djbaxter

Administrator
Administrator
Moderator
Joined
Jun 28, 2012
Messages
3,488
Reaction score
1,622
Mozilla’s new Firefox update puts user security at risk with TRR feature
by AnkitGupta, TheWindowsClub.com
August 7, 2018

Mozilla is all set to introduce two new features to its Firefox browser in its upcoming patch. Called as ‘DNS over HTTPs’ (DOH) and Trusted Recursive Resolver (TRR), Mozilla says that they are meant to enable additional security, with many security experts thinking otherwise. Signaling out TRR among the two, security experts at Ungleich say that this feature by default routes requests with a 3rd party service; thus making it less secure.

With Trusted Recursive Resolver (TRR) turned on as default, any DNS changes that a Firefox user configured in the network will be overridden. This is because Mozilla had partnered with Cloudflare and will resolve the domain names from the application itself through a DNS server of Cloudflare located in the US. This allows Cloudflare to read user’s DNS requests.

Lashing out on Mozilla for advertising TRR as a feature that ‘increases security’, the security expert at Ungleich mentions,

“From our point of view, us being security geeks, advertising this feature with slogans like “increases security” is rather misleading because in many cases the opposite is the case. While it is true that with TRR you may not expose the websites you call to a random DNS server in an untrustworthy network you don’t know, it is not true that this increases security in general.”


Cloudflare on its part, though commits to a ‘pro-user privacy’ policy and the detection of all personally identifiable data after 24 hours, there is no guarantee where a user’s data may finally end up.

Mozilla’s TRR disables user’s anonymity
With TRR allowing all DNS requests seen by Cloudflare, user’s anonymity stands completely destroyed. Government agencies always have the right to request data from the service owners, and even for a small suspicious, Firefox users risk their data being shared with the government or any investigating agency.

Finally, it is up to the users if they really trust Cloudflare or their local ISP. Still, as Ungleich mentions, users can very easily turn TRR off. Follow these steps to do so.

  • Enter about:config in the address bar
  • Search for network.trr
  • Set network.trr.mode = 5 to completely disable it
“Change network.trr.mode to 2 to enable DoH. This will try and use DoH but will fall back to insecure DNS under some circumstances like captive portals. (Use mode 5 to disable DoH under all circumstances.)”


Read more...
 
Similar threads
Thread starter Title Forum Replies Date
djbaxter Firefox Users: Update Now to Patch Remote Execution Flaw Websites, Software, and Security 0
djbaxter Tired eyes or dry eyes? Firefox has an extension to help Websites, Software, and Security 1
Ross Barefoot Limitations Viewing a Listing on Mobile with Firefox Google My Business & Google Maps 4
djbaxter Firefox disabled all add-ons because a certificate expired: Update Websites, Software, and Security 3
djbaxter Google Chrome vs Firefox Quantum on Windows 10 Websites, Software, and Security 0
djbaxter Chrome and Firefox Extensions Alert You to Stolen Passwords Websites, Software, and Security 0
djbaxter New Firefox Faster than Chrome, 30% Less Memory Websites, Software, and Security 7
djbaxter Chrome and Firefox Phishing Attack Uses Domains Identical to Known Safe Sites Forum Tech Support 7
djbaxter Security risk: Autofill in browsers except Firefox Break Room: Chat and Off Topic 4
Margaret Ornsby Google Maps playing up in Firefox. Bug? Google My Business & Google Maps 0
K Google & Google Users Removing Items From Service Menu Google My Business & Google Maps 4
djbaxter Millions of users affected by malicious Edge and Chrome browser extensions Websites, Software, and Security 1
djbaxter PHP 8: What WordPress Users Need to Know Websites, Software, and Security 0
Bryan Bloom Users added to a GMB but never get an invite.... 👿 Help & Support for Google Local 5
C Finding Google User Google My Business & Google Maps 2
Tim Colling How to find the email address of another User on a GMB listing Google My Business & Google Maps 3
Rich Owings Is anyone having trouble adding users to GMB listings? All Things Google My Business [PRIVATE] (LocalU) 5
F Just a Little Warning (GMB User Account Safety) Google My Business & Google Maps 3
Rich Owings Is anyone having trouble adding users to GMB listings? Help & Support for Google Local 2
Eoghan_MFeed Does anybody have any idea how many users Apple Maps actually has? Local Search 0
Theo1313 A lot of Unknown Users Requesting GMB Access Google My Business & Google Maps 12
Nick 11 User-agent: * Crawl-Delay: 20 Robots.TXT File Organic SEO 1
djbaxter Ban issued to user aalmarusy Warnings and Bans 0
djbaxter Ban issued to user Dimitri Warnings and Bans 0
djbaxter Ban issued to user Dimitri Warnings and Bans 0
A Form to Report Google Users for Spam? Local Search 3
Lanerizz Multiple Users Reporting Spam Spam on Google 2
Paul Lappage Do you need to have specific User permissions to update the Attributes? Google My Business & Google Maps 2
djbaxter Ban issued to user polos001 Warnings and Bans 0
Jorge User with more than 45 Spam Tokens Help & Support for Google Local 2
Bryan Bloom 👉 Ahrefs Users - Are you aware they removed client alerts? Is this an issue for you also? Local SEO Tools & Software 5
M Multiple reviews changed to “A Google User” Help & Support for Google Local 2
djbaxter Ban issued to user Wonders Warnings and Bans 0
djbaxter Ban issued to user Amanikane22 Warnings and Bans 0
djbaxter Ban issued to user mechristophe Warnings and Bans 0
djbaxter Ban issued to user mamahealer Warnings and Bans 0
M All Users Audience Disabled Due to Policy Violation > Personal Injury Attorney Paid Search and Local Service Ads 2
Annika Neudecker Microsoft forcing Office ProPlus users to Bing Paid Search and Local Service Ads 5
djbaxter Avast antivirus caught spying on user data - and selling it Websites, Software, and Security 1
JoyHawkins New Discounts User-Contributed Attribute in GMB? Google My Business & Google Maps 3
O User edited our list with wrong information Google My Business & Google Maps 2
TomW User Profiles on Maps Google News: Important Changes & Features 1
B Does verifying my GMB prevent users from changing location details so often? Google My Business & Google Maps 3
JoyHawkins Google Maps Allows Users to Report Spammy Users Google News: Important Changes & Features 16
vivekrpatel A Sudden Spike in Bounce Rate and Users Local Search 6
R User deleted: Backlinking to GMB Listing Recycle Bin 0
ashley.smith Does Google My Business prioritize reviews from Local Guides over other users? Local Reviews 7
djbaxter Ban issued to user babysitter91 Warnings and Bans 0
djbaxter Ban issued to user Chris_Tax Warnings and Bans 0
Nathan_NZ Adding New Users in Google Search Console - Help Needed Organic SEO 2

Similar threads

Login / Register

Already a member?   LOG IN
Not a member yet?   REGISTER

Most UpVoted Answers

Trending: Most Viewed

LocalU Podcasts

  Promoted Posts

New advertising option: A review of your product or service posted by a Sterling Sky employee. This will also be shared on the Sterling Sky & LSF Twitter accounts, our Facebook group, LinkedIn, and both newsletters. More...
Google Product Exert


Top Bottom