14 ms·
NextDNS Joins Firefox’s Trusted Recursive Resolver
- cj 7y agoInteresting, I wasn't aware of Mozilla's Trusted Recursive Resolver program (https://wiki.mozilla.org/Security/DOH-resolver-policy https://wiki.mozilla.org/Security/DOH-resolver-policy). > The following providers have contractually agreed to abide by these policy requirements: [Cloudflare, NextDNS] Are these agreements made public?
- deleted 7y ago[deleted]
- comboy 7y agoGov agencies requests still take precedence over any such agreements don't they? In other words, I would add some canary that nobody forced them to break rules of those contracts.
- jtbayly 7y agoIs there going to be an option in FF to select which “trusted partner” to use? And an option to use a provider not in their list?
- fiysp 7y agoThere already is in advanced network options I think?
- thayne 7y agoyes. And "trusted partner" just means they have preconfigured settings in the drop down. It's also possible to specify a custom DoH provider (or disable DoH).
- giancarlostoro 7y agoOr an option to randomize it per request with the ability to remove / blacklist specific partners. Now that would be great.
- kardos 7y agoNot sure that randomizing is going to do anything useful. Randomizing over three providers will give each of them one third of your requests, but they would just need more time to get a (near) complete list of the domains you resolve. Eg, if you resolve hackernews once a day, they'll each have that information in approximately three days.
- tomatocracy 7y agoYou could deal with this by splitting requests based on the domain to be looked up on a deterministic basis, so that the same lookups always go to the same server. You'd ideally do that in such a way that related lookups (eg everything under google.com and all of Google's other related domains) also go to the same server.
- sp332 7y agohttps://support.mozilla.org/en-US/kb/firefox-dns-over-https#w_switching-providers https://support.mozilla.org/en-US/kb/firefox-dns-over-https#...
- slipheen 7y ago> Our trusted recursive resolver program aims to standardize requirements for three areas: limiting data collection and retention from the resolver, ensuring transparency for any data retention that does occur, and limiting any potential use of the resolver to block access or modify content. This seems like a win overall, and I'm glad that they're pushing to build a list of trusted resolvers. It sounds like they've got some sort of contract ensuring they don't use the data, so that's a positive. That said, given that Windows 10 is going to going to start supporting DoH natively, I'm not sure I understand the reasoning to use Mozilla's chosen DNS providers, rather than the system default. It seems a bit like enabling a proxy or VPN by default- Even if Mozilla trusts the proxy provider, routing traffic to unneeded third parties seems somewhat user-hostile.
- cremp 7y agoI never heard of NextDNS. I am appalled. From their site: https://nextdns.io https://nextdns.io > See what's happening on your devices with in-depth Analytics and real-time Logs. > Protect your kids and control what they can access online. Their pricing page is also extremely troubling. > We may adjust this later on based on actual costs at scale, but it will follow this logic. What the hell is this Mozilla... This is not a company you should be dealing with. They tell you up front that they log and monitor... They also aren't at scale, and have to learn lessons the hard way with outages. Mozilla is dead to me now. Edit: As others have pointed out, Mozilla's own policies: https://wiki.mozilla.org/Security/DOH-resolver-policy https://wiki.mozilla.org/Security/DOH-resolver-policy Transparency Requirements, section 2. Where on earth is a transparency report for NextDNS? They were started in March, and I would think that Mozilla would check their requirements before giving the 'lets add them.'
- sp332 7y agoIf not specifically requested by the user, no data is logged. Some features require some sort of data retention. In that case, our users are given the option, control, and full access on what is logged and for how long.
- core-questions 7y ago> Protect your kids and control what they can access online. Yes, god forbid some parents would like to have a little bit of control and the ability to protect their children from seeing obscene material when they're too young to handle it. Evil! Mozilla needs to quash these terrible people! May they burn with Brendan Eich!
- saagarjha 7y ago"Protecting your kids" is often "we log everything and have complete visibility over how people are using our service, and we're willing to share a bit of that with parents to spy on their children". It's a valid concern to have unless there's evidence to the contrary.
- 7y ago
- thayne 7y agoI'm not sure how I feel about Firefox's strategy for DoH. On the one hand, moving DNS out of the hands of ISPs that (at least in the US) have no real incentive to respect user privacy is probably a good thing. On the other hand, circumventing the system DNS will cause problems for anyone who has explicitly configured DNS, such as corporate networks, schools, households that use DNS for security/adblocking/parental controls, etc. I realize firefox has some heuristics to try and detect these cases, but heuristics aren't perfect.
- tptacek 7y agoIt's probably a good thing? US ISPs actively collect data from DNS lookups. They're an actual according-to-Hoyle threat actor in the IETF's supposed threat model.
- josteink 7y ago> It's probably a good thing? US ISPs The world is hella lot bigger than the US. And Firefox runs in the rest of the world too.
- icebraining 7y ago> And Firefox runs in the rest of the world too. But Firefox only enabled DoH by default in the US.
- catalogia 7y agoIs it only enabled in the US, or is it only enabled in the en-US build? How does firefox actually know what country I'm in? If I downloaded firefox in Washington and then drive up into BC, does Firefox disable DoH? How does it know?
- dictum 7y agoIt's also a lot bigger than the EU.
- dblohm7 7y ago
- colmmacc 7y agoHow do these DoH partnerships work with DNS split views? If folks are running an internal copy of "something.company.com" and it's expected to resolve to RFC3330 space "on the company network" ... that depends on folks computers and devices using the corporate DNS. If Firefox is going to a public DoH endpoint, they'll get the public IPs instead and connect to the wrong copy of the service, or it might not even resolve if it's an internal-only record.
- sp332 7y agoThey expect that Firefox will be configured by the enterprises where this would be an issue. But if a domain simply fails to resolve via DoH it will fall back to plain DNS. https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs#w_how-does-firefox-handle-split-horizon-dns https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs...
- ignoramous 7y agoCongratulations NextDNS! You've been relentlessly executing on every front [0] with super-novel solutions [1] that a few, if any, incumbents have matched [2]. That said, I'm surprised Mozilla doesn't look at the uptime metrics before partnering with TRRs. I've been using NextDNS ever since it was announced here [3] and have been subject to a fair share of "outages" including once when everyone at home thought the internet was down...but couldn't remedy it [4]. Cloudflare's data-plane availability with 1.1.1.1 is a tall-order to match for anyone that's not Google or AWS [5]. The NextDNS founders built DailyMotion, so I'm guessing they know a thing or two about high availability and hopefully fix whatever they need to before they GA with Firefox TRR. I must point out that Adguard DNS [6] is a viable non-configurable free alternative, which is what I now recommend to folks not savvy/bothered enough to configure NextDNS. It would be wonderful to see them added to TRR. [0] https://news.ycombinator.com/item?id=21543038 https://news.ycombinator.com/item?id=21543038 [1] https://news.ycombinator.com/item?id=21604825 https://news.ycombinator.com/item?id=21604825 [2] https://news.ycombinator.com/item?id=20851626 https://news.ycombinator.com/item?id=20851626 [3] https://news.ycombinator.com/item?id=20012687 https://news.ycombinator.com/item?id=20012687 [4] https://news.ycombinator.com/item?id=20785712 https://news.ycombinator.com/item?id=20785712 [5] https://aws.amazon.com/blogs/architecture/category/networking-content-delivery/amazon-route-53/ https://aws.amazon.com/blogs/architecture/category/networkin... [6] https://news.ycombinator.com/item?id=18788410 https://news.ycombinator.com/item?id=18788410
- Terretta 7y agoIt’s not clear to me AdGuard’s uptime avoids the “is the internet down?” scenario either. I observe normals hitting same “WTFs/month” rate with AdGuard, NextDNS, Zscalar, Cleanbrowsing (built into Ubiquiti UniFi), as any other ad blocking DNS offering. I personally had to give up on Warp+ and even 1.1.1.1 — which to be clear does not block ads or trackers — due to instability with enterprise, airline, and hotel portals. By contrast, NextDNS shot up in reliability over past couple months across all kinds of connections, to where I’ve begun recommending that option to tech friends (not yet to normals). I have had no issues with OpenDNS Umbrella now Cisco once I turned off their typo-squatting, but it also is a “security” product not anti-tracking.
- heavyset_go 7y agoI'm a fan of DoH, but I'm also a Chromecast owner, so I get to experience the downsides of application-level DNS resolvers. Chromecasts will ignore the DNS servers set by DHCP, and will cease to function if they cannot communicate with Google's DNS servers[1]. That means my network-enforced DNS preferences that block ad and malware sources are ignored, and I see more ads than I want to. It also means that when Google drops support for my Chromecast model like they did with the older Chromecast models, I'll be slightly less secure than I would be if I could enforce my own DNS preferences. [1] https://news.ycombinator.com/item?id=19170671 https://news.ycombinator.com/item?id=19170671
- wnevets 7y agoOh wow I did not know that.
- slenk 7y agoI believe you are referencing possibly old data. I have a Chromecast. I also redirect all port 53 traffic (DNS) back through my own DNS server at the firewall level (does not go to Google DNS). It works perfectly fine wihtout directly using Google DNS. Yes, they do ignore the DNS set by DHCP, but that can be worked around.
- yegle 7y agoAFAIKT, you can block Google DNS and all your Google Cast devices should fallback to DHCP assigned DNS.
- slenk 7y agoOh, good to know. I just let it think it's using Google and like redirecting it behind the scenes
- bourbonjuggler 7y agoThis is accurate. I drop all of my google gadgets access to google DNS services and they use my local DNS.
- 7y ago
- 3xblah 7y ago“For most users, it’s very hard to know where their DNS requests go and what the resolver is doing with them.” said Eric Rescorla, Firefox CTO. “Firefox’s Trusted Recursive Resolver program allows Mozilla to negotiate with providers on your behalf and require that they have strong privacy policies before handling your DNS data. We’re excited to have NextDNS partner with us in our work to put people back in control of their data and privacy online.” It sounds more like the work is to put Mozilla and their partners in control of users' data and privacy online. Let's be honest. This is really a transfer of control from one third party, e.g., a company providing internet service (ISP), to another third party, e.g., a company/organization providing a browser (Mozilla, Google, etc.), not to mention their "TRR" partners. Surely it is only a fortuitous coincidence, but DOH in the browser makes it easier to track users by device, which appears to be the Holy Grail of the internet ad industry. Putting Mozilla (and their partners) in charge of user privacy is different from putting users in charge of their own privacy. Also, the "back in control" language is interesting. It implies the author believes users were "in control" in the past.
- fabrice_d 7y agoIt's about trust: would you rather trust your ISP, or Mozilla's choice of DoH partners? Users never really had a reasonable (ie. non geek) opportunity to be in charge of their DNS privacy, and for most it's not something they can be bothered with.
- davidu 7y agoThis is the wrong dichotomy and it's a false one perpetuated by Mozilla. Users can have end to end encrypted DNS and browsers shouldn't be hijacking it. To put it another way, you don't want the people who only care about eyeballs (Google, Mozilla, etc.) picking your DNS provider.
- icebraining 7y agoSo disable DoH in Firefox, or change the provider? If you know enough to choose a DoH provider, the browser defaults are not very relevant, presumably.
- nimbius 7y agoSo im curious to know, what is stopping Mozilla from selling "Trusted Recursive Resolver" positions to private companies just like they sell search engine placement in their browser? whats to prevent a VC firm from just...quietly acquiring NextDNS (or any of the other DoH providers) and selling your browse history back to anyone who wants it?
- LamaOfRuin 7y agoPossibly contractual obligations? That's what Mozilla did with Pocket before simply acquiring it themselves. edit: Yes, it is with contracts. https://wiki.mozilla.org/Security/DOH-resolver-policy#Conforming_Resolvers https://wiki.mozilla.org/Security/DOH-resolver-policy#Confor...
- tech234a 7y agoDuplicate of https://news.ycombinator.com/item?id=21811739 https://news.ycombinator.com/item?id=21811739
- captn3m0 7y agoMozilla is yet to announce an actual application process for becoming a TRR. I've been trying ever since they announced CloudFlare, but they only have a policy - no application process.
- kiwidrew 7y agoThis extreme focus on DoH is really concerning me. If you're worried about your recursive DNS resolver spying on you, the correct solution is to run your own recursive resolver. I've been running unbound(8) on my OpenBSD systems at home for most of 2019, and (except for the time that I experimented with turning on strict DNSSEC checking) there hasn't been even one time that it has caused me grief. It was as simple as "rcctl enable unbound". And OpenBSD has recently introduced unwind(8), a dead-simple recursive resolver (using libunbound) that's suitable for any system (even laptops that sometimes use broken Wifi access points or networks that block outbound port 53). It is simply unacceptable for a modern operating system to lack its own recursive resolver. By all means, allow the network administrator to configure the system to use a network-provided resolver if required, but the default ought to be an intelligent unwind(8)-style resolver provided by the OS itself.
- tptacek 7y agoRunning your own non-DOH recursive server does absolutely nothing to protect your queries from snooping; in fact, it increases your exposure, because every single step in the recursive queries you run are now in plaintext on the wire and each attributable to your server. Running your own recursive DOH server is a fine idea, and easy to do, but then you have little to be angry at Mozilla about, because they're the ones enabling you to do that. The fact that no mainstream consumer OS runs a local recursive resolver should be a clear signal to you that people disagree with you about this; in particular, because doing so eliminates DNS caching, which is something most people want. People are "extremely focused" on DOH because it works, and works without having to secure the cooperation of every DNS operator on the Internet, and with almost no configuration. It is a clean, easy win, unlike every other DNS security mechanism ever proposed.
- zzzcpan 7y agoYou are saying nonsense. Your own DoH server is the same recursive resolver with queries in plaintext on the wire each attributable to your server by whoever is looking. In fact, if you move your DoH server outside of your home, you are roughly doubling amount of parties involved in looking at your metadata, because pretty much none of the metadata is hidden when you just remove DNS queries from your wire and replace it with TLS, but now a whole set of other parties get to see your queries and your TLS connection towards your DoH server with identifiable IP address, likely even recorded and stored for years by more parties. There are no "wins" with DoH no matter how you look at it.
- smitty1e 7y ago"For more than 30 years, DNS has served as a key mechanism for accessing sites and services on the web." I value dry jokes such as this.
- tatersolid 7y agoConsistent hashing by gTLD with a random local seed instead of simple randomization then. I’m sure 1/3 of your data is still valuable but 1/10 or less probably not. A sort of K-anonymity for DNS.