Firefox Installs non-free binaries from Cisco and Google again (2018)
bugs.debian.org
bugs.debian.org
A substantial user and developer base prefers Debian precisely because of these Guidelines. Inclusion of free software (as-is) that automatically installs non-free binaries would violate almost all of these guidelines.
An analogous situation would be the non-free NVidia blob. Debian fully supports installing it, but it would be very much verboten to do so by default, automatically.
And your browser will download linked javascript from third party websites to make it run. As firefox downloads a codec from a third party to make the media you've requested run.
I actually agree about the conflict between this codec behavior and the Debian philosophy. But they need to come to terms with the much greater conflict with their philosophy that the modern internet experience presents.
Stallman, for all his faults, was right about a lot of things. We live in a world where people don't own their own books, and buy software on a subscription model. For a few years back in the late 90s and early 2000s it looked like free software was the answer. But the internet made an end run around it, and Debian, etc., hasn't caught up. We're all digital renters instead of owners.
Standard versions of Firefox include non-free components by default because most users expect Netflix to work. ("Free" means "open source" in this context.)
Debian repositories (that aren't named "non-free") are supposed to contain only free software, so the Debian-packaged version of Firefox needs to be stripped of any non-free components. Should any slip through, that's a critical bug as far as Debian is concerned.
I don't think there's an issue here, it's just two projects with different goals proceeding as they're supposed to. We can have a discussion about all the things wrong with Encrypted Media Extensions and the like, but it's somewhat beside the point unless Firefox gains way more marketshare.
On the other hand, Widevine is actually proprietary DRM.
both issues are still open after more than 1 year! There seems to be a disconnect in how FF security is perceived by tech savvy users and how security/privacy critical bugs get prioritized by Mozilla.
edit:
Just recently I discovered DoH was activated by default now and bypassing my /etc/hosts block list without any warning. This opened me up to tracking from sites I thought I had blocked (discovered it only by accident and after several months when I actively looked into DoH and the network.trr.mode setting).
In all above cases the failure-modes are insecure. It's like a firewall that suddenly switches its enforcement policy from a deny-all+whitelisting to allow-all+blacklisting without properly informing users.
Totally unacceptable!
Are FF sending all my DNS data to a private third party now then? Doesn't sound a very FOSS thing to do?
You can of course change it, but it's opt-out and not communicated to users that this is happening.
https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs
For many, maybe even most, the situation is reversed. ISP-provided DNS (the default for 99% of web users) is very often intentionally mis-configured to return ad-laden "search results" instead of NXDOMAIN. The situation is more authoritarian administrative districts is even worse. You're right that trusting Cloudflare isn't ideal either, but they are at least better behaved than most ISPs, so it's the lesser of two evils, I think. Non-technical users shouldn't be expected to know how these things function, they should just get the least-bad option by default.
It's a tradeoff and people should weigh the pros/cons seriously. Firefox claims it shows a notification popup, but it may be too easy to click away. (I didn't see it.)
It should be front-and-center.
Big claim, with no evidence what so ever. Consider this a "Citation needed".
https://en.wikipedia.org/wiki/DNS_hijacking#Manipulation_by_...
Unless they explicitly say so, your ISP is not spending a boat-load of money running a DNS server for you to use because they're nice. They're not even doing it because you're paying them for a service. They're doing it because they can monetize the data and serve you ads.
Nope. You have to provide the address of a resolver, but that doesn't mean you have to run one yourself. There's nothing stopping the ISPs shipping a standard DHCP config that points their customers at (for example) 8.8.8.8, or 1.1.1.1, or whoever.
A few minutes walk from me some people opened a gelato place. You go there, you buy some gelato. Nice. Warm summer evening, drop in, buy a cone, delicious. I am 100% certain that by selling me frozen desert they get money! Their plan may not specifically have focused on me enjoying this at all. And yet, since the effect is that I can enjoy desert that's exactly what I do, and I don't begrudge them their money.
I don't trust my ISP, so I'd prefer not to use their DNS or to pass requests up to root servers over cleartext. I also had some performance issues with root server requests since they have to chase the authoritive servers.
Right now I'm sending TLS requests to cloudflare, but obviously since I'm not paying for them, I'm the product.
Then switch to one you do trust.
Especially if you do not count satellite, which I do not. My house has one crappy DSL 18Mbps provider and that's it. Their way or the highway.
https://arstechnica.com/information-technology/2016/08/us-br...
But let's be real: the internet is quickly becoming a walled garden, so having access to DNS requests is mostly only going to give you a billion facebook.com + twitter.com + youtube.com + google.com + google-analytics.com lookups anyway.
Kinda like a “free market”, except it’s “regulated“ to not allow scamming end-customers. I find it quite enjoyable.
Maybe you in the US should fix the root cause of your problem (legislation) instead of deploying rogue technology making life complex for everyone else?
Guess what? The big ones are still awful: hijacking DNS, providing horribly congested service and laughable "support". All in the race to cut as much cost and increase profit in the name of being able to undercut the next guy by £1/pm. Competition isn't the pancea you seem to think it is.
> Maybe you in the US should fix the root cause of your problem (legislation) instead of deploying rogue technology making life complex for everyone else?
Maybe you should use a different browser. Or learn how the one you're using works at least.
I would guess between monopolies and hostile governments, more people worldwide have no choice, and it's a good default, but I don't know.
In any case, both Firefox and Chrome should make it super clear to users that they are doing this.
Hopefully starlink will change this :)
You're not just getting connectivity, though. You are getting Mars. Or, buying it for somebody else, really.
Do you also trust everyone in the same Internet Cafe as you? And your ISP? And everyone else on the network path to your DNS provider? Because they all can see all of your DNS requests. Your ISP can even alter them. DoH ensures privacy and integrity of your DNS requests, so they are _only_ shared with your DoH provider.
It reads your /etc/hosts before going to DoH I believe.
also if you have unbound or local dnsmasq caching you could set a canary domain (https://support.mozilla.org/en-US/kb/canary-domain-use-appli... ). To set it up with dnsmasq just add the line for the canary to /etc/dnsmasq.conf:
address=/use-application-dns.net/* https://github.com/pi-hole/pi-hole/pull/2915
* https://github.com/pi-hole/pi-hole/pull/2916
* https://github.com/pi-hole/pi-hole/compare/master...developm...
[1] https://support.mozilla.org/en-US/kb/firefox-dns-over-https
I wonder if the devs get a bonus for everyone they fix.