5 ms·
> Note that some countries have an underdeveloped ISP market, with large fractions of the population having no choice of broadband service provider. Regulation
by souterrain 7y ago
> Note that some countries have an underdeveloped ISP market, with large fractions of the population having no choice of broadband service provider. Regulation is then of the utmost importance to keep everyone honest, but in some of these countries the regulator has been captured by industry and is no longer very effective. This mostly goes for the US.
I think this is the key motivator for a move to DoH. Large US ISPs can’t be trusted.
- gsich 7y ago>Large US ISPs can’t be trusted. But why trust Cloudflare?
- bepvte 7y agoA clear privacy policy and an third-party audit.
- shkkmo 7y agoProvided in return for a competitive advantage and a reduction in network neutrality.
- cremp 7y agoAll ISPs have privacy policies. 99% of all privacy policies are either copy/pasted from elsewhere or written in legalese so that company can do whatever they want. 'Internal business use' is a nice fodder for 'Selling data to increase this general ledger account for later business use.' An audit is almost always under bad pretenses. If I spend $$$ on an audit company, the company itself has bias. The difference between third-party audits and government issued audits (think food safety) is that the government has nothing to gain by a positive, or negative result. IANAL, just cynical of people.
- gsich 7y agoISPs have those too (ISO 27001 is common). Again, why trust Cloudflare?
- tialaramex 7y agoISO 27001 is a standard for how to do policy. So from ISO 27001's point of view this is fine: "Our policy is we'll do anything to make a buck". The ISO standard sets out a correct way to develop this policy, write it down, ensure employees know about it, measure whether they're implementing it, and then for auditors to reassure management that all this is being done as described. But it doesn't say there's anything wrong with that policy I mentioned, beyond that maybe your ISO 27001 consultants will struggle to charge their usual fees for such a short and on-the-nose policy document. It also matters who the auditors work for, and who they report to. Have you /read/ the audit reports for your ISP? No? Because they're confidential, only the ISP sees them. So, what use are they to you? For all you know the auditors found that the ISP doesn't comply with its own policies and shows no interest in doing so. If you later find out the ISP isn't complying but the audit reports said everything was fine, you'll never know about that, and you can't fire the audit firm and get a better one, all of this is totally opaque to you. In contrast Mozilla gets to insist upon reading the audit reports for the policy they agreed with Cloudflare and can insist upon a different audit firm if it decides the auditors aren't up to scratch. This has happened with CA root trust, the Hong Kong auditors for WoSign were disqualified in this way and the franchise owner's office in London informed of the problem. Now, maybe you don't trust Mozilla either, but if you're running their web browser you're in a real pickle if you don't trust them. And if you don't run their browser who cares which TRR is configured in the browser you don't run?
- gsich 7y agoI mentioned ISO 27001 because you mentioned audits, that it doesn't hold to much is clear. Where can I read the Cloudflare audit that Mozilla got? If I can't then there is really no difference between them and the audit from an ISP. CA audits are somewhat different, so I don't know why they should matter here. That still doesn't answer the question why Cloudflare should be more trustworthy then an ISP.
- baggachipz 7y ago> Large US ISPs can’t be trusted. It's certainly unfortunate that we've gotten to this point. The net result is that nobody can be trusted: Not ISPs, not Cloudflare. There is a clear conflict of interest in Cloudflare's strategy, and their "aww shucks, we're just being the good guys" attitude is dishonest. At this point, one or many not-for-profit DoH providers (with easy selection of service in your browser or OS) would be the only true solution to this issue.
- tptacek 7y agoSo don't trust Cloud Flare. DoH in no way depends on them. You can simply run your own DoH resolver.