Really? That's the only bar? So you're going to trust any company who isn't in this business without even reading & comparing their privacy policy or looking at their past history?
I also have to say I don't understand what you guys' true fear (read: threat model) is. It seems like for Google your criterion is "if they could potentially keep such data, they're automatically dangerous (doubly so if their name is 'Google')", whereas for anyone else not in the advertising business your standard suddenly changes to "I don't care what data they have, as long as I don't see evidence of active misbehavior". To me this sounds like what you really fear is personalized advertising itself rather than an actual privacy or security breach, which doesn't entirely make logical sense considering what the dangers of each of them are.
I never said that. I said that I'm not going to trust a company that has this business model. That by no means implies that I'm going to blindly trust a company with another business model, rather that trust in such a company is possible.
Telling me you wouldn't trust someone who meets some disqualifying criterion isn't useful if you have so many disqualifying criteria that you wouldn't trust anybody, which frankly is the impression I get reading people's comments on this issue. If you have an actual company that you would trust, and a clear rationale for doing so, that's where we can have a real discussion.
You presupposing that it is necessary to send all DNS traffic to one entity. I run a local recursive nameserver (unbound) instead of sending all of my queries to a different nameserver.
Combined with aggressive caching, any particular DNS server (from .ROOT-SERVERS.NET down to the specific authoritative nameservers for a specific domain) is only able to view a tiny subset of my browsing behavior. Most of the time the query to the final authoritative nameserver is to be followed quickly by a TCP SYN packet that reveals roughly the same information.
Yes, running the full recursive resolver locally can be very slightly* slower than asking e.g. the local ISP's server that probably has the query cached. Fortunately, local caching limits this (very minor) problem to only the first request for a domain.
NS records don't change very often. They can see that I looked up the delegation data about "example.com" once every $CACHE_TTL (~months). They do not get repeated queries at the beginning of every session I have with a website.
A lot of security is about being in the habit of minimizing attack surface. The only thing a TLD (or ISP) nameserver needs to know if I want to use the Doomain Name System is "pdkl95 asked for example.com's nameserver once last month" Instead of giving Google (or whomever) an update e.g.:
;; ANSWER SECTION:
news.ycombinator.com. 300 IN A 209.216.230.240
...every 5 minutes. This is not trying to stop someone discovering that I have ever been a domain; I'm limiting the ability to model my pattern of life[1].Separating the requests allows for different cache policies. If you simply delegate the entire recursive resolution work to Google (or whomever), they get to record that you needed "www.example.com" every TTL (5min?). You don't even need to see the domain's NS records in that case, so there isn't an opportunity to choose a cache policy.
"No", because the system depends on running a recursive resolver locally to separate queries onto different nameservers.
Aggressive caching of NS records for TLDs doesn't do anything to prevent a single upstream nameserver from leaning your pattern of life from the frequent DNS lookups for A records that are not cached longer than normal.
Setting $CACHE_TTL to "months" on everything, and doing nothing else.
> I'm still sending frequent short-TTL (normal caching) DNS lookups for most hosts that would betray my pattern-of-life in aggregate.
Your system does that. This theoretical mildly-inferior system would not have frequent DNS lookups for any record type.
That will break a lot.
DNS isn't static; IPs regularly change as servers move, CDNs are introduced/changed. Long-term caching only works on NS records because changing DNS delegations is relatively rare. NS record caching does cause problems, but they are infrequent. Caching the addresses of the actual servers will break some things within days, and most of the internet the next time each server is updated/moved/etc.
Even if you have an evil ISP, and they're selling your data for $0.50/month, you're still paying them $50/month for service. A bunch of angry customers could change their policy quickly. Few ISPs would try to squeeze those extra quarters from you, given the potential blow-back (some do, and they'll get their comeuppance). However generally, ISPs incentives are to keep you as a customer and get your fitty beans every month.
However, with Google, it's not clear why they are giving DNS services away for free or what they're getting in return. It clearly costs them some money to do so, and they're not being paid for it directly. It's possible that they're doing it purely altruistically, but they also have an extremely long history of using data for advertising or other forms of monetization.
I'm not saying that if you use 8.8.8.8, you'll search ads will target you. But I would bet they use your anonymized browsing history to fight bots, test internet speeds at various locations, identify browser technology, and who knows what.
And regarding this bit:
> I'm not saying that if you use 8.8.8.8, you'll search ads will target you.
Hm, well others here have been suggesting this would be the case.
> But I would bet they use your anonymized browsing history to fight bots, test internet speeds at various locations, identify browser technology, and who knows what.
Even if I take this at face value, how are these things you listed bad things? If my DNS queries are going to fight bots, by all means, please fight bots! If they're going to help them improve internet speeds, by all means, they should do that! That's what data is good for. Everyone here is freaking out about privacy, not improved service. (!)
That said, they are selling a service, and you're paying for it. Quite a bit for it. It would be pretty stupid for AT&T to use your DNS data and risk your $150/month cable, phone, internet subscription for an extra buck or two.
But with Google, you just don't know and their entire business model is predicated on selling your data. They are almost certainly using their DNS servers for some data-based operation.
And a last quasi-technical point... I'm sure AT&T and Comcast have good engineers on staff, but I'm even more sure that Google has better ones. I am less concerned about AT&T and Comcast because I honestly don't think they have the wherewithal and talent to come up with ways to monetize DNS. I'm pretty sure Google could.
And to your point, even if Google is giving away DNS services to only fight bots and measure internet speeds, they should at least say that in their privacy policy. They don't. They just say they keep detailed data temporarily and anonymized data long term. I don't use Google's DNS because I really have no clue what they're doing with it. In contrast, if my ISP does something, I can always try to sue them, or if that fails cancel my service.
https://www.eff.org/deeplinks/2014/11/verizon-x-uidh
http://www.latimes.com/business/la-fi-lazarus-20150818-colum...
There is no point in discussing what companies might do in some theoretical framework - they do not care about your privacy, they monetize NXDOMAIN, etc. This isn't about what might happen - these abuses have already happened.
My own ISP already knows all the ips I connect to, so telling them what the domains are doesn't tell them much, especially as the trend towards ipv6 means that multiple-domains-on-one-ip has gotten less popular.
Cloudflare's main prerogative isn't to sell clicks the way google's is, which earns it points already. In addition, if you believe the official documents, they permanently log a lot less[1] than google[2].
I would also, needless to say, feel ok hosting my own dns.
Quad9 and opendns both filter content, and as such I don't trust them because the fact that they're willing to do that means that they are willing to censor content if they so choose.
I don't know any other dns servers off the top of my head.
1: https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... 2: https://developers.google.com/speed/public-dns/privacy
> I would also, needless to say, feel ok hosting my own dns.
Yeah let's avoid options that 99%+ of people wouldn't find realistic.
> Quad9 and opendns both filter content, and as such I don't trust them because the fact that they're willing to do that means that they are willing to censor content if they so choose.
Right, I think I agree on that.
> Cloudflare's main prerogative isn't to sell clicks the way google's is, which earns it points already.
Sure, some points there for the increased likelihood of hypothetical data mishandling due to their incentives.
OTOH, don't forget it was Google who found this issue in CloudFlare, which earned Google some points and earned CloudFlare /quite/ the demerits in my book... and note that this was an _actual_ massive security incident, not a hypothetical one: https://blog.cloudflare.com/incident-report-on-memory-leak-c...
> My own ISP already knows all the ips I connect to, so telling them what the domains are doesn't tell them much, especially as the trend towards ipv6 means that multiple-domains-on-one-ip has gotten less popular.
I find this to be quite the odd argument for most people (maybe you're in the 1% of people who uses unconventional ISPs or email/search/map/etc. sites). Not only do major ISPs (thinking e.g. Comcast, AT&T here) not exactly have a great reputation on the privacy or security front (wasn't it just a few days ago someone posted about your home address being linked to your IP on Comcast?) -- meaning whatever data they do collect is prone to being hacked even if you believe they're really honestly keeping it private, which I'm not sure I always would -- but for most people Google already knows pretty much their life. And on top of that, they do their own tracking with Google Analytics, so they already know what websites most people are visiting -- not just from home, but also from work and on the go. And unlike with your ISP, it's likely already linked to your personal identity, not just your household or work office.
Oh, and in case you would like your advice to apply to those who have, say, Comcast, may I point you to quotes like this [1]:
> Comcast today said it has "no plans" to sell its customers' individual Web browsing histories, but Comcast can still deliver personalized ads based on its customers' browsing history. Comcast, the nation's largest home Internet provider, said it will continue to offer customers a way to opt out of targeted ads.
I don't know about you, but I would be shocked if they did this solely based on IP and did not find DNS information to be important for this task.
[1] https://arstechnica.com/tech-policy/2017/03/comcast-we-wont-...
I don't quite understand this one. Are you saying that you have an expectation that all software be bug-free? That just doesn't happen, unfortunately. Cloudflare had a problem, they fixed it promptly and then published a post-mortem on it. That, imo, is exactly what should happen. And as for google, it was discovered by their dedicated team of security researchers. Having such a team arguably reflects well on google, but do remember that monolithic corporations such as google are rarely unified.
Even if they don't use your traffic history to help with personalized advertising, they could conceivably use it for other things (e.g., bot detection, usage stats).
Google discusses what they collect in their privacy policy (https://developers.google.com/speed/public-dns/privacy), but not how they use it.
That's a difference between Apple and Google - Apple is at least partially in the hardware business. Google is in the ad business - the surveillance business - full stop. And I say this as a fan of Google and someone who still uses their public DNS. But it's not surprising that people wonder how they use data.
https://www.schneier.com/blog/archives/2018/03/facebook_and_... But for every article about Facebook's creepy stalker behavior, thousands of other companies are breathing a collective sigh of relief that it's Facebook and not them in the spotlight. Because while Facebook is one of the biggest players in this space, there are thousands of other companies that spy on and manipulate us for profit.
Harvard Business School professor Shoshana Zuboff calls it "surveillance capitalism."
Now what I'm not seeing is exactly which company's DNS is avoiding what credible harm that people here believe is potentially likely to result from using Google DNS.
As far as Google (or any company, really) internally is concerned, the fact that they are merely "using" the data for themselves (to show you ads, or whatever) is not itself a harm to you. (And maybe worth mentioning, they have used a lot of information to make life a lot better for everyone, like location for traffic data.) The harm would be if they used it to (say) discriminate against you in advertising goods/services, or to harass you, or if they did not secure it properly and your data leaked, etc. None of these are things I'm aware of happening inside Google, but if you know of evidence of this happening, I would love to know.
As far as Google is concerned externally, the only threat you seem to have hinted at here is that you believe they are likely to sell your data to other parties who are then likely to abuse them (such as by harassing you directly, or sharing/exposing your data online to others who might harm you). I have seen no evidence that this has been the case with Google (or Facebook) either -- which should make sense given that you believe user data is their most important asset -- but again, if you have any, by all means do share.
Given the above, combined with the facts that (a) so many people here seem to be disregarding the actual privacy policy, and (b) for most people Google probably already has more information to screw you with than your third-party DNS provider ever will, I'm led to believe there isn't really anything to be gained by avoiding Google DNS. But to each their own...
But it does. If you need a product generally you would just go out and buy it. Ads are psychologically manipulating you to buy things you don’t need and spend your limited time on this Earth doing things that aren’t beneficial to you. It wasn’t too bad when it was just billboards and TV slots but now it’s you vs the algorithms on a personal level.
1. Targeted ads requires enormous machineries of surveillance and file-keeping. Having too much information in closely related form is akin to having too much uranium in close proximity; it causes problems all of its own almost just by merely existing.
2. Ads in general, even the beneficial ones are, by definition, distracting from whatever content we were trying to read. See: São Paulo’s “Cidade Limpa”.
Pervasive Monitoring Is an Attack:
You're right, a threat is potential damage, these things are done damage.
You are welcome to believe that Google is just actively causing harm. But I don't understand why you'd specifically do this for them but not other businesses.
Especially since people asking that generally know nothing about the people who criticize a thing, and what else they might criticize in other contexts. It's not like they're busy criticizing some bigger evil and criticism of $thing_under_current_discussion blocks their noble work. At worst they're doing nothing, yet expect others who are doing something -- even if that's just making one decision against one product or company, rather than zero, and making one comment about their own personal actual stance, instead of about synthesized hypothetical persons -- to take some time out of their day to answer pointless "questions".
I personally try to advocate for good privacy education at places of work, study and play usually with a combination of a) the naritive / context, b) Provide simple examples (of why it probably matters), c) Explain with metaphors, and d) Give some simple advice where possible.
It’s not a perfect strategy but I think it does noticeably help lift the awareness bar.