TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

On Firefox moving DNS to a third party

53 pointsby supakeenover 6 years ago

10 comments

supakeenover 6 years ago
An update is that on Reddit a Firefox employee has responded on my crosspost to reddit: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;firefox&#x2F;comments&#x2F;9cx8hk&#x2F;on_firefox_moving_dns_to_a_third_party&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;firefox&#x2F;comments&#x2F;9cx8hk&#x2F;on_firefox_...</a><p>Clarifying that this is just an A&#x2F;B test and there are no plans to continue using CloudFlare for all users.
评论 #17911129 未加载
评论 #17911474 未加载
briansover 6 years ago
This seems well-intentioned but incredibly dangerous. There&#x27;s no promise CF can make that justifies trusting them to receive a stream of every request from every FF browser, with all this trackable metadata.<p>In particular, I think it would be unsurprising if CF&#x27;s lines were tapped upstream. CF and Mozilla staff have a history of treating TLS as if it protects all content, rather than as a tool for keeping narrowly defined secrets. I explain further at <a href="https:&#x2F;&#x2F;weblog.evenmere.org&#x2F;posts&#x2F;2014-05-16-tls-is-not-for-privacy.html" rel="nofollow">https:&#x2F;&#x2F;weblog.evenmere.org&#x2F;posts&#x2F;2014-05-16-tls-is-not-for-...</a> .
评论 #17910914 未加载
评论 #17910678 未加载
评论 #17910732 未加载
评论 #17911183 未加载
dschuetzover 6 years ago
This is just like when Facebook wanted to handle all of your iOS traffic via a VPN app for &quot;secure Internet&quot; reasons. &quot;Trust us, you have nothing to worry about, your traffic is safe with us&quot; and then they were caught analyzing traffic data of all apps other than Messenger or Facebook. Yeah. &quot;Trust&quot;
评论 #17911004 未加载
评论 #17911000 未加载
sudhirjover 6 years ago
Given that my ISP currently tracks DNS and blocks whatever they feel like at that level, I actually think this is a good move.<p>The measure I&#x27;m looking at is that of sensible defaults: is this default more sensible for a majority of the user base than the existing default? For anyone outside the rule of GDPR using a regular ISP, this option is far better. The joint privacy policy Mozilla + Cloudflare is much better than a regular ISP.<p>And given that we all go and change the DNS of every computer we and our extended families own to 8.8.8.8, 8.8.4.4 or 1.1.1.1, I don&#x27;t see why we&#x27;d think Mozilla doing it by default is a bad thing.
buckminsterover 6 years ago
A friend of mine has a simple static hobby website on his own .net domain. It isn&#x27;t reachable through CloudFlare DNS. This has been true for over two months. Google DNS can see it, as can my ISP&#x27;s.<p>I recently noticed that his self-hosted email is sometimes being flagged as spam because it lacks spf.<p>Is CloudFlare filtering their DNS results, maybe against a spam blacklist?
评论 #17911104 未加载
评论 #17910931 未加载
justinzollarsover 6 years ago
Is there any easy way to change&#x2F;update the DNS lookup server? I do not trust Cloudflare or Google or anyone for that matter.
LinuxBenderover 6 years ago
Have Mozilla figured out how they are going to handle corp users enabling this and not breaking corporate DNS?
评论 #17910557 未加载
评论 #17910544 未加载
zaarnover 6 years ago
That title is a hell of a lot misleading considering this is for an early A&#x2F;B test and there are no plans to enable this for all users.
_4xjrover 6 years ago
Cloudflare&#x27;s 1.1.1.1 DNS already censors torrent&#x2F;piracy focused domains, for example rarbg and thepiratebay.<p>On the other hand, they resolve websites which are considered illegal in my country, which would normally be censored by my ISP (e.g. not approved betting websites).
评论 #17911161 未加载
评论 #17916102 未加载
RcouF1uZ4gsCover 6 years ago
The big issue with Mozilla, is that they are dependent on outside revenue (which for the most part ultimately comes from advertising). A big chunk of their revenue comes from Google. If CloudFlare were to offer Mozilla a lot of money to use CloudFlare DNS, they would likely do it.
评论 #17911210 未加载