19 ms·
Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
- gruez 6y ago>Comcast told Ars yesterday that "Firefox users on Xfinity should automatically default to Xfinity resolvers under Mozilla's Trusted Recursive Resolver program, unless they have manually chosen a different resolver, or if DoH is disabled. How would this work? Is the detection done once, everytime firefox starts, or everytime the network changes? Would you ever get into a situation where you're not using comcast, but are still using comcast dns? eg. you have VPN enabled or your laptop moved to somewhere else. >Joining Mozilla's program means that Comcast agreed that it won't "retain, sell, or transfer to any third party (except as may be required by law) any personal information, IP addresses, or other user identifiers, or user query patterns from the DNS queries sent from the Firefox browser," along with other requirements. And how is this enforced? If comcast breaches the agreement, is anyone going to sue them for punitive damages? Given the current state of the US legal system (eg. what happened equifax after the breach), these assurances are worthless to me.
- ta576248_743568 6y agoMy understanding is that Comcast signs a legally-binding contract with Mozilla which imposes the requirements on them [0]. This obviously isn't perfect protection, but it substantially increases the risk of failing to adhere to the requirements. Mozilla claims "We intend to publicly document violations of this Policy and take additional actions if necessary." [1]. Presumably the additional actions include suing for damages pursuant to the breach of contract. [0] https://blog.mozilla.org/netpolicy/2020/02/25/the-facts-mozillas-dns-over-https-doh/ https://blog.mozilla.org/netpolicy/2020/02/25/the-facts-mozi... [1] https://wiki.mozilla.org/Security/DOH-resolver-policy#Enforcement https://wiki.mozilla.org/Security/DOH-resolver-policy#Enforc...
- pbhjpbhj 6y agoSurely damages will be approximately zero? There has to be something else to sway Comcast's executives to abide by the contract, surely. Like the CEO agrees to forfeit an amount equal to their previous years total earnings, from all sources, ... that would be an interesting contract!
- mantap 6y agoIf Comcast breaks the contract then Mozilla will simply change the default back to Cloudflare DNS.
- mike_d 6y agoOut of the pot into the fire. 24 years ago a group of Stanford students started Architext. They took a few million from Kleiner Perkins, called themselves Excite, and started a search engine and internet provider. They were a good, ethical, well ran technology company. Over the years bits and pieces were chopped up and merged and acquired and spun off based on what generated shareholder value. Parts of that old soul live in on now in the current Comcast. The same thing will happen to Cloudflare. Matthew Prince will move on, or retire, or get hit by a bus. The board will be taken over by an activist investor. It will get merged with ExxonTacoBell, which also now owns the 2nd largest ad network. They will figure out the data gold mine the company built under total ethical pretenses, and the stock price will triple. There isn't a damn thing a single current Cloudflare employee can do to stop it except stop participating in the centralization of the internet behind a single MitM proxy.
- Nemo_bis 6y agoI sure hope that Mozilla writes contracts so that they can't be transferred by sale or merger. That's the most basic protection from your friendly counterparty joining your sworn enemy.
- zamalek 6y ago> Presumably the additional actions include suing for damages pursuant to the breach of contract. Given that the sky is blue, and Comcast is Comcast, Mozilla should have some more funding pretty soon.
- themacguffinman 6y agoI think it's more likely that Mozilla should be dragged into a prolonged and expensive lawsuit that Comcast has the legal might and connections to win pretty soon.
- jlivingood 6y ago> How would this work? A 1st draft of the steering mechanism just posted today for comment at https://tools.ietf.org/id/draft-rescorla-doh-cdisco-00.txt https://tools.ietf.org/id/draft-rescorla-doh-cdisco-00.txt
- Washuu 6y agoConsidering that Comcast sniffs, intercepts, and injects into HTTP web sites for their customer notification system(data cap overages and such) this just screams suspicious to me even if it seems like it is meant to be a good announcement. I am not sure how I am supposed to trust that they will do the right thing for their customers.
- tmikaeld 6y agoAgreed, if it was cloudflare I would have at least given them the benefits of a doubt, but not Comcast.
- rydre 6y agoCloudflare is harmful to independent CDN's. They hide the originating i.p. address (no other does it) to the nameserver in the name of "privacy" so you can only have as much granularity as the nearest cloudflare server to user (anti-competitive). That is unless you buy an ipv4 block (because everyone is still on ipv4) and set up anycast. For non 1.1.1.1 dns users I can just set up varnish and they'll be served via GEO ip lookup so the domain gets pointed to the nearest ip address. This is much cheaper. I'm not going to buy an ipv4 block just for cloudflare dns users. Their privacy claim is a lie because your webserver is going to be exposed to the end user i.p. address anyways after resolving from the nameserver.
- DoctorOW 6y agoEDIT: I associated the name Cloudflare with the main product. I forgot the context of this being about DNS and therefore my comment is about Cloudflare CDN not 1.1.1.1 > Cloudflare is harmful to independent CDN's. Cloudflare is a competitor to CDNs. You don't need to use a CDN with Cloudflare, they proxy your content fully and do caching along the way as needed. > Their privacy claim is a lie because your webserver is going to be exposed to the end user i.p. address anyways after resolving from the nameserver. It's not a lie. Cloudflare is the nameserver, and the CDN. So after resolution the end user still has just a Cloudflare IP.
- CWuestefeld 6y agoAt home I've got a pihole handling my DNS, including using DoH to Cloudflare. I assume that this configuration is superior to whatever FF is doing natively, and I should disable FF's DoH support?
- apocalyptic0n3 6y agoIf you do not disable Firefox's DoH support, it will by pass your Pi-Hole entirely. So you'd lose all the benefits of that and be limited to just the protections Firefox provides (which are great, to be clear. Just not as good as a well-sourced Pi0Hole)
- deeter72 6y agoThis is why I absolutely despise DoH. SysAdmins have no direct control over it. In my organization we have blocked direct IP access from userspace VLAN's to all known public DNS servers thus forcing all clients to rely on the company DNS servers, which is not the most ideal way to do things.
- yjftsjthsd-h 6y agoDon't you just set a canary domain - https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli... - and then it's disabled for your network?
- deeter72 6y agoAgain not the most ideal way to do things and Mozilla is doing a different approach to Chrome and Edge. and also a concern is that malware can use DoH to retrieve data without logging suspicious DNS queries on Firewall DNS logs which are monitored to highlight of new domains that have not been pre-approved. DNS should be something that is handled by the OS. I favor DoT which is secure and practical over DoH.
- deleted 6y ago
- danShumway 6y agoThis is a net increase in privacy for most people on Comcast networks, I'm glad to see Mozilla striking a deal like this -- especially with the privacy agreements Comcast is signing. But you should still switch your encrypted DNS provider to someone else like Cloudflare or similar. In short, good move, but you personally can make better moves than trusting Comcast.
- WarOnPrivacy 6y ago> Mozilla in November accused ISPs of lying to Congress in order to spread confusion about encrypted DNS. Mozilla's letter to Congress criticized Comcast > NCTA cable lobby that Comcast belongs to wrote a letter to Congress objecting to Google's plans for encrypted DNS. Comcast gave members of Congress a lobbying presentation that claimed the encrypted-DNS plan would "centraliz[e] a majority of worldwide DNS data with Google". Comcast's lobbying presentation also complained about Mozilla's plan for Firefox. Compromise, 2020 style: Comcast retains access to it's users DNS data and Mozilla doesn't dogpiled by NCTA-purchased legislators.
- Andrex 6y agoThis says to me they've cleared the "but what about encrypted DNS in Firefox?" excuse from the boards so they can focus all their lobbying power fighting the only other encrypted DNS implementation (in Chromium.) Comcast's anti-DoH argument doesn't work with Mozilla as an adversary. The basis of it is squarely anti-Google so having any other reputed organization backing DoH against them sinks that argument. This is potentially a very evil move and Mozilla is not only complicit but actually aiding. Concerning.
- kodablah 6y agoHow does FF know my DNS is a Comcast-provided one? Is there an IP list kept inside of browsers and updated?
- jlgaddis 6y agoComcast's ASNs and networks are documented in ARIN's WHOIS database and various route registries. Hell, Comcast probably publishes a list on their own web site. So, yeah, Mozilla can easily determine if a user is on the Comcast network just from their IP address. Also, while Comcast actually has a bunch of DNS servers spread across the country, I believe that nowadays they're mostly "promoting" the use of 75.75.75.75 and 75.75.76.76 (which, AFAIK, are anycasted and direct end users to their "local" DNS servers).
- kodablah 6y ago> So, yeah, Mozilla can easily determine if a user is on the Comcast network just from their IP address. I mean, how can the determine it's a Comcast DNS server configured on my network? I might be a Comcast customer w/ a custom DNS server configured. If it's a fixed IP check, I suppose that list is in the browser.
- TheSwordsman 6y agoWhat makes you think they are doing that? To jlgaddis's point, they are likely checking what IP address you are coming from over the public Internet. They can see who operates it, and knows that it's Comcast. Then they change the options in your browser.
- floatingatoll 6y agoA draft RFC was published today: https://news.ycombinator.com/item?id=23644068 https://news.ycombinator.com/item?id=23644068
- bosswipe 6y agoWeird that a network or OS level concern is being moved to the application layer. But considering that trust in all the other layers has been lost, from the ISP to the OS (specifically Windows), maybe this makes sense.
- jbverschoor 6y agoThe whole newroling stack needs encryption etc. This is one reason why you see everything moving of the layers. The other is, that Http servers are widely available, tested and easily scalable
- noncoml 6y agoI don't know how we can have privacy and Comcast in one sentence. We have a saying where I come from that translates roughly to "Putting the Wolf to Guard the Sheep". If you don't have any other option but to be with comcast my recommendation is to run Pi-Hole + DoH.
- jlgaddis 6y agoLet me make sure I've got this right: * Comcast sniffs / records / tracks their user's DNS traffic * Mozilla announced they would enable DoH by default, to protect end user's DNS data from shady ISPs like Comcast * Comcast then raised hell about Mozilla's decision (presumably because they would no longer have access to this data) * Now, Comcast and Mozilla come to some sort of agreement which effectively restores Comcast's access to their customer's DNS traffic? --- I'm really confused why Mozilla would agree to this. I really hope this isn't one of the ways they're exploring to "diversify" their revenue streams but, in the last few years, Mozilla has made a lot of decisions that I don't agree with so I suppose I really wouldn't be all that surprised.
- jlivingood 6y ago> Comcast sniffs / records / tracks their user's DNS traffic Actually not only does Comcast say they don't do that (https://www.xfinity.com/privacy/policy/dns https://www.xfinity.com/privacy/policy/dns) but now has signed a contract to this effect as well, thereby meeting the same level of commitment as the other TRR operators. This means IMO that Mozilla is doing a good job leading the industry on DNS privacy and convincing many of the merits of a strong pro-privacy philosophy. (disclosure: I work for Comcast and have been working on encrypted DNS)
- hellcow 6y agoRespectfully, Comcast has an ATROCIOUS privacy record. Full stop. A quick search came up with [1] [2] [3]. Your employer actively and repeatedly abuses the privacy and trust of its customers. It also lobbies for damaging policies. I do not trust Comcast. Firefox associating itself with Comcast makes me trust Firefox significantly less. [1] https://oag.ca.gov/news/press-releases/attorney-general-kamala-d-harris-reaches-33-million-settlement-comcast-over https://oag.ca.gov/news/press-releases/attorney-general-kama... [2] https://www.king5.com/article/news/local/comcast-fined-9-million-for-violating-washingtons-consumer-protection-act/281-b52a12ff-d09b-4b3a-aa95-f3f0e5a85703 https://www.king5.com/article/news/local/comcast-fined-9-mil... [3] https://consumerist.com/2016/04/01/comcast-says-fcc-privacy-rules-will-hurt-consumers-by-not-allowing-them-to-see-more-ads-online/ https://consumerist.com/2016/04/01/comcast-says-fcc-privacy-...
- nfoz 6y ago> "Adding ISPs in the TRR program paves the way for providing customers with the security of trusted DNS resolution, while also offering the benefits of a resolver provided by their ISP such as parental control services and better optimized, localized results," the announcement said. What? No! Why would DNS have "optimized, localized results"?
- bzbarsky 6y agoConsider a hostname that can map to different, widely geographically separated, IPs. You probably want the one with the lowest latency, which is likely to be the closest-located one. Not guaranteed, of course.
- parliament32 6y agoYou should just use anycast for that instead of trying to shoehorn it in with DNS trickery.
- sprayk 6y agoIt's interesting that the DNS-based solution is considered "trickery", when I don't really know anyone except for very networking-focused people who can explain how anycast works to achieve the same thing. While BGP is definitely not magic, it feels way more magic to me than DNS. The DNS-based solution, in comparison, seems way simpler to explain: get general location of IP of requester, send back the IP of a server in a DC closest to that location.
- WatchDog 6y agoRunning any connection/TCP based service on an anycast IP seems to require a large and effective network operations team. Dealing with BGP route flapping, single connection traffic being split between different servers, is a difficult problem that requires extensive relationships among other network operators. Implementing EDNS Client Subnet, on the other hand is pretty simple.
- stx 6y agoSo Mozilla wanted encrypted DNS Comcast did not. Now they made a deal. Comcast agreed in writing not to monitor DNS. So what did Mozilla give up to make this deal? Mozilla wont encrypt DNS on Comcast connections? Something does not add up.
- tofaz 6y agoWould be Comcast able to intercept the TLS SNI requests anyway and see at least were the traffic is directed?
- yarrel 6y agoHeadline announces opposite of what has happened.
- Nemo_bis 6y ago"Encrypt" !== "Protect"
- saltedonion 6y agoWhy can’t mozilla roll out a encrypted dns service in a form of a browser setting or plugin? Does the browser not have control over how the dns is resolved ?
- surround 6y agoI’ve never understood the purpose of DOH. It doesn’t really hide your traffic from any party, does it?
- floatingatoll 6y agoIt encrypts your DNS traffic over the public wire in a way that only the DOH endpoint operator can decrypt, preventing plaintext interception/modification attacks by unauthorized malicious actors positioned between you and the DOH endpoint It represents your DNS traffic over the wire as encrypted HTTPS traffic, which decreases the effectiveness of deep packet inspection and traffic shaping systems operated by some network providers. When hosted at heavily-used CDN endpoints that receive other (non-DOH) HTTPS traffic, it requires a network provider who wishes for whatever reason to block your DNS traffic to block all HTTPS traffic to all CDN endpoints.
- beezle 6y agoOK sure but what good is that when my next TCP/UDP activity after a dns lookup is to actually connect to that host? The upstream ISP knows exactly where you are going right? They can store and reverse that info and do with it as they wish.
- SheinhardtWigCo 6y agoAn IP address is often less specific than a hostname, and will become less useful over time due to IPv4 address space exhaustion and concentration of internet services among a small number of cloud providers. Widespread use of DOH therefore makes it harder for ISPs and middleboxes to interfere without collateral damage. It's far from perfect, but it'll help.
- Santosh83 6y agoProvided we get eSNI everywhere too, or it is easy for middlemen to sniff out your actual hostname even though the IP may be shared with thousands/millions of other hosts.
- ohnope 6y agoI'm confused. For me, a major selling point of DoH is it hides DNS queries from your ISP, which has detailed personal information about you. And if you're locked into Comcast, you're operating with completely eroded trust from the get-go. Clearly, DNS statistics are extremely valuable to Comcast, or they would not have engaged with Mozilla to get back the data, nor would they have raised hell with Congress. I would not have expected an organization like Mozilla to sign a data deal with Comcast, even if Comcast is now theoretically restricted on how they use the data. This is a weak move.
- bad_user 6y agoMozilla cannot enable one provider by default. People already complained that Cloudflare was initially the only choice. Users at the moment are expected to choose their provider anyway. This deal is about Mozilla picking Comcast by default for Comcast customers. This is essentially as if they'd be using the network's default, because Comcast is the network's default already, being what people get via DHCP. They can always choose a different provider. And Mozilla apparently struck a privacy deal with them too.
- ohnope 6y agoI understand the arrangement. From a Comcast user’s perspective, very little has changed, depending on how much trust you assign to a “we promise” privacy agreement. Are Comcast users better off than default? Yes. But decoupling DNS from ISPs which sit in such a privileged position is, for me, 85% of the threat model. I’d like to read more about how the choice will be presented to users, beyond about:config. I’d also like to understand more the community’s reaction to Cloudflare default. What if there was a round robin setup between neutral operators? Pairing Comcast users to Comcast just seems like a wtf move.
- TheSwordsman 6y agoHaving just done a Firefox install recently, the UX when prompted to enable DoH on first run did not set the expectation of choosing a provider. Is there something you can point to that speaks to that expectation?
- CKN23-ARIN 6y agoIf you can run your own local, recursive resolver, you should.
- ruffrey 6y agoIs this the same Comcast that: 1) created an RFC to inject JavaScript into non-TLS pages 2) created an RFC to intercept failed DNS lookups / connections with their own error page Both of which I reported to the FCC as MITM attacks. Comcast followed up referenced the bunk RFCs saying "it's fine."
- shirro 6y agoTin foil hat time but I can't help feeling a lot of things promoted as privacy solutions like VPNs and DoH are just aggregating data in a handful of locations so it is easier to intercept. Sure they have privacy policies but are they worth the paper they are written on when state actors are bound by a totally different set of rules? I recently changed my local dnssec resolver to forward to quad9 and cloudflare using DoT because I was sick of the high latency with DNS resolving on boot. I would forward to my own DoT server if there was some authentication built into it and I could deny other traffic. But I have gone from dns requests being aggregated at my ISP for easy inspection my the democratically elected government of my own country, to a my own dns resolver which while it isn't aggregated is still easy enough to intercept under warrant for local law enforcement (which I generally support) to aggregating my queries in a few logs which are likely in foreign countries where I have no say in how they are used or abused. I am not sure what problem we are trying to solve with this technology.
- Santosh83 6y agoIndeed. As it stands, trust is merely being shifted from one set of parties (ISPs) to another set (big DNS/CDN providers). Apparently that's attractive enough to a lot of people who prefer to send their queries to a foreign company than to their own ISP, but has it changed anything fundamental?
- MaxBarraclough 6y agoThe hope is that it's a change away from an untrustworthy provider, toward a trusted provider. Not sure if it counts as being a fundamental change, but it seems worth doing.
- tptacek 6y agoIf you're in the US, you can't trust your ISP (most of them farm DNS data), and shaking your fist at the clouds won't change that. If you don't Cloudflare or Quad9, stand up your own DoH server somewhere; it's trivial to do.
- 6y ago
- rabanne 6y ago"Let's encrypt DNS queries but send them to the ISP which can associate the query with subscriber info!"
- daguava 6y agoRegardless of how good this deal actually is, I have a knee-jerk reaction to anything regarding Comcast. I would not trust them with anything whatsoever. Mozilla even if they made a good decision here seems to be taking a step backwards just by virtue of associating with Comcast in any slight form whatsoever.
- twirlock 6y agoThat's cool how these comments are being used as a PR platform for Comcast. Dear Comcast employees, this is really simple: My web browsing behavior is none of your fucking business at all.
- Ericson2314 6y agoEveryone is complaining: - No DOH: "DNS is trivial to snoop" - DOH with Cloudflair: "DNS is not longer distributed" - DOH with ISPs: "Great, the ISPs get the data again" Well, guess what? With the current changes we get rid of the arbitrary snooper problem while preserving DNS as a distributed service: not bad, not amazing, but strictly better than before this all began! Of course ISPs are sketch, and Comcast in particular, but I rather have multiple providers to play off against each other. The upcoming IETF draft they mention would also restore the ability of network admins to adjust the default DOH (just like with regular DNS)---also good. Actual anatomized and distributed DNS querying would require vastly different technology that anything being proposed in these comments.
- MaxBarraclough 6y ago> Actual anatomized and distributed DNS querying would require vastly different technology that anything being proposed in these comments. I hope the everything should be solved with blockchain! crowd don't get any ideas.