Canary domain – use-application-dns.net
support.mozilla.org
support.mozilla.org
I am against individual applications making their own DNS queries. This is a responsibility of the OS.
I love the idea that I can query DNS without being spied upon. However, at home, for the protection of my family and me I want all devices to go through a certain DNS server.
So where does this leave us? We're delegating the statement of 'I'm being secure' to the DNS server itself.
Shoutout to my Google Mini which ignores DNS servers in the DHCP response.
Put Roku on that list. They also break in a spectacular fashion if you redirect the queries to a DNS server that returns NXDOMAIN. Its like they query in an infinite loop with no rate limits. They absolutely hammer the DNS server.
Kindle Fire tablet has hard-coded Google's 8.8.8.8 DNS server, bypassing the Pi-Hole ad blocker.
People like you are the reason DoH is being rolled out. I hate the concept, but I would immediately enable it if I caught my IT unapologetically getting in the way of my work like you do.
It's not just ISP operated DNS. There are many other scenarios where multiple parties share one DHCP server, where the DHCP admin's choice of DNS might not be what every other participant desires. For instance, using a public wifi, roommates sharing a router, visiting someone's house, etc.
But every other network request they will ever make is fine if they do it themselves? Like at some point we have to be like DNS being a service provided by the system to apps was mostly a historical accident or an idea for a network model that never really panned out.
I would have loved to see the alternate universe where your typical unprivileged app has no direct access to sockets and routes all requests through a system service that handles all the application-layer protocols and encryption.
I think that I prefer the network model where I the system owner have control over what the programs executing on my behalf are doing on my system and my network. I really don’t want to be presented the choice of binary blob A, binary blob B or living without Internet access.
> I would have loved to see the alternate universe where your typical unprivileged app has no direct access to sockets and routes all requests through a system service that handles all the application-layer protocols and encryption.
Ditto.
DoH as protection of my own traffic against snooping ISPs is very much welcome. DoH as protection of locked down apps and devices against their owners - not so much.
Yeah. Once DoH succeeds in preventing DNS based blocking of ads, trackers, etc., I’m sure all the big tech companies will come back to the table and agree on a standard that gives that power back to users.
/s for anyone that needs it.
I'm not sure how DoH dramatically changes this. Even absent DoH a device can always ignore your network's DNS settings and just query 8.8.8.8 or whatever "known good" DNS server they wanted. This isn't uncommon with IoT devices today, usually to avoid ISP tampering with DNS.
I actually think Chromium adopted the better solution. Chromium will "upgrade" to DoH when you are already connecting to a DNS server known to support DoH anyways. It also bothers to implement /etc/hosts resolution, as well.
Of course Google could use DoH to defeat AdBlock, but they can do that regardless of whether or not DoH is adopted by browser vendors. You already have control over the DNS resolution on your browser/most devices, so it hardly does anything. If they really wanted to defeat DNS based filtering, there's no reason they need to use DNS in the first place.
For some reason, unencrypted DNS has a lot of fans. I don't understand it. I can understand why Firefox's approach is not loved, but Chromium's approach seems entirely reasonable and has basically no conflict of interest whatsoever.
I am my DNS provider. I choose to apply content filtering.
DoH just increases the set of parties who see my traffic.
DNS-over-HTTPS has nothing to do with your traffic being sent to somewhere you didn't intend for it to. If you experienced something like this, it's because some software decided to ignore your configured DNS resolver, which has absolutely nothing to do with DNS-over-HTTPS and is not how it is implemented in all software. If a piece of software wishes to, it can use any name resolver it wants, and bypass the DNS system altogether.
You can also run your own DNS-over-HTTPS resolver. It's probably even a good idea to.
> The canary domain only applies to users who have DoH enabled as the default option. It does not apply for users who have made the choice to turn on DoH by themselves.
So basically it sounds like a way for system administrators to disable DNS over HTTPS on their local network when DoH is enabled by default on the machine.
Though I'm not sure what's preventing people from abusing this on public networks and ISP level.
So a public network, which you already have to trust enough to use, tells you which DNS servers to use, and there's an implicit agreement and understanding about that. So which is more abusive - this implicit agreement and understanding, or some third party changing your defaults without asking you which then sends all your lookups to a third party you probably didn't even know anything about?
You may not have a reason to trust Cloudflare, a company that you have no contract with, and a company that you do not pay, and a company that blocks most of the internet to people using browsers/extensions to protect their privacy.
But if DoH is off, you are essentially trusting your hardware, and your ISP with which you have a paid contract.
Enforcing a hard-to-enforce contract is possible, and such contracts have been enforced before.
You will have a more difficult time getting anyone to enforce good behaviour from an entity that you do not pay, and have no contractual relationship with. Especially if that entity is subject to a law that requires them to access not only their data on US servers, but foreign ones as well.
Additionally, any network along the way can inspect unencrypted packets not just your ISP. Unless your ISP is just one hop from the DNS server you're using (or you use your ISPs DNS).
You are trusting potentially dozens of parties... some of whom you have a contract with any many you don't and some of whom may be a malicious government (depending on where in the world you are).
But I do agree with, implicitly, what you are saying. I wish the default wasn't Cloudflare and if you change it explicitly it sounds like the canary won't work anyway.
In short, it is a *cricket*
Was going to say: as a DNS administrator of 30 years, this stuff does not fully nor adequately explains how this feature is used or benefit the end-user.
Shouldn't matter btw. On iOS everyone uses Webkit as that's the only engine Apple allows on the App Store.
Isn’t the purpose of DoH to increase privacy?
But then if I go to a coffee shop that wants to inspect my DNS queries, they can respond for this mentioned domain in a certain way, and it will result in DoH being disabled and leaving the coffee shop free to inspect the unencrypted DNS I am making?
If a network implements DNS-based content filtering and blocks DOH requests, not responding to a query for this domain could allow an application to know to not bother trying DOH, since it will definitely fail every time.
I could be totally off the mark here, though.
It’s on port 443, probably to the IP of a huge CDN. How would you block it?
I block DoH/DoT quite successfully on my network, not to invade privacy but to block privacy invading sites and usage statistics that the current DoH/DoT providers gather. Thus far it has not been an issue.
I was surprised to find that cell phones automagically discover my DoT 853 listener on my firewall that is served up by Unbound. I do have a "_dns.resolver.arpa" hint record but nothing has ever queried it.
How would you even know it’s happening? Is it even possible to snoop on HTTPS traffic if you have a mobile device like an iPhone? Making it impossible to see is the entire point AFAIK.
[Edit] I should also add that I do not block VPN's. If someone wants to manually bypass my DNS they can do so with a VPN client. Perhaps some day all the browsers will start creating VPN tunnels to random CDN's on 443.
> I block DoH/DoT quite successfully on my network
How do you block encrypted traffic that’s mixed in with normal HTTPS? I get that you can block the well known IPs, but that’s only a partial solution.
The argument for this is specious at best - people who don't care enough to change their own DNS servers on their own networks apparently have to be saved from themselves, which is why Firefox decided to turn it on without prompting the user, in spite of many people complaining about changing the default without asking.
Enabling this canary domain doesn't disable DoH, if you've explicitly turned it and/or configured DoH with your own settings. DoH still stays on.
The Cloudflare DoH privacy policy is already one of the least privacy friendly, so anyone who remotely cares about their privacy should not be using Cloudflare DoH.
For example, "transactional and debug log data" is stored for 25 hours at Cloudflare.
If you're in a coffee shop and not using a VPN then, well....
But in direct answer to your question. No.
If you setup DoH correctly then you are not reliant on the initial DNS lookup. For example 9.9.9.9 has a valid cert for 9.9.9.9, so no initial DNS lookup needs to be done.
As an application, don't do your own DNS lookups but respect the ones from the OS.
Which makes me wonder, does Windows respect `use-application-dns.net` when I enable DoH?
> The canary domain only applies to users who have DoH enabled as the default option. It does not apply for users who have made the choice to turn on DoH by themselves.
I'm sure many applications and devices are already doing it. Who has the time and inclination to monitor the network traffic of all their appliances to ensure they're not being spied on? I wish someone would and we'd publicly shame all the scumbags that do it, but alas...