6 ms·
I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice. Interference from browsers with network level operatio
by daedalus_j 7y ago
I'm fine with encrypted DNS as long as it's from my router to the (encrypted) DNS provider of MY choice.
Interference from browsers with network level operations is my real worry. As far as I'm concerned, as long as the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers, no problem. I'm worried about the "to protect the users we've hijacked their DNS directly via the browser" possibility though.
I know it used to be that using ISP DNS servers gave you access to some of their local caching and such. I don't hear that talked about much in these discussions. Is that no longer a thing, and thus we truly don't need ISP DNS?
- shakna 7y agoChrome's design attempts to use your current DNS settings to access a DoH resolver and fallsback to the current behaviour if it fails. The browser isn't interfering in any of your network operations.
- daedalus_j 7y agoSo, assuming my local LAN DNS resolver, which serves my own custom DNS information to LAN clients, doesn't support DoH itself, but uses DoH to reach out to the authoritative servers, chrome will bypass this my local resolver? Sounds like interfering with the way my intranet operates to me.
- Spivak 7y agoChrome doesn’t know that your local intranet is trusted or that the local resolver is trustworthy. You need to tell Chrome this by flipping a switch to either change your DoH provider or disable it all together. This change is explicitly protecting users from malicious network operators. Since you control the endpoints it should be no big deal, you apply GPO, run Puppet, whatever and everybody is talking to your local DNS again but it is absolutely right to not trust local unencrypted DNS by default for every network you connect to.
- daedalus_j 7y agoIn that context, I'd be perfectly happy if chrome had a "I'm on an untrusted network right now" switch, like incognito window. Not sure we should assume that the entire network between the browser and cloudflare is untrusted though. Aren't there some "hijacks" that are actually valuable to users? For example, if I run a network inside an extremely limited internet environment, I can hijack the user's DNS and redirect them to a "Hey, we're sorry, but running Netflix here will ruin the network for everyone, we hope you understand" page. If their browser is ignoring my local DNS server my option would seem to be simply black-hole netflix packets in the firewall, which is a lot less friendly to the user. Would I be a malicious network operator in this case?
- schoen 7y agoThere's presumably no way to allow that without also thereby allowing you to change the apparent content of the Netflix service—or of other sites! (Suppose that you could hijack the user's DNS to redirect ubuntu.com to a page that said "Thanks for your interest in Ubuntu! To download the latest version, click <a href='https://evil.com/ubuntu/ubuntu.iso'>here</a>." https://evil.com/ubuntu/ubuntu.iso'>here</a>." How can you allow one kind of hijacking without also allowing the other?) There has been work on allowing networks to communicate out-of-band to browsers for administrative purposes. Even this is risky in general because of the phishing possibilities, among other things. Showing users arbitrary messages from network operators in the middle of the users' other browsing activities is likely to make it even easier to confuse the users into taking actions that they really didn't intend to do.
- mulmen 7y ago> Not sure we should assume that the entire network between the browser and cloudflare is untrusted though. The network is compromised. This is the fundamental assumption of networks. If you operate from this position you are much less likely to get burned.
- Jonnax 7y agoYes. You would be malicious. Doesn't matter what your intentions are if someone with bad intensions could do something bad in that scenario. For example redirecting the user to a fake webpage asking for their username and password. A user will learn that there's blocking if they try and access Netflix and it doesn't work. You can get something like a Juniper SRX firewall which can recognise applications via signature and do blocking that way. Rather than against IP ranges only. Also as a network admin you're not saying why you won't be able to block DNS over HTTPS providers. Unless you're thinking there's going to be some unknown DNS server used by the browser. But if that's your fear you'll need to block all the online DNS lookup websites. What if a user just types the IP address directly? Totally circumnavigates DNS.
- Ericson2314 7y agoNo it should use your local resolver.
- YokoZar 7y agoWhy can't your local LAN DNS resolver support DoH itself if it can act as a DoH client to authoritative servers? That way the browser would know it can trust it to begin with.
- tptacek 7y agoIf you're on a mainstream US ISP, interference from your browser with your ISP's "network level operations" is a privacy necessity. They're passively monitoring DNS to collect data on their customers and hijacking it to send users to advertising sites. ISP DNS is manifestly untrustworthy.
- daedalus_j 7y agoWell no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.) I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.
- olliej 7y agoDNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements. So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any connection you make.
- daedalus_j 7y agoIt's a good point, but it is preventable by the network admin. For example, I bypass that by tunneling everything out over a VPN, and the local resolver attempts to use HTTPS to connect to upstream anyway. Obviously not every user is in a position to protect themselves in such a way, so I get why the browser is attempting to protect them. Just seems very wrong to me to take the control away from the user/network-admin in any way. I mean, if you're gonna do it, go whole-hog. Delete HTTP from the browser entirely, right? I don't think that would go over well either, although it could certainly be justified by the same logic. Maybe I'm misunderstanding something about the issue, there has been a fair bit of FUD, but I simply don't feel good about the browser taking authority outside it's "please render this code into a webpage" scope.
- dcow 7y agoExactly this. I build a DNS security product that works at the router level. Everything is secure on home networks running the product and it uses DoT for privacy so that ISPs can’t view your data—no browser intervention needed. Browsers interfering with user-configured defaults is incredibly presumptuous. I’m worried browsers are becoming less user-agent and more platform-agent...
- evilsnoopi3 7y agoGreat. Now I've taken my laptop out of my house (where I'm using your router) to the coffee shop downstairs where they use an ISP provided gateway... And the ISP is spying on me again. Until DNS request is encrypted there are no solutions outside of a wholly self-managed network.
- mulmen 7y agoI’m unsure why this has to be set at the browser level instead of the OS level. What happens to all the DNS calls made by non-browser services on your laptop?
- Jonnax 7y agoGo pay Microsoft and/or Apple to implement DNS over HTTPS.
- ordu 7y agoI believe it is due to technical problems of switching everything to DoH. Moreover if we think about it, I'll see that it is not a Google or Mozilla problem, it is a problem of OS developers. For example, it might be done by gethostbyname using DoH to resolve names. But it is up to libc developers, and it would lead to other problems, like system after update stopped working, due to custom configuration incompatible with DoH. Mozilla and Google become unsatisfied with gethostbyname but they cannot change that part of OS. So they are solving their problems on their side.
- judge2020 7y agoFWIW, Chrome using an upgrade list only checks the system config (doesn't do any "do I eventually end up using 8.8.8.8" checks), so it shouldn't upgrade DoH even if your backend resolver is a third-party.
- Jonnax 7y agoIf you're so technical. Why not just put some firewall rules to block known DoH providers? If a malicious app was to use their own DoH server then there's nothing you can do. Well you can get a MITM web security product to inspect traffic. Or only allow internet traffic through a proxy on your network and then block DNS providers. Local caching via DNS? Perhaps on unencrypted HTTP traffic.
- bjoli 7y agoThat's what I do. I actively block third party DNS and known DNS services except cloudflare and quad9, but only when coming from my raspberry pi. I haven't allowed an unencrypted DNS request from my local network in a long time. At least not that I know of. I have blocked a lot of apps/appliances trying to use their own DNS, and so far that has been enough. When they figure out that they can use DNS on non-standard ports I'm fudged.
- tiergaryen 7y agoYour key takeaways align with mine, but FYI: > the browser speaks HTTPS to my router, and my router speaks HTTPS to the servers Usually this isn't the case. Browsers that aren't configured to use a proxy connect directly to some web server using TCP and as speak HTTP to it. On a lower level, it's being facilitated by IP traffic routed by your own router, the ISP and the Internet. There are "Forward" HTTP proxies (e.g. software like Squid) that act like HTTP clients on the web and provide the real user with results. I suppose they're being set up at large organizations by IT, or at home by privacy geeks but I know no consumer router that does that out of the box.
- aschatten 7y agoI am not sure if interfering is appropriate here. Even in the current state, usually, browser perform DNS queries directly with DNS server, that they take from DHCP, which in it's turn supplied to the router by ISP. This has nothing to do with other web clients or IoT performing DNS lookups. The question is whether Chrome is going to ignore system settings by default.