Doug Lhotka

Technical Storyteller

  • Home
  • Cybersecurity
  • State of Security
  • Photography
  • 3D Modeling & Printing
  • About

Opinions and commentary are mine, and do not reflect those of my employer.

(C) Copyright 2019-2023
Doug Lhotka.
All Rights Reserved.
Use of text, images, or other content on this website in generative AI or other machine learning is prohibited.

Sly like a (Fire)Fox

June 25, 2020 By Doug

Mozilla has been overriding network settings for DNS in the browser for a while now, motivated by privacy concerns, but recent actions to default to an ISP DNS service raise questions and seem inconsistent with that design.

DNS over HTTPS is an attempt to block eavesdropping on DNS requests, which is great in theory, but causes a number of problems, especially with the current design in Firefox.  From an architectural standpoint having any application use its own DNS system rather than the network stack’s configuration is poor design.

First, network administrators have real requirements to monitor DNS requests.  For more formal networks, this is often used to block malicious links, track malware, and prevent access to prohibited content.

In my own case, I run a Pi-Hole to block advertising and track across all of the devices on my network, and in turn have that pointed to Quad9 (secure DNS of course) to leverage their block list, with CloudFlare as a backup.  Other home users will have parental control software active.  In both cases, Firefox overrides those settings and bypasses any local blockers.  By default.  With no notification or consent.

Their original argument for making this opt-out was because most users won’t turn it on if it’s opt-in.  I can sort of get that, and previously the default DNS servers were pretty benign.  However, with the announcement recently, Firefox will now default to an ISP’s ‘secure’ server if you’re on their network.  Mozilla claims that making this change is OK because users can opt-out, but again, that’s contradictory to their reasoning for opting users in by default in the first place. In any case, this doesn’t seem exactly in line with their previous position on providing secure DNS to avoid ‘ISP eavesdropping’ is it?

I’m not mentioning the specific ISP, because I expect it’s just the first of several that are going to go down this path.  And while it’s possible that they’ll actually provide secure, private, non-tracked, non-filtered DNS lookups, there are loopholes in the Mozilla DOH Resolver Policy. And when it comes to ISPs, let’s just say that past practices are cause for reasonable concern.

What Firefox should do instead is pop a configuration screen that allows the user to opt-in both to DNS over HTTPS, and then select the server they’d like to use.  No default.  No automatic enablement.  When new server options are added, just pop that screen up again and ask if they’d like to change.   Empower the users to make a choice based on their own priorities and interests.

That’s how you support user privacy.

Filed Under: Security Tagged With: cybersecurity, dns, firefox, mozilla, security

River snow in Estes Park

June 12, 2020 By Doug

Continuing to mine the archives for new zoom background, and also thinking of cooler times as we start to get into the 90’s.  This was from a spur of the moment trip to Estes Park – typical tourist cabin, nothing special, until the next morning.  We woke up to a winter wonderland, with that wonderful soft quiet air.  Magical.

Filed Under: Photography Tagged With: colorado, estes park

Winter Lavender in Tasmanaia

May 18, 2020 By Doug

Tasmania always conjured up images of Bugs Bunny, but after visiting there, now one indelible memory is of their lavender fields.  I can only imagine what this looks like when they’re in bloom (we went in the winter), but the rows still made for a neat image.

Filed Under: Photography

  • « Previous Page
  • 1
  • …
  • 3
  • 4
  • 5
  • 6
  • 7
  • …
  • 48
  • Next Page »

Cybersecurity

Photography

3D Modeling & Printing

Recent Posts

  • Cabin Ruins in Montana
  • Grand Canyon HDR
  • Grand Canyon First View
  • Grand (foggy) Prismatic Spring
  • Sunny Day at Grotto Geyser