4 ms·
Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work s
by daedalus_j 7y ago
Well no, because my router is proxying DNS requests, and it's not to my ISP's DNS servers. (It's also serving a number of custom DNS records for internal/work stuff.)
I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods.
- olliej 7y agoDNS requests are transmitted in plaintext through the ISPs connections. Because DNS is not remotely secure there isn’t any reason they couldn’t simply redirect your selected DNS to their own, or replace “not found” responses with a link to their own advertisements. So without DoH an ISP knows everything you request, even if you have a different DNS server set, and if they really wanted to they can simply hijack any connection you make.
- daedalus_j 7y agoIt's a good point, but it is preventable by the network admin. For example, I bypass that by tunneling everything out over a VPN, and the local resolver attempts to use HTTPS to connect to upstream anyway. Obviously not every user is in a position to protect themselves in such a way, so I get why the browser is attempting to protect them. Just seems very wrong to me to take the control away from the user/network-admin in any way. I mean, if you're gonna do it, go whole-hog. Delete HTTP from the browser entirely, right? I don't think that would go over well either, although it could certainly be justified by the same logic. Maybe I'm misunderstanding something about the issue, there has been a fair bit of FUD, but I simply don't feel good about the browser taking authority outside it's "please render this code into a webpage" scope.
- tptacek 7y agoIf you're going to the trouble of VPN'ing your DNS, you're fine in the Chrome scenario and could I suppose reasonably just disable DoH everywhere. Your ISP absolutely does not want you to do this, but they don't want you DoH'ing either. DoH is, after all, just a VPN for DNS.
- glennpratt 7y ago> take the control away from the user/network-admin You are confusing the network admin and the user. Most users have little reason to trust their router, they often don't own it, update it or have any clue about it. Even experts change roles here when they use any other entities network. I understand your use case, but I personally think the end devices should increasingly allow interception by network devices only with user consent, not implicitly. In other words, opt-in on the device with DNS settings and certificates. If you don't own the device (e.g. have root/admin/etc), you don't get to control it - beyond blocking it.
- comex 7y ago> Delete HTTP from the browser entirely, right? It’s not being deleted, but Chrome at least has been gradually phasing in a warning in the address bar whenever you visit an HTTP site. [1] (Firefox will apparently do the same starting soon.) I wouldn’t be surprised if the warning UIs get more aggressive a few years down the line, as HTTPS adoption continues to increase. [1] https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html https://blog.chromium.org/2018/05/evolving-chromes-security-...
- tialaramex 7y agoFirefox currently shows a red crossed out padlock for HTTP sites with form elements, but not yet for HTTP sites without form elements which for now get neutral treatment. The rationale is that you definitely shouldn't be using insecure forms, what could you possibly be writing where you really don't care about at least confidentiality (to prevent eavesdroppers from reading it) or integrity (to prevent a MitM from changing it) ? If you set HSTS and then subsequently remove HTTPS from a site it should (will for Firefox, kind of for Chrome) brick wall you, saying that it isn't able to reach the HTTPS site without offering to let you see the insecure and perhaps compromised HTTP site even if you spell out the HTTP URL. Unlike HPKP this isn't considered a foot gun because you can fix it by just enabling HTTPS, and why didn't you have HTTPS anyway? The biggest forward pressure for HTTPS is that newer protocol versions (after HTTP/1.1) do not in practice exist for plain HTTP. The way to do plain HTTP/2 is documented but nobody has plans to implement it, and there isn't even intent to document a plain HTTP/3 because the stuff it's built on is all encrypted from the ground up. From my point of view this is good news.
- chrismorgan 7y agoI encountered this in a local ISP in India in 2012: they were intercepting all DNS requests and forcibly using OpenDNS’s annoying NXDOMAIN advertising thing. When I returned in 2016 they’d stopped doing that. No idea if the technique is widespread.
- boring_twenties 7y agoThis is easily solvable if you're using dnsmasq -- which isn't altogether unlikely as it's in basically every free router firmware (OpenWRT, DD-WRT, etc) as well as, until recently (replaced by systemd-resolved, but still an easy option to go back) used by default by NetworkManager on Linux desktops. Basically, you just give it the bad IP addresses and it will replace every query result containing them with an NXDOMAIN.
- ignoramous 7y agoIndian ISPs have intercepted HTTPS traffic to inject ads [0]. And DPI is now a thing among Indian ISPs. [0] https://news.ycombinator.com/item?id=12091900 https://news.ycombinator.com/item?id=12091900
- topranks 7y agoEven with DOH, as things stand right now the ISP can see with SNI what sites your visiting, or certificate name for sites still using TLS 1.2 or lower. So moving the DNS to Cloudflare only means “now Cloudflare have my entire browsing history as well as my ISP.” I do appreciate there is a draft on ESNI but it’s not there yet.
- KaiserPro 7y ago_with_ DoH you are passing not just network information, but session information as well. DoH is not a privacy boon. DNS, whilst plaintext is at least federated, and is a network level service. That is, its not tied to a single session in a browser. as I understand it, there is nothing stopping a browser from appending metadata to the get request, or putting extra headers in. This means that its perfectly possible to nail your complete browsing history, down to the server you've been given.
- feanaro 7y agoYou can use a personal installation of dnscrypt-proxy which supports both dnscrypt and DoH and allows you to select multiple providers. It even supports round-robin. This is what I'm doing.
- deleted 7y ago[deleted]
- comex 7y ago> I don't understand how trading one ISP for another (Cloudflare?) is an improvement long-run. The system itself needs to be resilient, not just depend on the kindness of the upstream gods. Mozilla and Cloudflare negotiated a special privacy policy for Firefox DoH requests [1] that limits what Cloudflare can do with the data – in particular, most information must be deleted after 24 hours. There is no technical measure holding them to that policy, but it’s a contract enforceable through the courts. Nothing similar applies to your average American consumer ISP. [1] https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/firefox/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
- xorcist 7y agoOh, they promised not to be evil, did they? That link isn't very reassuring. Who are parties to the contract? Who can enforce it? What does it cost to breach?
- comex 7y agoThe parties to the contract are presumably Cloudflare and Mozilla, since that page keeps mentioning their "agreement with Firefox" and "agreement with Mozilla". Therefore Mozilla can enforce it. As for costs to breach, that would be determined by a judge or jury based on damages suffered by Mozilla. Depends to some extent on the actual text of the contract, which hasn't been published. That's the main mechanism for enforcement, but there are a few additional ways it could theoretically be enforced: - The FTC and state attorneys general can sue companies for violations of their own privacy policies, as "unfair and deceptive acts and practices". For example, they sued Cambridge Analytica recently. [1] - The California attorney general in particular would also be able to sue under the California Consumer Privacy Act once it goes into force. - As for ways for individual consumer to sue... well, it's more difficult, but possible. For instance, a class action suit against Facebook on a grab bag of claims, also related to Cambridge Analytica, recently survived a motion to dismiss. Among other things, the judge held that users could sue for breach of contract if Facebook violated its privacy policy. [2] [1] https://www.ftc.gov/news-events/media-resources/protecting-consumer-privacy/privacy-security-enforcement https://www.ftc.gov/news-events/media-resources/protecting-c... [2] https://www.cand.uscourts.gov/filelibrary/3755/Order-re-Motion-to-Dismiss.pdf https://www.cand.uscourts.gov/filelibrary/3755/Order-re-Moti...
- zifnab06 7y agoIt doesn't have to be to their servers - they can just dump all data going anywhere on udp/53 from one of their routers. DNS isn't encrypted, anyone between you and whatever server you're using can see everything.