Live data from Hacker News

1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

webcache.googleusercontent.com

241–250 of 253 posts

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#241

To use this on iOS, download DNSCloak from the App Store and choose "Cloudflare" in the list.

You can change the dns server easily from wifi settings on ios.

DNSCloak app makes it uses DNSCrypt, not standard DNS you can set on the Wifi Settings.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#242
post #222

Earlier quoted context omitted.

Not sure your point. Who exactly do you anticipate is opt-ing? The website owner's settings defaults to secure, and they can intentionally take action to make the website less secure if they'd like to. That is their decision, of course we do not default to a less secure posture.

What I meant. This default setting is the reason why Cloudflare is not off the hook here. This is the default, so website owners who don't care or know about it won't change it. Like all default settings where you have to actively change it.

Default settings should be secure. As the Cloudflare article points out, 94% of their traffic over Tor was malicious.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#243
post #222

Earlier quoted context omitted.

What I meant. This default setting is the reason why Cloudflare is not off the hook here. This is the default, so website owners who don't care or know about it won't change it. Like all default settings where you have to actively change it.

Default settings should be secure. As the Cloudflare article points out, 94% of their traffic over Tor was malicious.

then at least force the user to set this. I don't care if the traffic is 'malicious' whatever the definition of that is.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#244

To use this on iOS, download DNSCloak from the App Store and choose "Cloudflare" in the list.

Or use DNS Override app: https://www.iphonedns.com And they've just listed 1.1.1.1, 1.0.0.1, 2606:4700:4700::1111, 2606:4700:4700::1001 officially as Cloudflare DNS. Looks like everything is here: https://developers.cloudflare.com/1.1.1.1/

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#245
post #115

Earlier quoted context omitted.

Plenty of captive portals operators use the 1.1.1.0/24 ip subnet for their authentication pages. A shame they thought these IPs would never be used

Don't some VoIP devices use 1.1.1.1 too to check connection type or something? There was a paper from a couple years ago when 1.1.1/24 (or bigger, don't remember) was still unassigned; at some AS they logged what kind of traffic was targeted at that subnet, by IP, port and protocol and 1.1.1.1 stood out. Can't find that paper just now unfortunately. :-(

https://www.nanog.org/meetings/nanog49/presentations/Monday/...

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#246
post #154

Earlier quoted context omitted.

They also provide 9.9.9.10, which doesn't have a blocklist. https://www.quad9.net/faq/#Is_there_a_service_that_Quad9_off...

However, 9.9.9.10 does not perform DNSSEC validation, as 8.8.8.8 (Google), 64.6.64.6 (Verisign), 9.9.9.9 (Quad9), and now 1.1.1.1 (CloudFlare) do, so results may not be as trustworthy.

It does.

  $ dig @9.9.9.10 +dnssec +short verisignlabs.com
  72.13.58.64
  A 8 2 3600 20180413202737 20180330202737 31485 verisignlabs.com. KrnT9i6qytaYWDZWThBmBwc6anOmawNxJTxmSlpaY3L7Yfupga9FS70l 8nMVp8ggbEtA+CnS9AbNwObkPaYvk3nFpDvo4C+2hg+PECsP1HVTgGxl G3eblfnYAMNfYzLYlfUnSBgM7kLSIXY4rLBxsl01KiPJYezNhmQ53KYf ygs=

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#247
post #220

Earlier quoted context omitted.

abmx maybe?

First I've heard of them (but I'm not any kind of expert). Are they good? I usually just hear the usual suspects mentioned such as iXSystems and Supermicro. Linux guys will mention one called PogoLinux every once in a while also

I have bought a few servers from them (4 or so over the years), and they have served me pretty well so far. I haven't had to do any RMA's or replacements though, so not sure how good the company is about that.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#249
post #241

Earlier quoted context omitted.

You can change the dns server easily from wifi settings on ios.

DNSCloak app makes it uses DNSCrypt, not standard DNS you can set on the Wifi Settings.

Yep, and it works well with Cloudflare (and has for quite some time).

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#250

Earlier quoted context omitted.

What about akamai? They are a much larger CDN (no one talks about it on HN because they are not a startup). I agree with your assertion that it will become a single point of failure with many web properties but also I think that HN has a sort of filter bubble on startups (for obvious reasons) and I'm not sure cloudflare is as big as people make it out to be. Also, Google has 8.8.8.8 which could be for the same thing…

CloudFlare publishes their pricing. Akamai doesn't. Dealing with salespeople is a massive PITA. They're not going to tell me anything that's not in the docs or support forums and I don't want to spend a week negotiating. I've seen many others make this point on HN over the years. Maybe Akamai only focuses on large enterprise customers while CloudFlare also goes for the SMB market. IDK. The HN crowd seems to work at S…

You can get Akamai CDN through Azure: https://azure.microsoft.com/en-us/blog/azure-cdn-from-akamai...

and they publish their pricing, no minimum purchase: https://azure.microsoft.com/en-us/pricing/details/cdn/

Post reply on HN