Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

91–100 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#91
post #55
post #19

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…

Tokyo, Japan: [mason@iMac-Pro-No-5 fubastardo (master)]$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=56 time=2.310 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=56 time=2.287 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=56 time=2.103 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=56 time=2.785 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=56 time=2.276 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl…

You're just trying to make Australians jealous aren't you?

    ping 1.1.1.1

    Reply from 1.1.1.1: bytes=32 time=366ms TTL=58
    Reply from 1.1.1.1: bytes=32 time=366ms TTL=58
    Reply from 1.1.1.1: bytes=32 time=365ms TTL=58
    Reply from 1.1.1.1: bytes=32 time=365ms TTL=58

    ping 8.8.8.8

    Reply from 8.8.8.8: bytes=32 time=402ms TTL=59
    Reply from 8.8.8.8: bytes=32 time=373ms TTL=59
    Reply from 8.8.8.8: bytes=32 time=373ms TTL=59
    Reply from 8.8.8.8: bytes=32 time=374ms TTL=59

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#92
post #19

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…

I get roughly the same 45-48ms from the EU for both.

EU, but my network setup is shitty as one can be:

    --- 8.8.8.8 ping statistics ---
    23 packets transmitted, 20 received, 13% packet loss, time 22093ms
    rtt min/avg/max/mdev = 37.756/51.634/75.856/12.714 ms

    --- 1.1.1.1 ping statistics ---
    7 packets transmitted, 7 received, 0% packet loss, time 6007ms
    rtt min/avg/max/mdev = 38.920/43.627/52.355/4.547 ms
same same

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#93

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

And since it's cloudflare if some site's politics don't align with the owner's politics they'll just block it arbitrarily.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#94

This is bad, bad, bad advice. You don't set the DNS on your local machine. That breaks things. The DNS needs to be set at the gateway. If you change your PC/mac's DNS to an external service, you won't be able to resolve any addresses on the local network. Come on, CloudFlare. You guys know better than that. Please stop breaking the (local) internet.

[deleted]

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#95

9.9.9.9 [1] has been praised by a bunch of people in the thread from a couple days ago [2]. How do those two compare? [1] https://www.quad9.net/ [2] https://news.ycombinator.com/item?id=16716606

Quad9 not friendly to CDN.

  $ dig +short @8.8.8.8 icnerd-1e5f.kxcdn.com
  p-rumo00.kxcdn.com.
  188.42.31.172
  $ dig +short @1.1.1.1 icnerd-1e5f.kxcdn.com
  p-rumo00.kxcdn.com.
  188.42.31.172
  $ dig +short @9.9.9.9 icnerd-1e5f.kxcdn.com 
  con-na00.kvcdn.com.
  p-ussj00.kxcdn.com.
  209.58.130.199
  $ dig +short @9.9.9.10 icnerd-1e5f.kxcdn.com
  con-na00.kvcdn.com.
  p-ussj00.kxcdn.com.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#96

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

"I can't be arsed to pay $3/mo for a VPS that I can tunnel my DNS requests through, so I'm gonna nitpick on hackernews about a company trying their best to offer it to /everyone/ for free"

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#97
post #48
post #9

Earlier quoted context omitted.

Yes they have: "Privacy First: Guaranteed. We will never sell your data or use it to target ads. Period. We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say. Frankly, we don’t want to know what you do on the Internet—it’s none of our business—and we’ve taken the technical step…

> Frankly, we don’t want to know what you do on the Internet—it’s none of our business In the DNS resolver space, what is their business?

Making the internet fast and reliable, and arguably DNS resolution plays into that.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#98

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

AFAIK the only data is domain name, record and the incoming ip. I don't care if they store the first two. Do you have any actual points against or are you just trying to nitpick? And do you have anything better?

Unfortunately, nitpicking is quite necessary. Haven't we seen enough instances of corporations lying through omission? Where is the trend that indicates we should give a more favorable, trustworthy reading to terms and promises like these? I don't see it.

Cloudflare is a for-profit corporation--you know, "duty to shareholders" and all that. We must assume, almost by definition, that they actually have their own self-interests at heart.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#99
post #48
post #9

Earlier quoted context omitted.

Yes they have: "Privacy First: Guaranteed. We will never sell your data or use it to target ads. Period. We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say. Frankly, we don’t want to know what you do on the Internet—it’s none of our business—and we’ve taken the technical step…

> Frankly, we don’t want to know what you do on the Internet—it’s none of our business In the DNS resolver space, what is their business?

Could be a precursor to launching an OpenDNS competitor.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#100

9.9.9.9 [1] has been praised by a bunch of people in the thread from a couple days ago [2]. How do those two compare? [1] https://www.quad9.net/ [2] https://news.ycombinator.com/item?id=16716606

Note that 9.9.9.9 is NOT a regular DNS service and does not give you an unrestricted view of the global internet domain name system.

They match your requests with IBM's X-Force threat intelligence database and give you filtered results.

https://www.theregister.co.uk/2017/11/20/quad9_secure_privat...

Post reply on HN