Live data from Hacker News

1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

webcache.googleusercontent.com

61–70 of 253 posts

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#63
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

This seems to be a general rule-of-thumb tendency with "distributed anything".

In general, in distributed systems a number of inconveniences arise as a natural cost of the distributed nature of the system.

This creates a tendency for a critical mass to circle around a single central entity that uses its central position to provide convenience and further creating a "distributed in theory if you really want it but not really" environment (example: Github).

Not really super related to Cloudflare, just a general observation.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#64
post #51
post #35

Earlier quoted context omitted.

I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remember. Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.

Most ISPs provide their own DNS server via dhcp, why not use that?

For servers you typically have no DHCP. Also ISP often have annoying behaviours like redirecting you to their own websites for failed lookups. And my ISP doesn’t allow local non routable IPs (192.168.1.x) in DNS responses while google does.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#65
post #51
post #35

Earlier quoted context omitted.

I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remember. Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.

Most ISPs provide their own DNS server via dhcp, why not use that?

Because most of them suck (Censorship, NXDOMAIN fuckups). Or are not reachable outside the ISP network.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#66
post #7

This is awesome to hear, and for all of the criticism Cloudflare has gotten in the past, they have spoken loudly against censorship, not just for people they like, but those they dislike as well. I'd much rather point my DNS at them than Google, an ad company where tracking is the whole business model.

On the other hand they've also censored some of their users without being legally obliged to do so on a couple occasions. They don't have a clean track record. I'd rather point my DNS settings at my own server than anyone elses.

I would much rather have a company with a long but nearly clean track record, than a short and spotless one.

The difference is that when a company with a spotless record decides it's time to change their ways, it can be a pretty radical change (look at Reddit). But with cloudflare I know we're a long way from that.

It's kind of absurd how everyone expects spotless companies. I'd like to live in that world as well but the reality of this one is that such companies do not exist. Cloudflare gets criticism on both too much censorship and not enough. I don't envy them...

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#67
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

You're overestimating their market share. Akamai is bigger. Cloudfront, fastly and some others are very credible competition.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#68
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

I definitely have single point of failure concerns both with Cloudflare and Let's Encrypt, but as another user points out, right now 8.8.8.8 is the much more common single point of failure for DNS, and it's run by an ad/tracking company.

It's definitely possible Cloudflare may go the way of Google at some point in the future, but right now, I'd rather have the former than the latter involved in my Interneting. And in this case, it's a new/additional option, a second point.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#70
post #39

This is awesome to hear, and for all of the criticism Cloudflare has gotten in the past, they have spoken loudly against censorship, not just for people they like, but those they dislike as well. I'd much rather point my DNS at them than Google, an ad company where tracking is the whole business model.

How much tracking can you do on a v4 DNS? There can be thousands of people behind the same IPv4 at a given time, or it could change in a matter of minutes. A state could probably be able to exploit that (as in there is a political opponent living at this address) but if the aim is just to track an individual’s browsing habit I would think it is impractical. IPv6, other debate.

Well, they do seem to plan to offer IPv6 DNS. And you'll probably want to be using that anyway, although they don't seem to recommend using that, as they mention it only briefly.
Post reply on HN