8 ms·
> Are things like DNS sinkholes and domain blacklisting still possible with DoH? they aren't, which is part of the reason DoH is implemented in the first place
by luto 5y ago
> Are things like DNS sinkholes and domain blacklisting still possible with DoH?
they aren't, which is part of the reason DoH is implemented in the first place.
- rank0 5y agoCan you expand on this a little more? I do not understand the reasoning here
- Kalium 5y agoThe tools to administer a home network, such as DNS blocking and DNS sinkholes, are the same tools nations use to administer their populaces. If the default in Firefox is to enable blocking and sinkholes for the home administrator's benefit, it will similarly be to the benefit of oppressive administrations. Home administrators who control their endpoints can turn DoH off with relative ease. By comparison, most governments cannot.
- swiley 5y agoIt would be nice if it would check the resolver config files (like the hosts file) with it enabled though. That was a really easy way to block harmful stuff or name things without requiring DNS. Having to choose between encryption and easy configuration is pretty poor UX.
- Kalium 5y agoNaively, that seems like something that could be a very useful configuration option to set! Though I can also see why you might default to having it off if you don't trust the host resolver very much in the country-administering-people case.
- swiley 5y agoYou have to trust the local OS config. No amount of clever application programming will ever let you get around that.
- ZeroCool2u 5y agoDoH makes widespread censorship and surveillance via intercepting plaintext DNS queries much more difficult. Of course, this is just one weapon in the arms race. It doesn't completely protect you, but every bit helps.
- JoshTriplett 5y agoThe vast majority of people don't run their own DNS server, or have any control over the DNS server they use. Most people use their ISP's or organization's DNS server, and have no control over it; instead, it's something used against them. In many cases, that DNS server may do some combination of tracking, redirection to ads, or other things that make it undesirable to use. DoH eliminates one of the last major unencrypted protocols on the Internet, and instead uses an encrypted protocol to talk exclusively to the intended server without the possibility of interception. If you want to talk to your ISP's DNS server, you're free to do so. But that should be your choice, not your ISP's.
- ocdtrekkie 5y agoYep. The entire point is to make it impossible to block ads at the network level. And since ad companies control the application level too, they then have a complete end-to-end ad delivery stack that you can't tamper with.
- donmcronald 5y agoYep. Everything's going to be locked from the bootloader to the screen and you WILL watch the ads. What I think will really happen is the same thing as everything else. They'll use tech to take away features / abilities we have right now and then rent it back to us as a subscription. "OpenDNS is now part of Cisco" Add it up.
- tomjen3 5y agoWe are talking about Firefox, a web browser, that allows you the most control over your computer, has the best adblock technology, on which the author of Ublock origin has said his software runs the best, which comes with built-in anti tracking, which now comes with technology making it harder for public wifi to trick your computer into going to captive portals, often with ads. And somehow you ad this up to making it impossible not to see ads and locked down computers. How?
- ocdtrekkie 5y agoFirefox's primary sponsor is still Google. And whether they are pushing it because of malice or just incompetence, DoH was designed and built by Google to protect ad companies from network security. Implementing it by default is a hostile act, and one Mozilla should reconsider.
- slashdot2008 5y agoi have a pihole and have been worried that DoH would break it. i checked the network settings in firefox and the DoH setting is there but it is disabled. I doubt that chrome will allow one to disable DoH but at least firefox does for now.
- swiley 5y agoYes they are but you'd have to run your own DoH server or follow the instructions to disable DoH like an ISP would (the possibility of which makes one wonder what the whole point is.)
- josephcsible 5y agoOr just use one of the many public DoH servers that already do this.
- swiley 5y agoThe won't block my specific list of websites (reddit.com for example.)
- josephcsible 5y agoDon't NextDNS and OpenDNS both let you do that?
- swiley 5y agoEven if they do, you're now sending all of your DNS queries to some external service. That's a pretty serious privacy violation, even worse than 8.8.8.8.
- josephcsible 5y agoIsn't this what basically everyone does anyway pre-DoH? Most people don't run their own recursive resolvers.
- Tijdreiziger 5y agoNo, pre-DoH people are sending their queries to their ISP, not to a third party.
- 5y ago
- Asdrubalini 5y agoPardon my ignorance, but can’t you simply host your own DoH server where you choose the domains you want to block, which in turn points to a DNS / DoH server you trust? I guess it wouldn’t be more difficult than hosting your own filtered DNS server like Pi-Hole.
- hulitu 5y agoYes you (or we) can. But you need to manually alter the settings everytime a new ff version is out. And other people can not. Brave new world. BTW how is Brave at this chapter ?
- ralphm 5y agoWhy every time? Isn't this a user config that overrides whatever default there is?
- cpeterso 5y agoWhy would you need to manually change your settings every time a new Firefox version is out? Firefox has settings UI to point to the DoH server of your choice and that setting does not get reset by new Firefox versions: https://support.mozilla.org/en-US/kb/firefox-dns-over-https#w_switching-providers https://support.mozilla.org/en-US/kb/firefox-dns-over-https#...
- cuillevel3 5y agoHere's a blog post from someone who uses nginx 'doh-to-dns' to connect their DoH clients to Pi-hole. So, yes you can blacklist domains, as long as you can configure the DoH servers that the client uses.
- AlexCoventry 5y agoI think you left the link out.
- duckmysick 5y agoI believe it's this one: https://www.aaflalo.me/2018/10/dns-over-https-with-pi-hole/ https://www.aaflalo.me/2018/10/dns-over-https-with-pi-hole/
- cuillevel3 5y agoOops, I meant this one: https://www.bentasker.co.uk/documentation/linux/407-building-and-running-your-own-dns-over-https-server https://www.bentasker.co.uk/documentation/linux/407-building...
- iso1210 5y ago> as long as you can configure the DoH servers that the client uses. Which now involves not just getting every machine, but every application on every machine
- depingus 5y agoDevs will just hard cord DoH servers into their products so that you can't block their tracking and ads.
- josephcsible 5y agoThey aren't possible for the network to unilaterally impose on unwilling users. They're still possible if the user actually wants it, by just setting their client's DoH server to one that does them.
- iso1210 5y agoA network suggests a DNS server You can choose to use that server or not If a network intercepts your DNS traffic, you can encrypt it yourself. If you don't trust the network you should be encrypting everything anyway
- josephcsible 5y ago> You can choose to use that server or not If you're not using DoH, a malicious network will just redirect your requests to legitimate DNS servers to instead go to its own.
- LinuxBender 5y agoStill possible. The control moves from your home network, corporate network or local ISP to the default DoH resolvers defined in the browser. This can be changed, but we know most people outside of a corporation will not change this. So in this case, CIRA will be logging DNS requests and sink-holing undesirable domains presumably by Canadian standards. People can still use browser add-ons to block domains, URL's, objects on sites, etc... uBlock is my favorite for this.