5 ms·
You may trust Cloudflare, but I do not. I trust my DNS provider. It's fine for me, I keep up on these things and I have disabled DoH already (I don't care for a
by byuu 7y ago
You may trust Cloudflare, but I do not. I trust my DNS provider. It's fine for me, I keep up on these things and I have disabled DoH already (I don't care for any current DoH provider, and I also rely on /etc/hosts entries.) In any case, my post was only meant to inform. To each their own, use them if you like or if you trust their privacy promises more than I do. But people should be aware that Mozilla silently changed where all your DNS requests are routed to.
- coldpie 7y ago> You may trust Cloudflare, but I do not. I trust my DNS provider. For many, maybe even most, the situation is reversed. ISP-provided DNS (the default for 99% of web users) is very often intentionally mis-configured to return ad-laden "search results" instead of NXDOMAIN. The situation is more authoritarian administrative districts is even worse. You're right that trusting Cloudflare isn't ideal either, but they are at least better behaved than most ISPs, so it's the lesser of two evils, I think. Non-technical users shouldn't be expected to know how these things function, they should just get the least-bad option by default.
- brnt 7y agoI think this a mostly US issue.
- josteink 7y ago> For many, maybe even most, the situation is reversed. Big claim, with no evidence what so ever. Consider this a "Citation needed".
- basch 7y agoMost people use their ISP provided DNS should be the null hypothesis / status quo. I wouldnt expect someone to prove that claim. I would expect someone to prove the claim "most people change their DNS from the ISP default to google."
- pbhjpbhj 7y agoI thought they were questioning whether ISPs in general routinely hijack DNS. I've not heard of this happening in the UK, but haven't scoped around looking for it.
- basch 7y agoIt was normal in the US for an ISP to return a "helpful" page when you entered a nonexistant domain. It sort of looked like a search results page. In reality it usually turned into a page of ads. Each ISP may have been different with the volume of actual search results they returned on the page.
- jfk13 7y agoI've seen things like that in the UK, too; it's certainly not a US-only practice.
- zaarn 7y agoGerman Telekom does this, just get a german DSL link and you'll find out the joy of getting redirected to shitty search engines plastered with ads.
- whoopdedo 7y agoHas it been suggested by anyone yet that Google is pushing for DoH because those DNS-typo advertisers are a competitor to its ad/search hegemony and eliminating them as a business model helps Google's bottom line.
- judge2020 7y agoYou can say anything Google does is because it ends up pushing its own ad model, but I don't think many users would actively want ad results to show up when you would regularly get a NXDOMAIN.
- tialaramex 7y agoI am certain it's been suggested. But I can't see Google's motives I can only see its actions. If you do good things whatever the reasons the good things stay done while the reasons die with you. A few minutes walk from me some people opened a gelato place. You go there, you buy some gelato. Nice. Warm summer evening, drop in, buy a cone, delicious. I am 100% certain that by selling me frozen desert they get money! Their plan may not specifically have focused on me enjoying this at all. And yet, since the effect is that I can enjoy desert that's exactly what I do, and I don't begrudge them their money.
- zaarn 7y agoI doubt it, from what I know, the money the ISPs make from typo-searching is barely noticable, mostly a leftover from when ads where valuable.
- growse 7y agoThis phenomenon is so popular it has its own section on the "DNS Hijacking" wikipedia page. https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_ISPs https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_... Unless they explicitly say so, your ISP is not spending a boat-load of money running a DNS server for you to use because they're nice. They're not even doing it because you're paying them for a service. They're doing it because they can monetize the data and serve you ads.
- mondoshawan 7y agoThey're doing it because it's been a standard ISP practice for years because most people don't run their own recursive resolver and have no skills to do so. End result is that to provide an internet connection, you have to also provide a DNS resolver, full stop. Monetizing and ads came later when business stopped caring about the RFCs.
- growse 7y ago> End result is that to provide an internet connection, you have to also provide a DNS resolver, full stop Nope. You have to provide the address of a resolver, but that doesn't mean you have to run one yourself. There's nothing stopping the ISPs shipping a standard DHCP config that points their customers at (for example) 8.8.8.8, or 1.1.1.1, or whoever.
- anon73044 7y agoBoth of the major ISPs in my area do this. AT&T and Cox Communications I'm fairly certain Comcast and Verizon does this as well.
- fourthark 7y agoCompletely agree with both sides here. It's a tradeoff and people should weigh the pros/cons seriously. Firefox claims it shows a notification popup, but it may be too easy to click away. (I didn't see it.) It should be front-and-center.
- sergiosgc 7y agoIt should not. Firefox is not designed for the tech-savvy, it is a general public product. The average user has no idea what DNS is, couldn't care less. In the best case he is only bothered by the question, in the worst will call me for instructions on cleaning up a "virus".
- rakah 7y agoYou seem like you may know what you're doing. Would you mind sharing who your DNS provider is? Do you pay for recursive service? I don't trust my ISP, so I'd prefer not to use their DNS or to pass requests up to root servers over cleartext. I also had some performance issues with root server requests since they have to chase the authoritive servers. Right now I'm sending TLS requests to cloudflare, but obviously since I'm not paying for them, I'm the product.
- josteink 7y ago> I don't trust my ISP Then switch to one you do trust.
- TheCraiggers 7y agoI'm not sure where you call home, but at least in the US, that is impossible for many people. Or rather, impossible without physically moving your house.[0] Especially if you do not count satellite, which I do not. My house has one crappy DSL 18Mbps provider and that's it. Their way or the highway. https://arstechnica.com/information-technology/2016/08/us-broadband-still-no-isp-choice-for-many-especially-at-higher-speeds/ https://arstechnica.com/information-technology/2016/08/us-br...
- josteink 7y agoI live in Norway, Europe and around here ISPs compete for my business. Kinda like a “free market”, except it’s “regulated“ to not allow scamming end-customers. I find it quite enjoyable. Maybe you in the US should fix the root cause of your problem (legislation) instead of deploying rogue technology making life complex for everyone else?
- fourthark 7y agoIt would be interesting to see stats on this. I would guess between monopolies and hostile governments, more people worldwide have no choice, and it's a good default, but I don't know. In any case, both Firefox and Chrome should make it super clear to users that they are doing this.
- smarnach 7y ago> I trust my DNS provider. Do you also trust everyone in the same Internet Cafe as you? And your ISP? And everyone else on the network path to your DNS provider? Because they all can see all of your DNS requests. Your ISP can even alter them. DoH ensures privacy and integrity of your DNS requests, so they are _only_ shared with your DoH provider.
- byuu 7y agoWhat I don't trust is Cloudflare. When a DoH provider I trust pops up, I will move to that.