4 ms·
That's why we need DNS over HTTPS and Encrypted Client Hello to become widely used. Then there would be no way of knowing, as long as Netflix uses the same infr
by stepanhruda 4y ago
That's why we need DNS over HTTPS and Encrypted Client Hello to become widely used. Then there would be no way of knowing, as long as Netflix uses the same infrastructure to serve fast.com and netflix.com
- denton-scratch 4y ago"Need" is too strong. Without going into the arguments against DoH, we don't "need" it, because there is an alternative: run your own recursive DNS. That should be something that a consumer could switch on or off. A default install of Unbound, for example, seems to /just work/. Downside: if you have any kind of home network, running your own recursive DNS probably implies running your own DHCP, which isn't normally a consumer alternative (you could do it using settings on a domestic router, but not if it's crippled or locked-down). Also, DNS caching shouldn't be so effective (but I haven't noticed that effect). Upside: all kinds of problems resulting from relying on DNS servers controlled by others disappear. You're not relying on them any more.
- DanAtC 4y agoRecursive DNS is still unencrypted and would be visible to your ISP
- denton-scratch 4y agoYes, they can observe my queries to authoritative servers. But I didn't claim that running your own recursive DNS guaranteed privacy; I only claimed that it dispelled all problems arising from relying on someone else's DNS recursors. I happen to trust my ISP, BTW; I really just like running my own because I can observe what it's doing.
- stepanhruda 4y agoSo your “alternative” is strictly worse / solving a different problem.
- kevin_thibedeau 4y ago> I happen to trust my ISP, BTW Unless you can prove otherwise you should assume they're selling you out.
- denton-scratch 4y agoI can't "prove" it. But my ISP is a nerd ISP; it's Andrews & Arnold, a rather unusual outfit. If they were caught selling us out, they'd lose all their customers in a flash.
- stepanhruda 4y agoWhat if I want privacy on a non-home network? Huge part of my traffic is over 5G/LTE.
- dspillett 4y agoVPN if that isn't blocked or throttled by your carrier? Though you need a trusted host to act as the other end, or you are just swapping one monitored link with another, and finding that could be a task in its own right depending on your threat model / paranoia level.
- cpv 4y agoThere are some apps (like Intra) which allow you to connect to a built-in (cloudflare, google) or custom DoH server (your own or other providers which support DoH). Nextdns have their own app for this as well. For android 9 or higher there should be an option in network settings.
- stepanhruda 4y agoRight, I specifically use DoH with Cloudflare on my phone. I'm talking about the "we don't need this" reply above, which is a suggestion for tinkerers, not a good recommendation for general population.
- tomatotomato37 4y agoThat wouldn't really help; the network activity signature of a speed test is noticably different from browsing or video streaming, and even if it wasn't, the connection for streaming lasts a lot longer than the test. You could defeat it with a timer.
- stepanhruda 4y agoNetflix can literally implement fast.com to do the exact same operation as when streaming and then measure performance of the stream. Yes you could do a timer, but that would mean e.g. first 30s of all Netflix streams to be much faster and then slow down just in case they were in fact speed tests. Also would be difficult to differentiate between running a speed test vs a stream that gets its connection closed and reconnects. All of this is an order of magnitude for ISPs to deal with than unthrottling traffic for specific domains. It doesn’t have to be perfect, but making it prohibitively more expensive helps a lot.
- gsich 4y agoVery different IPs for me.