Closed Bug 1624112 Opened 4 years ago Closed 4 years ago

Hosts file ignored on Windows with DNS over HTTP enabled

Categories

(Firefox :: Settings UI, task)

74 Branch
task
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 1544233

People

(Reporter: me, Unassigned)

Details

(Whiteboard: [reporter-external] [web-bounty-form] [verif?])

I use https://github.com/StevenBlack/hosts to add ads, malware, social media, etc to my hosts file in order to stop the pervasive tracking by adtech and social media companies. With the latest Firefox (stable) 74.0 and the default settings of DNS over HTTP thru cloudflare my hosts file is ignored. Even though facebook.com is supposed to route to 0.0.0.0 I am still able to resolve this in Firefox (but not via ping or any other hosts respecting software). This seems like a major issue and people should be aware of the risks of this default setting being enabled.

Flags: sec-bounty?

(Hopefully) setting the correct bug components and flags.

Group: websites-security → firefox-core-security
Component: Other → Preferences
Product: Websites → Firefox
Version: unspecified → 74 Branch

Ignoring the hosts file is a known consequence of the DoH implementation, cf. https://www.reddit.com/r/firefox/comments/c9e60m/how_to_use_localhost_file_along_with_dns_over/ , https://www.reddit.com/r/firefox/comments/8b4u9z/with_dns_over_https_enabled_in_nightly_firefox/ - even https://github.com/StevenBlack/hosts/issues/968 on the same list you're using, etc. etc.

There's a pref ( network.trr.excluded-domains) that you can use to accomplish what you want, but really, if you're trying to DNS-block things, pihole or similar solutions will likely work better for what you're intending to do.

Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE

Looks like bug 1544233 is a better dupe.

Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.