Live data from Hacker News

1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

webcache.googleusercontent.com

101–110 of 253 posts

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#101
post #23

Earlier quoted context omitted.

Ah yes. There’s nothing to censor if you keep your mouth shut ;)

There's a difference between saying "[highly controversial statement]. We know company X will not censor us." and "[highly controversial statement]. We know company X will not censor us because the people at company X are really on our side!"

Especially when "our side" is literally Nazis.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#104
post #63

Earlier quoted context omitted.

This seems to be a general rule-of-thumb tendency with "distributed anything". In general, in distributed systems a number of inconveniences arise as a natural cost of the distributed nature of the system. This creates a tendency for a critical mass to circle around a single central entity that uses its central position to provide convenience and further creating a "distributed in theory if you really want it but not…

Github's existence does nothing to change the distributed nature of git, just like GMail's existence does nothing to change the nature of email. They offer/sell a service that is built using those technologies. People go to them for the convenience you mention. If there were other convenient ways to use those services people would use them as well. ... and there are! Github has competitors (Gitlab, bitbucket, ...) an…

GitHub has gotten a ways there socially. Repositories which are not on GitHub are not socially first-class for many subsets of contributors, because the only habits you can rely on them having in easily-accessible brain memory are based on GitHub-specific workflow. So if you are used to Git and not GitHub, projects you want to contribute to may ask/demand that you do the GitHub-specific thing instead (and feel justified by norms in doing so), and contributors to any projects you publish may do the same in the other direction (more likely, just quietly give up if they can't use GitHub to interact with you). When that happens, you can't move your repository around and still be able to collaborate even if your server's publishing on perfectly good Git-accessible protocols, because the centralized convenience has turned into a necessity in order to keep up / because it was common enough.

That's far from the perfect opposite of “distributed and open”, since these habits can be more fluidly shifted and alternate versions of the convenience processes can exist in theory, but it's also far from what I usually hear people implying when they expect things to be socially distributed as well as technically.

(I'm told that GMail similarly changes the nature of email by making it socially unsafe to operate email addresses in certain ways, but I believe this effect is weaker and I don't have real experience with it.)

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#105
post #23

Earlier quoted context omitted.

Ah yes. There’s nothing to censor if you keep your mouth shut ;)

There's a difference between saying "[highly controversial statement]. We know company X will not censor us." and "[highly controversial statement]. We know company X will not censor us because the people at company X are really on our side!"

They really should have booted them for that reasoning rather than by feeling. They even have it in their Terms of Service (and when I looked, did have it at the time of terminating the site)

> Section 18 - Because Cloudflare has no control over such sites and resources, you acknowledge and agree that Cloudflare is not responsible for the availability of such external sites or resources, and does not endorse and is not responsible or liable for any content, advertising, products, or other materials on or available from such sites or resources.

It's a clear ToS breach, a bit of thought would have avoided the whole thing. You got lawyers on hand? Talk to lawyers!

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#107

Interesting that https://1.1.1.1/ has a valid SSL Cert when you can't issue public valid certs for IPs

Publicly-trusted CAs can issue trusted certificates for IP addresses. It's simply far less commonly used, and most CAs either don't offer it at all or only for enterprise clients.

(You might have been thinking about issuance for IP addresses in private/reserved IP space. That is indeed prohibited nowadays, just like "internal names", i.e. domains that don't end in a public suffix.)

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#108

Interesting that https://1.1.1.1/ has a valid SSL Cert when you can't issue public valid certs for IPs

It's dependant on CA support, rather than being impossible per se. E.g. GlobalSign: https://support.globalsign.com/customer/portal/articles/1216...

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#109
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

What about akamai? They are a much larger CDN (no one talks about it on HN because they are not a startup). I agree with your assertion that it will become a single point of failure with many web properties but also I think that HN has a sort of filter bubble on startups (for obvious reasons) and I'm not sure cloudflare is as big as people make it out to be. Also, Google has 8.8.8.8 which could be for the same thing…

When was the last time Akamai forced you to fill out a CAPTCHA?

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#110
post #35

Earlier quoted context omitted.

I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remember. Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.

There is quad9 - 9.9.9.9 :)

Does quad9 offer encrypted DNS?
Post reply on HN