15 ms·
Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period
- saurik 6y agoOperating systems can and should implement DoH, not every single individual application (which can then decide to use poorly chosen servers and will have to get updated in the future for whatever the next spec might be). That the people who make operating systems put so little effort into this stuff that application developers feel they need to take this into their own hands is a travesty :/. (This is particularly annoying given that it is already the case on every operating system that if you want to use DoH and choose your DNS server you can easily do that as long as the software in question lets you by using the system resolver; it makes absolutely no sense to embed and hardcode this functionality into every app.) (For more detailed complaints and arguments on this topic, I wrote a long comment about it a year ago.) https://news.ycombinator.com/item?id=21701808 https://news.ycombinator.com/item?id=21701808
- Santosh83 6y agoIs there no space between "operating system" and "applications"? How about a group of established hackers with expertise get together and create an open source, system-level, DoH service which can be made easy to install on the different mainstream OS (Windows installers/store/chocolatey, MacOS app store, Linux repositories, Google Play)? Is this asking for too much coordination among parties with disparate interests?
- saurik 6y ago(I am wondering if the parenthetical I added a minute after I left my original comment wasn't there when you left this reply, but I go into detail on this topic in the linked comment: it already is the case that on every operating system you can do this and in fact people already have... as an example, if you want to use Cloudflare DoH, install their app!)
- octoberfranklin 6y agoThat already exists, it's called dnscrypt-proxy.
- simias 6y agoI agree with you but I just... gave up. The web ate the net, the browser is the new OS. It's silly, it's lazy, it's inefficient, it's everything I dislike about software engineering but at this point it feels like preaching in the wind. I just try to ignore it, keep writing low level code and if someday I can't find a programming job outside of web technologies anymore I'll just become a shepherd in the mountains or something. I'll make cheese.
- saurik 6y agoYou made me feel a lot better, actually (I'm serious). <3 Maybe one day I will open the sandwich shop I sometimes threaten to leave software for, and I can buy your cheese. (I know that is a horrible business, but there was a great article I read 15 or so years ago about a developer quitting software to open a hot dog stand, and he seemed so happy about it.)
- rsj_hn 6y agoBoth of you have renewed my faith in humanity. It means a lot to run into a kindred spirit.
- basicneo 6y agoI'm also a bit disheartened by the direction of the web. Emacs has been a decent haven for me in my search for privacy, interopability, programmability: my user agent.
- dhimes 6y agoIt'll probably bounce back. We've been here before, when computing was centralized and everybody logged into the mainframe. Then it turned out that to have independent computers gave users a huge advantage and helped control costs. Now, we're back to centralized systems- and I couldn't believe it when I watched the shift: What first caught my attention that this could get serious was gmail. Then g-office (whatever they called it then). Meanwhile a whole host of other services started. I was developing a desktop app because I still wasn't convinced that people wouldn't prefer having their software and data "in hand," as it were. I expect a new advantage will emerge and we'll want our machines and data back.
- oefrha 6y agomacOS 11 and iOS 14 already added support for DoT and DoH. See https://github.com/paulmillr/encrypted-dns https://github.com/paulmillr/encrypted-dns.
- saurik 6y agoAs did Windows (I saw this as I read over the last six months of changelogs a few days ago)... so why exactly is this a thing Firefox is doing again? :/
- mmwelt 6y agoRight, it looks like it should be coming soon to Win10 2021H1: https://www.bleepingcomputer.com/news/security/microsoft-adds-windows-10-dns-over-https-settings-section/ https://www.bleepingcomputer.com/news/security/microsoft-add...
- shawnz 6y agoIt works in Firefox today, whereas Microsoft wasn't even talking about DoH before Mozilla started pushing it.
- gruez 6y agoSame for android https://blog.cloudflare.com/enable-private-dns-with-1-1-1-1-on-android-9-pie/ https://blog.cloudflare.com/enable-private-dns-with-1-1-1-1-...
- nitrohorse 6y agoShameless plug: DoH configuration profiles for several more DNS providers can be found here: https://gitlab.com/nitrohorse/ios14-encrypted-dns-mobileconfigs/-/tree/master/mobileconfig https://gitlab.com/nitrohorse/ios14-encrypted-dns-mobileconf...
- pimeys 6y agoCan DoH be used to bypass home DNS servers, such as the pihole?
- CarelessExpert 6y agoBecause DoH is implemented in the browser and bypasses the OS resolver configuration, it will specifically break things like pihole. The correct solution is a) do this at the OS so users can configure the behaviour, b) add support to pihole or similar for making DoH requests out to somewhere like CloudFlare, c) also add support for receiving DoH requests for those people using a pihole over untrusted networks.
- pimeys 6y agoThat's what I've figured out too. A while ago I started blocking port 443 to known DoH servers to prevent any machine from internal network bypassing the pihole. I expect televisions, smart lights and many other IoT devices to start using DoH to be able to track the users with pihole installed...
- Datenstrom 6y agoIs there a comprehensive list to block somewhere? I would like to do the same.
- LinuxBender 6y agoComprehensive, no. There are growing numbers of git repos of DoH names. [1] [2] [1] - https://github.com/bambenek/block-doh https://github.com/bambenek/block-doh [2] - https://github.com/Sekhan/TheGreatWall https://github.com/Sekhan/TheGreatWall
- deleted 6y ago[deleted]
- shawnz 6y ago
- hannob 6y ago> Operating systems can and should implement DoH I see a comment like this basically every time something about DoH comes up. What I haven't seen: A plan how this should be implemented, a proposal to OS vendors and developers, ideally with patches. This raises a few questions. How should the OS decide which server to use? It obviously can't be DHCP, because that's not a secure thing to begin with. How does this interact with things like captive portals if you have a disconnect between the DNS functionality and the gui application? Do you have good answers for these?
- detaro 6y agoThe questions also apply to browser implementations, don't they?
- hannob 6y agoSome do, some don't. For example the captive portal issue, browsers can try to connect without DoH to a captive portal test page and provide a special non-DoH login tab. You can't do that on the OS level. You could create some interaction between the browser and the OS, but that's nontrivial and needs a solution.
- Spivak 6y agoSure you can! iOS, Android, and GNOME/NetworkManager just open up a webview to handle the portal. I’m sure others do too I just can’t say for certain.
- zinekeller 6y agoWindows: Network Connectivity Status Indicator (NCSI) will ping www.msftncsi.com on older versions (8.1 and lower) or www.msftconnecttest.com on newer versions (10), and then prompts to open the web browser. Since IE/Edge will be always there, it works. macOS: same as iOS (a dedicated window pinging www.apple.com). Firefox: Detects detectportal.firefox.com and asks the user if the want to access the captive portal. Android: Detects connectivitycheck.android.com on Android 5 and connectivitycheck.gstatic.com on Android 6+. I don't know if it applies to all phones, but I'm sure (that except for phones on Android One or Nexus/Pixel) Samsung also does this for phones outside of China.
- josephcsible 6y ago> Operating systems can and should implement DoH, not every single individual application I agree that it would be better for DoH to be done in the operating system than in applications, but the reality is that today, operating systems don't do this, and it's better to do DoH in applications than to not do it at all.
- vetinari 6y agoDoT or DoH are supported in Android (9+), iOS (14+), Linux (systemd-resolved, stubby, other resolvers), macOS (11+) and coming to Windows in 2021. So what exactly having separate implementation in apps achieves? That is, except for the possibility of mismatched configuration between such applications and the OS, leading to hard to debug problems?
- josephcsible 6y agoDoT is not DoH. Since it uses its own protocol and port, it's easy for networks that want to do censorship or surveillance to block it. Of those platforms that do support DoH, how many of them have it on by default, rather than requiring the user to know it exists and turn it on?
- vetinari 6y agoNo DoT is not DoH. They both are blockable; DoH servers must use either well-known IPs, or to be bootstrapped by the plain DNS. First one you can block as well, the second you can filter. > Of those platforms that do support DoH, how many of them have it on by default, rather than requiring the user to know it exists and turn it on? Being off by default is a feature. Those road warriors that do not trust their coffee shops can turn it on if they want it, but elsewhere it causes nothing but trouble.
- josephcsible 6y ago> DoH servers must use either well-known IPs, or to be bootstrapped by the plain DNS. The easy solution is for the well-kmown IP to be in the same pool that a major CDN uses, so it can't be blocked without major collateral damage. As for being off by default, that's absolutely not a feature. Basically nobody who's non-technical will ever turn this on, even though it will improve privacy for no downside for most people. What "trouble" does it cause anyway?
- detaro 6y agoFrom your linked comment, I would disagree with "web browsers decided that they didn't like end users being able to have this control". They don't like the default that requires users to make an active change to the get "upgraded", without ever being prompted so, not that the user can control it, and believe that in that situation, giving it a push is justified. See e.g. Chrome's policy: it checks if the configured DNS server also has a known DoH option, and if yes uses that.
- danShumway 6y agoRight, it's not about taking away user control, because users have the same exact level of control that they had before. Firefox/Chrome still offer all of the same customization options, and you can even turn off DoH entirely. What it is about is that the defaults for pretty much all OSes are bad. Maybe if we lived in a world where DoH was shipping by default enabled in Linux/Mac/Windows and set to something private like Cloudflare, it would make sense not to even provide browser options at all. But as it stands, the current solution (while a little unintuitive and hacky) give you the best of both worlds. If you're a normal user, you get secure defaults. If you're a power user, you can go into Firefox and point at your own DoH provider, or turn off DoH entirely if that's what you want. And if you're an admin deploying Firefox on a network, you can deploy it with a custom profile that sets its internal DoH/DNS settings to whatever you want.
- eikenberry 6y ago> See e.g. Chrome's policy: it checks if the configured DNS server also has a known DoH option Do you know of any references that describe how it determines if the DNS service offers a DoH option or not? I can't find anything more than vague descriptions.
- detaro 6y agoThey maintain a list. See https://docs.google.com/document/d/128i2YTV2C7T6Gr3I-81zlQ-_Lprnsp24qzy_20Z1Psw/edit https://docs.google.com/document/d/128i2YTV2C7T6Gr3I-81zlQ-_... for information about the inclusion process and criteria and for the list in source code form: https://source.chromium.org/chromium/chromium/src/+/master:net/dns/public/doh_provider_entry.cc https://source.chromium.org/chromium/chromium/src/+/master:n...
- Someone1234 6y agoWhy not both? You're essentially arguing that more flexibility is bad without real justification. Per application DNS/routing (split routing) is something most Operating Systems don't support today (or setting it up is incredibly complex). Giving this kind of flexibility might open up a future where a competitor to ICANN-DNS could exist, and users could dogfood it via single browser/window/tab instead of having an all-or-nothing situation as per today. But let's throw out incredible new capabilities that allow user flexibility/choice because it is different to how it was historically done.
- zerolog 6y agoFull Linux system DoH/DoT resolver: https://firejaildns.wordpress.com/ https://firejaildns.wordpress.com/ and a survey of public DoH servers: https://firejaildns.wordpress.com/2020/09/22/a-survey-of-public-dns-over-https-servers/ https://firejaildns.wordpress.com/2020/09/22/a-survey-of-pub...
- n0nc3 6y agoIs it possible to add root CA's for DoH only, so that I can intercept requests at the gateway and terminate the TLS connection there? Can anyone link to the part of the source tree containing their DoH implementation? I would like to test whether it is possible to distinguish Firefox DoH from unbound.
- 1vuio0pswjnm7 6y agoTo summarise, there is nothing inherently wrong with DoH (serving DNS RRs via HTTPS), but there is something inherently wrong with enabling applications to ignore the user's OS DNS settings by default and perform their own DNS resolution, whether via DoH or otherwise.
- ohazi 6y agoWe should assume that this ship has already sailed for user-hostile applications and devices, and start working on mitigations. i.e. Smart TVs will do this to get around pi-hole style ad blocking.
- 1vuio0pswjnm7 6y agoWill these user-hostile appllications and devices allow you to set the gateway? As long as you can use an OS of your choice on the gateway you should be able to control routing, including DNS.
- j15e 6y agoCool but ISP and others can still spy on IPs you make requests to and simply ask for reverse DNS of that IP to still get a good idea of what you are doing? Not sure how we could really achieve 100% privacy from the ISPs.
- pilif 6y ago> ask for reverse DNS of that IP to still get a good idea of what you are doing these days, this will be mostly some *.amazonws.com domain.
- EQYV 6y agoIsn't this more to prevent ISPs from modifying the results of your DNS queries? Also, in the future when we get encrypted SNI, users of websites behind CDNs like CloudFlare or similar (where the website you are visiting will not be discernible from the IP you're connecting to) will benefit from DoH + eSNI.
- octoberfranklin 6y agoAnother goal is to deal with the problem of "no log" VPN providers being forced to tag all internet-bound traffic on port 53 with the customer IP it originated from. This has evolved into the universal compromise, since the VPN provider still gets to claim that they themselves aren't doing any logging. But of course their upstream ISP is now easily able to do so. This is why mullvad intercepts all DNS queries (even to 8.8.8.8 or 1.1.1.1). Try using OpenNIC from behind mullvad: you won't get the extra TLDs. Logging DNS makes it easy to selectively deanonymize people. All you have to do is get them to browse to a website that resolves a weird domain name.
- throwaway525142 6y agoWhere can I read more about VPN providers tagging internet-bound traffic on port 53 with the customer IP address?
- 6y ago
- kingludite 6y agoFor a good while DoH bypassed the piratebay block but I just tried it on this windos box and its just blocked on the ISP level. I can get torrents just fine ofc. More curious how Ziggo is intercepting the requests.
- jorams 6y agoZiggo and XS4all also have to block their IP addresses. Not sure if Ziggo has a page about this, but the one for XS4ALL is rather comprehensive: https://www.xs4all.nl/geblokkeerd/ https://www.xs4all.nl/geblokkeerd/
- quicksilver03 6y agoI don't have a specific position on the use of DoH, but from a personal point of view I don't like that an application makes this choice for me and sends DNS traffic to providers I might not trust. However, as a system administrator, I don't see in Firefox the equivalent of dig and nslookup: if a user reports an issue with Firefox, how can I ask him to verify which IP address a domain name resolves to? If I ask for a nslookup or dig result, I can no longer be sure that the OS resolver is giving the same answers that Firefox is returning.
- Spivak 6y agoYou can ask the user to go to about:networking#dns and it will show Firefox's internal DNS cache. This is actually much more user-friendly today than asking them to open a terminal.
- EvanAnderson 6y agoGrizzled sysadmin / desktop admin perspective here: I can't easily remotely interrogate a user's Firefox process, as you describe, like I can w/ the OS by remotely running "dig", "nslookup", etc, on the user's computer. With the Firefox model I have to interrupt the user and ask them to become an active part of the troubleshooting process. I'd prefer fixing the problem "behind the scenes" without engaging the user, except to let them know when the problem is fixed. I consider it vastly more "user friendly" to enable support personnel to solve problems w/o distracting the user. I don't think very many developers consider that use case. Tools that enable "concierge" support for VIPs, executives, Customers who will pay more to be doted-upon, etc, is a valuable attribute in software to me. Moving toward user self-service is laudable, but not if it's at the expense of dedicate support personnel's capabilities. In my experience, at least, the satisfaction and praise users express from having issues resolved without bothering them has been significant.
- quicksilver03 6y agoThanks, that is useful to know. I will add it to our standard troubleshooting procedures.
- 6y ago
- firebird84 6y agoWhat's the issue with having TLS-based authoritative lookups? I know it seems out of scope for what Mozilla's asking, but it seems like the missing piece of the puzzle to me. It's great if your recursive resolver is trusted (maybe you trust cloudflare or nextdns), but what if you don't trust anyone and want to run your own TRR? From what I can see from my own TRR the queries to authoritative DNS are sent in the clear... Edit On further thought, I realize that querying myanimememes.com's authoritative DNS CAN reveal which site you're interested in, but I believe most sites delegate their authoritative DNS these days to third parties.
- Spivak 6y agoI don't know if this is a solvable problem that doesn't require boiling the ocean. Opportunistic TLS would work fine but if the authoritative server for some domain doesn't do TLS then you're kinda stuck.
- tristor 6y ago> but what if you don't trust anyone and want to run your own TRR? You can do that today. Run your own DNS server w/ DoH as an endpoint (dnscrypt-proxy provides an avenue, you can also use nginx to do this). Then have enterprise policies on your network to point DoH clients to use this resolver.
- firebird84 6y agoThe problem is if your TRR can be associated with you, then outgoing queries to authoritative servers can be tracked.
- fanf2 6y agoThere are a bunch of awkward constraints and trade-offs that make it difficult to do DNS-over-TLS to authoritative servers. I have some work in progress trying to write a reasonably comprehensive analysis of how to go about it (I have been waiting years for someone else to and finally lost patience...) https://mailarchive.ietf.org/arch/msg/dns-privacy/Fv91jt_n2-xLKrNidhcxYDFF4-Y/ https://mailarchive.ietf.org/arch/msg/dns-privacy/Fv91jt_n2-... https://github.com/fanf2/draft-dprive-adot https://github.com/fanf2/draft-dprive-adot
- peterwwillis 6y agoWhy do people use DoH? - they want DNS over TLS [multiple reasons why]. - they want to work around "problems" in the architecture of DNS. - they want to force new functionality [read: protocol changes] on users without other DNS infrastructure adopting it. - they can. Are there lots of problems with DoH? Yes. Are we ignoring them all so we can get the above? Yes. If you love privacy more than freedom, DoH is great. If you want the internet (and local/private networks) not to resemble America Online, DoH should frighten you.
- egberts1 6y agoI concur. Not sure why OC got downvoted but I do have a whitelisted Piehole at my home gateway in which to ensure that DNSSEC is clean AND that DNS nameserver is a well-known vetted one. And DoH is harder to block once they go port 53 or https “incorrectly”.
- belorn 6y agoThis article focus a lot on the technical and operational aspects of DNS and DoH, and only a single sentence about Trusted Recursive Resolver and a link. The trust model in this change for improved security do not sit in the technical and operational aspects of DNS and DoH (assuming we trust the math involved in encryption that we already use for things like https). What the model depend on is the Trusted Recursive Resolver, and if we find those third-party to be more trusted than other alternatives. Mozilla is however not doing much work to convince and explain why that program should be trusted. Who verify that the logs and commitments are followed through? What is the consequences if someone fails? How can the individual user who is giving away their private data exercise control and agency? In the linked document the only answer that I can find is this: The decision of who to include in (or remove from) Mozilla’s Trusted Recursive Resolver (TRR) program is at Mozilla’s sole discretion. I personally do not think that is enough for me in regard to my own data. Where I live (EU) I at least got GDPR to use if my ISP decide to go rouge with my data. I also got a contract with the ISP. In additional my country have a few different government agencies that in theory could jump in. Neither of those would be an option if the data is shipped over seas.
- tristor 6y ago>Who verify that the logs and commitments are followed through? https://wiki.mozilla.org/Security/DOH-resolver-policy https://wiki.mozilla.org/Security/DOH-resolver-policy Mozilla publicly lists the policies which TRRs contractually agree to. In addition to the above, the contracts (some of which have become public) also contain third-party audit requirements. > What is the consequences if someone fails? They lose their TRR status, presumably. > How can the individual user who is giving away their private data exercise control and agency? DoH is surfaced in Firefox, you can choose not to enable it, or you can choose to configure it to explicitly use any DoH endpoint your choose. On my network I use a Pi-Hole which talks to DoH on the backend and everything on my network is forced through the PiHole and all other DNS/DoH is blocked. You can use similar mechanisms, and Firefox surfaces preferences for DoH. Just like any other decision, a sensible default which serves users needs to be made, and advanced users can configure things. Firefox chooses the sensible default of using encrypted DNS to trusted resolvers for users, and if you want to do otherwise, you are free to do so. Nothing removes your agency as a user. > I personally do not think that is enough for me in regard to my own data. Where I live (EU) I at least got GDPR to use if my ISP decide to go rouge with my data. I also got a contract with the ISP. In additional my country have a few different government agencies that in theory could jump in. Neither of those would be an option if the data is shipped over seas. Nothing in the current implementation ships data outside your jurisdiction. DoH is only enabled in the US pointed at a US-based provider (CloudFlare). There are numerous providers in the EU that may sign up to the TRR program as Mozilla gets to the point of rolling out DoH in Europe. This comment period gives them an opportunity to get feedback prior to getting to that point. I think perhaps you should send them your feedback directly.
- egberts1 6y agoDNS-over-HTTPS needs to die in a fire. There’s absolutely no way for home gateway/DNS to defend against malicious use of DNSSEC proper through DoH at application level.
- detaro 6y ago> defend against malicious DNSSEC what does that mean?
- iso1631 6y ago> DNS-over-HTTPS needs to die in a fire. Sadly not going to happen
- tptacek 6y agoDNS-over-HTTPS has protected more people in just a couple years than 25+ years of DNSSEC standardization attempts. DNSSEC is moribund; meanwhile, it's not a bad bet that most DNS lookups in 5 years will originate over DoH.
- blissofbeing 6y agoIf you are on BigSur and would like enable DoH for a variety of providers I would check out https://encrypted-dns.party https://encrypted-dns.party there is pre-made profiles for many. All open source.
- antman 6y agoWell after Firefox 69 DoH is overriden by laptop's company policy so effectively if one wants DoH always on and free use of addons, 69 is the last usable version.
- protomyth 6y agoSo, with Chrome and Firefox having decided to bypass anything set on a given network, how exactly do people propose libraries and schools that are required to block site do so?
- unixsheikh 6y agoI almost look forward to the day when it all blows up in the face of those who thought that all of these, in reality economical driven half-baked solutions - disguised as privacy or security, end up causing such a break down, that nothing works any longer. The amount of sheer stupidity that goes into the "modern web" is just mind bugling. DoH does absolutely nothing that helps privacy since the destination IP address is always clear and DoH only obscures that which it never should have touched with in the first place. I have just about had it with the IT industry and the modern web!
- danShumway 6y ago> DoH does absolutely nothing that helps privacy since the destination IP address is always clear There are multiple situations where destination IPs are shared across multiple websites, and DNS blacklisting is a common censorship technique in multiple firewalls and ISP blacklists. This take is just completely wrong. Of course DNS records should be handled via HTTPS, of course it's a bad idea to do DNS via plaintext. This shouldn't be complicated, why are we still fighting over whether or not encrypting personal data in transit is a good idea? I have seen more people on Hackernews than anywhere else on the entire web bash HTTPS encryption, and I genuinely do not understand how this forum, of all places, can be home to such a bad security take. Stop designing and advocating for Internet protocols to be monster-in-the-middled!
- unixsheikh 6y agoYeah, let's start feeding our mail, ftp, ntp, and everything else over HTTPS as well now we're at it! DoH is DNS done completely wrong. It's the worst patch solution to a problem that should have been solved correctly long ago!
- danShumway 6y ago> Yeah, let's start feeding our mail, ftp, ntp, and everything else over HTTPS as well now we're at it! ...yes? Holy crud, this is practically the most basic principle in security. If you don't want somebody to read it, encrypt it. This is exactly why we don't use email, unencrypted ftp, or SMS for anything that needs security or privacy. Don't send important information over plaintext!!
- eikenberry 6y agoWhat I'd like to see would be a roving/untrusted-network setting. Something easy to flip on/off when you move from home/trusted networks to remote/untrusted networks. With hooks for plugins to be written that let you write rules for flipping it on/off automatically. Instead of making the decision for people, make it a nice feature for then to use as they see fit. As toggleable feature, it could provide options for not just DoH but for VPN usage, TOR, maybe other things.
- rasz 6y agoWanted: Firewall blocking all traffic directed at IP addresses not obtained from OS DNS resolver.
- charliebrownau 6y agoFirefox cant be trusted anymore, why should any logical and reasonable person keep using corporation driven software Open source , alt tech and self hosted is the future