Talk about the fox guarding the hen house. Comcast to handle DNS-over-HTTPS for Firefox-using subscribers
- Reference: 1593133633
- News link: https://www.theregister.co.uk/2020/06/26/firefox_comcast_dns_https/
- Source link:
This means the ISP, which has joined Moz's Trusted Recursive Resolver ( [1]TRR ) Program, will perform domain-name-to-IP-address lookups for subscribers using Firefox via encrypted HTTPS channels. That prevents network eavesdroppers from snooping on DNS queries or meddling with them to redirect connections to malicious webpages.
Last year Comcast and other broadband giants were [2]fiercely against such safeguards, though it appears Comcast has had a change of heart – presumably when it figured it could offer DNS-over-HTTPS services as well as its plain-text DNS resolvers.
At some point in the near future, Firefox users subscribed to Comcast will use the ISP's DNS-over-HTTPS resolvers by default, though they can opt to switch to other secure DNS providers or [3]opt-out completely .
"Comcast has moved quickly to adopt DNS encryption technology and we’re excited to have them join the TRR program," Firefox CTO Eric Rescorla [4]said on Thursday.
“Bringing ISPs into the TRR program helps us protect user privacy online without disrupting existing user experiences. We hope this sets a precedent for further cooperation between browsers and ISPs.”
Incredibly, DNS-over-HTTPS was heralded as a way to prevent, among others, ISPs from snooping on and analyzing their subscribers' web activities to target them with adverts tailored to their interests, or sell the information as a package to advertisers and industry analysts. And yet, here's Comcast providing a DNS-over-HTTPS service for Firefox fans, allowing it to inspect and exploit their incoming queries if it so wishes. Talk about a fox guarding the hen house.
ISPs "have access to a stream of a user’s browsing history," Marshall Erwin, senior director of trust and security at, er, Mozilla, [5]warned in November. "This is particularly concerning in light of the rollback of the broadband privacy rules, which removed guardrails for how ISPs can use your data. The same ISPs are now fighting to prevent the deployment of DNS-over-HTTPS."
DoHn't believe the hype! You are being lied to by data-hungry ISPs, Mozilla warns lawmakers [6]READ MORE
Mozilla today insisted its new best buddy Comcast is going to play nice and follow the DNS privacy program's [7]rules .
That means, according to Moz, Comcast "must not retain, sell, or transfer to any third party (except as may be required by law) any personal information, IP addresses or other user identifiers, or user query patterns from the DNS queries sent from the Firefox browser." Nor can it "combine the data that it collects from queries with any other data in any way that can be used to identify individual end users" nor "sell, license, sublicense, or grant any rights to user data to any other person or entity."
We're told Comcast started testing a DNS-over-HTTPS service in October – at the same time it was [8]lobbying on Capitol Hill against the technology. Now it's rolling out the security mechanism anyway.
If this was TV, this would be the part where Moz turns to the camera, looks straight into the lens, and puts on its best no-really-this-is-a-good-thing voice. "Also in October, Comcast announced a series of key privacy commitments," the Mozilla team said today, "including reaffirming its longstanding commitment not to track the websites that customers visit or the apps they use through their broadband connections. Comcast also introduced a new Xfinity Privacy Center to help customers manage and control their privacy settings and learn about its privacy policy in detail."
Well, at least a broadband provider is now signed up for DNS-over-HTTPS with Firefox rather than fighting to outlaw the tech. And subscribers aren't forced to use Comcast's secure DNS service, though it will be the default. And it's better than using plain old DNS that isn't encrypted. If you trust Comcast to handle your normal plain-text DNS, logically you should trust it for DNS-over-HTTPS.
"We’re proud to be the first ISP to join with Mozilla to support this important evolution of DNS privacy,” said Jason Livingood, Comcast Cable veep of technology policy and standards. "Engaging with the global technology community gives us better tools to protect our customers, and partnerships like this advance our mission to make our customers’ internet experience more private and secure."
Mozilla launched the TRR program in March, and so far Cloudflare and NextDNS have jumped in to provide DNS-over-HTTPS resolvers. Google [9]rolled out its own flavor of the tech for Chrome users in May.
"Adding ISPs in the TRR Program paves the way for providing customers with the security of trusted DNS resolution, while also offering the benefits of a resolver provided by their ISP such as parental control services and better optimized, localized results," Team Mozilla concluded this week. "Mozilla and Comcast will be jointly running tests to inform how Firefox can assign the best available TRR to each user." ®
Sponsored: [10]Running Your Modern .NET Application on Kubernetes
[1] https://blog.mozilla.org/netpolicy/2019/12/09/trusted-recursive-resolvers-protecting-your-privacy-with-policy-technology/
[2] https://www.theregister.com/2019/11/04/mozilla_doh_congress/
[3] https://support.mozilla.org/en-US/kb/firefox-dns-over-https#w_about-the-us-rollout-of-dns-over-https
[4] https://blog.mozilla.org/blog/2020/06/25/comcasts-xfinity-internet-service-joins-firefoxs-trusted-recursive-resolver-program/
[5] https://blog.mozilla.org/blog/2019/11/01/asking-congress-to-examine-isp-data-practices/
[6] https://www.theregister.com/2019/11/04/mozilla_doh_congress/
[7] https://wiki.mozilla.org/Security/DOH-resolver-policy
[8] https://www.vice.com/en_us/article/9kembz/comcast-lobbying-against-doh-dns-over-https-encryption-browsing-data
[9] https://www.theregister.com/2020/05/20/google_chrome_83/
[10] https://go.theregister.com/tl/1956/-8477/running-your-modern-net-application-on-kubernetes?td=wptl1956
Re: So will Tor be using Comcast for DNS? Will my VPN also start going through my ISP?
No, Tor [1]routes DNS through Tor. Your VPN will work as usual. But Firefox, if you use the default and are on Comcast's broadband network, will send its DNS via Comcast over HTTPS.
Bear in mind most or many subscribers send their plain-text DNS via Comcast anyway, due to their cable modem's DHCP setup, so for them this is no change except it's via HTTPS and Moz has made Comcast swear it'll be nice.
In a way, DNS-over-HTTPS was an opportunity to shield DNS lookups and route them where you want, but instead, yeah, nah, Comcast will just handle it anyway.
C.
[1] https://tor.stackexchange.com/questions/8/how-does-tor-route-dns-requests
Comcast will just handle it anyway
So at best, a no-op, and at worst, a false sense of security.
If you're using ISP resolver(s) anyway, who are you hiding your DNS queries from using DoH?
In any case, applications like Web browsers shouldn't be making their own name resolution plans; that's a site-based setting and apps should use the OS's setup (including proxy setup). Neither should 'devices' be hardcoded with 8.8.8.8 for DNS. That's how leaks happen.
Why can't people just run operating systems with recursive DNS resolvers?
For what end?
In this example, Comcast can inspect all your UDP/53 traffic coming out of your home which contains all your questions.
Sure, might be a bit harder than correlating some DNS logs and it (shouldn't) allow them to choose one answer over another... but Comcast is running DPI throughout their environment, so let's consider it a trivial matter.
The correct answer to this is to look no further than DoT.
I might add that DoH (and DoT) isn't the panacea that everyone is talking about. Pure opaqueness (outside of the company that's providing that DoH infrastructure) for DoH and DoT requires TLS 1.3, Encrypted SNI and DNSSEC to be supported by both ends of each query/connection. We're still a long way from that, and that seems like a lot of potential weak links in each request.
I knew that a centralized commercial system would be exploited, but that was FAST. Nice work, Comcast.
...but it is DOH!
"Comcast has moved quickly to adopt DNS encryption technology and we’re excited to have them join the TRR program," Firefox CTO Eric Rescorla said on Thursday.
Eric, you need to stop drinking the Kool-aid. Really.
So will Tor be using Comcast for DNS? Will my VPN also start going through my ISP?
It's like musical chairs. Trying to figure out which browser you trust, and then which ISP and which DNS provider.
I'll just use whatever Jared uses. It must be secure and have multiple exit points in Moscow and St. Petersburg. With some undisclosed hops to Israel and China. Damn, my latency is really g.r..o...w...i.....n.....