10 ms·
If you are a network administrator and want none of this, look at that: https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://suppo
by aduitsis 7y ago
If you are a network administrator and want none of this, look at that:
https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
Basically, make use-application-dns.net. return an error (any kind will do). Filter it in your recursor for example.
Having the browser change a fundamental behaviour that used to stand for decades is highly problematic. If nothing else, it is the network administrator who should have the final say on WHEN (if ever) DoH will get deployed inside their network.
- techdevangelist 7y agoI wonder if we’ll start to see Comcast and other large snooping ISPs start to filter the resolution of this domain in the name of stability...
- jeroenhd 7y agoIf they do that, Mozilla will probably immediately update the check or remove it all together. I don't understand why systems administrators don't just use their existing policy management to disable DoH if it really causes an issue. There's a group policy specifically for DNS over HTTPS [1] The only reason I can think of is that they can't because of BYOD or Firefox being part of the company's dark IT. The DNS workaround doesn't help much in those cases because the underlying problem is a lack of oversight, not an issue with Firefox. [1] https://github.com/mozilla/policy-templates/blob/master/README.md#dnsoverhttps https://github.com/mozilla/policy-templates/blob/master/READ...
- jfk13 7y agoI'd guess that the overwhelming majority of Mozilla's users do not have a "network administrator" looking after issues like this for them. All they have is an ISP, and the ISP is not on the user's side.
- pbhjpbhj 7y agoThe ISPs can easily be swapped out, they're was much on the client side as Cloudflare, probably more so.
- EvanAnderson 7y agoEveryone who uses DNS-based content filtering (OpenDNS, a "Pi Hole", etc) to do filtering on a home network is a "network administrator".
- jfk13 7y agoCare to guess what percentage of Mozilla's users are included in that group? The HN crowd is far from being a typical sample.
- EvanAnderson 7y agoMy point is that the definition of "network administrator" is wider than the corporate network administrator vision the phrase evokes. A quick search shows me a number of parental control features in routers that use OpenDNS. All of the parents using those features would be "network administrators", too. I think more people are "network administrators" than the average HN reader realizes.
- Spivak 7y agoThis logic makes no sense to me. Can you imagine if AT&T or Spectrum made a statement like this? The “network administrator” is an untrusted 3rd party who should have basically 0 say in how my device operates. The device administrator, ie the owner of the machine, is the one who should have the final say over when DoH is used. The use-application-dns record is for businesses that want an easy way to stop DoH on machines they administer. If random “network admins” start deploying it as you say then Mozilla will have no choice but to ignore the record entirely.
- 72deluxe 7y agoSo what if I run a Pihole at home as a DNS server and want to stop being able to resolve various domains? I would like to know how to stop all devices (actually worse, individual applications!) on my network deciding to DoH of their own accord (and therefore bypassing my local DNS server). This kind of centralised ability to block DoH is very useful to me.
- Spivak 7y agoThere are a couple use-cases here. * On devices that you own and control you don't need a network level control like this except for convenience. This is when you should be applying the override record. * On devices that you do not own or control (family/friends/guests) disabling DoH makes you the malicious network operator. Connecting to your Wi-Fi doesn't make you trusted in any sense of the word. * On devices that you own but do not control (Google Home/Alexa) you make a valid point that techie types have been able to take some level of control by exploiting the fact that DNS is an unencrypted "hole" in the security of the device. You would have a lot more control if the HTTP traffic they sent was unencrypted and inspectable/modifiable but that doesn't mean devices shouldn't be allowed to use HTTPS without your approval.
- 72deluxe 7y agoThanks. Not to be argumentative, but I find it odd/interesting that guests connecting to my WiFi and using my DNS set up makes me a "malicious network operator" in your eyes. That's a very odd view of the world in my opinion, as it is my WiFi and DNS set up. That's like saying that me stopping guests taking photos of my daily activities (showering, using the toilet) whilst in my house is a malicious behaviour too. I suppose I should let them post the photos off to whomever they choose? If someone is in my house and using my WiFi, I don't want their device looking up domains that I choose to block. How do I know that their device is not recording its surroundings and sending them off to the said domain? How do I know that my guest is not up to nefarious/illegal activity using domains that I have blocked? I would be the one prosecuted due to the IP address = a person approach by the law in most circumstances (should they ever deduce the requested domains from the DoH set up). Being that the DoH provider is under law, I am pretty sure that the DoH will have to hand over any records they have, which will lead it back to me and my network. And then once again we are stuck in a situation where I cannot control what domains are being looked up by devices and applications on my network. My devices are no longer mine. I have handed off control to some company the other side of the planet with employees I will never meet. How do I stop the 5+ tracking domains that the Instagram app uses on my wife's iPhone, for example? Am I a malicious network operator for stopping that garbage being sent off?
- rndgermandude 7y ago>Having the browser change a fundamental behaviour that used to stand for decades is highly problematic. No, this is far too broad of a statement. Browsers pushing for TLS, deprecating the old SSL versions and now the old TLS versions, deprecating SHA1 use in certificates, going from quirksmode to a living html standard (not without problems such as Google's over-influence), etc all have been a net positive, but there was breakage too. Now, DNS - a really antiquated protocol written at a time when security played no role and everybody was assumed to be a good actor and (next to) nobody bought shit online or banked online or dated online or got medical advise online - is somehow the holy grail that MUST NEVER change? Because... "it works" (only superficially, without proper security) and status quo. I don't buy it. We may discuss DNS and alternatives/add-ons (such as DoH, DoTLS, DNSSEC, DNSCrypt, etc) and their pros and cons, but rejecting any kind of innovation isn't something I am willing to do.
- aduitsis 7y agoThe elephant in the room is that many networks need to have content filtering, and you are proposing nothing useful. DoH torpedoes content filtering to its very core and, fortunately, the knob Mozilla provides can (hopefully) be utilized. That's all there's to it.
- rndgermandude 7y ago>The elephant in the room is that many networks need to have content filtering First of all, we're talking about domain filtering, not content filtering. And no, they want domain filtering, hardly anybody needs it, and there are better solutions than NXDOMAIN, such as actual content filters. >and you are proposing nothing useful. Why would I need to provide "something useful"? mozilla already described the many ways this can be disabled, from browser preferences, to automated checks for known disable-me domains, etc.
- pbhjpbhj 7y agoI need domain filtering: if the domain serves malware I want to block it, not just the known malware coming from it. If a domain serves porn, I want to block it on my kids computers (and mine) not just the content that is recognisable as porn. If a domain is used by malware I want to block it, and probably use the domain to determine the server, and block that too (too because the domain can move IP).
- jdwithit 7y agoHas anyone verified that this actually works? My company's DNS administrators have already made this change. use-application-dns.net returns SERVFAIL when I run "dig" on my machine on the corporate network. But if I enable DNS over HTTPS in Firefox, it very clearly still uses the Cloudflare resolvers. We have some split-horizon zones set up (resolve to 10.x IP's internally, and public IP's externally). When I tick the DoH box, Firefox starts resolving the public IP, verified in the Dev Tools network pane. Curious if the issue lies with us or Mozilla.
- aduitsis 7y agoIf you did it explicitly, I think there are no heuristics. https://bugzilla.mozilla.org/show_bug.cgi?id=1614751 https://bugzilla.mozilla.org/show_bug.cgi?id=1614751
- corford 7y agoCan't imagine that will last for long. Otherwise what stops Telcos/ISPs blocking this in their resolvers.