24 ms·
Firefox DNS-over-HTTPS
- michaelje 4y agoI went to the effort of setting up a pihole, and pointing all the devices on my network to it. When I saw this notification for the first time yesterday I was a bit annoyed - do I now have to think about every application ignoring OS level settings and using its own?
- fguerraz 4y agoYes, I use ipset on openwrt to block all known public DoH IPs. That is still not enough. You need custom DNAT rules to forward all queries to port 53 to your local resolver (at my home at least, Google and Garmin devices insist on using their own DNS servers)
- denkmoon 4y agoDNS over HTTPS is a trojan horse to allow application developers to subvert the system administrator's DNS policy. Specifically, so that companies like Google, Microsoft, Amazon can ensure that you cannot prevent ads being displayed in their little black boxes (hardware or software). This is dangerous, anti-user, and should be avoided at all costs. DNS over TLS is the correct and appropriate solution here. You can ensure your (Firefox) browser does not use DNS over HTTPS by configuring a canary domain: https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet https://support.mozilla.org/en-US/kb/canary-domain-use-appli... but let's be clear here, nobody besides Firefox is going to respect user choice about using DoH.
- jeroenhd 4y agoDoH and DoT both hide DNS requests from the sysadmins. If the sysadmins want to capture DNS for some reason, they can just provision their own DoH server (I do that with my Pihole) or disable the feature all together with a simple canary domain (https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https https://support.mozilla.org/en-US/kb/configuring-networks-di...) in the local DNS resolver. Although I hate the idea that everything must now be layered on top of HTTPS because shitty middleboxes can't deal with internet protocols, I think Oblivious DOH is superior to simple DoT. It not only provides security, but also anonymity in DNS requests. I'm not sure if that's what Firefox actually implements by default, though.
- jeena 4y agoSo how do you deal with what the parent mentioned that Chromecast will stop using your piholes DNS and just always go directly to Googles?
- jeroenhd 4y agoChromecast doesn't respect any settings and only communicates over TLS (and some local broadcast protocols for compatibility). If you don't like that, don't buy a Chromecast. I've managed to get it to use my PiHole by forwarding all outbound traffic to UDP/53 that's not coming from my PiHole to the PiHole itself through a DNAT rule in Firehol: ipv4 dnat to "${pihole4}" proto udp dport 53 src not "${pihole4}" dst not "${pihole4}" inface not "${world}" ipv6 dnat to "${pihole6}" proto udp dport 53 src not "${pihole6}" dst not "${pihole6}" inface not "${world}" So far, I haven't seen any weird traffic that's trying to bypass this rule, but honestly, I don't really care. Whenever I block any of its domains I just get weird error messages about connectivity problems, or a non-working Chromecast. The real meat is inside the TLS connection anyway, and I can't block that. You can't buy a closed-source, always-online Google product and expect it to let you block it. If I wanted that, I would've disconnected it from the internet or just used a Kodi box instead. We've lost to ability to introspect and filter connections the moment we started switching to TLS. If you don't trust a device, don't install it in your network, that's my take.
- zamadatix 4y agoIf you're on current macOS/Windows/Linux/Android/iOS/ChromeOS you probably just want to configure DoH or DoT at the operating system level so it is done system wide. The other half reading this probably want a "how to force disable" guide instead of a "how to" guide. The automatically rolled out browser specific method described in this article is really directed at users that don't know this is even a choice and probably wouldn't have an opinion one way or the other if they did. Somewhat unrelated but Firefox also supports SOCKS proxying independent of the OS config. Combining this with ssh -D and you can effectively VPN your Firefox traffic out any box you can ssh to, including the DNS requests. This has been both useful for me as a troubleshooting tool and as a simple internet VPN.
- josephcsible 4y ago> If you're on current macOS/Windows/Linux/Android/iOS/ChromeOS you probably just want to configure DoH or DoT at the operating system level so it is done system wide. Indeed. The problem is that a lot of operating systems still don't support it at all yet. > The other half reading this probably want a "how to force disable" guide instead of a "how to" guide. Sadly, yes. And the only reason I've heard for this is that they want to be able to censor or surveil traffic from other people's computers.
- zamadatix 4y agoI'm actually in the "how do I force disable" camp for reasons unrelated to other people's computers. On my personal network I've got an inside view of my domain that will resolve internal services if you hit the resolver from the inside, this breaks if an external resolver is used and it'd be more work for no real gain to set this up as an internal DoH resolver and make sure clients used that. On my work laptop I have a similar need for split resolution in many cases, particularly when connecting to customer's networks. I also have an additional need to be using the same resolution flow as their computers when troubleshooting, if one of their DNS servers is misconfigured I'll never see the issue resolving to an external server. I've not found the browser fallbacks to fully cover the 2 above scenarios and, even for the parts that are covered, I've not seen it be particularly reliable. Particular if you switch networks often. I've also seen people against browsers pushing users to fewer centralized services but I'm not really in that boat myself, I point DNS to 1.1.1.1, 8.8.8.8 anyways. That said I run across a lot of customers that don't understand it's easier to build and enforce a proxy config on a managed fleet than to try to play whack-a-mole with every user packet that doesn't match this policy and try to avoid DoH at the network layer as a result. I don't really expect this to change until security auditors stop accepting these implicit policies as meeting requirements. Outside of finance/government that still seems forever away.
- throwaway81523 4y agoI just got this automatic up/down/side-grade. DNS to be handled by a partner service provider, so they get all my data instead of my ISP getting it? Doesn't seem like an improvement. I think I will turn this off.
- josephcsible 4y ago> DNS to be handled by a partner service provider, so they get all my data instead of my ISP getting it? Doesn't seem like an improvement. It's an improvement in two ways. One, the DoH provider will only know that your IP address looked up certain hosts, unlike your ISP who also knows the association between your real-life identity and your IP address. Two, most ISPs (especially in the US) have horrific privacy policies and practices compared to the DoH servers.
- johnklos 4y agoWe have a financial relationship with our ISPs. What kind of contracts and understandings do we have with Cloudflare? What do we know about them aside from the fact that they protect scammers and spammers? Sorry, but that's not an improvement at all.
- throwaway81523 4y agoIs it known that the partner service provider is Cloudflare? At least that's a recognized organization, instead of a mysterious unnamed one as the Mozilla announcement made it sound. When that happens we have to assume the worst.
- josephcsible 4y agoYes, it is. You can see that in this article from the screenshot in the "Switching providers" section. They also say it explicitly here: https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs#w_what-resolver-will-firefox-be-using https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs...
- 4y ago
- josephcsible 4y agoThe point of DNS-over-HTTPS is to protect users from censorship and surveillance by their network operators. Does anyone have any reason to try to block it on their networks (not just wanting to turn it off on their own devices), other than that they're network operators who want to be able to censor and surveil traffic from other people's computers?
- nobody9999 4y ago>Does anyone have any reason to try to block it on their networks (not just wanting to turn it off on their own devices), other than that they're network operators who want to be able to censor and surveil traffic from other people's computers? I do. You're absolutely correct that some folks want/need to be concerned about censorship/surveillance by their network provider(s). I do not, and if I did, I'd go full on VPN to avoid their intereference/spying. That said, there are various devices on my home network that are not fully under my control like streaming devices and "smart" TVs. That could also, presumably, extend to various bits of software that try connectng to sites of which I do not approve. As time goes by, more and more devices will integrate DNS-over-TLS/HTTPS whose resolver settings are hard-coded and can't be disabled. I want to be able to audit (and block) DNS lookups by all devices on my network. As such, I use both a DNS filter (ala PiHole) and a local recursive resolver. Yes, my ISP can see all the DNS requests my local resolver makes, but then they can see all my traffic anyway. IMHO, DNS over TLS/HTTPS benefits the big DNS providers (since most folks will just use Google/Cloudflare for such stuff), giving them (especially Google) unprecedented access to browsing and other internet application traffic. For me, at least, I'd much rather have my ISP see the cleartext UDP packets that my local resolver generates than give Google/Clouflare a list of every IP address to which I might wish to connect. That's not to say there isn't a use case for DNS-over-TLS/HTTPS, but that's not my use case. Edit: Changed emphasis from local to local recursive resolver.
- josephcsible 4y agoFor devices that aren't fully under your control despite you owning them, couldn't they still do whatever they want by hardcoding the IPs of whatever services they want to talk to, instead of using DNS or anything like it at all? Blocking DoH doesn't fix that problem.
- pabs3 4y agoI wonder when the DNS root servers are going to adopt DoT or DoH, or something that isn't plaintext.
- FreeHugs 4y agoIt is amusing that in Europe, there is this big DGPR drama playing out about websites embedding resources from US companies. Like Google Fonts, Tweets and Facebook like buttons. Yet the browser sends each and every website the user visits to a US company. All in all, I tend to think that it is a net positive. Downside: Now one US companies gets all my DNS queries. But can they stitch them together? I tend to think they can't easily. And will hopefully not keep enough logs to do so later. Upside: My ISP and the cafes and hotels I visit do not get the info which websites I visit. The protection could be made even stronger if the browser would send 5 DNS requests for every IP it needs. So if you visit news.ycombinator.com it additionally sends 4 random hostnames to cloudflare.
- CSSer 4y ago> The protection could be made even stronger if the browser would send 5 DNS requests for every IP it needs. So if you visit news.ycombinator.com it additionally sends 4 random hostnames to cloudflare. I can’t find it now but forever ago there was a tool/project that more or less did this. It would purposefully flood your history with random entries meant to confuse advertisers.
- Tijdreiziger 4y agoIt was called AdNauseam, I think
- sschueller 4y agoUse a non-US DoT or DoH like for example the one provided by the Digitale Gesellschaft [1] in Switzerland. [1] https://github.com/DigitaleGesellschaft/DNS-Resolver https://github.com/DigitaleGesellschaft/DNS-Resolver [2] https://www.digitale-gesellschaft.ch/dns/ https://www.digitale-gesellschaft.ch/dns/
- guu13456789 4y ago... and the DNS-over-HTTPS providers that come with Firefox / Chrome censure DNS as they like, very obvious now due to our east friends news sites being blocked that being said, I use this at my work machine so that the local IT agent cannot access the DNS resolver cache
- snthpy 4y agoI have a Pihole set up as my DNS resolver on my home network. My understanding is that this blocks ads at the DNS level. So if I it anyone in my family enabled DoH this would defeat the Pihole services? Can someone confirm this?
- landgenoot 4y agoYes
- msravi 4y agoYes. Configuring DoH in firefox will make it bypass the OS configured DNS (usually advertised by your router).
- midasuni 4y agoThis is the whole point of DoH
- josephcsible 4y agoYes, DoH bypasses the Pi-hole. If you want to use DoH and still block ads at the DNS level, then instead of using Cloudflare, use someone else's DoH resolver that does block ads.
- lovelearning 4y agoIf you're a dev who uses curl / requests / HTTP libraries, just browser-level DoH isn't enough for ISP privacy or govt censorship evasion. On Ubuntu 18, I installed "dnss" at the OS-level to send all DNS requests as DoH. Currently, it just forwards them to CloudFlare's DoH URL. But I can also install it as a DoH proxy on my remote server if I want to move away from CloudFlare. It works fine and is easily installed without any builds or PPAs. The only problem with it is that I had to disable systemd-resolved first to reserve port 53 for dnss.
- msravi 4y agoI use pihole configured with nextdns DoH as primary upstream server and cloudflare as backup. So all devices connected to the network end up using DoH. Works very well. In addition, if you configure tailscale on your mobole devices, they can still use your pihole+nextdns/cloudflare even when roaming over 4g.
- harry8 4y agoHow does this work with pi-hole? Or it basically doesn't because it bypasses any blocking of the malicious you're performing like that?
- josephcsible 4y agoDoH in your browser will bypass your Pi-hole. If you set up cloudflared on your Pi-hole, then it will do DoH itself, so you could turn it off in Firefox and then get the best of both worlds.
- slim 4y agoburried lede : > We began our rollout by default to Russia and Ukraine Firefox desktop users in March 2022.
- lizardactivist 4y agoForget Cloudflare and Google DNS, and use an independent and private resolver. Both uncensoreddns.org and mullvad.net offer DoH and DoT.
- madeofpalk 4y agoCloudflare an Google DNS are both independent and private, no?
- johnklos 4y agoNo.
- throwaway892238 4y agoThis is objectively a terrible decision. Technologically, politically, culturally. We had a very good design in DNS, and people are throwing it away because they're terrified about the potential that their ISP might use their data. Never mind that Netflix already does it to them when they watch TV, Target does it to them when they buy condoms at the store, Google does it with their mail and search results, ESPN does it to them when they play fantasy football, and Starbucks does it to them when they buy their venti mocha frap. But because Comcast might also know what they do in their private life, we should ditch one of the internet's most important protocols, and give all our data to Cloudflare, a central TCP-based US-owned DNS resolver. Nobody in the world needs DNS over HTTPS. If you actually need to hide your DNS requests, you have bigger problems that you need a real VPN for. This is a unilateral political decision by the people who have the most power over browsers because they have an emotional obsession with privacy, even if it makes technology in general worse.
- klntsky 4y agoI do not agree with you. DoH allows to bypass blocking of HTTPS websites by domain, which is done by a number of authoritarian regimes. > people are throwing it away It is not meant to replace DNS or make it impossible to work.
- rusk 4y agoSounds like what I need is a VPN or Tor in these cases. To such regimes if FF provides a way to bypass their restrictions FF would end up being classed contraband similarly.
- klntsky 4y agoTor is actually worse in this regard. E.g in Russia public Tor bridges are blocked, so you can't connect to it without extra steps. Some public VPNs are blocked too. But DoH makes the price of blocking a single domain too high, for example, if Cloudflare were to use it, the only way would be to block every service that uses CF.
- Animats 4y agoFirefox by default directs DoH queries to DNS servers that are operated by a "trusted partner". That's what I don't want - Firefox offering services. Once you have a centralized server, with a huge number of minor queries passing through it, the operators get uppity. They start thinking they have editorial authority. Someone will decide that the DNS server should censor something. Child porn is the usual excuse, and then, after a while, you can't see sites that mention Tienanmen Square or Ukraine any more. I'm quite happy with Sonic's classic DNS server. It just answers DNS queries and forwards requests to the appropriate upstream DNS server as required.
- asimpletune 4y agoCan I ask what you would prefer? If FF adds an additional choice among the status quo, are you saying you would prefer the status quo minus the additional option of FF?
- ev1 4y agoSonic is a decent provider. This is rare. Most ISPs in the US will sell your queries, use it for marketing, inject fake NXDOMAIN ads, etc.
- zrm 4y agoSo choose a different one. You don't have to use your ISP's. The danger is in everyone using the same one, which is what you get if the browser vendors are choosing for everyone. Better yet, give the browsers a way to detect this (e.g. generate a random domain known not to exist and make sure it gives NXDOMAIN) and switch to the other DNS only if the normal one is broken.
- daneel_w 4y agoI prefer to avoid Mozilla as much as Google. I use DoT (which I think is a better alternative than DoH) against uncensoreddns.org and Quad9.
- josephcsible 4y agoCan you elaborate on why you think DoT is better than DoH? Aside from DoT being easier for an adversary to block (which is really bad since blocking it forces a silent fallback to insecure DNS), what material differences are there between them?
- daneel_w 4y agoI think it's a better choice because it's less complex and avoids "useful features". Bert Hubert goes through most of the points in this talk: https://www.youtube.com/watch?v=pjin3nv8jAo https://www.youtube.com/watch?v=pjin3nv8jAo > Aside from DoT being easier for an adversary to block HTTPS is also TLS. On the surface of things it's just a matter of two different standardized ports. > ...since blocking it forces a silent fallback to insecure DNS That depends entirely on your setup.
- tialaramex 4y agoWhy do you think DoT is better? Notable features DoH gets by being HTTP include: An extra (encrypted) configuration point in the form of a pathname, DNS privacy servers can use this to offer you a distinct feature set e.g. maybe you want them to blackhole ads but not porn, another user wants no porn 'cos they're worried about their kids, and I want full fat. NextDNS offers this I believe. Error messages aren't restricted to what can be expressed in DNS itself. So instead of NXDOMAIN the error can tell me myblanket.example was blocked because it's an advertising source, or that gooogle.example wasn't found but maybe it's a typo and I should try google.example ?
- daneel_w 4y ago> Why do you think DoT is better? I prefer DoT over DoH. I'm not getting into a discussion of "technically better". > ...DNS privacy servers can use this to offer you a distinct feature set e.g. maybe you want them to blackhole ads but not porn No, I don't want any that. I want DNS between my resolver and the remote to do only what it's intended for. I don't want that specific leg of the communication to involve any features, bells or whistles.
- iamevn 4y agoI think encrypted DNS as a default is a good thing and swapping (with a notification to let you know what they did, why, and an easy button to revert the setting) in an update would be great. > We completed our rollout of DoH by default to all United States Firefox desktop users in 2019 Why did this setting change for me today mid-session? Did someone malicious use this functionality to change my settings outside of the context of an update? I don't want anyone to be able to remotely change my privacy settings. Knowing this feature exists makes me extremely uncomfortable and has broken my trust in my browser.
- autoexec 4y agoYeah, I've been wondering this too... I've disabled a lot of things like experiments/normandy and telemetry so I'm wondering what I'll have to find and disable now.
- jrootabega 4y agoSame here. Anyone here have any good arguments for why Mozilla should implement changes like this outside of a version upgrade? I just got the prompt on a version of Firefox that is not the latest version. At first I just tuned it out; it's very easy to think it's some banner on the page annoying you unless you're actively looking for it. Or maybe a notification or location request. I then thought my Firefox installation had been upgraded without my consent, which alarmed me briefly. And I don't mean just arguments focused on benefits to Mozilla, like it's easier for them, it lets them run experiments, etc. I mean arguments why they should, in the process of doing this, take away my ability to make informed decisions as the owner of my computer. If I choose not to upgrade something, it should not change its behavior in a significant way like this.
- dblohm7 4y agoFirefox has a mechanism for off-cycle updates called system add-ons.
- iggldiggl 4y agoOne problem I've found when trying to switch to an alternative DNS provider is that e.g. different parts of Akamai's CDN servers have different peering arrangement with ISPs and Akamai uses DNS for directing you to a server that is well-connected to your current ISP. So when using an alternative DNS server, download speeds for anything hosted by Akamai would always slow to a crawl in the evening because I got directed to the wrong set of Akamai servers.
- tbyehl 4y agoChoose a public DNS that supports ECS. https://en.wikipedia.org/wiki/EDNS_Client_Subnet https://en.wikipedia.org/wiki/EDNS_Client_Subnet
- johnklos 4y ago...and Akamai compete with Cloudflare, so Cloudflare is not in any sort of rush to fix this... When you wonder about motivation, you don't have to go very far to see how this is obviously about money.
- rythmshifter 4y agoIs it possible to configure this to use the same cloudflared redirection I am using for my pi hole?
- billpg 4y ago"Are parental controls enabled?" I wonder how it does that. Will the browser be making DNS requests for playboy every so often?
- sltkr 4y agoThis is described in more detail here: https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https https://support.mozilla.org/en-US/kb/configuring-networks-di... Part of it is doing a test DNS query to a canary domain to see if it's intercepted, but the domain is use-application-dns.net, not an actual adult domain.
- billpg 4y agoWhy would a parental filter modify or otherwise interfere with use-application-dns.net? I'd have thought a filter would pick up the DNS request, see that it isn't on the list of adult-only domains and pass the request along.
- madeofpalk 4y agoI imagine the idea is that any DNS-based filtering tech would also block use-application-dns.net. An ad-hoc spec. Kind of like how captive wifi portals "block" (or allow) canary domains like captive.apple.com so the OS throws the captive portal login dialogue.
- markoutso 4y agoHow hard can it be for Firefox to embed its own recursive resolver that talks only to the root servers? If you are really concerned about privacy that’s the only way to go. Other than that it makes little sense to me to trust one company over another.
- bityard 4y agoWhy do I want an application doing its own DNS resolution at all when that's actually the job of the OS?
- markoutso 4y agoIf you think that users can setup-configure their dns servers then this feature (DOH) is completely useless. I guess the point is valid for users that don't want / are not allowed / cannot configure the dns server of their operating system.
- josephcsible 4y agoIdeally you wouldn't. But until operating systems default to using DoH with a trusted resolver themselves, this approach is the lesser of the evils.
- autoexec 4y agoI'd have less issue with this is Mozilla ran the servers themselves. I already put a lot of trust in Firefox, I have zero reason to trust cloudflare.
- josephcsible 4y agoThis wouldn't solve any of the problems that DoH does, because DNS queries issued by a recursive resolver are themselves in cleartext and so vulnerable to a hostile network.
- deleted 4y ago[deleted]
- beagle3 4y agoDoes anyone know how well modern DoH infrastructure works with geographically specific results? E.g., google.com on any "real" DNS points me to a google proxy on a nearby ISP, usually mine -- netflix also has local ISP boxes. Don't see how this can work unless Cloudflare/NextDNS is all knowing about the world DNS infrastructure.
- pornel 4y agoCloudflare routes DNS requests to its nearest point of presence (through BGP magic, 1.1.1.1 is not a single place).
- flerchin 4y agoI donate $10 a month to the Mozilla foundation, and I see this as: Good, not perfect.
- legrande 4y agoFunny, I reported a bug to Mozilla about their NextDNS offering being mis-configured, and it leaked DNS queries. I turned it on by going to Preferences > General > Network Setting and then fired up Wireshark, and all the queries were sent in the clear, even with NextDNS set to 'Enabled'. They seem to have fixed it. Lesson here: sniff your network traffic and don't blindly trust that DoH is configured properly.
- boesboes 4y agoI see a lot of people who do no like this. And that is totaly fair. I do not want or need this either, I have my own resolver on my pi-hole and why the f whould I want FF to mess with that. However, for 'normal' users, this is actually an important an big improvement imo. You cannot expect everyone to understand how it all works and how to run a dns server. If you can, you might not be the target audience for such features. That being said, I'd prefer my FF without all the 'services' and bullshit. I tried Librefox, but couldn't get it to run. Gave up after 30s. Guess I'm not the target audience for that and I'll deal with disabling mozilla's spam ;)
- sublimefire 4y agoDoH creates a precedent where parents are not able to easily control the internet access for their kids. It is fairly easy to setup the router these days and block porn,gambling,malware,social media. Not to mention the OS level config on devices to use a particular DNS server. Now, we (parents) need some remote management OSS (like in a corporate world). I want to ensure the config of the laptops,tablets,phones does not use DoH but only the DNS of the PiHole. DoH is great but I feel the pain.
- Beta-7 4y agoI am surprised Mozilla is pushing for DoH. I was expecting Google to lead the front since most of their revenue comes from ads and the DNS-level ad blockers are easily defeated by DoH.
- nuker 4y agoWhat is the latest on use of http cookies in DoH?
- jbirer 4y agoI had problems accessing RT from Romania because our ISPs blocked it (something that is uncommon in this country). I chose a DNS server from the Firefox config page and managed to get it. Really great feature.