3 ms·
Reading the comments I think it may sound worse than it is. > The canary domain only applies to users who have DoH enabled as the default option. It does not a
by throwaway2016a 3y ago
Reading the comments I think it may sound worse than it is.
> The canary domain only applies to users who have DoH enabled as the default option. It does not apply for users who have made the choice to turn on DoH by themselves.
So basically it sounds like a way for system administrators to disable DNS over HTTPS on their local network when DoH is enabled by default on the machine.
Though I'm not sure what's preventing people from abusing this on public networks and ISP level.
- johnklos 3y agoHow is it abuse? Think about it - something is turned on for you by default, without asking you, which sends all of your DNS lookups to some third party (Cloudflare), which we have no reason to trust (rather, we have plenty of reasons to not trust). So a public network, which you already have to trust enough to use, tells you which DNS servers to use, and there's an implicit agreement and understanding about that. So which is more abusive - this implicit agreement and understanding, or some third party changing your defaults without asking you which then sends all your lookups to a third party you probably didn't even know anything about?
- throwaway2016a 3y agoYou may not have a reason to trust Cloudflare but if DoH is off you are essentialy trusting every router / NAT gateway / anyone capable of packet inspection between you and the DNS server.
- gkbrk 3y agoI think this can be translated pretty accurately as follows. You may not have a reason to trust Cloudflare, a company that you have no contract with, and a company that you do not pay, and a company that blocks most of the internet to people using browsers/extensions to protect their privacy. But if DoH is off, you are essentially trusting your hardware, and your ISP with which you have a paid contract.
- djbusby 3y agoOne must have technical expertise and lots of available time to enforce said contract
- gkbrk 3y agoAnd one must have magical powers to enforce a contract that doesn't exist. Enforcing a hard-to-enforce contract is possible, and such contracts have been enforced before. You will have a more difficult time getting anyone to enforce good behaviour from an entity that you do not pay, and have no contractual relationship with. Especially if that entity is subject to a law that requires them to access not only their data on US servers, but foreign ones as well.
- throwaway2016a 3y agoMy point was this can be done on any network you join... a coffee shop, a coworking space, etc (unless your using encrypted VPNed obviously) so not just your hardware. Additionally, any network along the way can inspect unencrypted packets not just your ISP. Unless your ISP is just one hop from the DNS server you're using (or you use your ISPs DNS). You are trusting potentially dozens of parties... some of whom you have a contract with any many you don't and some of whom may be a malicious government (depending on where in the world you are). But I do agree with, implicitly, what you are saying. I wish the default wasn't Cloudflare and if you change it explicitly it sounds like the canary won't work anyway.
- AviationAtom 3y agoIf you're doing it right then you're using GPO and/or the policies file to lockout the ability to tamper with your preferred DNS settings on browsers in the enterprise.