GCHQ planning UK-wide DNS ‘firewall’
thestack.com
thestack.com
I've used it for about two years and it's very reliable, even on a laptop. I do recommend using it in conjunction with a caching DNS recursor such as Unbound[1] to save bandwidth.
It also works great on OpenWRT if you have that luxury.
For UK residents, please also consider changing to an ISP that cares about your online rights. I only know this one: http://aaisp.net.uk
Only know of those two free of shaping, blocking and bad support beloved of all the other UK ISPs.
Their blog is consistently anti surveillance.
The owner's blog is also worth a read:
[edit] From DNSCrypt's own front page:
Please note that DNSCrypt is not a replacement for a VPN, as it only authenticates DNS traffic, and doesn't prevent "DNS leaks", or third-party DNS resolvers from logging your activity. The TLS protocol, as used in HTTPS and HTTP2, also leaks leaks websites host names in plain text, rendering DNSCrypt useless as a way to hide this information.
Because this definitely isn't a step towards state censorship, no siree!
Russia went a similar route, but did a "think of the children!" angle, among other things.
For those interested, The Red Web does a good job covering this (and many other topics). - https://www.theguardian.com/books/2015/sep/02/the-red-web-re...
But isn't the truth that it is already implemented in UK ISP's DNS offerings anyway, and that this is just extending the filter so you can't bypass it by changing to a different DNS server?
This should be a textbook case on how to achieve censorship. Start by having it "optional", but not an option a user opts into explicitly, just implicitly in a way they don't understand (by "choosing" their ISP).
Then when 99% of people are already covered, roll it out in a compulsory way across everywhere because "This won't affect most people, just a small number of people".
No debate needed.
No, many people will just use VPNs
Then the government will find a need to ban VPNs for the safety of its citizens.
I'm not evangelizing the idea, I just think it's something worth debating and I don't see enough of it yet.
That's not to say we don't need to fight for rights, to keep this sort of thing from happening, but that I have confidence that we can and will fight these things successfully.
Australia, as one example, has tried on many occasions to put up very restrictive firewalls and has mostly failed. https://en.wikipedia.org/wiki/Internet_censorship_in_Austral...
Stay vigilant, stay informed, and you can control the future.
It's our job as citizens to oppose these things. Raise a fuss. Write letters. Get upset. Donate to causes that oppose this.
The enemy here is not these corporations but complacency.
https://en.wikipedia.org/wiki/Numbers_in_Chinese_culture#Eig...
Apartment 88 sold for nearly 50% more than 78 or 68, because it was seen as lucky by the Chinese buyers.
I'm in Sydney btw.
If VPNs are blocked then DNS filtering likely is not your only problem. You would already be behind a something akin to the great firewall.
And you also have to consider that when you start using counter-measures then you're already retreating and relying on foreign, more-free societies to support you. What if they succumb to the same thing too which obviously is not so far-fetched since it already happened to your society?
Trustworthy guys to put in charge of something like this.
–---
419.ng freemail, exceptional service for fr33!
Dear sir or madam the crown prince of Contantanople is having trouble transferring his considerable fortune..
Cpoc@419.ng
By designing a system for distributing filter rulesets to the endpoints. Works fairly well for in-browser malware blocking and adblocking. And if users can retrieve rulesets from configurable sources, it allows them to tune how aggressive their filtering is, and avoids turning every rule into a potential national censorship row.
By comparison, making ISPs do DNS filtering is of middling effectiveness and screams of "just give me all the control and trust me to sort it all out."
It's not like it wasn't being done before by intercepting DNS requests but this way its legal.
This also paves the way to ISP 's requiring to conform and building an infrastructure to associate an subscriber id to a given DNS request.
If the US government were to force the root zone key holders into issuing a false update for the .is top level domain, for example, that should rightly be treated as an act of war, and be detected before it could be used. Such an expensive attack could only be used once, and would achieve nothing.
Do you have a different threat model in mind?
Tell me: what's the TLD you'd choose for your new site if protection from governments was your goal? We already know: it's not .IO, which is is controlled by GCHQ. Which one is it? Are we all getting .IS names in your bright DNSSEC future?
Alternatively I could (in theory) set up my own generic TLD, like Apple has done. Here is their DNSSEC practice statement:
https://www.apple.com/legal/intellectual-property/tld/dps/
It's still not clear why you think that being able to choose your trust path is strictly worse than being at the mercy of all CAs in the world.
Do you have another TLD besides .IS you might "trust more than the least trustworthy CA in your browser"? Could you name it?
You still haven't said what your threat model is, though. The fact you mentioned "protection from governments" earlier suggests that the threat model you are envisaging is "I am trying to run a website that will be attacked by every country in the world". If that's your threat model, I would be interested to know what technology you suggest to counter that threat.
Alternatively, if your threat model only includes "US, UK, Canada, or Australia" then there are various other TLDs that are more trustworthy than the Turkish or Chinese governments (no disrespect to those countries). For example, the TLDs of .ch, .dk, .li and .lu. Even .de and .fr should be managed in ways that are independent from the 5 Eyes.
No. No no no.
A situation where people can avoid the governments they don't trust is strictly better than this, but you seem to be arguing that it is strictly worse.
(a) They do not (go ahead and try to get a Google Mail cert).
(b) They need not (CA's can be --- and have been --- and will probably within a few weeks be again --- untrusted by browsers)
(c) It is insane --- as in, "definition of insanity" insane --- to double down on a hierarchical PKI controlled by governments as a response to problems with the CA system. It is literally the opposite of the direction we should (and are!) going in.
I note: in no exchange we have ever had about this issue have you ever so much as rebutted my contention that adopting DNSSEC+DANE would escrow .COM TLS keys with the US government. That's unsurprising, because my contention is true. But I'd like to point it out anyways.
(b) Waiting a few months after an attack for a CA to be shut down is not as much comfort as being able to choose in advance which ccTLD or gTLD you are under. As I keep saying, with DNSSEC, the malfeasance of a third party trust source has no effect on your security, unlike the existing case with CAs.
(c) Switching from a "chain is as strong as its weakest link" model to one where you can be free from any subset of governments you choose is a strict improvement and very much the right direction to be going in.
In response to your note: you have made many claims on this site, and I have rebutted those made in discussions I have been involved in, but I don't remember you making the "escrow" claim in one of the discussions I was involved in. I do remember seeing it recently, though, and laughing to myself about it, trying to work out what was going through your mind when you made that claim. Eventually I realised that by "escrow" you mean "The US government could force Verisign to issue a fake DNSSEC response for a website under .COM", i.e. a situation which is strictly better than "The US government could force Verisign to issue a fake TLS certificate for any website with any domain name." Presumably you would call that key escrow too.
I hope I have understood you correctly, and that this counts as a rebuttal, but it's 03:30 here so I'll have to leave this interesting discussion for the night. I look forward to hearing what you have to say in this or another thread soon.
They don't get the bits of your private key exponent. They don't need them; the DNSSEC key escrow system is subtle enough to let people think their secret keys matter.
They don't get the bits of your private key exponent. They don't need them; the CA key escrow system is subtle enough to let people think their secret keys matter.
The question then becomes "Is the amount of work to use DANE on top of DNSSEC (and potentially changing the TLD of my domains, depending on my threat model) too great to justify the extra security of being insulated from malfeasance by unrelated third parties (i.e. any of the CAs in the world)?"
I think that reasonable people can disagree about both the amount of work and the amount of extra security, and it is probably a different balance for each domain being considered. I don't think it is reasonable, though, to say that DANE as a technology shouldn't exist and be available to people who would benefit from it.
Nobody benefits from DANE. DANE takes the existing broken CA system we have now, retains it, because a large fraction of the deployed base of browsers can't actually handle DANE lookup queries, and then adds a new hierarchical PKI that is suborned by governments from the very beginning.
There is no amount of extra work we should spend to deploy DANE or DNSSEC. In fact: the potential deployment of DANE merits some work to prevent it from happening.
You earlier argued that the strength of the CA system is that they "can be --- and have been --- and will probably within a few weeks be again --- untrusted by browsers", but that just sounds like you're saying "the good thing about the CA system is that it keeps failing, and our repeated belated steps to punish malfeasance do not work as a deterrent".
Again, I look forward to reading what you propose instead of the CA system and DANE.
I think it's part of the state's mandate to provide security to the citizens, offline and online. Unfortunately I haven't really seen alternative plans that don't give the state more power at the same time.
It doesn't matter the "real" reasons behind this kind of decision, unless people are presented with a sane alternative.