Live data from Hacker News

1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

webcache.googleusercontent.com

171–180 of 253 posts

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#171

So am I correct assuming they support DNSCrypt if they claim they support encryption? If that's the case that's really nice actually. Google DNS kinda silently launched DNS-over-HTTPS in 2016 but still no DNSCrypt; opendns are the only major ones supporting it. Of course I stopped using dnscrypt at some point because it was a pain to maintain, and wasnt supported on most of my devices :/

Cloudflare resolvers are supported by dnscrypt-proxy. See https://dnscrypt.info/public-servers

Should point out though that it is using DNS-over-HTTP/2 and not DNSCrypt it seems, because the DNS stamp you provided in a sibling comment starts with "Ag" and not "AQ".

https://dnscrypt.info/faq mentions some drawbacks of DNS over HTTPS;

- Requires a full TLS stack and a web server

- Interception/monitoring tools are readily available

- Key management can be surprisingly hard especially if public key pinning is used by clients

- Allows insecure algorithms and parameters

- Requires TCP

- RFC is in draft stage

So the question remains; does 1.1.1.1 support DNSCrypt or are there any plans for it to do so?

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#172

Earlier quoted context omitted.

Cloudflare resolvers are supported by dnscrypt-proxy. See https://dnscrypt.info/public-servers

Should point out though that it is using DNS-over-HTTP/2 and not DNSCrypt it seems, because the DNS stamp you provided in a sibling comment starts with "Ag" and not "AQ". https://dnscrypt.info/faq mentions some drawbacks of DNS over HTTPS; - Requires a full TLS stack and a web server - Interception/monitoring tools are readily available - Key management can be surprisingly hard especially if public key pinning is use…

When you are a CDN and already have a massive infrastructure to handle HTTP/2 traffic, DNS-over-HTTP/2 makes more sense.

I also totally trust Cloudflare for the TLS security part, especially since they support TLS 1.3 already.

Quad9 said they will support DNSCrypt soon, and the software they use just got an update to do it nicely. So, this will be a decent alternative if you are looking for an anycast resolver.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#173
post #112

Earlier quoted context omitted.

Google is very transparent about what they log with their public DNS servers[0]. [0] https://developers.google.com/speed/public-dns/privacy

And how do we know this information is accurate?

Lawyers exist and any case against Google would be a huge payday in settlement alone

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#174

Earlier quoted context omitted.

Level 3's resolvers will return fake NXDOMAIN responses that redirect to searchguide.level3.com.

I thought NXDOMAIN responses indicated that the domain doesn't exist and there wasn't a way to actually direct the user anywhere. Your resolver could of course lie and return an IP instead of NXDOMAIN however. Perhaps I'm wrong.

You are correct, their resolver is basically lying.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#176
post #75

>supports encrypted DNS as well as DNS over HTTPS Are encrypted DNS requests used by default? Does 1.1.1.1 somehow advertise to your client (whether it's a browser, the OS or a router) that encryption is possible? Do I have to configure my endpoint, which may expect to be able to send normal plaintext DNS requests, for it? I guess DNS over HTTPS will surely not be supported by normal routers, but I don't know what ot…

Encrypted DNS usually refers to making TLS-secured connection to a DNS server over port :853. You can read more here: https://tools.ietf.org/html/rfc7858

Thanks a lot, that was what I looking for. Seems most realistic to configure DNS-over-TLS on the OS level then.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#177

Earlier quoted context omitted.

What about akamai? They are a much larger CDN (no one talks about it on HN because they are not a startup). I agree with your assertion that it will become a single point of failure with many web properties but also I think that HN has a sort of filter bubble on startups (for obvious reasons) and I'm not sure cloudflare is as big as people make it out to be. Also, Google has 8.8.8.8 which could be for the same thing…

CloudFlare publishes their pricing. Akamai doesn't. Dealing with salespeople is a massive PITA. They're not going to tell me anything that's not in the docs or support forums and I don't want to spend a week negotiating. I've seen many others make this point on HN over the years. Maybe Akamai only focuses on large enterprise customers while CloudFlare also goes for the SMB market. IDK. The HN crowd seems to work at S…

Why do startups that sell to other startups hire sales people to do this instead of just having clear pricing?

Obviously they must extract some value for the business but the experience of haggling with some sales bro to get a decent price leaves me so annoyed with services that I usually skip signing up when it’s the only option.

> Let’s talk about solutions!

No thanks. I just want to insert dollars and get the service.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#178
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

What makes that even worse is that Cloudflare is vehemently against anonymity on the Internet. I get it, it is part of their business model, but with the privacy concerns today ... well ... let's just say I am not a fan of theirs.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#179
post #43

Earlier quoted context omitted.

"We will never log your IP address" doesn't sound that vague.

But it is. They don't say what they do log. For example if I zero out the highest octet of your IP address and I log the ASN, I have effectively identified you without "logging your IP address".

I know nothing about how auditing companies like the stated KPMG work.

If Cloudflare did this, would they pass the audit?

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#180
post #173

Earlier quoted context omitted.

And how do we know this information is accurate?

Lawyers exist and any case against Google would be a huge payday in settlement alone

To sue someone for doing something illegal, you first need some evidence that they're doing it. Google heavily employs confidentiality for that reason. Case in point: Antitrust investigations across the globe were launched into the Android MADA... but that didn't happen until years later, when the confidential agreements were revealed in the Oracle v. Google case.

As long as nobody knew what was happening, it went unpoliced. One of the ongoing HR-related lawsuits explicitly claims Google prohibits employees from revealing illegal conduct that the company engages in.

Post reply on HN