{"id":1853,"date":"2020-11-18T14:03:58","date_gmt":"2020-11-18T22:03:58","guid":{"rendered":"https:\/\/blog.mozilla.org\/netpolicy\/?p=1853"},"modified":"2021-01-21T00:17:43","modified_gmt":"2021-01-21T08:17:43","slug":"doh-comment-period-2020","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/","title":{"rendered":"Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver  (TRR) Comment Period:  Help us enhance security and privacy online"},"content":{"rendered":"<p><em><strong>Update:<\/strong><\/em> <i data-stringify-type=\"italic\">The comment period has now closed. Thank you for everyone who submitted. Please stay tuned for further updates from us in the coming months as we review the comments<\/i>.<\/p>\n<p>For a number of years now, we have been working hard to update and secure one of the oldest parts of the Internet, the Domain Name System (DNS). We passed a key milestone in that endeavor earlier this year, when we rolled out the technical solution for privacy and security in the DNS &#8211; DNS-over-HTTPS (<a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2020\/11\/DoH-Explainer-1.pdf\">DoH<\/a>) &#8211; to Firefox users in the United States. Given the transformative nature of this technology and our mission commitment to transparency and collaboration, we have consistently sought to implement DoH thoughtfully and inclusively. Therefore, as we explore how to bring the benefits of DoH to Firefox users in different regions of the world, we\u2019re today launching a comment period to help inform our plans.<\/p>\n<p><b>Some background<\/b><\/p>\n<p>Before explaining our comment period, it\u2019s first worth clarifying a few things about DoH and how we\u2019re implementing it:<\/p>\n<p style=\"padding-left: 40px;\"><b><i>What is the \u2018DNS\u2019? <\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\">The Domain Name System (DNS for short) is a shared, public database that links a human-friendly name, such as<a href=\"http:\/\/www.mozilla.org\"> www.mozilla.org<\/a>, to a computer-friendly series of numbers, called an IP address (e.g. 192.0.2.1). By performing a \u201clookup\u201d in this database, your web browser is able to find websites on your behalf. Because of how DNS was originally designed decades ago, browsers doing DNS lookups for websites \u2014 even for encrypted https:\/\/ sites \u2014 had to perform these lookups without encryption.<\/p>\n<p style=\"padding-left: 40px;\"><b><i>What are the security and privacy concerns with traditional DNS?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\">Because there is no encryption in traditional DNS, other entities along the way might collect (or even block or change) this data. These entities could include your Internet Service Provider (ISP) if you are connecting via a home network, your mobile network operator (MNO) if you are connecting on your phone, a WiFi hotspot vendor if you are connecting at a coffee shop, and even eavesdroppers in certain scenarios.<\/p>\n<p style=\"padding-left: 40px;\">In the early days of the Internet, these kinds of threats to people\u2019s privacy and security were known, but not being exploited yet. Today, we know that unencrypted DNS is not only vulnerable to spying but <i>is<\/i> being exploited, and so we are helping the Internet to make the shift to more secure alternatives. That\u2019s where DoH comes in.<\/p>\n<p style=\"padding-left: 40px;\"><b><i>What is DoH and how does it mitigate these problems?<\/i><\/b><b><br \/>\n<\/b><\/p>\n<p style=\"padding-left: 40px;\">Following the best practice of encrypting HTTP traffic, Mozilla has worked with industry stakeholders at the Internet Engineering Task Force (IETF) to define a DNS encryption technology called DNS over HTTPS or DoH (pronounced &#8220;dough&#8221;), specified in <a href=\"https:\/\/tools.ietf.org\/html\/rfc8484\">RFC 8484<\/a>. It encrypts your DNS requests, and responses are encrypted between your device and the DNS resolver via HTTPS. Because DoH is an emerging Internet standard, operating system vendors and browsers other than Mozilla can also implement it. In fact, <a href=\"https:\/\/blog.chromium.org\/2020\/09\/a-safer-and-more-private-browsing.html\">Google<\/a>, <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/networking-blog\/windows-will-improve-user-privacy-with-dns-over-https\/ba-p\/1014229\">Microsoft<\/a> and <a href=\"https:\/\/developer.apple.com\/videos\/play\/wwdc2020\/10047\/\">Apple<\/a> have either already implemented or are in late stages of implementing DoH in their respective browsers and\/or operating systems, making it a matter of time before it becomes a ubiquitous standard to help improve security on the web.<\/p>\n<p style=\"padding-left: 40px;\"><b><i>How has Mozilla rolled out DoH so far?<\/i><\/b><\/p>\n<p style=\"padding-left: 40px;\">Mozilla has deployed DoH to Firefox users in the United States, and as an opt-in feature for Firefox users in other regions. We are currently exploring how to expand deployment beyond the United States. Consistent with Mozilla&#8217;s mission, in countries where we roll out this feature the user is given an explicit choice to accept or decline DoH, with a default-on orientation to protect user privacy and security.<\/p>\n<p style=\"padding-left: 40px;\">Importantly, our deployment of DoH adds an extra layer of user protection beyond simple encryption of DNS lookups. Our deployment includes a <a href=\"https:\/\/wiki.mozilla.org\/Security\/DOH-resolver-policy\">Trusted Recursive Resolver<\/a> (TRR) program, whereby DoH lookups are routed only to DNS providers who have made binding legal commitments to adopt extra protections for user data (e.g., to limit data retention to operational purposes and to not sell or share user data with other parties). Firefox\u2019s deployment of DoH is also designed to respect ISP offered parental control services where users have opted into them and offers <a href=\"https:\/\/support.mozilla.org\/en-US\/products\/firefox-enterprise\/policies-customization-enterprise\/policies-overview-enterprise\">techniques<\/a> for it to operate with enterprise deployment policies.<\/p>\n<p><b>The comment period<\/b><\/p>\n<p>As we explore bringing the benefits of DoH to more users, in parallel, we\u2019re launching a comment period to crowdsource ideas, recommendations, and insights that can help us maximise the security and privacy-enhancing benefits of our implementation of DoH in new regions. We welcome contributions for anyone who cares about the growth of a healthy, rights-protective and secure Internet.<\/p>\n<p><b>Engaging with the Mozilla DoH implementation comment period<\/b><\/p>\n<ul>\n<li><b>Length: <\/b>The global public comment period will last for a total of 45 days, starting from November 19, 2020 and ending on January 4, 2021. <em><strong>Update:<\/strong><\/em> The deadline of the comment period has been extended to January 20 2021.<\/li>\n<li><b>Audience: <\/b>The consultation is open to all relevant stakeholders interested in a more secure, open and healthier Internet across the globe.<\/li>\n<li><b>Questions for Consultation<\/b>: A detailed set of questions which serve as a framework for the consultation are available <a href=\"https:\/\/blog.mozilla.org\/netpolicy\/files\/2020\/11\/DoH-Public-Comment-Period-Question-for-Comment.pdf.pdf\">here<\/a>. It is not mandatory to respond to all questions.<\/li>\n<li><b>Submitting comments<\/b>: All responses can be submitted in plaintext or in the form of an accessible pdf to doh-comment-period-2020@mozilla.com.<\/li>\n<\/ul>\n<p><b>Unless the author\/authors explicitly opt-out in the email in which they submit their responses, all genuine responses will be made available publicly on our blog. <\/b>Submissions that violate our <a href=\"https:\/\/www.mozilla.org\/en-US\/about\/governance\/policies\/participation\/\">Community Participation Guidelines<\/a> will not be published.<\/p>\n<p>Our goal is that DoH becomes as ubiquitous for DNS as HTTPS is for web traffic, supported by ISPs, MNOs, and enterprises worldwide to help protect both end users and DNS providers themselves. We hope this public comment will take us closer to that goal, and we look forward to hearing from stakeholders around the world in creating a healthier Internet.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Update: The comment period has now closed. Thank you for everyone who submitted. Please stay tuned for further updates from us in the coming months as we review the comments. &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/\">Read more<\/a><\/p>\n","protected":false},"author":1559,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[283198,173936,847,10127,69,10136],"tags":[],"coauthors":[318937,327270],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period: Help us enhance security and privacy online - Open Policy &amp; Advocacy<\/title>\n<meta name=\"description\" content=\"We&#039;re crowdsourcing ideas and recommendations to help us enhance the privacy and security benefits of DNS-over-HTTPS (DoH) for users around the world\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Owen Bennett, Udbhav Tiwari\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/\",\"name\":\"Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period: Help us enhance security and privacy online - Open Policy &amp; Advocacy\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\"},\"datePublished\":\"2020-11-18T22:03:58+00:00\",\"dateModified\":\"2021-01-21T08:17:43+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63\"},\"description\":\"We're crowdsourcing ideas and recommendations to help us enhance the privacy and security benefits of DNS-over-HTTPS (DoH) for users around the world\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/netpolicy\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period: Help us enhance security and privacy online\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/netpolicy\/\",\"name\":\"Open Policy &amp; Advocacy\",\"description\":\"Mozilla&#039;s official blog on open Internet policy initiatives and developments\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63\",\"name\":\"Owen Bennett\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/e46a666e0d8a768b13461b5a1539a34a\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g\",\"caption\":\"Owen Bennett\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period: Help us enhance security and privacy online - Open Policy &amp; Advocacy","description":"We're crowdsourcing ideas and recommendations to help us enhance the privacy and security benefits of DNS-over-HTTPS (DoH) for users around the world","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/","twitter_misc":{"Written by":"Owen Bennett, Udbhav Tiwari","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/","url":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/","name":"Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period: Help us enhance security and privacy online - Open Policy &amp; Advocacy","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website"},"datePublished":"2020-11-18T22:03:58+00:00","dateModified":"2021-01-21T08:17:43+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63"},"description":"We're crowdsourcing ideas and recommendations to help us enhance the privacy and security benefits of DNS-over-HTTPS (DoH) for users around the world","breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/netpolicy\/2020\/11\/18\/doh-comment-period-2020\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/netpolicy\/"},{"@type":"ListItem","position":2,"name":"Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period: Help us enhance security and privacy online"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#website","url":"https:\/\/blog.mozilla.org\/netpolicy\/","name":"Open Policy &amp; Advocacy","description":"Mozilla&#039;s official blog on open Internet policy initiatives and developments","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/netpolicy\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/5b3cc3909c8b5ee76eb51df71ec36d63","name":"Owen Bennett","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/netpolicy\/#\/schema\/person\/image\/e46a666e0d8a768b13461b5a1539a34a","url":"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6f774b07d5ad0d800fe5ec879c4be6c7?s=96&d=mm&r=g","caption":"Owen Bennett"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1853"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/users\/1559"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/comments?post=1853"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/posts\/1853\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/media?parent=1853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/categories?post=1853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/tags?post=1853"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/netpolicy\/wp-json\/wp\/v2\/coauthors?post=1853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}