Thai Database Leaks 8.3B Internet Records
rainbowtabl.es
rainbowtabl.es
Actually, for most people that are not technically savvy this is definitely not an easy thing to set up, nor are they even aware that DoH/DoT exist.
Unless this feature starts being turned on by default in routers and popular software, the average user's DNS lookups will not be protected.
Firefox has DoH turned on by default for US-based users. Unfortunately being US-only, it won't protect Thai users just yet. Especially considering the fact that Thai ISPs have known to be hijacking port 53 and NXDOMAIN since forever[1] with ISP in the article being one of the biggest offender.
It might also worth nothing that PDPA, Thailand's equivalent of GDPR, is to become in effective in two days (May 27th) so this incident will be... interesting.
[1]: Starting in early 2000s, with NIPA (that I never see anybody uses), who aim to provide IDN-enabled Thai domain names by providing NXDOMAIN-hijacking services to ISP
I wish Firefox would expose the option from about:config in its user-friendly Preferences page so it will respect the "system default" (the advertised dns server).
I am - for no legitimate reasons - avoiding Cloudflare as a resolver. As far as I know Firefox uses Cloudflare.
I really want to use uncensoreddns.org, but availability has been a little flaky in the past. I'm not sure about Quad9. Google and CloudFlare are obviously out of the question. What else is there?
It really depends what you view as being "trustworthy". Outside of the US good enough? Or do you want non 5/9/14-Eyes? (https://en.wikipedia.org/wiki/UKUSA_Agreement#9_Eyes,_14_Eye...)
DoT: dns.digitale-gesellschaft.ch
DoH: dns.digitale-gesellschaft.ch/dns-query
Source:
https://de.wikipedia.org/wiki/DNS_over_HTTPS
https://de.wikipedia.org/wiki/DNS_over_TLS
https://www.digitale-gesellschaft.ch/dns/
Sorry, for not being available in the en-wiki
I trust CF much more than my ISP, but it makes the potential leak much worse...
edit: On the other hand, DoH makes DNS requests independent of ISP, which is nice. ISPs are often monopoly by nature.
Obviously, for Thai users this is a reasonable option, but I would understand why American users would not want to use Cloudflare, Google or even Quad9, as these are all US-based.
HQ
1442 A Walnut Street
Suite 501
Berkeley CA 94709
Bonus if you are interested: forum thread where Quad9's director of the board comments about DNS are surprisingly informational.
They are, but because this is all Cloudflare's 1.1.1.1 service does, that log only tells you that the IP address used Cloudflare's service.
So whereas this Thai data more or less says e.g. You watched Netflix between 18:40 and 19:26 and then again 21:33 to 22:09 the Cloudflare data says you own a device that uses Cloudflare's 1.1.1.1 DNS service. Maybe you can try to do some kind of activity estimate e.g. me idly browsing random web sites probably causes more DNS queries versus a SmartTV just periodically doing auto-updates when I'm asleep, but the 2000:1 dilution would make that more unreliable.
It isn't strictly nothing but it's damn close.
It is much better than just having normal logs laying around, and since the data is split in two data set, there is a possibility that having access to one does not automatic result in having access to the other. The dilution is also helpful, through I am uncertain to the extent given the amount of traffic generated.
For example Facebook probably said they would keep your data secure, but their system to prevent abuse from 3rd party "Quiz" developers was "Developer, by clicking here you agree not to abuse the data you can access."...
If you want it solved find a protocol that can be used in the libc resolver and make it ubiquitous rather than goofing around with browser defaults.
Blocking popular DNS providers is a common tactic deployed by ISPs. It is technically easy enough to bypass depending on your skill level and interest in doing so. Their strategy is make it difficult for majority of their users, who won't know or care, users doing all this will not make substantial impact on revenue generated from selling this data, or from showing adds etc so they don't make the effort.
DoT/DoH is not going to change this, Firefox's market share is not enough for that. I don't see Chrome or Safari implementing this functionality at all.
Is this confirmed? I couldn't find a source for this statement.
With enough DNS data I can assure you I can see when you leave to work, get back, determine the moment when you leave for vacation and no one is home, etc.
Especially in Thailand, where free speech is almost non-existent.
Few months ago there were Twitter user who goes by the name "Anonymous" ("นิรนาม" in Thai) who have been arrested for spreading fake news and being a threat to the country. The Twitter user mainly tweets about topics subjected to lèse-majesté law. He never leave any traces, which leaves question on how officials managed to track him down if Twitter claims they didn't received any requests from our government.
My small group of friend came up with one scenario where official sent a honeypot URL via Twitter DM, then trace him via DNS query logs. This is assuming the scenario where he don't click on random links and using a browser that performs DNS prefetching of sorts. Everyone thought it was unlikely at the time, partly because nobody thought ISP would actually logging all DNS queries.
Apparently, all of us were wrong, at least on the latter.
Don't get me wrong, I really don't like this in Thailand and it's absurd that you would even need something like that. As a foreigner visiting Thailand I don't feel that comfortable with my browsing habits. Usually I trust a local provider enough to just browse and not care about what I'm looking up, Thailand is not one of those places and I always use a VPN. (Mostly routed to Singapore)
One likely non-malicious explanation is that the telco is offering some plan with data caps based on social media such as instagram, facebook, etc. Searching around, I found the offering below for unlimited data on 9 social media apps http://www.ais.co.th/one-2-call/simcard/en/super_social.html...
I'm guessing one way the telco implements the selective cap is by tracking user's DNS, and is probably interested to know traffic to facebook
Also AIS mobile is IPv6 (2001:44c8:4400::/44) with CG-NAT since 2017. IIRC they were giving out /64 to every mobile client, but I'm not sure how long does /64 assignment lasts.
To be clear: I do this research in my free time. This is 100% independent of my $dayjob at Cloudflare.
I guess I've been dealing with those issues for so long they don't bother me anymore!
Also, I use a great extension for Firefox, so I can switch to/from the proxy in 2 clicks, "Proxy Switcher and Manager".
May be a long time ago, in a galaxy far away, such a thing once existed. It's a sweet thought though.
In my tinpot banana republic (Australia) ISP metadata retention is required by law, and warrantless access to that is granted to organisations involved in fighting terrorism, child abuse, and other serious crimes - and those agencies include local councils, animal control, the taxi commission, and various horse racing oversight organisations... :sigh:
Even moving your meta data to a different legal jurisdiction makes it less likely to be abused. My local nosy dog catcher is unlikely to attempt to get hold of any useful internet meta data when my ISP hands over their records and say "Ahhh, yes - bigiain's metadata here shows about 2TB of bandwidth for May, all to the ip address of a VPN endpoint in <checks ip geolocation> Belize... I can look up the Belize police phone number for you, do you speak creole?"
Still gonna put off the local dog catcher who's trying to work out if I'm video chatting with his ex girlfriend...
(If _actual_ FVEY or equivalent national security agencies are curious about me, I'm pragmatic enough to know none of my tradecraft live action role playing is gonna make any difference at all. I could buy some magical amulets, fake my own death, and live in a submarine. I am still gonna be Mossad'ed upon... I'll avoid running shipping containers full of drugs/weapons/children across international borders, and try to keep my harshest criticism of the Saudi/Trump Royal families to myself...)
https://www.insideprivacy.com/data-privacy/thailand-passes-p...
All Thai constitutions have had strong privacy requirements, but that has never been important for what actually happens.
It's really not clear what compliance will be like. If it's anything like most things here then it'll only be if the government gets annoyed that a company will be in any danger of prosecution.
And with the complexity of modern software, imagine if the defaults in the whole software stack all the way down to the OS and hardware were open by default. You would need to be an expert in security to set up anything. Thanks god everyone else goes secure by default.
The other place, where "product owners" and pointy haired managers mingle - that place will be quite crowded when their TTL expires.