News: 1589957709

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google rolls out pro-privacy DNS-over-HTTPS support in Chrome 83... with a handy kill switch for corporate IT

(2020/05/20)


Google released Chrome 83 on Tuesday after skipping version 82 entirely due to coronavirus-related challenges, bringing with it security for DNS queries, a revised extension interface that developers dislike, and a few other features.

The latest iteration of Google's browser implements DNS-over-HTTPS (DoH), a way to prevent domain-name queries from being observed on the network, between the browser and the DNS server, at least. Traditionally, DNS queries and replies sent using TCP or UDP are not encrypted, even when internet users are interacting with websites over an encrypted HTTPS connection.

DoH was proposed to improve privacy and security by wrapping TLS encryption around the DNS queries that convert human-friendly domain names, like theregister.co.uk, into network addresses computers can connect to, such as 104.18.5.22.

Google has been testing DoH [1]since Chrome 78 last year, and is now rolling it out proper. Mozilla has been doing the same in its Firefox browser, and in February made DoH available [2]to US Firefox users by default.

Not all smiles and sunshine

The technology remains controversial because some people and organizations expect or demand less privacy in certain scenarios.

Paul Vixie, CEO of Farsight Security and developer of several DNS protocol extensions, has [3]argued for DNS-over-TLS (DoT), an alternative query protection protocol because it can be blocked by firewalls and controlled by systems administrators.

Cloudflare [4]contends DoT is better from a network security perspective while DoH is better from a privacy perspective. The fact DoH provides corporate IT administrators with less visibility into network traffic isn't ideal when oversight is desired, it noted.

It's also not ideal for business models that benefit from network traffic snooping. Last summer, the UK Internet Services Providers’ Association nominated Mozilla as the internet's [5]2019 villain of the year due to concerns its DoH implementation would bypass British internet filters and parental controls. Though the trade group backtracked, both Mozilla and Google have had to convince lawmakers in the US and UK that DNS privacy won't lead to the unrestrained transmission and receipt of unlawful content.

DNS-over-HTTPS primarily stops ISPs and others on the network path snooping on DNS queries to hit subscribers with targeted ads based on the sites they've visited, though it has other benefits. For instance, it stops miscreants on the network path silently tampering with domain query results to redirect people to password-stealing imitation websites, or unexpectedly blocking look-ups. It also reassures the browser it is speaking to the DNS server it was expecting.

Enterprise excepted that is

Aware of the needs of corporate network administrators to have visibility on their users' activities, Kenji Baheux, Chrome product manager, said in a [6]blog post that Chrome will disable DoH in managed environments that declare relevant enterprise policies.

Microsoft joins Google and Mozilla in adopting DNS-over-HTTPS data security protocol [7]READ MORE

"We’ve also added new DNS-over-HTTPS enterprise policies to allow for a managed configuration of Secure DNS and encourage IT administrators to look into deploying DNS-over-HTTPS for their users," said Baheux. "We believe that our approach strikes a good balance between moving security and privacy forward and maintaining user expectations."

Chrome 83, initially available for Chrome OS, Windows and macOS, with Android and Linux updates coming soon, will automatically activate DoH if the user's current ISP supports it. Users can also configure a secure DNS provider in the Advanced security menu, or disable it completely.

Google's Chrome developers have reworked various browser Privacy and Security settings menus, to make cookie management and sensitive permissions like location, camera, and microphone access more easily accessible. Finally, Incognito mode will block third-party cookies by default.

Also, the “Clear browsing data” control has been moved to the top of the Privacy & Security settings menu "because many people regularly delete their browsing history," explained senior product manager AbdelKarim Mardini in a [8]blog post .

A Safety check section has been added so that Chrome users can click the "Check now" button to see if any of their Chrome-stored passwords have shown up in Google's database of publicly exposed credentials.

Google's extension issues

The browser also supposedly checks for compromised extensions, presumably those flagged by Google after days or months of misbehavior – the Chrome Web Store [9]hasn't been known for catching malicious extensions before they can do harm, though that's a goal of the company's ever tightening developer rules and [10]Manifest v3 API hobbling .

The update adds a new puzzle icon in the Chrome toolbar to access a reworked extensions menu. "It’s a neat way to tidy up your toolbar, and gives you more control over what data extensions can access on sites you visit," said Mardini. "With this addition, you’ll still be able to pin your favorite extensions to the toolbar."

But Chrome no longer pins extensions to the toolbar by default, a change of convention that hasn't gone over well with Chrome extension developers. When Google initially discussed the revised extension management interface, those making extensions [11]objected because requiring users to take action to pin an extension so it's always visible makes interaction less likely.

Last week, Chrome extension developer advocate Simeon Vincent acknowledged that concern and said Google would do nothing to accommodate it.

"Many commenters have expressed reservations about action buttons being unpinned by default," he wrote in [12]a forum post .

"We understand this concern. An extension's action in the toolbar is an important interaction mechanism, and we don't intend to decrease extension usage. However, after several discussions and lengthy consideration, we think that leaving actions unpinned by default is the best course for our longer-term plans for the Chrome extension platform."

That left extension developers [13]grumbling that Google never had any intention of testing the feature or incorporating developer feedback. ®



[1] https://www.theregister.co.uk/2019/09/10/chrome_78_dnsoverhttps/

[2] https://www.theregister.co.uk/2020/02/25/mozilla_turns_on_dns_over_https_by_default_for_usa/

[3] https://twitter.com/paulvixie/status/1171154286316679168?s=20

[4] https://www.cloudflare.com/learning/dns/dns-over-tls/

[5] https://www.theregister.co.uk/2019/07/06/mozilla_ukisp_vallain/

[6] https://blog.chromium.org/2020/05/a-safer-and-more-private-browsing-DoH.html

[7] https://www.theregister.co.uk/2019/11/19/microsoft_joins_doh/

[8] https://blog.google/products/chrome/more-intuitive-privacy-and-security-controls-chrome/

[9] https://www.theregister.co.uk/2020/04/15/google_malicious_chrome/

[10] https://www.theregister.co.uk/2019/06/17/chrome_extensions_security/

[11] https://www.theregister.co.uk/2020/04/07/chrome_hiding_extensions/

[12] https://groups.google.com/a/chromium.org/d/msg/chromium-extensions/rOso__zU_sM/UTxbb5gnAgAJ

[13] https://groups.google.com/a/chromium.org/d/msg/chromium-extensions/rOso__zU_sM/399FrnlaAAAJ

Can no longer Easily see what extensions are installed

tip pc

“ Chrome no longer pins extensions to the toolbar by default”

I assume extensions can’t be silently installed etc etc, what if I use someone else’s pc briefly, do I have to check their extensions list before I use their browser?

Having an obvious place for running extensions to show by default looks like an obvious safety thing to do.

DoH

tip pc

Will chrome tell me I’m using DoH or will it silently work in the background.

What about my local dns filtering, will it bypass my pi-hole in favour of its own DoH, maybe not today but what about in the future if my isp decides to do DoH?

I’ve blocked all port 53 traffic out and in and have a DoH proxy running internally, if chrome decide to silently use DoH in addition to my OS’s DNS I will never know, unless I now also use a proxy and inspect, TLS decrypt - inspect - encrypt, everything. With my tin foil hat I can see how that benefits state actors.

Re: DoH

chris 143

The way you'll know is all the adverts start loading again.

Re: DoH

Stuart 22

I converted to Vivaldi long ago - so when I reverted to Chrome/Chromium on new Linux/Android devices I was shocked to see adverts re-appearing despite having a pi-holed network. It was sneakily checking 8.8.8.8

Result - Vivaldi quickly installed alongside our old friend Firebird - in case Vivaldi becomes similary 'infected'. The claim the Google is trying to enforce it on me for my own good is a little suspect methinks.

This is a good move to lose the love of Chrome/Chromium. They thought that as the No1 browser it is invincible. Will hubris (and bloat) rather than ad-blockers be their eventual nemesis?

Re: DoH

lkm

Nope, Chrome will only upgrade your DNS if your current DNS provider supports DoH. I.e. if you are using 8.8.8.8 currently, it will use DoH to talk to 8.8.8.8. Nothing will change if you have something custom setup. See https://www.chromium.org/developers/dns-over-https for the list of supported DoH providers - which is really small still.

Re: DoH

Yet Another Anonymous coward

You can then configure pi-hole to do doh so you still get ad blocking without your ISP selling all your site visits

DoH

djvrs

Can anyone seen a 'doh' coming when it goes wrong?

DoH

Anonymous Coward

So we already deploy client-side certificates for our Sophos XG firewalls so we can do HTTPS/SSL inspection and decryption anyway... will this include DoH traffic?

Nanny statism strikes again

Jason Bloomberg

"Chrome will disable DoH in managed environments that declare relevant enterprise policies"

Why can't it just be a checkbox which anyone can turn on or off as best suits them?

The one with the "do as we say" motivational poster in the pocket ->

"We understand this concern"

Pascal Monett

And we don't give a flying fuck about it.

Typical behavior these days. We want it this way, so you can wave goodbye to every habit you have because this is how we roll.

I absolutely hate web developers that believe they have the right change people's habits. Once upon a time, before the Internet was a thing, Microsoft had put out a document where it set down the rules for making a proper UI. Rules that it shat upon liberally when it created its PlaySkool interface called Metro, but I digress.

I really would like to get my hands on that document. I remember reading it and thinking to myself : "this is very sensible". Yes, I know, a Microsoft document about UI that was sensible. What can I say ? It was before Y2K.

Things have changed since.

Get off my lawn.

Power grab

BenDwire

If DoH catches on as anticipated, then the potential for serving targetted ads gets swept away from carriers and ISPs, and over to the Chocolate Factory. I suspect that any improved privacy for users is just a side effect.

Oh, your DNS isn't DoH capable? Let me check 8.8.8.8 to "protect you"

Who do you want to hide from ?

alain williams

DoH needs a server to answer DNS queries - that server gets to know a lot about you.

Use normal DNS and your ISP/company can see what you are trying to resolve. Even if you do not use its DNS servers it can sniff the packets as they go by.

If you live in a repressive regime (eg Egypt, China, ...) they can make your ISP hand over your DNS history or change stuff on the fly; so DoH might be good, although they can still see where your IP packets go to.

What about the DoH provider - what does it gain ? Knowledge of all the sites that you visit - good meat to the advertising machine for Google & pals - even when those sites do not run google analytics (or you have blocked the javascript). These DoH providers are subject to the Patriot Act or local equivalent - so, for some, the security is a fig leaf.

Oh - just because you do not think that your regime is repressive does not mean that your government is not snooping on you. DNS over TOR might be an interesting idea.

If you do run DoH then you might be visited by shady men and told to change your browser options - packet sniffing via your ISP will make it obvious if you have taken their 'advice'. So: will you make yourself a target for future visits ?

Peter Galbavy

Well, just updated and the flag is still there to turn it off - not checked if it's a null op though

Nothing will dispel enthusiasm like a small admission fee.
-- Kim Hubbard