8 ms·
Why are people so down on DNS over HTTPS? DNS is the primary way governments control and spy on web access.
by drenginian 7y ago
Why are people so down on DNS over HTTPS?
DNS is the primary way governments control and spy on web access.
- deadbunny 7y agoI'm not down on encrypting DNS, I'm down on moving DNS from a network/system level to an application level.
- falcolas 7y agoJava poisoned this well a decade ago by not respecting DNS TTL settings.
- Legogris 7y agoAnd now they have a one-stop shop for all their DNS surveillance needs.
- drenginian 7y agoWell it’s absolutely happening right now to every unencrypted DNS server, so what’s your point? DNS is the most openly insecure aspect of the entire internet. It’s wide open.
- teddyh 7y agoSo you’re arguing that everybody should switch to DNS over TLS (DoT), then? Sounds great!
- bepvte 7y agoDNS over TLS is just DoH but with an easily blocked separate port
- Legogris 7y agoWhich is great from a local sysadmin perspective. With DoH I have no control of what various apps on devices on my devices are querying.
- bepvte 7y agohttps://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli..., also if you can block it this easily so can the government. The difference with a canary domain is that mozilla can disable it if its misused.
- vetinari 7y ago1) other applications or malware won't respect canary domain 2) to implement this canary, you have to break DNSSEC on entire .net root domain. Great.
- JoshTriplett 7y agoOr in other words, DoH works better on hostile networks because it looks like just one more HTTPS connection. That's an intentional design feature. You're attempting to intercept traffic, and any mechanism you could use to do so "transparently" could be used by any hostile network to do so. You can still intercept traffic from cooperating devices if you want, just not transparently. That's a feature, not a bug, and the Internet will be better for it.
- Legogris 7y agoRight, but I do think this is better handled at the OS layer. Hardcoding everyone to route through Cloudflare is a hardly a net win, and might be better or worse than your ISP depending on who and where you are.
- gaius_baltar 7y ago> And now they have a one-stop shop for all their DNS surveillance needs. There are a few dozens of DoH services out there [1] and nothing prevents anybody else from running their own. [1] https://github.com/curl/curl/wiki/DNS-over-HTTPS https://github.com/curl/curl/wiki/DNS-over-HTTPS
- pbhjpbhj 7y agoBut Mozilla's justification tables around making security better for all users by dictating default settings that are expected not to change. So, defaults need to achieve the goals.
- 0xdeadb00f 7y agoThere are dozens, and yet Mozilla chooses the same company that forces Google captcha on site visitors that try to protect their privacy by using a VPN or Tor?
- detaro 7y agoHow many of those "dozens" would you consider usable as a default for a browser?
- alexis_fr 7y agoAt least when I use my government-controlled DNS which pretends a website doesn’t exist, I can go somewhere else.
- nicolaslem 7y agoMy main gripe is that before DoH, setting a custom DNS via DHCP was enough to get all devices on a network and all applications on these devices to use a custom DNS. Now we are headed to a future where each software vendor decides how to make DNS queries. I can predict that all of them will apply their own custom heuristics to detect things like split-horizon.
- kibwen 7y agoWe are headed toward that future because the broader network has proven that it cannot be trusted; it should come as no surprise that user agents would develop defense mechanisms. If this is another step toward ensuring that ISPs are nothing but dumb pipes, I welcome it.
- vetinari 7y agoThis is another step toward ensuring that _you_ won't have any visibility what applications running on your computer do, where they connect and why.
- Avamander 7y agoUnless OSs quickly implement DoH, if they did, software makers won't have any excuse to roll their own opaque ones, aside of malicious reasons.
- user1980 7y agoEnd-to-end TLS is dead. It started with PCI compliance. Next up was Corporate IT making sure idiots weren't signing up for Dropbox with their LAN password. Schools: Well, they always used proxies with no expectation of privacy whatsoever so traffic inspection was nothing new. In 5 years TLS-recryption -- whether through software or a hardware middlebox -- will be as ubiquitous as a NAT firewall is now. The only question is if the keys will be in the hands of the consumer or in escrow with Big Gov. The idea that anyone in their right mind would allow uninspectable traffic to egress their network is beyond ridiculous. I'm glad that DoH is making people realize that.
- 7y ago
- josteink 7y agoDNS is something network operators (and not just governments and ISPs) has managed and controlled in their own networks for decades. It has been part of the network stack, with a clear hierarchy in how it is governed: - network operator - network default - operating system - application default - end-user override - when the defaults doesn't work When something has not worked, you could reliably assume this was the stack used. And you could rely on it being used consistently across all applications. Needed to deploy internal applications? Great: Just override the (local, internal) DNS. Need to access servers or machines on internal servers? Use DNS! Now if you make some random applications and decide to flat out ignore the established stack and just ask the internet about DNS... You're effectively breaking the network and the conventions which has been established to build them. Ofcourse people are going to hate you. That's a given.
- kibwen 7y ago> end-user override - when the defaults doesn't work To my mind, the lack of privacy of classic DNS does indeed count as the the defaults failing to work. Yes, it would be more ideal to solve this at the OS level, but until OS vendors start providing solutions I don't begrudge applications that care about privacy for taking matters into their own hands.
- Jonnax 7y agoI think part of the negativity you see is network admins working in businesses. Their opinion is that it's a way for people to get around corporate firewalls. Kinda blind to the idea that if a browser can implement DNS over HTTPS then anything can. Especially since there's some of ways that Mozilla have implemented for a local area DNS server to override its settings. There's also another camp, if you remember the "internet villain of the year" award that Mozilla got for DNS over HTTPS from an ISP industry group. Of course their argument was parental controls being made ineffective. But of course it's transparent that this was a gambit to change public opinion so they can keep collecting browsing data to sell. Interesting to note they went after Mozilla not Google who are also implementing it. But really the messed up thing is that this improves privacy for the vast majority of users. Especially those people around the world where searching the wrong thing up online can lead to imprisonment or worse. This kind of thing is a privacy improvement for millions. And I find it shocking that people in Business IT care more about managing their corporate devices than the good of the majority of internet users.
- userbinator 7y agoI'm not a network admin working in a business, but I am the network admin of my home network, and I really do not want applications starting to effectively contain their own VPN clients and subverting my control.
- Jonnax 7y agoDNS isn't a VPN nor really a security product. It's just a look up table. The job blocking domains should be the job of a firewall. Of course this becomes more complex. But any application can implement DNS over HTTPS. Malware could even just get a list of IPs from another IP. An application can even just hard code IPs rather than using DNS and then they're in the same position.
- userbinator 7y agoTunneling DNS inside HTTPS effectively forms part of a VPN already (and I wonder when Mozilla will decide to also stuff the rest of the traffic through...) DNS-based blocking is not perfect, but is currently still very powerful for things like adblocking. You're basically saying that Firefox is now behaving like malware, which I agree with... Windows 10's telemetry is also another piece of software which has started to become hostile in this manner, hardcoding IPs and such.
- ocdtrekkie 7y agoFor one, it’s ironically first being deployed in countries where DNS manipulation by the government isn’t happening (US first generally), but Google has competitive concerns with ISPs getting ad targeting data. I feel like defending against oppressive governments is being used more as an excuse than a driving motivation. The primary concern seems to be that Google really wants to protect its monopoly, and Firefox, as a major benefactor of Google money, has fallen in line. And second, as an IT admin, I’m annoyed web browsers keep trying to develop new ways to bypass my network security.
- userbinator 7y agoDecades of experience have told me that whenever some big organisation wants to do something in the name of "security", it's almost always an excuse to remove freedom and force their control over everyone. Yes, that includes oppressive governments too... but I hardly think that even more centralisation is the solution. The old security vs freedom quote is surprisingly relevant in so many situations today.
- bepvte 7y agoThis argument can be applied to the encouraging the rollout of HSTS and HTTPS by firefox and google, which cant be disabled very easily by administrators.
- swiley 7y ago1) Instead of proposing changes to the C resolver or a caching resolver the user might run they modified their application to ignore the operating system configuration which is just kind of crappy. Its probably the easiest and most reliable way to block things you don't like and now it doesn't work in firefox. 2) They are the singular (maybe there's one other now heh) resolver operator whereas with DNS anyone (even you) could (and did) run a recursive resolver. 3) I don't think anyone cares so much about this but http is probably the wrong protocol. The DNS protocol was pretty elegant in its efficiency and simplicity (IMO.) Yeah the compression was slightly complex (it's really not) but I've written clients without anything other than a socket library. HTTP on the other hand can do all kinds of complex things and has plenty of room for weirdness and tracking and unintuitive behavior that just isn't necessary for resolving names. TL;DR: DoH is an unimaginative hack that has a lot of problems from a technical perspective but the social problems are much worse.
- jeroenhd 7y agoAs for 1, if you're choosing to use a special resolver to do content filtering, you can disable DoH yourself. That's suboptimal but in my opinion it's better than not dealing with the broken DNS of the general public. As for 2), it's not hard to run a DoH server yourself. In fact, it's much safer because it doesn't allow for amplification attacks like traditional DNS. The same goes for DNS over TLS (over TCP). I agree with you on your third point though. I'd much rather have seen DNS over TLS being built into Firefox, especially as most DoH providers built into Firefox also provide DoT. DoT is easier to set up as well because you don't need any specific DNS server software (just have an nginx proxy the TCP connection to your existing DNS, it's about 10 lines of config). I discovered that Android's "private DNS" functionality uses DoT. I feared they'd use DoH but luckily I was proven wrong.
- jsjddbbwj 7y agoI am not down on doh, I'm down on the possibility of Mozilla sending my DNS queries (ie my entire browsing history) to a company I haven't signed a contract with. And I say the possibility because I'm not American so that's not enabled here (yet). But I trust my ISP and my government much more than I trust Cloudflare (zero) and I will be very disappointed (even more than I already am) at Mozilla if they enable it in the rest of the world.
- tbyehl 7y ago> DNS is the primary way governments control and spy on web access. And DoH will enable every device you own to continue spying on you for the benefit of corporations. DNS is the last bastion of preventing devices I can't sufficiently control from spying on me. I use DNS filtering to block their tracking domains. I use my firewall to prevent devices from accessing DNS resolvers I don't control. DoH takes those options away from me. Ridiculously, in the name of privacy. Ha! Unfortunately, the battle was lost the moment someone created a DoH implementation. It hardly matters what the browsers do. All the other things I don't want to have DoH will eventually implement it. And they won't respect use-application-dns.net or whatever other frameworks Mozilla comes up with for controlling DoH at the network level. (Also, does anyone really believe that governments, ISPs, and public DNS resolvers aren't going to disable DoH with use-application-dns.net? I'm sure whomever came up with DoH in the first place had great intentions but the end result is a disaster that will cause more harm than benefit)
- afiori 7y agoSo your point is that your attack model was that makers of malwareApp would try to connect to malwareapp.net instead of a random IP? If you are worried about traffic in the browser you can not enable it, it you are worried about anything else then VPNs were already a thing since some time ago.
- tbyehl 7y agoI suppose my model is that every connected device and app, every web site someone visits, is malware. My household is full of things collecting data and passing it on to entities I don't wish to share that data with. How do I stop that when my ability to control what happens on my own network has been been reduced to Can access the Internet over 443, or not?
- afiori 7y agoMy question is how does DoH contributes to that in practice/theory. If a malicious/incompetent app/device wants to access random servers with DoH they would need to include a DoH implementation and then DoH offer nothing more than VPNs. In this context I do not understand if you are worried to have wireguard installed on your connected devices. If you are talking about Firefox itself, then disable it. I sympathize with wanting more control, but I do not understand how DoH changes things in a household settings. (I am assuming your is not a corporate point of view, in that case I agree that DoH might cause significant headaches)
- mavrc 7y ago> Why are people so down on DNS over HTTPS? It added yet another thing I have to implement, test and maintain through whatever changes they decide to make. Nothing like adding extra work for every enterprise IT team to make new friends. There are also some massive security issues with making all https traffic blind that making only the data blind didn't create - like the ability to blackhole known unsafe domains as they appear.
- alerighi 7y agoThe problem I have with DNS over HTTPS is that it's something implemented in the browser, that ignores the DNS configuration of your PC and your local network. That has some implication, for example you are unable to access local hosts on your network by their hostname (for example https://fileserver https://fileserver). Also you have a solution that works only on one program, while the rest of the system DNS requests remain unencrypted, that is bad. Browsers shouldn't implement DNS theirself, and should use operating system APIs to do all the DNS queries. That is how networks work, and doing that differently creates problems (imagine if every program has its implementation of DNS over HTTPS, you have to configure correctly the DNS server in each of them, and good luck debugging it when one implementation is broken...) As a technical motivation, HTTPS in an high level protocol, and using it for DNS is kind an overhead. We already have DNS over TLS that is a standadized protocol, that can be used, and that the operating systems are starting to implement. I use DNS over TLS in my local network, but rather than having configured all the computers to use it I have configured a local DNS server that encrypts the requests, for every host in the network, and also filters trackers and ad servers. Thus I don't want Firefox to mess aroung with my local network configuration that is fine.
- cmcd 7y agoI'm not against DOH but there are definitely some downsides. For example, your token does not get reset on network changes. This means your DNS provider can track your DNS requests across networks, including VPNs. With normal DNS anyone in the request chain can see a stream of DNS requests but there is no context. By the time the request is one or two hops from you it will be interwoven with tens of thousands of other requests making it impossible to know which one came from who. With DOH the DNS provider will have a unique identifier to correlate requests back to a specific system/user. Google offers one of the most used DNS services, with DOH they will be able to track all DNS requests you make even if you turn on a VPN.