Re: Speakers?

2019-09-09 Thread Gabriel Gunderson
What kind of numbers do you get at each meeting? Asking for a potential IoT topic. Best, Gabe On Thu, Sep 5, 2019 at 3:56 PM James Simister wrote: > > Hey, everyone! > > We are in need of some speakers for our PLUG meeting! > > Do you want an opportunity to present a topic you're passionate abou

How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Michael Torrie
As many of you know recent releases of Firefox have implemented DNS over HTTPS (their own idea as opposed to the standard DNS over TLS), which bypasses your local DNS and uses cloudfare's DNS server on port 443. Ostensibly this is to protect users from bad actors who might alter the DNS responses a

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Chris Wood
On Mon, Sep 9, 2019 at 3:04 PM Michael Torrie wrote: > > As many of you know recent releases of Firefox have implemented DNS over > HTTPS (their own idea as opposed to the standard DNS over TLS), which > bypasses your local DNS and uses cloudfare's DNS server on port 443. > Ostensibly this is to p

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Andy Bradford
Thus said Michael Torrie on Mon, 09 Sep 2019 15:04:09 -0600: > Ostensibly this is to protect users from bad actors who might alter > the DNS responses and redirect unsuspecting users to bogus sites for > nefarious purposes. And yet, it will funnel all DNS queries through central

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Andy Bradford
Thus said Michael Torrie on Mon, 09 Sep 2019 15:04:09 -0600: > As many of you know recent releases of Firefox have implemented DNS > over HTTPS (their own idea as opposed to the standard DNS over TLS), > which bypasses your local DNS and uses cloudfare's DNS server on port > 443. I was not

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Andy Bradford
Thus said Chris Wood on Mon, 09 Sep 2019 16:04:15 -0600: > Good info, thanks. I've been wondering about how to block this as > well. The following link (referenced in the article) indicates how it can be done by users: https://support.mozilla.org/en-US/kb/firefox-dns-over-https Once I di

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Michael Torrie
On 9/9/19 7:58 PM, Andy Bradford wrote: > Thus said Michael Torrie on Mon, 09 Sep 2019 15:04:09 -0600: > >> Ostensibly this is to protect users from bad actors who might alter >> the DNS responses and redirect unsuspecting users to bogus sites for >> nefarious purposes. > > And yet, it w

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Andy Bradford
Thus said Michael Torrie on Mon, 09 Sep 2019 20:22:38 -0600: > Individual users can turn it off or on in preferences, or they can go > into about:config and change "network.trr.mode" to "5." Why Mozilla > didn't make this opt-in I don't know. Indeed. So when I browse to Options->General->Ne

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Michael Torrie
On 9/9/19 8:41 PM, Andy Bradford wrote: > Thus said Michael Torrie on Mon, 09 Sep 2019 20:22:38 -0600: > >> Individual users can turn it off or on in preferences, or they can go >> into about:config and change "network.trr.mode" to "5." Why Mozilla >> didn't make this opt-in I don't know. > >

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Andy Bradford
Thus said Michael Torrie on Mon, 09 Sep 2019 20:45:54 -0600: > I'm pretty sure that if Firefox is trying DoH and it fails for > whatever reason, it will fall back to normal DNS. On Slashdot several > folk talked about blocking the cloudfare dns servers' IP addresses. Yes, according to t

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Jason Healy
For those that use pihole for DNS level filtering, there was a pull request merged 2 days ago to return an NXDOMAIN for this request. https://github.com/pi-hole/pi-hole/pull/2915 On 2019-09-09 20:55, Andy Bradford wrote: Thus said Michael Torrie on Mon, 09 Sep 2019 20:45:54 -0600: I'm prett

Re: How to use Bind response policy zone to stop Firefox from using DNS over HTTPS

2019-09-09 Thread Joel Finlinson
Looks like Google wants in on the game with Chrome too. https://support.google.com/chrome/a/thread/10152459?hl=en Chrome Browser Enterprise 7/18/19 DNS-over-HTTPS Setting Hi al