Hacker News new | past | comments | ask | show | jobs | submit login

>Because DoH is meant to work on the application level, not OS level.

And thus, we arrive at the crux of the issue, as stated in my original post. It is not the job of everyday applications to be making decisions about name resolution.

>In fact, if Mozilla's application based resolver started mucking with /etc/hosts

Mozilla's application doesn't even need to know about /etc/hosts. It needs to ask the system name resolution interface to resolve a name for it, and then run with what it is given, rather than Mozilla deciding that their baby is too important to use that interface and then proceed to implement one on their own.




You can have that.

Don't turn DoH in FF on if you don't like it (or turn it off).

You're acting like mozilla is deciding this for you without giving you a say. They're not. They're offering you something you don't even have to accept - because they care about your privacy online and they're not happy about little governments dabbling in the censorship game either.

I'm pretty sure the TOR browser is using its own name resolution too - as a privacy feature. This isn't very different.


Great, another obnoxious Firefox feature I have to disable - and that's assuming they deign to allow me to do this once it hits mainstream.

I'd like it if there were less of those.


Are we certain they will never change from opt-in to opt-out?


> It needs to ask the system name resolution interface to resolve a name for it, and then run with what it is given

Despite me agreeing with your need for hosts to work, your suggestion here wont. As the others have mentioned the hosts integration is down way down deep in the code (libc and kernell.dll as far as I know) and is basically an automated part of getting the address of a name, which does a proper DNS lookup automatically (if not found in hosts), meaning DoH wont get a chance.

This means that FFox will need to independantly look up and parse the hosts file as part of it's DoH lookup, basically mimicking what libc is doing on 'nix boxes. It's what the other GPs are mentioning as a no-go/non-starter, whereas I suggest it's not hard to parse a text file.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: