On Firefox moving DNS to a third party
blog.powerdns.com
blog.powerdns.com
Clarifying that this is just an A/B test and there are no plans to continue using CloudFlare for all users.
The article is right to be fearful that FF is pondering a default change, but until that is even on the table, I'm not worried. Now if they wanted to make it really really easy for regular users to change from your default ISP DNS to CloudFlare, I'd actually be OK with that, but I'd expect it to be implemented like search engine providers where anyone could just as easily be the DNS provider chosen (ideally without any CloudFlare favoritism). And it would be clear who your DNS provider is maybe via an icon (if there is real estate for it).
0 - https://blog.nightly.mozilla.org/2018/06/01/improving-dns-pr...
1 - https://blog.nightly.mozilla.org/2018/08/28/firefox-nightly-...
In general I agree that using other DNS providers besides the ISPs has benefits. But not sure I think it should funnel to a single, preferred company. Nor do I think that they should collect anything at all, reduced compared to their original or not. I think some transparency is deserved here about the contract if/when a regular FF release is shipped encouraging users to use Cloudflare, specifically around the motives of wanting this data. Granted, I am a bit more paranoid than most.
If they intended to ship with DoH default-enabled, I'd hope Mozilla would not go with any single provider as a default.
In particular, I think it would be unsurprising if CF's lines were tapped upstream. CF and Mozilla staff have a history of treating TLS as if it protects all content, rather than as a tool for keeping narrowly defined secrets. I explain further at https://weblog.evenmere.org/posts/2014-05-16-tls-is-not-for-... .
You can explicitly enable DNS over HTTPs on recent FF versions if you want to, then you need to pick a provider. There are a few available choices out there. There’s a list on the cURL docs IIRC. Due to the standard being finalized right now, the list is understandably quite short, by there’s no particular reason you ISP shouldn’t offer a suitable DNS server in the future.
Like many of the things the Mozilla Corporation has been doing these last years.
Source?
"The tool shaped Facebook's decision to buy WhatsApp and informed its live-video strategy, they say. Facebook used Onavo to build its early-bird tool that tips it off to promising services and that helped Facebook home in on Houseparty."
https://www.engadget.com/2017/08/13/facebook-knew-about-snap...
https://www.foxbusiness.com/features/the-new-copycats-how-fa...
The measure I'm looking at is that of sensible defaults: is this default more sensible for a majority of the user base than the existing default? For anyone outside the rule of GDPR using a regular ISP, this option is far better. The joint privacy policy Mozilla + Cloudflare is much better than a regular ISP.
And given that we all go and change the DNS of every computer we and our extended families own to 8.8.8.8, 8.8.4.4 or 1.1.1.1, I don't see why we'd think Mozilla doing it by default is a bad thing.
I recently noticed that his self-hosted email is sometimes being flagged as spam because it lacks spf.
Is CloudFlare filtering their DNS results, maybe against a spam blacklist?
ns3.cisws.nl
ns6.cis-websolutions.nlPicking a random domain hosted on those nameservers, mdfs.net, it looks like, of the 4 IPs, 2 are down and 1 of the remaining ones doesn't support TCP.
http://dnsviz.net/d/mdfs.net/W48OcQ/dnssec/ https://ednscomp.isc.org/ednscomp/4040283963
1.1.1.1 is less tolerant than some resolvers of that level of breakage.
https://community.cloudflare.com/t/ipv6-timeouts-appear-to-b...
I'm not sure nothing else is wrong, but the IPv6 issue is likely why 1.1.1.1 is having trouble resolving it.
Don't know what the iOS stance on this is.
[1] - https://support.mozilla.org/en-US/kb/customizing-firefox-usi...
On the other hand, they resolve websites which are considered illegal in my country, which would normally be censored by my ISP (e.g. not approved betting websites).
[1] https://www.reddit.com/r/Piracy/comments/8aa0ba/cloudflare_d...
While this is technically true it is kind of misleading to single Mozilla out as depending on a certain large sponsor given who owns Chrome (and who owns Edge, IE and possibly less problematic, Safari).