Mozilla urges Congress to reject ISPs' lobbying against encrypted DNS in Firefox and Chrome, says the campaign is using Google as boogeyman to spread confusion
ISPs lobby against DNS encryption, but Mozilla tells Congress not to trust them. — Mozilla is urging Congress to reject …
Context & Ripple Effects
The fight over encrypted DNS has been escalating on two fronts: a leaked Comcast presentation showed the ISP lobbying US lawmakers against Google and Mozilla's DoH plans, and House investigators separately questioned Google about its Chrome implementation after ISPs raised tracking concerns (House investigators asked Google about DoH). Mozilla had already retreated once under pressure, declining to enable DoH by default in the UK after pushback from ISPs and the government (Mozilla's UK DoH retreat).
With this letter, Mozilla takes the fight to Capitol Hill directly, reframing the ISP campaign as fear-mongering that casts Google as a boogeyman rather than a debate about user privacy — an attempt to keep the legislative pressure from stalling both browsers' rollouts.
First-order effects
- Congressional attention shifts from whether encrypted DNS should exist to whether ISP claims about it hold up, with Mozilla explicitly asking lawmakers to discount the Comcast lobbying campaign as confusion-spreading.
- Google's Chrome DoH plans, already under House investigation per the WSJ-reported inquiry, gain a public defender in Mozilla at the moment they were most politically exposed.
Second-order effects
- ISPs who lose the lobbying route face a commercial one instead: Mozilla's Trusted Recursive Resolver program lets them stay in the DNS path by partnering rather than blocking — the path Comcast ultimately took when it became the first ISP to join the program (Comcast joins Firefox's TRR program).
- Browser makers must invest in resolver vetting and operator relationships, since default-on encryption only works if trusted resolvers exist at scale — a cost ISPs can convert into partnership leverage.
Third-order effects
- If the pattern holds, DNS resolution migrates from ISP infrastructure to browser-vetted resolvers, shrinking the data ISPs can observe by default and forcing them into paid or negotiated roles in the lookup chain.
- The episode sets a template for how platform-level privacy defaults get contested: technical changes framed as user protection trigger lobbying campaigns, congressional inquiries, and eventually co-optation through certification programs rather than outright defeat.
The trend: Control over internet's foundational lookups is shifting from ISPs to browser vendors, with lobbying, regulation, and resolver-certification programs determining how fast — and on whose terms.