Firefox Will Soon Encrypt DNS Requests By Default

'This month Firefox will make DNS over encrypted HTTPS the default for the U.S., with a gradual roll-out starting in late September, reports Engadget: Your online habits should be that much more private and secure, with fewer chances for DNS hijacking and activity monitoring. Not every request will use HTTPS. Mozilla is relying on a "fallback" method that will revert to your operating system's default DNS if there's either a specific need for them (such as some parental controls and enterprise configurations) or an outright lookup failure. This should respect the choices of users and IT managers who need the feature turned off, Mozilla said. The team is watching out for potential abuses, though, and will "revisit" its approach if attackers use a canary domain to disable the technology. Users will be given the option to opt-out, explains Mozilla's official announcement. "After many experiments, we've demonstrated that we have a reliable service whose performance is good, that we can detect and mitigate key deployment problems, and that most of our users will benefit from the greater protections of encrypted DNS traffic." "We feel confident that enabling DNS-over-HTTPS by default is the right next step."' -- source: https://news.slashdot.org/story/19/09/08/0318237 Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 http://www.cms.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/

On Mon, 9 Sep 2019 08:57:51 +1200, Peter Reutemann quoted:
'The team is watching out for potential abuses, though, and will "revisit" its approach if attackers use a canary domain to disable the technology.'
The “canary domain” is a special indicator agreed on between Mozilla and outfits that offer parental-control systems; if Firefox detects that this domain is blocked, then that means parental controls are in effect, so the DNS-over-HTTPS system is disabled for that user. More here <https://www.theregister.co.uk/2019/09/09/mozilla_firefox_dns/>.

On Mon, 9 Sep 2019 08:57:51 +1200, Peter Reutemann wrote:
'This month Firefox will make DNS over encrypted HTTPS the default for the U.S., with a gradual roll-out starting in late September, reports Engadget'
Google Chrome will be following suit <https://www.theregister.co.uk/2019/09/10/chrome_78_dnsoverhttps/>, but only for a small fraction of users among those who are already using one of a set of supported DNS services. This is in contrast to the Mozilla approach, which works exclusively through the Cloudflare DNS. Long-time Unix luminary Paul Vixie is not keen on DNS-over-HTTPS (which is what both these browsers are implementing). He prefers DNS-over-TLS, because it can be selectively blocked at firewalls, giving more control to local admins.
participants (2)
-
Lawrence D'Oliveiro
-
Peter Reutemann