3 ms·
// 3. what is their privacy policy? can Mozilla get assurances of this? // 4 providers have contractually agreed to abide by Mozilla’s Trusted Recursive Resolv
by throwawayt215 5y ago
// 3. what is their privacy policy? can Mozilla get assurances of this? //
4 providers have contractually agreed to abide by Mozilla’s Trusted Recursive Resolver (TRR) program's policy requirements, so far.
https://wiki.mozilla.org/Security/DOH-resolver-policy#Conforming_Resolvers/ https://wiki.mozilla.org/Security/DOH-resolver-policy#Confor...
CIRA Canadian Shield
Cloudflare
NextDNS
Comcast
I think you need to use the specific DoH URL in the above link to get the contract benefits, but maybe I'm wrong
- ttybird2 5y agoCloudflare's DNS violates this: https://wiki.mozilla.org/Security/DOH-resolver-policy#Blocking_.26_Modification_Prohibitions https://wiki.mozilla.org/Security/DOH-resolver-policy#Blocki... I had a user of my email server complain about not being able to receive emails from "cock.li". Turns out that this happened because I was using dnscrypt-proxy with cloudflare's dns (as it is the default in my distro) and thus the DKIM check was failing because it was not able to resolve the domain as it is being filtered by cloudflare. I changed to NextDNS after that.
- throwawayt215 5y agoI guess it's because the contract is valid only for Mozilla Firefox. cock.li resolves perfectly fine on Firefox with Cloudflare DoH.
- ttybird2 5y agoAre you sure? It does not for me. Although I am using my distro's release of Firefox. I will be trying it on my windows pc with the official FF release later.
- throwawayt215 5y agoSure. Maybe your ISP is blocking the domain or something.
- ttybird2 5y agoI can access it with my ISP, I can also access it with NextDNS (over DoH) and 8.8.8.8. My friends also reproduced my results from their machines. Can you run dig @1.1.1.1 cock.li just in case?
- throwawayt215 5y agoThat command runs fine. No errors.
- ttybird2 5y agoDig does not throw an error when it does not get a result, instead you get an output like this: ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 49352 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ; EDE: 0 (Other): (time limit exceeded) ;; QUESTION SECTION: ;cock.li. IN A ;; Query time: 115 msec ;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP) In contrast with a successful run like ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 21996 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;cock.li. IN A ;; ANSWER SECTION: cock.li. 300 IN A 193.239.85.202 ;; Query time: 159 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP)
- throwawayt215 5y agoGot NOERROR and got the IP of cock.li