12 ms·
With both a DNS-over-HTTP client and potentially a DNS-over-QUIC in the browser and serving advertisements over QUIC... there is a good chance that the world wi
by Randor 6y ago
With both a DNS-over-HTTP client and potentially a DNS-over-QUIC in the browser and serving advertisements over QUIC... there is a good chance that the world will see unblockable advertisements in our near future.
I don't think this is a good idea... about a decade ago... as a research project I ran honeypot farm of 13 machines to learn more about malware. The honeypot machines were autonomously surfing the net, parsing the DOM and choosing random links. I ran them in a sandbox and was getting weekly malware hits.
Much to my surprise... most of the malware was coming over advertisement networks on shady websites.
- judge2020 6y agoYou can still define a custom HTTPS endpoint[0], you just need to trust (within Windows) the self-signed certificate your pihole/etc device has, in order to use it on Chrome; your endpoint setting isn't messed with when you select 'enhanced protection' or anything[1]. The only downside to this is that rogue IoT devices or hacked IoT devices can easily get around DNS filtering, but that was already possible before DoH by using or running some benign free public http api for dns lookups. 0: https://i.judge.sh/hollow/Lyra/chrome_hxURk11GDb.png https://i.judge.sh/hollow/Lyra/chrome_hxURk11GDb.png 1: https://i.judge.sh/bony/Fleet/s4HD5OqNvf.gif https://i.judge.sh/bony/Fleet/s4HD5OqNvf.gif
- tialaramex 6y ago> unblockable advertisements in our near future. Why? The user agent will still be able to choose what to display, and protocol improvements don't prevent you choosing an agent that has your interests at heart. Using secure transport means nobody else gets to decide, and I certainly have a long list of people I don't want deciding whether I see things, so that helps.
- swiley 6y ago> The user agent will still be able to choose what to display, Will it? Even on Mozilla Firefox (which fewer and fewer sites are tested against) you're pretty limited in controlling this. I have zero faith that google will keep that working in chrome
- Liquid_Fire 6y agoCan you clarify how you are limited? I can block anything I want using uBlock Origin today in Firefox. Admittedly sites could switch to rendering everything in JavaScript using canvas or WebGL. But so far no one is resorting to this, because you have to effectively reimplement big chunks of the browser. Maybe one day there will be a JS framework that does this, but then it will be easy for adblockers to target that specific framework.
- throwaway2048 6y agoChrome is also crippling adblockers, plenty of websites are already chrome only, and I'm guessing if you can ensure ad delivery, a whole lot more are going to jump on that train.
- mixedCase 6y agoThe easy way out is to choose a different Chromium fork that has your interests at heart.
- mrec 6y ago> a different Chromium fork Well, that's a depressing sentence to read. The vultures may be circling, but Firefox isn't dead yet.
- garmaine 6y agoFirefox has been a dead browser walking for a number of years now. I don’t like this any more than you, but it’s the truth.
- dont__panic 6y agoI'm not sure if this is true -- there was a dark time during the period where Google started to advertise Chrome on literally all google websites, but all of the internal refactors and engine improvements over the past 2-3 years have made an enormous impact on my user experience. And as far as I'm concerned, Firefox isn't dead as long as there isn't a viable replacement that: - doesn't update via a sketchy background process (Google Updater, or whatever they've renamed it to this month to avoid scrutiny) - allows me to customize the UI to fit my needs (tree style tabs are an absolute must for me) - allows me to use a full ad blocker like uBlock Origin instead of arbitrarily limiting the ad blocker API to advance the interests of advertisers Of course, Firefox's management is an enormous problem, from the way they've prioritized features to the recent layoffs to the enormously stupid decisions (letting a certificate expire that disabled almost all add-ons, the Mr. Robot tie-in "experiment", pushing pocket, default disabling userChrome.css, forcing auto-updates) they've made in the past 5 years. But the core of Firefox is good. I would love a startup that builds an entire business off of a fork of Firefox that's completely based on privacy, perhaps with some non-invasive monetization like: - a $5-20 one-time fee to use (with weak enforcement, a la Sublime Text's "annoy you every 5 saves" model) - a paid vs. free split where the free version of the browser adblocks ads but replaces them with in-network, verified safe ads - Linux kernel donation-style only model, with no parent corporation Because of all of the Firefox devs floating around who just got laid off, you could even snatch up some guaranteed capable talent already familiar with the code base. And the best part? They're already vetted to not be part of the management-industrial complex that's taken over Firefox these days.
- zo1 6y agoI would pay for an ISP that can read my web traffic and alter it to remove ads, optimize images, filter out unwanted content, and a gazillion other things.
- dimitrios1 6y agoWhy not just run pi-hole?
- caseyohara 6y agoI don't think that will work with DNS-over-QUIC in the browser, but I could be wrong.
- JoshTriplett 6y agoIt will if your device speaks QUIC; you can configure your browser to talk to that device. But I do think it makes much more sense to make the browser just do the job directly, rather than delegating that to a separate device. Firefox continues to block ads just fine, and it'll keep doing so in a QUIC world, while protecting me even more from malicious local DNS servers. The average person is much more likely to encounter a hostile DNS server than a "helpful" one.
- OptionX 6y agoISPs are more likely to move in the direction of reading your traffic to inject ads rather than remove it.
- userbinator 6y agodon't prevent you choosing an agent that has your interests at heart I choose Dillo or Netsurf. Now how can I still use sites it can't even render because the developers have drunk the Google-aid and used some trendy framework that requires the latest version of Chrome and JS just to display some static text and images? Fuck Google and its creeping control over the Internet.
- Arnt 6y agoDo you even want to visit that sort of site?
- muxator 6y agoMaybe he wants. Once these practices become sufficiently spread, the majority of developers and content producers will never understand that an alternative is possible. Or maybe he will need it: those same developers can perfectly be contractors for a government agency whose site the user has to access. Trends slowly creep everywhere, independently on technical merit.
- swiley 6y agoWhen my brother got married his then fiance sent everyone in the wedding party this site with a form on it: It's mostly radio buttons (with a loading screen and a pile of js/css to make it pretty of course.) You fill it out, click submit and a matching suit gets shipped to your house. I couldn't get some of the controls to work and sent the support people an email. It turns out the form they built uses some special chrome only API and doesn't work in Firefox. Ditto when I submitted my rental application for my current apartment (how can you screw up a single page with a file form that badly?) The trends are definitely going the wrong way.
- trhway 6y ago> It turns out the form they built uses some special chrome only API and doesn't work in Firefox. history repeats itself (or more exactly we humans repeatedly step upon the same pile of stuff) Back then it was IE only APIs. Those APIs of course were for better and richer functionality and user experience. And we all know how it ended.
- d3nj4l 6y ago> The user agent will still be able to choose what to display Isn't one of the biggest advantages of ad blocking that it can cut your bandwidth use? I mean, if you aren't going to show the ads, why download them in the first place?
- wmf 6y agoBrowser extension ad blockers block requests before they are made which does save bandwidth. This still has nothing to do with QUIC.
- tracker1 6y agoAgreed to some extent, though not really sure the protocol matters here... As an alternative, limiting IFrame to 1-3 layers would do a LOT in terms of reducing the overhead/bloat/risk... you get a full ad network payload, that injects an iframe because of a buy miss, then another, another, etc and so on. In the end, limiting IFrame depth would probably do more than many things for stopping some of the bad actors. I use uBlock Origin and EFF Privacy Badger for most surfing, which does a decent enough job. I don't think that the enhancements to the protocol really do that much... though I also don't know that some of the tradeoffs are worth losing a human-readable protocol.
- mixedCase 6y agoI think it's simply a case of this being the job of the user agent instead of middle-boxes that manipulate traffic. Of course, this makes it more annoying to deal with user-hostile user agents such as some kinds of appliances and other locked-down devices; in which case I would suggest "don't buy user-hostile devices".
- wolco2 6y agoWhich will soon be don't buy appliances. Ever try to buy a non-smart tv these days?
- DarkWiiPlayer 6y agoTry finding a TV-Sized computer monitor and you'll know my pain xD
- frank2 6y ago>don't buy user-hostile devices Such as the Chromebooks many on this site like to rave about.
- staticassertion 6y agoI genuinely don't see how DNS-over-http/quic is leading to unblockable advertisements. Adblocking extensions, which have got to account for at least 99% of all adblocking, don't work on DNS at all afaik - they work on already resolved hostnames?
- lukeramsden 6y agoAlso, couldn't you just MITM the secure transport layer if you want to run a pihole?
- frank2 6y agoHave you tried browsing through mitmproxy? I have. It works, mostly, but is quite unpleasant.
- userbinator 6y agoHOSTS files are the simplest and can already remove quite a bit of cruft, but what's effectively tunneling DNS in its own VPN will bypass that. Ad blocking extensions are really a "last defense" and can be slowly lobotomised as they are under browser vendors' control.
- stefan_ 6y agoYou got it the wrong way around. Ad blocker extensions should be your first choice, this DNS blocking business is really for devices where that is not possible ("Smart" TV et al) and it's getting less effective by the day.
- staticassertion 6y agoI assume DNS over Whatever will still respect the HOSTS file? I'd be really surprised to find otherwise, but would love to hear if that's the case! If you don't trust the browser you already have very little defense against ads, no? After all, the browser could always just resolve DNS itself. HOSTS files may also be simplest (I totally disagree btw), but I can't imagine they're anywhere near the most common.
- bashinator 6y agoI wonder how difficult it would be to use machine vision to identify and block advertising elements.
- hsbauauvhabzb 6y agoMost services can fallback to HTTP1.1 gracefully. You should be able to configure a proxy which hard drops HTTP2, HTTP3 and DNS tunnelling. You’re up to the mercy of the server to actually respect HTTP1.1 but I’ve not yet herd of a 2+ only service. You will lose performance, but you’ll gain control.
- majewsky 6y agoIf it's not happening already, I absolutely expect there to be API endpoints that only accept HTTP/2, esp. for APIs that only assume their own inhouse apps to be talking to them (esp. smartphone apps).
- onion2k 6y agothere is a good chance that the world will see unblockable advertisements in our near future I don't think we'll ever have unblockable adverts. It would give users a huge incentive to change browser. Google get a great deal of value from people using Chrome and I don't see them giving that up just to serve ads to people that want to block them.
- Penguinx628 6y agoAt this current date 10/08/2020 from what I see nobody is able to block youtube ads on a smart tv or through the youtube app on a non-rooted phone. You can set up a pihole or dns ad blocker but this will not block any of the ads due to sneaky use of dynamic video ID to serve ads. More information here: https://discourse.pi-hole.net/t/how-do-i-block-ads-on-youtube/253 https://discourse.pi-hole.net/t/how-do-i-block-ads-on-youtub...
- JamesSwift 6y agoUnblockable ads have always been and will always be possible. The host site just needs to resolve and inject the ad content on their side of the wire. For video they just need to interleave the ad content into the video stream. Good luck fighting that.
- nuker 6y ago> With both a DNS-over-HTTP client and potentially a DNS-over-QUIC in the browser and serving advertisements over QUIC... there is a good chance that the world will see unblockable advertisements And better tracking. In DoH RFC [0], 8. Privacy Considerations, 8.2. In the Server: "HTTP's feature set can also be used for identification and tracking in a number of different ways. For example, Authentication request header fields explicitly identify profiles in use, and HTTP cookies are designed as an explicit state-tracking mechanism .." "Determining whether or not a DoH implementation requires HTTP cookie support is particularly important because HTTP cookies are the primary state tracking mechanism in HTTP. HTTP cookies SHOULD NOT be accepted by DOH clients unless they are explicitly required by a use case." I will stick to DoT. [0] https://tools.ietf.org/html/rfc8484 https://tools.ietf.org/html/rfc8484
- ignoramous 6y agoThere are valid uses for DoH, the most important being its counter against internet censorship. For DoT, a block on UDP/853 is all that's needed. Blocking DoH requires much more effort. Also, it isn't like one couldn't be tracked by DNS resolvers without cookies: https://news.ycombinator.com/item?id=20219878 https://news.ycombinator.com/item?id=20219878 and https://news.ycombinator.com/item?id=19828702 https://news.ycombinator.com/item?id=19828702
- nuker 6y ago> For DoT, a block on UDP/853 is all that's needed. I cannot imagine it happening, it has to be blanket ban. Real life examples, excluding China? > tracked by DNS resolvers without cookies Thats Very clever :)) Safari fixed similar thing that was using HSTS, but I bet they'll kill this one too.
- ignoramous 6y ago> I cannot imagine it happening... I'm sorry but this is very much going to happen since nearly 1B Androids are now DoT capable. ESNI may also be blocked for same reasons once it is widely deployed. > Safari fixed similar thing that was using HSTS, but I bet they'll kill this one too. Safari cannot cover for apps sending DNS requests.
- 1vuio0pswjnm7 6y agoThe world already sees unblockable ads. They're called "Ads by Google" on the first page of Google search results depending on the search query. DNS-over-HTTPS can actually be useful. I can do bulk DNS lookups from DOH servers using HTTP/1.1 pipelining, retrieving thousands of names at a time over a single TCP connection. I can look up every name for every HN item in one go, store this data in zone file served by a localhost DNS server and generally never have to use remote DNS when browsing HN. This makes for fast browsing with a text-only browser. The issue I am surprised more people are not raising is the decision of Google to encourage Golang developers to use a "built-in" DNS resolver in their applications rather than relying the system resolver and submitting to traditional user controls like resolv.conf, nsswitch.conf and HOSTS. Regardless of the motivation behind this choice, IMO it tips the scales toward developers instead of (non-Windows) users in terms of ease of control over DNS lookups, not to mention the privacy issue (shared by DOH) of enabling a third party DNS provider to segregate lookups by device.
- 1vuio0pswjnm7 6y agos/device/& and application/
- seszett 6y ago> The world already sees unblockable ads. They're called "Ads by Google" on the first page of Google search results depending on the search query. I don't see them even when searching for commercial things, so I guess they are blockable (I just have uBlock Origin).
- fomine3 6y agoThat's OP's point. Anyway DNS-based ad blocker can't block such ads (delivered from same host name as content) but browser extension can. I'm curious why DNS-based approach is such popular even for PC browser.
- 1vuio0pswjnm7 6y agoYou are still requesting and receiving the ads as they are part of the results page. View source in your browser to verify. Your ad blocker is probably modifying the page after you receive it so the ads do not display. I can do the same thing without an ad blocker using something like curl and sed. I edit out the ads, then view the page. The parent commenter OTOH is referring to DNS-based "blocking". In that case, the ads come from another domain and because we control DNS the ads are never requested, never sent and thus never received. There is nothing to discard. The word "block" is really not the best term to describe what is happening.
- bogomipz 6y agoCould you or someone else explain how QUIC as a transport protocol prevents the ability for things like browser extensions to do ad blocking? How did the research project you described support that assertion? That wasn't clear to me.