4 ms·
I don't understand why people can't see the dangers of moving everything to DoH. For example if you have a 3000 user network and 2900 of them are using a local
by Randor 6y ago
I don't understand why people can't see the dangers of moving everything to DoH. For example if you have a 3000 user network and 2900 of them are using a local resolver. You have almost no chance of finding those 100 nodes doing DoH without MITM everything over 443.
Someone will probably respond with something like: "Just block the IP address ranges of public DoH resolvers" and that would work for the resolvers we know about.
- userbinator 6y agoI don't understand why people can't see the dangers of moving everything to DoH Because "more security" is hard to argue against. The huge corporations who ultimately want to take control of the population have realised that, and are using that excuse to get in bit by bit.
- creata 6y agoHow will DoH help "huge corporations... take control of the population"?
- userbinator 6y agoFirst they take the DNS queries. Then they start routing the rest of the traffic through their servers, while advertising how it's all "for your privacy and security", of course. There's another article on the front page about how these companies already wield immense power: https://news.ycombinator.com/item?id=25802366 https://news.ycombinator.com/item?id=25802366 To be clear, I'm not against the principles behind DoH, and think traffic going from the local network into the Internet benefits from encryption; I'm against how it's being implemented at the application-level and its subversive nature.
- creata 6y agoThat's fair enough, but in the short term, Cloudflare is more trustworthy (and tolerant of free speech!) than my ISP and government. Is there an initiative in which I have to trust none of these parties?
- heavyset_go 6y agoDNS-based ad blocking worked pretty well, and DoH breaks that.
- MacsHeadroom 6y agoYou can reroute DoH to your own resolver. If you have a trusted wildcard certificate on the device you want to reroute DoH for this will work 100% of the time. If you don't have a trusted wildcard cert on the device in question it usually will either not care or will fall back to unencrypted DNS.
- nobody9999 6y ago>Because "more security" is hard to argue against. The huge corporations who ultimately want to take control of the population have realised that, and are using that excuse to get in bit by bit. But in reality, DoH doesn't really provide "more security." All it does is obfuscate DNS queries. If you're concerned about ISP tracking, DoH doesn't really help with that at all since the ISP can see where you're going just by looking at packet headers anyway. And the Googles and Facebooks of the world love DoH because it bypasses PiHole style ad/tracking blockers. The appropriate solution is to use PiHole (or PiHole style blocklists) in concert with a local recursive resolver (or an external resolver that supports DNS-Crypt), not to obfuscate your DNS requests, allowing all the ads/tracking/spying connections to proliferate. It's not a perfect solution, but it's a much better solution than needing to implement one or more ad/tracker blocking solutions on every single device on your network.
- seanieb 6y agoIf you’ve got 3000 nodes on your network without inventory, logging and configuration control on each of those devices you’ve already lost. You don’t have a secure network, at best you’ve got a guest network at a cafe.
- Randor 6y agoAn estimated 18,000 companies were affected by the SolarWinds incident. Many of those companies had excellent inventory, logging and configuration control. You simply cannot detect DNS over HTTPS in the network without performing MITM.
- seanieb 6y agoReally, you can’t detect that if you’re on the machine?... and if you’re not on the machine or its acting differently to what the logs show. Isolate it until you can investigate.
- Randor 6y agoActually, no you could not detect that even from the machine performing the DoH. You could probably detect it if you attached a debugger and set a breakpoint on the resolve functions being used. May I ask what you do for a living? Why even comment on things that you don't fully understand?
- seanieb 6y agoI'm a security engineer. It's pretty much my thing. I'm taking about logging it on the machine, that's not owned...and yes you too can do it... I'm doing right now. Even on my raspberry pi. The detection part I think you're misunderstanding is that you need to compare what the machine is logging and what it's actually doing, by looking network traffic, etc. Looking for parallax, differences between the two.
- Randor 6y ago