Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243707

Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From Dan Ritter <dsr@randomstring.org>
Newsgroups linux.debian.user
Subject Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Date 2022-01-05 13:50 +0100
Message-ID <DCdTQ-2AZ-5@gated-at.bofh.it> (permalink)
References (5 earlier) <DBWzE-b4-13@gated-at.bofh.it> <DBWT0-hr-25@gated-at.bofh.it> <DBXP3-QH-9@gated-at.bofh.it> <DBZxv-1VG-3@gated-at.bofh.it> <DC6Sm-6vm-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


tomas@tuxteam.de wrote: 
> On Tue, Jan 04, 2022 at 04:09:42PM -0500, Dan Ritter wrote:
> 
> [...]
> 
> > Here's what I do:
> > 
> > My local DNS resolver offers DNS, DNS over TLS, and DNS over
> > HTTPS.
> > 
> > I supply a use-application-dns.net zone that returns NXDOMAIN.
> > That tells browsers to not use DoH.
> 
> Oh, is it possible to tell the browsers which host to ask to resolve DoH
> requests? That would be... nice :)

Not precisely which host. A compliant DoH client (FF, Chrome) is supposed to
start by asking local DNS for a record from
use-application-dns.net, which Mozilla runs. If your DNS server has
use-application-dns.net and insists on returning NXDOMAIN, then
the client should fall back to using whatever DNS the operating
system supplies.

In Bullseye, unbound has support for both DNS-over-TLS and
DNS-over-HTTPS -- the latter is new.

> > I build an adblocker zone [...] that always answers with a 204 [...]
> 
> nice

Pick an IP in your local net - let's say, 10.0.0.254. Use that
as your DNS response instead of 127.0.0.1. This will work just
fine in /etc/hosts.

Make sure you have a machine listening to 10.0.0.254, and set up
a web server to answer regardless of name. 

For nginx:

server {
	listen 10.0.0.254:80;
	server_name _;

	root /var/www/blank;
	index blank.png;

	rewrite .+?(png|gif|jpe?g)$ /blankimg last;
	rewrite ^(.*)$ / last;

	location / {
              return 204;
	}

	location /blankimg {
		empty_gif; # See http://nginx.org/en/docs/http/ngx_http_empty_gif_module.html
	}
}

So if the page asks for an image, I supply a 1x1 transparent dot.
If it asks for anything else, 204, which is not an error.


-dsr-

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:10 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Roberto C. Sánchez <roberto@debian.org> - 2022-01-03 23:20 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:20 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Mark Allums <maa@allums.com> - 2022-01-03 23:40 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 00:30 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:00 +0100
        [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:10 +0100
          Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 19:20 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 21:30 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com David Wright <deblis@lionunicorn.co.uk> - 2022-01-04 20:40 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 21:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-04 22:10 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 14:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 18:30 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 18:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 19:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 22:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 21:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 22:30 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-05 13:50 +0100
            Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 19:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-03 23:50 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com Charles Curley <charlescurley@charlescurley.com> - 2022-01-03 23:40 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:30 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:40 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:50 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com RP <reyadmin@gmail.com> - 2022-01-04 00:50 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 07:00 +0100
    [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 13:00 +0100
      Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 13:20 +0100
    GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com) rhkramer@gmail.com - 2022-01-04 15:00 +0100
      Re: GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com) <tomas@tuxteam.de> - 2022-01-04 16:30 +0100

csiph-web