6 ms·
The points here aren't technically wrong, but it still feels like disabling DoH would be a reduction in security. For example: > Cloudflare gets all your DNS q
by creata 1y ago
The points here aren't technically wrong, but it still feels like disabling DoH would be a reduction in security. For example:
> Cloudflare gets all your DNS queries.
That's true, but Cloudflare is more trustworthy than my ISP, and probably most people's ISPs.
> Complexity is the enemy of security.
That's true, but that's no reason to go from an imperfect solution to a nonsolution.
> there is DNS over TLS
That doesn't solve most of the issues that the author brought up.
> How does a modern company in the IT business earn money? By selling data.
Maybe I'm naive, but I thought they made money by using all the data they collect for better threat prevention, and from their paid services.
- archerx 1y ago> That's true, but Cloudflare is more trustworthy than my ISP, and probably most people's ISPs. Based on what?
- ignoramous 1y ago> Based on what? The bar is real low, mostly for the fact that ISPs are mandated by law in most if not all countries to track traffic flowing through their pipes. Cloudflare provides relatively better privacy guarantees for the public DNS resolvers it runs: https://developers.cloudflare.com/1.1.1.1/privacy/cloudflare-resolver-firefox/ https://developers.cloudflare.com/1.1.1.1/privacy/cloudflare...
- pacifika 1y agoIn the UK you can typically pick from a dozen ISPs, some of which are more trustworthy
- ortichic 1y agoCan you also choose which company provides the physical infrastructure that connects to your home?
- tialaramex 1y agoIf you live in a city or other urban area, typically you have the option of the decoupled telco (BT Openreach) that more or less everybody has, the entity which bought all the cable television companies (Virgin Media) and usually a fibre-for-purpose Internet company that decided to do your city or region. If you live in a rural area where people are co-operative, there might be a community owned fibre operator plus Opeanreach, otherwise just Openreach. If you live somewhere very silly, like up a mountain or on your own island, your only practical option will be paying Openreach to do the work. Edited to add, Notably: Only Openreach is usable by an arbitrary service provider. So if you want to pick your service provider separately, the actual last mile delivery will always be Openreach. And if they're small it won't just be last mile, Openreach also sell backhaul to get your data from some distant city to the place where the ISP's hardware is, you're buying only the, like, actual service. Which is important - mine means no censorship, excellent live support and competent people running everything, but the copper under the ground is not something they're responsible for (though they are better than most at kicking Openreach when it needs kicking)
- chaz6 1y agoCityFibre is only available through wholesale ISP's. Other smaller alt-nets (such as the one I work for - Netomnia (including Brsk/YouFibre)) is gearing up to provide wholesale access. In the UK there are even aggregators like Fibre Café [1] that makes it easier for ISP's to connect through multiple networks. [1] https://fibrecafe.co.uk/ https://fibrecafe.co.uk/
- chaz6 1y agoIf you are lucky, yes. For example, I have a choice between CityFibre (XGS-PON), Openreach (GPON) and Virgin Media (DOCSIS) as well as 2 different 5G networks. It is rare for a property to only be covered by a single wired network these days in the UK.
- tankenmate 1y agoAll of which have infrastructure already in place to hand over all DNS queries if requested by HMG.
- aleph_minus_one 1y agoAnd you don't believe that Cloudflare has a similar infrastructure in place? :-(
- haiku2077 1y agoCloudflare specifically has infrastructure to prevent that: https://developers.cloudflare.com/1.1.1.1/encryption/oblivious-dns-over-https https://developers.cloudflare.com/1.1.1.1/encryption/oblivio.... It requires some additional setuo, but for example if you're on an Apple device using Private Relay you are using it. You're next argument might be "but how do you know the server is really using ODNS?" You don't. If your security threat profile doesn't allow for this, whatever you're doing shouldn't be using a public internet network anyway.
- chgs 1y agoCF certainly less trustworthy than my isp which is shibboleth compliant. Or my vpn provider. CF issues are dealt with “hope to get a post on HN trending”.
- bigfatkitten 1y agoMy ISP is bound by robust privacy, telecommunications interception and other legislation. Cloudflare, on the other hand is based in a foreign jurisdiction that offers none of these protections.
- zinekeller 1y ago> My ISP is bound by robust privacy, telecommunications interception and other legislation. It really depends on which jurisdiction are you in, unfortunately. US ISPs are selling everything they can hover (including DNS information) to advertisers, and it is impossible to switch to another one unless you're lucky (because the monopoly is essentially maintained).
- waynesonfire 1y agoAnd until TLS is made secure they'll continue to rape privacy by scraping your https traffic.
- immibis 1y agoSo is Cloudflare, which is a US ISP....
- mixdup 1y agoCloudflare is not an ISP. They have other services they sell. Maybe they're selling your data, maybe not. I honestly have not read their agreements and terms, but it's not nearly as obvious that you're the product as something like Google
- ta1243 1y agoSo this company based in the US which provides internet services is not an internet service provider. Given that they are funded and run by the same forces american parastical capitalism provides I would trust them as much as I'd trust google or alphabet. I'll continue to route my DNS to quad-nine over mullvad over my specifically chosen ISP, and everything on my network does that as I can easily intercept and redirect udp/53. The weak point are treacherous devices which use DoH which is a constant fight to block.
- AshamedCaptain 1y ago> That's true, but that's no reason to go from an imperfect solution to a nonsolution. This is textbook politician's fallacy. Yes, it may be preferable to continue with a "non-solution" if the solution proposed is stupid enough.
- deleted 1y ago[deleted]
- creata 1y agoNo it's not. I'm saying don't let the perfect be the enemy of the good. DoH does solve a problem for many people. Many large ISPs will sell your DNS requests, use them for targeted advertising, tamper with responses for various reasons, etc., and so DoH is an improvement over the status quo--not for everyone, but for many users, and I'd guess most users. You're right, DoH might not be worth adopting if it were "stupid enough", but... it's not stupid enough.
- AshamedCaptain 1y agoYour ISP already has all this metadata and more from other sources, so it is pointless to switch to DoH in this case, and if you do you willingly give this metadata to Cloudflare, which (for the majority of users) may even be in a better position to do evil.
- haiku2077 1y ago> Your ISP already has all this metadata and more from other sources If you combine this with ECH and a good blocker, no they do not. That's exactly why Spain is blocking around 60% of the internet during football games now; the ISPs cannot tell which websites and subscribers are pirating football streams.
- AshamedCaptain 1y ago> Spain is blocking around 60% of the internet during football games now [citation needed for the 60% figure] Precisely due to these blocks is why I know that Cloudflare is NOT 60% of the WWW, not yet at least. Certainly, if Cloudflare was serving 60% of the Internet, I would consider switching my DNS to them. But that would be a privacy nightmare for another day (replacing federated ISPs with a single big centralized one? great idea /s). It is not yet the case as of today. In fact, as of today, and even if you have a "good blocker", I, a total noob, have a high chance of reliably identifying which HN news item from the top #30 you clicked from just the addresses: https://news.ycombinator.com/item?id=44219061 https://news.ycombinator.com/item?id=44219061 . Imagine what the non-noobs at your ISP could do.