Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243730

Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From Celejar <celejar@gmail.com>
Newsgroups linux.debian.user
Subject Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Date 2022-01-05 18:50 +0100
Message-ID <DCiAa-5zx-7@gated-at.bofh.it> (permalink)
References (6 earlier) <DBY8q-XI-9@gated-at.bofh.it> <DBZe9-1P7-5@gated-at.bofh.it> <DC6Sm-6vm-7@gated-at.bofh.it> <DCePU-3a1-3@gated-at.bofh.it> <DCigN-5pq-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Wed, 5 Jan 2022 18:20:23 +0100
<tomas@tuxteam.de> wrote:

> On Wed, Jan 05, 2022 at 08:43:23AM -0500, Celejar wrote:
> > On Wed, 5 Jan 2022 06:10:48 +0100
> > <tomas@tuxteam.de> wrote:
> > 
> > > On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote:
> > > 
> > > [...]
> > > 
> > > > One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1"
> > > > is by using Pi-hole. Some people have *millions* of domains blacklisted
> > > > in Pi-hole:
> > > 
> > > Pi-hole won't help unles it also does HTTPS proxying (that means it
> > > would have to play MITM). As far as I know it "just" does conventional
> > > DNS proxying (which is a great thing to do, mind you).
> > 
> > Why won't it help? What won't it help with?
> 
> (See also Dan's response: it seems that a compliant DoH client first
> sends a local DNS request first, so you might have a handle through
> this)
> 
> With this caveat: how would you intercept a DNS request over HTTPS if
> not by proxying HTTPS traffic? And that is exactly what MITM means.

The configuration I'm talking about is as follows: the browser makes
ordinary, unencrypted DNS requests to the Pi-hole, over a trusted
network (your LAN, or a VPN). HTTPS isn't necessary here insofar as you
trust your own network to be secure. (And if you're really worried about
intruders and sniffers inside your network, you can always run Pi-hole
on the same system as the browser itself (possibly in a container or
VM), although that'll require dedicating some resources to the Pi-hole
installation.)

The Pi-hole then either blocks the request (if the address is on its
blocklists), or looks it up via DoH.

See, e.g., here:

https://www.reddit.com/r/pihole/comments/ku0i8k/configuring_dnsoverhttps_on_pihole/

Celejar

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:10 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Roberto C. Sánchez <roberto@debian.org> - 2022-01-03 23:20 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:20 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Mark Allums <maa@allums.com> - 2022-01-03 23:40 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 00:30 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:00 +0100
        [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:10 +0100
          Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 19:20 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 21:30 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com David Wright <deblis@lionunicorn.co.uk> - 2022-01-04 20:40 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 21:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-04 22:10 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 14:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 18:30 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 18:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 19:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 22:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 21:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 22:30 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-05 13:50 +0100
            Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 19:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-03 23:50 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com Charles Curley <charlescurley@charlescurley.com> - 2022-01-03 23:40 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:30 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:40 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:50 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com RP <reyadmin@gmail.com> - 2022-01-04 00:50 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 07:00 +0100
    [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 13:00 +0100
      Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 13:20 +0100
    GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com) rhkramer@gmail.com - 2022-01-04 15:00 +0100
      Re: GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com) <tomas@tuxteam.de> - 2022-01-04 16:30 +0100

csiph-web