What Google and Mozilla seems not to get, Microsoft gets 100%.
Good on them. Thanks for sticking up for the user, MS. At least someone did.
What Google and Mozilla seems not to get, Microsoft gets 100%.
Good on them. Thanks for sticking up for the user, MS. At least someone did.
https://9to5google.com/2019/10/28/chrome-encrypt-dns/
Mozilla (I believe) is doing rolling out DoH to users (in the US) to use CloudFlare's DoH server. This will bypass the system configured DNS servers. This can be disabled in settings. And if the DoH DNS lookup fails, it'll fallback to the system configured DNS.
https://support.mozilla.org/en-US/kb/firefox-dns-over-https
(I'm a googler, opinions are my own)
https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
https://support.mozilla.org/en-US/kb/customizing-firefox-usi...
https://support.mozilla.org/en-US/kb/customizing-firefox-usi...
https://github.com/mozilla/policy-templates/blob/master/READ...
Classy move, Mozilla.
It's intended as a way to allow DNS filtering software to work when admins aren't involved with user devices. DNS filtering software breaks DNSSEC anyway. So using it doesn't break anything extra.
With the DNSSEC breackage, the issue is the scope. With a little bit of thought, they could break just .application-dns.net instead of entire .net, if they used use.application-dns.net instead of use-application-dns.net. But I guess collateral damage wasn't in the mind of whoever suggested that.
Also, it is a difference, when a single second level domain has broken DNSSEC (especially one used only by single application that won't use DNSSEC anyway), and when entire top level domain is broken (which will be used by other applications, which do validate DNSSEC).
I know that DNSSEC is not favoured by browser makers; I'm personally not a big fan either. But just ignoring it as they were all the years is something different, than actively trying to undermine it and damaging other users of it.
This is true. Nothing has shaken my faith in Mozilla more than their efforts with DoH.
Chrome (and firefox) are providing their own DNS, away form the system. This means that loading www.blah.com in chrome, firefox and opera will result in 3 different DNS lookups, and potentially 3 different results.
Windows is doing it right.