Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

61–70 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#61
post #19

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…

Anycast is not based on latency, so that's normal.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#63
post #48
post #9

Earlier quoted context omitted.

Yes they have: "Privacy First: Guaranteed. We will never sell your data or use it to target ads. Period. We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say. Frankly, we don’t want to know what you do on the Internet—it’s none of our business—and we’ve taken the technical step…

> Frankly, we don’t want to know what you do on the Internet—it’s none of our business In the DNS resolver space, what is their business?

They want fast resolution of names that point to websites hosted by Cloudflare. Cloudflare makes their money selling their network to businesses that use it, and anything that makes that service better for the end-user increases customer stickiness.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#64
When I've seen DNS-over-HTTPS in the past I've always thought it odd that it's setup with a DNS name for the HTTPS address, requiring a plain DNS lookup before it starts using HTTPS. I assumed this was done because they didn't have a valid TLS cert for the IP address. But 1.1.1.1 actually has a valid TLS cert, yet their setup instructions say to use the DNS name cloudflare-dns.com instead of the IP.

https://developers.cloudflare.com/1.1.1.1/dns-over-https/

Is there a technical reason the DNS-over-HTTPS resolvers need their upstream resolvers to be looked up by name and not IP?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#65

9.9.9.9 [1] has been praised by a bunch of people in the thread from a couple days ago [2]. How do those two compare? [1] https://www.quad9.net/ [2] https://news.ycombinator.com/item?id=16716606

I love the fact that the consortium managed to get 9.9.9.9 (because Google's 8.8.8.8) and named themselves Quad9!

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#66
post #58

Just curious: can somebody shed light on how they got the 1.1.1.1 IP address?

APNIC's research group held the IP addresses 1.1.1.1 and 1.0.0.1. While the addresses were valid, so many people had entered them into various random systems that they were continuously overwhelmed by a flood of garbage traffic. APNIC wanted to study this garbage traffic but any time they'd tried to announce the IPs, the flood would overwhelm any conventional network.

We talked to the APNIC team about how we wanted to create a privacy-first, extremely fast DNS system. They thought it was a laudable goal. We offered Cloudflare's network to receive and study the garbage traffic in exchange for being able to offer a DNS resolver on the memorable IPs. And, with that, 1.1.1.1 was born

https://blog.cloudflare.com/announcing-1111/

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#68
post #58

Just curious: can somebody shed light on how they got the 1.1.1.1 IP address?

It is explained on the bottom of the page:

Who’s behind this?

1.1.1.1 is a partnership between Cloudflare and APNIC.

Cloudflare runs one of the world’s largest, fastest networks. APNIC is a non-profit organization managing IP address allocation for the Asia Pacific and Oceania regions.

Cloudflare had the network. APNIC had the IP address (1.1.1.1). Both of us were motivated by a mission to help build a better Internet. You can read more about each organization’s motivations on our respective posts: Cloudflare Blog / APNIC Blog.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#69
post #33

Earlier quoted context omitted.

PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=60 time=2.099 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=60 time=2.073 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=60 time=1.963 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=60 time=2.089 ms PING 8.8.8.8 (8.8.8.8): 56 data bytes 64 bytes from 8.8.8.8: icmp_seq=0 ttl=60 time=1.908 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=60 time=1.888 ms 64 bytes from…

Just him. Starhub Fiber: ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=59 time=3.111 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=59 time=3.172 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=59 time=3.301 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=59 time=3.018 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=59 time=3.218 ms ^C --- 1.1.1.1 ping statistics --- 5 packets transmitted, 5 packets r…

Interesting, mine is bad too. From singtel:

     Host                                                  Loss%   Snt   Last   Avg  Best  Wrst StDev
  1. 192.168.1.254                                         0.0%    75    1.3   1.6   1.1  14.8   1.6
  2. bbXXX-XXX-XXX-XX.singnet.com.sg                       0.0%    75    3.4   2.8   1.9  18.7   2.5
  3. 202.166.123.134                                       0.0%    75    3.2   3.5   2.7  15.9   2.0
  4. 202.166.123.133                                       0.0%    75    3.0   3.0   2.4   6.6   0.7
  5. ae8-0.tp-cr03.singnet.com.sg                          0.0%    75    3.1   3.3   2.8   6.9   0.7
  6. ae4-0.tp-er03.singnet.com.sg                          0.0%    75    2.9   3.1   2.6   6.7   0.5
  7. 203.208.191.197                                       0.0%    75    7.8   4.6   2.9  18.3   3.6
  8. 203.208.149.138                                       0.0%    75    3.0   7.5   2.7  67.2  13.4
  9. 203.208.153.126                                       0.0%    75  182.8 186.9 174.4 327.7  20.5
     203.208.172.226
     203.208.172.178
     203.208.158.50
     203.208.152.214
     203.208.173.106
     203.208.149.58
     203.208.149.30
  10. ix-xe-0-1-2-0.tcore2.pdi-palo-alto.as6453.net         0.0%    74  201.4 190.5 183.9 210.1   5.9
  11. if-ae-5-2.tcore2.sqn-san-jose.as6453.net              0.0%    74  181.4 184.7 179.4 197.9   4.6
  12. if-ae-1-2.tcore1.sqn-san-jose.as6453.net              0.0%    74  177.8 177.3 172.0 190.0   4.8
  13. 63.243.205.106                                        0.0%    74  179.2 184.2 179.1 196.2   4.5
  14. 1dot1dot1dot1.cloudflare-dns.com                      0.0%    74  191.9 184.7 172.4 202.3   6.6
Looks like singtel has some bad routing rules for Cloudflare and it's going through to the USA rather than hitting a local PoP.

Might send CloudFlare a quick email as they'll probably want singtel to correct this.

Post reply on HN