6 ms·
Doth protest too much. People don’t take issue with DoH, they take issue with an advertising supported browser like Mozilla’s unicast (and now bicast) centrali
by davidu 7y ago
Doth protest too much.
People don’t take issue with DoH, they take issue with an advertising supported browser like Mozilla’s unicast (and now bicast) centralization of DNS traffic that was previously distributed.
We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization.
They make this about DoH when really the primary issues are with how they went about it.
- drenginian 7y ago>> We invented DNSCrypt. There’s also DNS over TLS. Lots of ways to encrypt DNS without centralization. Ummm so what’s the downside then? Are those services arcane and hard to use and utterly forbidding blackest black magic, like almost all crypto stuff? If you’re thinking browser users will just do this then that then this and x and y and z to “get dns crypto going”, then I’ll take Mozilla’s “it just works” approach. It’s a much much better approach for the browsers to implement it rather than wait for everyone’s operating system to implement secure dns because that’ll happen .... well I can’t imagine any time in the future you could say everyone’s OS is using crypto DNS, whereas if browsers implement it for themselves, instant massive adoption.
- davidu 7y agoNot sure what any of your reply means. Adding OS support isn’t required. People just run a local resolver that supports these things. No different than any other application. Nothing arcane. Certainly no more than HTTP and SSL. I think you have some reading to do.
- drenginian 7y ago>> People just run a local resolver that’s support’s these things. Nowhere do “people just run a local resolver”. Grandma and aunty Beryl certainly don’t, nor does any other ordinary person. If you want secure DNS you have to build it in to the browser. Only systems people think that this is the sort of thing that ordinary people do.
- zaarn 7y agoI think the better solution is "build it into the browser and wait for systems to support it natively".
- SAI_Peregrinus 7y agoSo exactly what Mozilla is doing.
- whoopdedo 7y agoDoes Grandma have a small WiFi router that her cable modem is plugged into? Well that device provides local DNS for her.
- dreamcompiler 7y agoNot true. In the default case, Grandma's wifi router is just passing along -- via DHCP -- the IP address of the cable company's DNS resolver to Grandma's computer. Which the wifi router itself probably obtained via DHCP or a similar mechanism from the modem. This is in no sense a "local DNS resolver." If Grandma has a grandchild that knows how to set up a PiHole, it's a different story. But that's certainly not the majority of Grandmas or the majority of wifi routers.
- nemothekid 7y ago>* People just run a local resolver that supports these things.* How many people do you know that running local resolvers? How would this even work on Windows? The world doesn’t need another encrypted dns solution that only works on Linux
- WanderPanda 7y agoHow would this even work on iOS?
- saurik 7y agoYou write a network extension, which is what Cloudflare did for their 1.1.1.1 app.
- afiori 7y agoYou can literally do the same with DoH.
- bepvte 7y agoDNS over TLS and DNSCrypt both depend on servers... exactly as centralized as DoH. They are just different wire protocols that in the end do the exact same thing with a centralized DNS server.
- tptacek 7y agoIn fact, the only meaningful difference between DoH and DoT is that DoT runs on a separate port, so network operators (and ISPs) can filter it. DoT is DoH with a kill switch.
- zzzcpan 7y agoDoH can be blocked by IP addresses, DNS canary and probably SNI, while DoT by IP addresses and port number. So "DoT is DoH with a kill switch." is again nonsense.
- tptacek 7y agoVirtually every router on the Internet has the built-in capability to block DoT with a single configuration change, but you can attempt to create a blacklist of DoH resolvers to try to stop that, so they're totally equivalent. That's the argument you've got.
- vetinari 7y agoNot quite. Nothing prevents Google or Cloudflare to run DoH on the same IPs as their user-facing services. Unless you are willing to block Search, for example, you might be SOL without TLS-terminating proxy.
- tptacek 7y agoYes, sorry if I wasn't clear, I think the idea that DoH is just as filterable as DoT is silly.
- Someone1234 7y ago