5 ms·
At least in my case network provided DNS are the worst, Full of spyware, and tracking.
by acd10j 6y ago
At least in my case network provided DNS are the worst, Full of spyware, and tracking.
- waheoo 6y agoThey're referring to the local network configuration. Many sysadmins will hate this. > Full of spyware, and tracking. What do you use? Google?...
- iso1631 6y agoI run my own networks and my own devices, I choose what options go in my DHCP server If I were on a hostile network (say a hotel), then sure, I'll ignore their DNS server and use my own (or indeed just punch my way out via a VPN), but most of the time I use friendly networks, and I don't want to have to configure 20 different applications on a dozen different boxes to use a DNS provider of my choice. There's a reason I use DHCP in the first place.
- manquer 6y agoYou are able to run own network and have the know how to do so, typical physical Firefox users cannot. Given your knowledge you can disable or even build firefox with DoH disabled , it is a sensible default for vast majority of users who do not know what DHCP is, or control their network. It cannotis trivial configuration for people who can control and do not want the DoH service provider given by Firefox. Also many places do not allow VPN traffic either. It is not as easy to bypass monitoring in a locked down environment like typical corporate firewalls, college campuses etc. Yes for every block in place like deep packet inspection etc there is usually some workaround but these become increasingly difficult as more stringent the blocking becomes, and having options like DoH helps users who cannot or do not know how to run VPNs.
- iso1631 6y agoIf your network allows TLS to an arbitary DOH server it allows VPN over TLS to an arbitrary server
- judge2020 6y agoA lot of networks block VPNs via port number + DPI, but can't really block DNS over HTTPS if it looks like a connection to any other HTTPS website.
- iso1631 6y agoYes, which is why my VPNs are available on port 443 and 53, including a TLS based VPN. Now port 53 can and often is intercepted (but sometimes it gets through when 443 doesnt)
- manquer 6y agoit does not matter under what port including 443 you are running the service, deep packet inspection (DPI) can sniff out VPN traffic, perhaps you may not encountered this type of firewall as it somewhat more expensive to run both computationally and licensing wise. It is not possible to sniff out DoH traffic via DPI as looks exactly the same as regular traffic While running flash servers for media use in corporate environment (when flash was still a thing) back I used to run into similar problems with RTMP/ RTMPS constantly.
- shawnz 6y agoYou can use an HTTPS "CONNECT" proxy to protect your VPN traffic in the same way (I assume that's the kind of setup they were referring to on port 443)
- bscphil 6y ago> Given your knowledge you can disable or even build firefox with DoH disabled , it is a sensible default for vast majority of users who do not know what DHCP is, or control their network. It cannotis trivial configuration for people who can control and do not want the DoH service provider given by Firefox. I have mixed feelings about the issue, but it's not that simple. I run a variety of services on my LAN for my users and guests. That includes Unbound, so even though their browser doesn't know it, their queries are secure from my ISP. But more importantly I have other stuff behind hostnames (which are resolved by Unbound). For example, my guests can navigate to music/ and use a web interface to play any of the music in my library over the stereo. Hopefully it's obvious why this is something useful to have. Now that Firefox is intercepting DNS requests, a conversation with someone might go like this: "Oh, it's not working? Are you using Firefox? Yeah, Firefox broke this recently, let me get the IP address for you." And then I have to log in to a computer, ssh into the relevant system, and get its IP address on the LAN. And that's just the beginning. Last I checked Cloudflare still can't resolve the archive.is / archive.today domains. Even though I use Cloudflare over TLS in Unbound, I fix this for myself and my users by sending these domains to Google instead. Anything as convenient and simplistic as Firefox just sending everything directly to Cloudflare can't do that.
- manquer 6y agoIf you follow the DNS specs this will not a problem. If you use *.local for local domain names DoH will never be triggered From Mozilla documentation. "localhost" and names in the ".local" TLD will never be resolved via DOH. [1] Lan based services are pretty common use case. Mozilla is hardly going to release this feature without considering this. The Cloudflare / Archive.is point is esoteric debate and not a common occurence, DoH does support other providers than Cloudflare so not sure if this really a major concern [1] https://wiki.mozilla.org/Trusted_Recursive_Resolver https://wiki.mozilla.org/Trusted_Recursive_Resolver
- bscphil 6y ago> If you follow the DNS specs this will not a problem. If you use *.local for local domain names DoH will never be triggered I don't think PFsense + Unbound supports appending .local to every hostname automatically, so I'd have to change every last one of my hostnames to whatever.local and that seems like a real pain. (Surely most people are not using whatever.local in their /etc/hostname, right?) > The Cloudflare / Archive.is point is esoteric debate and not a common occurence, DoH does support other providers than Cloudflare so not sure if this really a major concern Sure, but my general point is that there's all sorts of different reasons why it can be useful for a LAN administrator to override the remote DNS response in certain specific cases. Given that Firefox is using Cloudflare by default, the fact that you can change it also doesn't really help anything, since after all the thing I'm specifically complaining about is that stuff randomly breaks for any of your guests using Firefox.
- pbhjpbhj 6y agoWhy should Firefox want enable users and devices to bypass network owners configuration in this way? A company should control their network, just as a home network's owner should have control.
- mantap 6y agoBecause Firefox represents their users' interests and not network owners' interests which are often hostile e.g. inserting ads into pages.
- JoshTriplett 6y agoFor the vast majority of people, "the network" is their ISP or a random hotspot, who should absolutely be treated as a hostile adversary.
- amenod 6y agoHow can DNS be "full of spyware"? Or are you saying that it is used for spying on you? But anyway, it is your decision to use them - you can use 1.1.1.1 (CloudFlare), 8.8.8.8 (Google - if you don't mind the tracking) or any other DNS provider.
- livre 6y agoI don't know what GP meant with "full of spyware" but the most popular ISP in my region (Telefónica) used to redirect to pages filled with ads when a domain couldn't be resolved. Changing to 8.8.8.8 wouldn't work because it was unencrypted, they intercepted the requests and still redirected to ads. They stopped doing it some time ago but any ISP or middle man has the ability to continue doing that if they want.
- acd10j 6y agoYes this is the same thing that happens with me, all unencrypted websites are redirected to adware. On phone i use 1.1.1.1 app from cloudfare but on other devices this is still issue.
- pbhjpbhj 6y agoAren't all these public DNS getting unencrypted requests, so I assume ISPs snoop the domain lookups already, regardless of Google/Cloudflare/OpenDNS/Yandex doing so.
- livre 6y agoThat's the point of using DoH, to avoid sending unencrypted DNS requests so your ISP can't spy or intercept those requests. If you are using unencrypted DNS from Google/Cloudflare/etc you are just adding one more party that can see your requests. If you use DoH, in theory, you are replacing who can see your requests. In practice your ISP can still know what websites you visit thanks to unencrypted SNI or if the domain you are visiting is the only one on that IP (and probably other techniques I'm not aware of). There are many more variables than just DNS requests so if you really don't want your ISP knowing what websites you visit you have no choice but to use a VPN or Tor.