Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243743

Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From Celejar <celejar@gmail.com>
Newsgroups linux.debian.user
Subject Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Date 2022-01-05 22:00 +0100
Message-ID <DCly1-7kq-1@gated-at.bofh.it> (permalink)
References (6 earlier) <DC6Sm-6vm-7@gated-at.bofh.it> <DCePU-3a1-3@gated-at.bofh.it> <DCigN-5pq-3@gated-at.bofh.it> <DCiAa-5zx-7@gated-at.bofh.it> <DCjwd-68S-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Wed, 5 Jan 2022 19:42:33 +0100
<tomas@tuxteam.de> wrote:

> On Wed, Jan 05, 2022 at 12:41:23PM -0500, Celejar wrote:
> 
> [...]
> 
> > The configuration I'm talking about is as follows: the browser makes
> > ordinary, unencrypted DNS requests to the Pi-hole, over a trusted
> > network
> 
> If the browser decides to make the DNS requests over HTTPS (DoH [1],
> that's what we are talking about), the DNS server in your Pi-hole doesn't
> even get to see those requests.

So tell the browser not to use DoH! Am I really being so unclear? My
point is that it's a straightforward matter to get the DNS requests of
your applications - browsers, and all other applications as well -
checked against blocklists, and then sent over DoH if they aren't
blocked by the lists.

> >         (your LAN, or a VPN). HTTPS isn't necessary here insofar as you
> > trust your own network to be secure. (And if you're really worried about
> > intruders [...]
> 
> No, no. I'm not worried about those things. I'm worried that the
> browsers do their own thing to do name lookup so they escape my control
> (be it via /etc/hosts, be it via an own DNS server, local or Pi-hole).

I'm not sure why you're worried about browsers doing their own things
despite your telling them not to, or where anyone mentioned such a
concern in this thread, but if you are worried about that sort of
thing, then I agree that it's pretty much game over. Even if you block
known DoH servers at the firewall, I suppose you can always worry about
browsers contacting some unknown DoH server. And why stop there? Maybe
the browser will do some nefarious phoning home, using some homegrown
protocol, encapsulated inside HTTPS so you'll never know about it! The
bottom line is that yes, if you don't trust your browser and you allow it to
contact arbitrary sites over HTTPS, then it's game over.

> > https://www.reddit.com/r/pihole/comments/ku0i8k/configuring_dnsoverhttps_on_pihole/
> 
> Again: I'm not that much concerned about my lookup's privacy. The
> Pi-hole having an option to do DoH lookups is fine. But do I trust my
> browser to not do direct DoH lookups all by itself, bypassing my Pi-hole
> (or whatever I've set up as a controlled DNS)? What about its next
> version?

Celejar

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:10 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Roberto C. Sánchez <roberto@debian.org> - 2022-01-03 23:20 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:20 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Mark Allums <maa@allums.com> - 2022-01-03 23:40 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 00:30 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:00 +0100
        [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:10 +0100
          Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 19:20 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 21:30 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com David Wright <deblis@lionunicorn.co.uk> - 2022-01-04 20:40 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 21:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-04 22:10 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 14:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 18:30 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 18:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 19:50 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 22:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 21:00 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 22:30 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-05 13:50 +0100
            Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 19:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-03 23:50 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com Charles Curley <charlescurley@charlescurley.com> - 2022-01-03 23:40 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:30 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:40 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:50 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com RP <reyadmin@gmail.com> - 2022-01-04 00:50 +0100
  Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 07:00 +0100
    [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 13:00 +0100
      Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 13:20 +0100
    GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com) rhkramer@gmail.com - 2022-01-04 15:00 +0100
      Re: GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com) <tomas@tuxteam.de> - 2022-01-04 16:30 +0100

csiph-web