifics of which website I'm looking up.
- amarshall 7y ago> how I can get a full DNS copy No such thing exists. Even if it did, the TTL of records and creation of new ones would make it out-of-date almost immediately. The only way to get all sub domains (and many domains) is to crawl or enumerate all permutations.
- Forge36 7y agoI'm probably missing how other DNS servers update and propagate changes. I update my website's registration with Google, it's not clear how other copies are notified (or poll?) About my updates with Google.
- devit 7y agoIs it feasible to use private information retrieval algorithms so that query privacy is preserved?
- megous 7y agoOn the contrary, because it's tcp and encrypted you can tunel your queries safely over tor. Of course, there are some things to take care of even if you do that, because privacy is not a simple binary switch you enable. If you own some not so popular domains, you also should make sure to exclude them from the queries, so that who you are not easily deanonimized by your query patterns. Both is easy relatively easy to do with dnscrypt-proxy. It's not enough by itself, but DoH enables ways to get secure DNS queries to your chosen provider anonmously and securely.
- mr__y 7y agoThere is one counterpoint for those concerned about all their DNS queries going through Cloudflare: since more and more[0] websites use Cloudflare (CF) service, the traffic goes through CF regardless of DNS lookups. I'm not saying its good, just pointing out that in more and more cases CF will know about a visit to a website whether their DNS/DoH is being used or not. In such a scenario using anything else than CF would actually harm the privacy as this would spray the information over other entities/providers. (If a website is behind a CF revproxy, CF "knows" about a visit to that website, if then a non-cf DNS service is used, that DNS provider becomes a second entity to have that information). Of course as of now majority of websites are NOT using CF, but apparently their market share is growing and this may become a larger issue in the future. [0] Already 10% in 2018 according to this: https://www.wired.com/story/cloudflare-spectrum-iot-protection/ https://www.wired.com/story/cloudflare-spectrum-iot-protecti...
- throw0101a 7y agoIf Mozilla cares about privacy and consent, it'd be nice they would have also implemented DNS-over-TLS and let people choose what to use. Also, their idea of "use-application-dns.net" is half-baked: it breaks DNSSEC because one has to override the responses from the .net folks--which are signed. One suggest I head (by the author of the linked article) was to use something like "use.application-dns.net" instead. So you are overriding the responses of a particular domain instead of a TLD. Further, once you have 'access' to ".applicaiton-dns.net" there are other things that can be done: * check for use-doh for DNS-over-HTTPS desirability * check for use-dot for DNS-over-TLS desirability It seems to me that Mozilla didn't bother talking to any DNS experts (e.g., DNS-OARC), and now everyone is scrambling. Most people aren't against encrypted DNS, but it just needs to be implemented properly.
- tptacek 7y agoIt's not clear to me why any user of Mozilla would care about DNSSEC (which Mozilla doesn't support anyways). For that matter: while it's obvious why Mozilla users would want to choose which resolver they trust (Cloud Flare, or something else), it's not at all clear why they'd actively want DoT, whose only real "benefit" over DoH is that it can be actively filtered by network providers who don't want users encrypting their DNS queries.
- throw0101a 7y ago> It's not clear to me why any user of Mozilla would care about DNSSEC (which Mozilla doesn't support anyways). So you talk to Cloudflare via DoH: how do you know that CF isn't manipulating the results? (Perhaps by government coercion.) > ... it's not at all clear why they'd actively want DoT, whose only real "benefit" over DoH is that it can be actively filtered by network providers who don't want users encrypting their DNS queries. Mozilla may want to support it because it could prevent them from being banned from corporate environments that may need to monitor queries for regulatory reasons. It doesn't have to be the default, but being able to enable it via a GPO could be useful.
- tptacek 7y ago
- everdrive 7y agoI have yet to hear a compelling argument that DNS poses much of privacy risk compared to: - Your ISP analyzing your IP addresses - Your ISP analyzing the names in your TLS certificates - The website you're visiting selling your information. (ie, this identify belongs to this IP and browser cookie. See where else you find him) - The advertising iframes doing the same as the website above. Tracking you everywhere, primarily by using cookies, canvas, etc.
- judge2020 7y agoCF is just as well hitting at the first two points with Warp VPN and eSNI.
- cracker_jacks 7y agoThis article doesn't do a good job of explaining the censorship-resistant benefits of DoH. The author conflates privacy and access as the same thing. They are entirely different. Access to information is the first step. Privacy is a luxury after access.
- smnthermes 7y agoCloudflare is not even remotely a trustworthy company: https://codeberg.org/crimeflare/cloudflare-tor/src/branch/master/README.md https://codeberg.org/crimeflare/cloudflare-tor/src/branch/ma...
- waz0wski 7y agolets also not forget cloudbleed, wherein they leaked sensitive data for 6 months > In total, between 22 September 2016 and 18 February 2017 we now estimate based on our logs the bug was triggered 1,242,071 times. https://blog.cloudflare.com/quantifying-the-impact-of-cloudbleed/ https://blog.cloudflare.com/quantifying-the-impact-of-cloudb... https://news.ycombinator.com/item?id=13766339 https://news.ycombinator.com/item?id=13766339
- auslander 7y agoThank you Apple we still have Safari.
- psic4t 7y agoWith all the discussion going on, I'm really wondering why nobody asks why Cloudflare is offering their DoH infrastructure for free.
- jedisct1 7y agoTo avoid centralization, help deploy more independent resolvers: https://dnscrypt.info/ https://dnscrypt.info/ And for more privacy, we will soon need DNS relays https://github.com/DNSCrypt/dnscrypt-protocol/blob/master/ANONYMIZED-DNSCRYPT.txt https://github.com/DNSCrypt/dnscrypt-protocol/blob/master/AN...