Internal DNS, split brain DNS aren’t catered for without disabling support? I don’t want my internal names leaking to the internet, nor necessarily are they the same for external resolvers. Now yes the latter is a hack, but it’s one widely used still today.
The idea is laudable. But it feels hostile. I can disable support, but for how long?
A fair number of resolvers support DoH and dnscrypt-proxy also supports DoT. It's fairly feature rich, you can configure a hosts file and then some.
I will do the occasional tests with network.trr.mode to 3 (only use DNSoverHTTP) but I seem to have issues resolving github. I haven't looked that far into it.
EDIT: there do exist solutions to run locally.
I know it’s lazy and I should’ve done more work. But, burn out
The positives certainly outweigh the negatives of inconveniencing some IT admins who, as you correctly point out, are implementing a dirty hack anyway.
You completely missed the point of the parent, which is to NOT let internal hostnames out of the network.
The positives certainly outweigh the negatives of inconveniencing some IT admins who, as you correctly point out, are implementing a dirty hack anyway.
This is a perfect example of the irritating attitude I see from people pushing hostile features like this. Everyone wants their network to operate the way they want, and yet you think you know better than the actual owners of those networks.
Corporate networks are a small percentage of network traffic and their use cases are less important in the grand scheme of the internet.
DNS over HTTPS is a solution because network owners can't be trusted. Either by blocking or by taking their DNS logs and selling it to advertiser's.
If applications decide to bypass you, they are hostile and cannot be trusted.
DNS is unencrypted and a security risk. For the user. It's an old technology that needs to be updated.
DNS over TLS/HTTPS allows the browser to get a trusted record of IP which is a public register.
The bypass here is looking up what the corresponding IP address for a hostname is.
DNS based blocking isn't as effective as IP blocking.
You can feed a DNS based list of IPs you want to block into a firewall and have the exact same behaviour.
Both Firefox and Chrome have the ability to set enterprise user settings that can force certain configurations.
So you should have the ability to disable it if you want in your network.
If you're worried about the security of your network don't allow devices that you don't trust into it and restrict internet access properly.
What's more anyone can configure a custom DNS resolver on their device when connecting to a network.
> Originally these names were stored in and provided by a hosts file but today most such names are part of the hierarchical Domain Name System (DNS).
On your own network, if you feel like doing a DNS lookup to what amounts to a public address book is unethical then don't allow arbitrary clients on the network.
If you want to do blocking based on a DNS list, configure your firewall to do that.
There are whole isps and even countries (including the UK shortly) which mess with DNS requests. Helping the millions of users who are in that situation, and don't even know what D Sits, seems like a net good. As you say, experts can choose to disable it.
As long as they can. The problem with these ideas is that it can get increasingly difficult to work around them. How many hoops you have to jump through to pcap your own software on your own machines now that certificate pinning is becoming popular? What when someone will have the bright idea of implementing certificate pinning for DoH inside browsers, "because security"?
(I could live with the choice between having to somehow acquire Chrome Enterprise Edition vs. switching to Firefox, to have a browser I can control. I'm worried now that Firefox might be turning into Chrome, though.)
If you're implying the porn filter, no, the porn filter has been shelved 'indefinitely' because a) it's against EU law, b) it was May's personal project (she pushed heavily for it when she was Home Secretary, and it became a thing under her PM-ship).
5 means explicitly disabled. 0 (default) is whatever is considered default for now.
1. about:config
2. network.trr.mode = 5
[1] https://news.ycombinator.com/item?id=20373444If the Mozilla Foundation see this as an issue they should instead be developing a separate solution to provide this system wide. If you must bundle it with Firefox and offer to install it at browser installation or upgrade time. Don't install it by default and certainly don't enable it without user permission.
test $# = 1|| exec echo usage: $0 query
# requirements: sed, wc, xxd, openssl, ldns, drill
# reference: https://tools.ietf.org/html/rfc8484#section-4.1
a=$(drill -q /dev/stdout $1 |sed '1,2d;s/;.*//;s/ //g'|xxd -p -r|wc -m);
(printf "POST /dns-query HTTP/1.1\r\nHost: cloudflare-dns.com\r\nAccept: /\r\nContent-Type: application/dns-message\r\nConnection: close\r\nContent-Length: $a\r\n\r\n"; drill -q /dev/stdout $1|sed '1,2d;s/;.*//;s/ //g;3s/..../0001/'|xxd -p -r)|openssl s_client -no_tls1 -no_tls1_1 -no_ssl2 -no_ssl3 -ign_eof -no_ticket -host cloudflare-dns.com -port 443 -servername 1.1.1.1|sed -n \$p|xxd -p|drill -i /dev/stdin|sed '/^;; Data: \\#/d'I wrote a glibc plugin that implements a caching DoH client for glibc, which can replace the DNS client or fall back to it - https://github.com/dimkr/nss-tls.
Not to mention that DNS over HTTP is one of the class of features where you might want to override sysadmin policy as a user.
I don’t buy that argument at all.
Why should we special case policies of one internet-protocol over all the others?
Also: implementing/marketing DoH as a way to bypass enterprise control and policies is a surefure way to find it permanently blocked at firewall level in said enterprises.
Ie your attempt at subverting control won’t gain you anything but deserved distrust.
I think you missed the nss-tls README and think nss-tls is not at the "OS level".
For the users, 99% of whom live in the self-updating browser these days, this is much better than waiting for an OS patch that they may or may not know how to install.
Nearly all applications use the standard library, i.e. getaddrinfo(3) or the old gethostbyname(3) or something that wraps them. Which itself uses the services configured in /etc/nsswitch.conf, one of which is DNS which will in turn query the DNS server(s) configured in /etc/resolv.conf.
You can also have other services configured in nsswitch.conf like "mdns" (multicast DNS for names of devices on the LAN) and "files" for /etc/hosts, or any other name resolution system. The general result is that you can change the settings for the whole system and even add completely new name resolution services (like, for example, DoH) and have substantially everything automatically use them.
https://linux.die.net/man/3/gethostbyaddr
It is one of the worst thing that can happen if this functionality moves into the application layer.
1: https://jrl.ninja/etc/2/strace-go-1.12.3.txt
src for above: https://jrl.ninja/etc/2/getaddrinfo.go.txt