4 ms·
Most DNS resolution libraries will read the libc resolver configuration (/ets/nsswitch.conf) and attempt to parse it into something they understand, and potenti
by vertex-four 6y ago
Most DNS resolution libraries will read the libc resolver configuration (/ets/nsswitch.conf) and attempt to parse it into something they understand, and potentially fall back to it (for example, if you're doing non-DNS resolution like mDNS).
If you'd like to standardise a way to require DNS-over-HTTPS in supporting software, and convince operating system distributors to generally ship it, I'm fairly sure Firefox would be up for using that rather than its current mechanism, similar to how it uses system proxy settings. As it is there is no such standard.
- someguydave 6y agoStill, it is reasonable to export a standard control interface to the user for site filtering and control.
- vertex-four 6y agoThere isn't one today, aside from running your own DNS server, and you can run your own DNS-over-HTTPS server. My understanding is that Firefox still respects /etc/hosts in DNS-over-HTTPS mode, too. I'm unaware of any such tooling that installs a glibc resolver stub. RFC8890 explicitly refers to "the interests of that child's parents or guardians" when the child is using a web browser, although individual system configuration is not within the remit of the IETF. RFC 8484 makes no reference to how DNS-over-HTTPS should be configured, and in the face of widespread DNS hijacking, enforcing DNS-over-HTTPS in browsers may have been the correct solution - but that doesn't mean we can't do better by defining a standard (perhaps under the remit of the Free Desktop XDG group), encouraging operating system vendors to ship secure DNS configured by default, and then convincing Firefox et al to use that standard.
- someguydave 6y agoSure, because big tech pretends to care about privacy and freedom of speech but only insofar as it results in them cutting out every layer of control between their servers and the end users they would like to own. So everything will be tunneled over opaque HTTPS proxies and there will be no facility for people to filter anything - even end users. Apple, for instance, pretends to care about user privacy and control but refuses to offer a configurable IP firewall in iOS or end-user control over name resolution for filtering.
- someguydave 6y ago>you can run your own DNS-over-HTTPS server. Yes, but is there a facility to force the browser to use your server or will Google re-write Chomium to "bypass" "rogue" DoH servers which filter content Google doesn't wish them to filter?
- zeveb 6y ago> If you'd like to standardise a way to require DNS-over-HTTPS in supporting software, and convince operating system distributors to generally ship it, I'm fairly sure Firefox would be up for using that rather than its current mechanism, similar to how it uses system proxy settings. As it is there is no such standard. There already is a standard way for me to tell all the programs which run on my system which DNS servers to use: /etc/resolv.conf. Any program which does not respect the values I set there is disobeying me.
- vertex-four 6y agoThere is no way to say in /etc/resolv.conf that you want to use a DNS-over-HTTPS server.
- zeveb 6y ago> There is no way to say in /etc/resolv.conf that you want to use a DNS-over-HTTPS server. Sure there is: nameserver 127.0.0.1 where I choose to run a nameserver which uses DNS-over-HTTPS on 127.0.0.1:53.
- vertex-four 6y agoAnd so we get incredibly far away from the very laudable goal of protecting Internet users - the majority of who primarily use a web browser - by default from malicious DNS servers.
- pseudalopex 6y agoChrome automatically upgrades known DNS providers to DoH.