You can also setup a custom DoH provider (that can also be configured on the system level, not just the browser) so neither Cloudflare or your ISP gets your DNS queries.
You know you are quite fortunate to be able to say so.
Firefox is a project with global impact. A lot of people around the world can benefit from DoH.
The German Grundgesetz (constitution) says "eine Zensur findet nicht statt" (censorship does not occur/there will be no censorship) yet, there is censorship.
I was sceptical about DOH in general (why do we need this?) but now I see why this can be a good thing and great as well that Firefox supports it so easily.
I'm not going to search for every single article. Or are you seriously suggesting that Reuters is 100% free of propaganda, especially in war times?
The answer your question: "common sense".
I don't care about either side of this argument, but you can't logically turn the question around. The burden of proof is on you, who made the claim.
Like "don't get caught by your own gov accessing restricted material get caught by USA gov-related organisations so they can sell you out to your own gov & benefit USA".
If you're bothered about who's watching your web traffic then it seems highly unlikely you want to add USA to the list of who is watching you??
And the States are watching you anyway: most of the Internet resides there. Even the websites that don't are likely using Cloudflare or etc to save on traffic.
I'm in Canada and the default provider is CIRA. I can also choose to switch to Cloudflare, NextDNS, or add my own.
You can check out the Network Settings at the bottom of the General tab to see what your default is.
And I simply don't trust Cloudflare.
The threat vector is understandable. Not making the choice to mitigate it is what does not make sense to me. Cloudflare is not an unknown operator. You can study their past behavior, their beliefs, and how their services work, and make that choice.
Saying 99% of people accept the defaults and claiming this is bad without learning about what the defaults are or how to change them when it takes a few straightforward steps to do so is what does not make sense to me.
Even installing Firefox in the first place is to make a conscious choice to change the defaults of nearly all operating systems that the vast majority of people on Earth use. It’s defaults will also now have a feature to encrypt your DNS queries to a third party vetted by Firefox. If you cannot trust them then why use their browser?
“Matthew Prince, Cloudflare’s chief executive. “It’s dangerous for infrastructure companies to be making what are editorial decisions,” he said.”
Not dangerous enough apparently.
It's just an option. In this case, both selected options are excellent providers that I'm happy to see.
apt install dnsmasq
is my preference.
Even a ten dollar router will let you pick who you trust for DNS.
Everyday people who are worried about state-actor threats - an incredibly targeted and unlikely scenario for the average person - but are less concerned about their personal information being harvested for marketing purposes - something that happens all the time to everyone.
Even if the foreign government spies more nether jurisdiction is likely to care enough about you specifically to make an international case of it.
In other words I'd think most Americans would be better off proxying through Europe, and most Europeans would be better off proxying through the US.
Even better would be to proxy through a third country that your own country is unlikely to cooperate with, and which won't care about you personally.
E.g. I wouldn't want to live in Iran or North Korea, but I'd think proxying DNS through them would in some way maximize my privacy if I was living in Europe or the US.
I'll never travel to either of them, and my authorities are vanishingly unlikely to cooperate with either of them for anything short of murder.
I agree with you that people should be more worried about companies collecting their personal info, but we know now that the state collecting your data isn't incredibly targeted or at all unlikely. They just take everything. It's happening to every last one of us every single day. It's been going on for decades.
https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Russ_Tice
And if I was an intelligence agency trying place spies, Cloudflare would be among the first tech companies I'd target.
This feature seems almost exclusively a feature for people in the ISP-monopoly-friendly United States.
This seems like a threat model swap in the conversation. The subject threat model here is (1) defending against companies stealing and selling my data. You swapped in the threat of (2) state level agencies spying on you through these companies.
The problem is that #2 seems to be an intractable problem. (but not so much because of an infiltrated DNS provider, more like cable taps and infiltrated hardware manufacturers)
#1 seems to be a more solvable problem (albeit at increasing levels of complexity). When you bring #2 into the conversation, it defocuses on the solution to #1 and gets to a point where we all throw up our hands and admit helplessness and defeat.
I see this happen often and I think every conversation should be clearly grounded in the threat model that is being addressed.
A while back, Sky Broadband was even intercepting all customer traffic to UDP or TCP port 53, and forcing it to go to their shitty DNS servers, which panic and drop the connection when they see something 'unusual'.
This is exactly why DNS over HTTPS is a thing. Unencrypted services are regularly abused by ISPs and DNS is no exception.