今天才发现firefox的几个秘密

an1xing 2026-09-28 20:40 1

已经使用最新版156测试所得,firefox的默认配置是不会请求ech配置的,虽然支持ech,但浏览网页查询dns的时候只查询a和aaaa记录,不会查询https记录的,也就没有ech配置了。和dns无关,和dns是否污染也无关,所以上linux.do也就无缘了。

firefox想要有ech配置,就要在配置-隐私与安全 里面配置 doh,这样才会请求dns的https记录,才能上linux.do。

但配置doh以后,firefox基于隐私的原因是没有ecs功能的,比如你访问163.com的时候是不会访问中国内地的163网站的,它只会访问doh所在国的163网站的,也就会很慢了。和doh是否支支持或配置ecs,也就是edns客户端子网无关。

以上我说的doh指非大陆的doh。

要想firefox支持ech和ecs,只有在本地网络或本机用adguard或其他软件建一个doh服务,并且配置上游服务器为支持ecs的非大陆doh。firefox配置里面再使用本地网络或本机的doh才同时享受ech和ecs。

chrome没有以上问题。

最新回复 (2)
  • 如意思 09-29 00:35
    1楼

    那这个问题是否可以提交上去让他们修正一下或者给个选项的办法,我们自己开。

  • listening 09-29 00:56
    2楼

    见:Security/Encrypted Client Hello - MozillaWiki



    Dependency on DoH

    Originally, Firefox required DoH to be enabled in order for ECH to function. Since Firefox 129, Firefox can fetch the necessary information via the OS DNS Resolver to enable ECH, allowing ECH to be used in more circumstances. Due a blocking bug with the MacOS DNS integration, MacOS still requires DoH to be enabled for ECH to be used, the work to fix this is tracked in 1882856.


    For the vast majority of users, their native OS resolver will use unencrypted DNS to contact their local router which in turn passes their queries unencrypted on to their network provider. Fetching ECHConfigs via unencrypted DNS means that the sites the user visits are still leaked in plaintext to the network and so ECH delivers less value in this scenario. For this reason, we recommend the use of DoH (whether with a self-hosted or external DoH service) in order to benefit fully from the privacy protections of ECH.



    这其实是有一个时间线的,早期主流浏览器把DOH和ECH强绑定,因为一个观点认为不使用加密dns的情况下,你保护了sni但dns还是泄露了,价值有限。当然后续是放开了(Chrome117+/Firefox129+)。


    RFC 9849的表述是should,并不强制依赖DOH或者DNSSEC,但是推荐。推测是你的环境问题,这块地方不会突然改坏的。

* 帖子来源Linux.do
返回