It's also a problem for obsolesce of cloud connected devices; I'm not able to, even if technically possible, to replace the cloud services some of my devices connect to because of certificate validation and encryption.
The reason we even want DoH is because we don't want others to control and filter our DNS queries at their gateway when we are on their network.
For this concern to make sense, you have to imagine threat actors determined enough to do bad things if they can look up hostnames with your standard DNS, but not determined enough to use some alternative lookup or C&C mechanism if standard DNS isn't available. Who are those threat actors? If they're browser-resident --- which they have to be if Firefox defaulting to DoH is your big concern! --- why can't they just do their own DoH regardless of what Firefox decides to do?
Any app that includes an advertising or telemetry SDK? App developers will appreciate the ease of just adding a library that from user's point of view is malicious, but neither the app developers nor the SDK vendors will likely want to bother with building and maintaining their own name resolution scheme.
If you consider advertising and telemetry to be hostile actions (as many here, myself included, do), the space of threat actors expands to encompass a large amount of "cooperative hostile programs".
Actually, I think it's the most common threat model these days. Viruses/Trojens? I haven't had one in years. I remember getting rooted on my first Linux box hours after connecting to the Internet -- that doesn't happen anymore either.
Instead, all the threats are cooperative hostile programs from my search engine, my television, my apps, etc.
> You have to imagine threat actors determined enough to do bad things if they can look up hostnames with your standard DNS, but not determined enough to use some alternative lookup.
But most of these bad actors don't believe they're doing anything bad. This is just the normal accepted operation of their software. Operating according to the normal and expected way that Internet applications are supposed to work. If a few "techie geeks" find a way around it so be it. The alternative methods you describe are just another point of failure.
--
We're moving towards a model where you have absolutely no knowledge or control of what goes through your network anymore. It used to be I could monitor and even re-write any IP traffic on my network to my hearts content through my Linux router but I can't do that anymore. DoH is just one piece -- perhaps the final piece -- that makes this transformation complete.
If it's a device on your network that you don't control, the problem is that you don't control or trust a device you've plugged into your network.
Either way: DoH is a red herring. It's making you aware of a problem you most definitely already had with untrusted devices, while mitigating another problem you had in your browser. Firefox didn't enable DoH in your Chromecast or whatever, and if DoH didn't exist, your Chromecast could (and should) have done something like DoH anyways.
Honestly, and I know I lose credibility by being intemperate enough to say this, I think people freaking out about DoH and all the low-rent control of low-rent bad-ware that it breaks need to grow up and either take the problems they're talking about seriously, or recite the Serenity Prayer and let it go.
Except if that computer is in your TV, or is in an iOS-based device, or in another piece of hardware.
> The problem is that you don't control or trust a device you've plugged into your network.
Yes. I would like to use the device and filter out any of its harmful effects -- the best of both worlds really. Same reason I run an ad-blocker on my browser.
> Either way: DoH is a red herring.
I agree. My point was not to single out DoH in this scenario. It's just one more way in which we've lost control of our local network. When it's not our network, it's a benefit. The same reason why use we SSL.
> It's making you aware of a problem you most definitely already had with untrusted devices
Oh definitely. We used to have at least this as a last line of defense. And now we won't. I think it's good to be aware of that. I'm not saying that we shouldn't use DoH or the benefits don't outweigh the costs -- but it should be noted that there are costs.
Honestly, I never considered the personal costs of all these good security practices until a cloud hardware device I own had the company go out of business. Their security was very good -- all SSL, pinned certificates, etc. There's no way to emulate the cloud services it connects to because there's no way it will connect to anything other than it's own services. It's just a black box on my network. I can see what DNS queries it uses but that's not very much help...
This is a problem, yes. We should fix that problem.
>It's just one more way in which we've lost control of our local network. When it's not our network, it's a benefit. The same reason why use we SSL.
I think part of the reason why I'm in favor of things like DoH and SSL everywhere is there are very few cases nowadays where services are running entirely on a local network. The vast majority of things that people do on networks now touch the internet.
>I would like to use the device and filter out any of its harmful effects ... We used to have at least this as a last line of defense. And now we won't.
Except that "last line of defense" was always an illusion; as tptacek mentioned, malicious devices have always been able to perform encrypted DNS lookups if their developers really wanted to. DNS filtering was never a reliable defense.
You still do have IP blocking as a last line of defense, and that _is_ reliable considering nothing's going to get routed through the internet without being in an IP packet.
>I never considered the personal costs of all these good security practices until a cloud hardware device I own had the company go out of business.
My recommendation: if it depends on someone running something out on the internet to function, avoid it like the plague. The service _will_ shut down, it's just a matter of time, and IMO it's a waste to buy something that could turn into an expensive paperweight at any time.
I agree that we should push for more configuration options, but the fact remains that it's the users decision to run software that doesn't respect their freedom of choice, and ultimately they control the code that runs on their machine.
DoH is overall a huge benefit to preventing in-flight tampering and protecting user privacy. The net-benefits far outweigh the downside that "good" network providers can no longer tamper with DNS results.
And it's always been possible to block access to all DNS resolvers except your local one. Until now.
> the fact remains that it's the users decision to run software that doesn't respect their freedom of choice
Unless that code is malware or some Javascript an advertiser has placed on a website. There is no way to stop software from doing its own DoH requests without using browser or OS services to do it, so the controls supplied by the browser or OS are of rather limited value.
> The net-benefits far outweigh the downside that "good" network providers can no longer tamper with DNS results.
I disagree. I'm of the opinion that DoH brought with it a security problem that is difficult to resolve. It does provide additional security in another area, but that's not something that couldn't have been done using a more reasonable approach that didn't hamper my ability to control what's happening on my own machines.
This is true irrespective of DoH. If software wants to ignore the OS settings and resolve names down via its own custom protocol, that's what it's going to do. Short of auditing that software and it's connections, you can't really stop it.
The OS settings are not a control, they're a convenience.
How do you distinguish, at a technical level, your ability to control what's happening on your own machines versus someone else's machines? Assuming that you're referring to using your control over the network, and given that it's very common for people to connect to networks controlled by entities they don't trust.
I don't need to distinguish between the two because I'm talking about my own network and machines, not other people's.
I don't buy it. Even if you do route all DNS through a resolver on your router, that's hardly "protected", unless that resolver is itself using DNS over HTTPS (or TLS). Do you trust your ISP? I don't, and like most of the US I'm not in much of a position to switch. But even if I did trust my ISP, I wouldn't trust that the entire path from me to whatever DNS server the router is contacting (whether it's a recursive resolver or an authoritative one) was free of intelligence agency taps. In fact it seems much more likely that there is a tap somewhere.
The vast majority of people can't do that, if only because getting a reasonable experience from most websites today means allowing arbitrary code (Javascript) to be executed on your machine.
In my opinion it was wrong to go down the path of using DNS for content blocking in the first place. Even without widely available DoH, bypassing dns-based content blocking is trivial.
If I'm aware of terrorism, weapons dealing, human trafficking, etc., traffic on my network, I'd certainly block that. That's a different issue from crypto.
Also, I'm not so interested in blocking advertising anyway. I'm interested in blocking unauthorized data leakage (tracking, telemetry, etc.)
> In my opinion it was wrong to go down the path of using DNS for content blocking in the first place.
It has never been an awesome approach, true, but it's often the only approach available.
> Even without widely available DoH, bypassing dns-based content blocking is trivial.
Possible, yes. Trivial, no.
Not really, because you have no way to enforce the use of your own resolver or filters without using a proxy to MITM your HTTPS connections.