4 ms·
Agree that analyzing DNS requests is the highest-value infosec practice when it comes to detecting compromises in enterprise networks. Shame that (mostly US-ba
by MarkovChain242 4y ago
Agree that analyzing DNS requests is the highest-value infosec practice when it comes to detecting compromises in enterprise networks.
Shame that (mostly US-based) ISPs realized the same thing (albeit for entirely different purposes), and therefore DoH is now pretty much the default.
And ensuring all DoH requests go through a corporate proxy is... not entirely trivial. On Windows, all major browsers respect their respective group policies, but that doesn't help for mobiles and such.
Shame!
- josephcsible 4y ago> And ensuring all DoH requests go through a corporate proxy is... not entirely trivial. Remember that it's a good thing that it's hard to do that. If it were easy, then the ISPs would just do it too.
- LinuxBender 4y agoI have found it trivial to block DoH/DoT public resolvers and I believe it would be trivial for an ISP to do it as well. My theory around why they don't is the customer support issues and potential negative PR. Adding to that, short of totalitarian regimes there really is not any incentive to block DoH. Totalitarian regimes can simply disable the internet or kick doors down if they think something is up. All other ISP's can still monitor what websites a person visits if they wish as server names in TLS handshakes are not encrypted. If anything DoH/DoT servers remove some load off the ISP's DNS resolvers. In my opinion DoH does not really add much privacy and in reality just doubles the number of organizations that can monitor a persons traffic patterns. Now instead of Comcast it is Comcast and Cloudflare that can analyze ones behavior. This would be a major win for governments should have an agreement in place with a centralized DoH/DoT provider. Instead of aggregating hundreds of ISP logs and having to chase down all the new ISP's, they get everyone that is using any of the popular browsers all in one fell swoop. One place DoH might make sense is in an organization such as a college campus or company that enable fascist firewall rules but have not yet blocked DoH/DoT. Or maybe non-technical parents using a consumer router to block content.
- josephcsible 4y ago> All other ISP's can still monitor what websites a person visits if they wish as server names in TLS handshakes are not encrypted. eSNI/ECH is a thing. > Now instead of Comcast it is Comcast and Cloudflare that can analyze ones behavior. No, because of the above, it'd be just Cloudflare instead of just Comcast, and there's two reasons to like that better: that Cloudflare is more trustworthy, and that Cloudflare doesn't know the real person behind the IP address like Comcast does. > One place DoH might make sense is in an organization such as a college campus or company that enable fascist firewall rules but have not yet blocked DoH/DoT. Or maybe non-technical parents using a consumer router to block content. It definitely does make sense in those places, but they're far from the only ones.
- LinuxBender 4y agoWhat browsers and how many sites are currently using eSNI by default? My understanding is that is a thing only in limited concept. The RFC [1] is still an active draft. Why is Cloudflare more trustworthy with my browsing habits? I have no contract with them and no agreements on what they may do with my internet activity. I have no contract stating how the data is to be used, how long it is to be kept or whom it may be shared with or sold to. For all I know they could sell that data right back to Comcast. Or worse, they could feed it into a ML training program for a social credit system for future use. [1] - https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
- josephcsible 4y ago> What browsers and how many sites are currently using eSNI by default? It's not widely rolled out yet, but it exists and it will be in the future. > Why is Cloudflare more trustworthy with my browsing habits? Because of a comparison of Cloudflare's and Comcast's past track record of privacy-related matters.
- LinuxBender 4y agoI suppose my personal experience varies from that a bit. I agree Comcast has a horribly shady past abusing their customers. Cloudflare's origins are lesser known, likely even to those currently working for them. That doesn't really matter for this purpose I suppose. Former volunteer for their previous honeypot project In the end, I have no contracts with anyone stating how my data may be (ab)used or how long it will exist. So instead of one company potentially abusing my data, now it is two. There is really no way around that other than to not participate. My personal preference is to assume the Only Two Rules. [1] In full disclosure, I use neither of those services for DNS but my I would not expect non-HN people to use my convoluted process combining open source VPN meshes, dozens of unbound caches and dozens on many VPS providers that talk to upstream DoT resolvers with cron jobs that pre-cache thousands of domains in random orders using "shuf" that I do not visit and dozens that I do visit and unbound configured to both override min-ttl and to hold onto 0-ttl records until requested again and running the same cron jobs on my home firewalls that talk to those VPS nodes over DoT and Tinc. [1] - https://www.youtube.com/watch?v=Wxi-IUnCN_8 https://www.youtube.com/watch?v=Wxi-IUnCN_8 [video]