Live data from Hacker News

1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

webcache.googleusercontent.com

41–50 of 253 posts

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#41

This is awesome to hear, and for all of the criticism Cloudflare has gotten in the past, they have spoken loudly against censorship, not just for people they like, but those they dislike as well. I'd much rather point my DNS at them than Google, an ad company where tracking is the whole business model.

The privacy statements on this service are vague. Google makes specific and strong guarantees about what it does with DNS service logs. Google does not keep DNS logs with client IPs longer than 48 hours.

I also note that Cloudflare doesn't make a performance comparison with Google DNS.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#42
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

What about akamai? They are a much larger CDN (no one talks about it on HN because they are not a startup). I agree with your assertion that it will become a single point of failure with many web properties but also I think that HN has a sort of filter bubble on startups (for obvious reasons) and I'm not sure cloudflare is as big as people make it out to be.

Also, Google has 8.8.8.8 which could be for the same thing and has similar problems (large scale data collection, singe point of failure).

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#43

This is awesome to hear, and for all of the criticism Cloudflare has gotten in the past, they have spoken loudly against censorship, not just for people they like, but those they dislike as well. I'd much rather point my DNS at them than Google, an ad company where tracking is the whole business model.

The privacy statements on this service are vague. Google makes specific and strong guarantees about what it does with DNS service logs. Google does not keep DNS logs with client IPs longer than 48 hours. I also note that Cloudflare doesn't make a performance comparison with Google DNS.

"We will never log your IP address" doesn't sound that vague.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#45
post #19

Earlier quoted context omitted.

example.org works well

I think he wants to make sure they do this at the DNS level.

No, you just need something without HTTPS so the intercepting proxy doesn't fail a certificate check.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#47
post #35
post #33

Earlier quoted context omitted.

To me that’s a diversification away from 8.8.8.8. I am absolutely not criticising google’s DNS, it’s a useful service. But I am happy to get more choice.

I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remember. Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.

There is quad9 - 9.9.9.9 :)

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#49
post #35
post #33

Earlier quoted context omitted.

To me that’s a diversification away from 8.8.8.8. I am absolutely not criticising google’s DNS, it’s a useful service. But I am happy to get more choice.

I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remember. Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.

For "easy to remember" my preference is to use Level 3 because I don't (directly) use them for any other service.

   4.2.2.1
   4.2.2.2
For as often as I manually configure DNS (I use DHCP) it's not onerous to look up the IPs of whatever DNS is preferable for your purpose.

edit: Depending on who you are this may redirect you to a search portal. Probably best to find an alternate DNS provider.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#50
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

And, thus, censorship, now that Silicon Valley has taken freedom of speech to the DNS level. They booted the daily stormer, knowing full well the ramifications: https://blog.cloudflare.com/why-we-terminated-daily-stormer/ "Get out of the way so we can DDoS this site off the Internet."

If you read the details of that decision, they're pretty interesting - they only did it because people were claiming CloudFlare were supporting their ideas.

Matthew Prince basically said "this is dangerous" and a month or two later that exact decision was being used against them in court to take down a copyright infringer.

Not saying one way or another about it being a good or bad decision, but they definitely knew they were setting a scary precedent when they did it.

Post reply on HN