Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

101–110 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#101
post #77

Earlier quoted context omitted.

Yup, the Subject Alternative Name (often misunderstood as an alias, but "Alternative" here is meant in the sense of this is the Internet's _Alternative_ way to name things versus the X.500 series directory hierarchy that the X.509 certificates are originally intended for) can be one of several distinct types, the two relevant for servers are dnsName and ipAddress. dnsName can be any er, name, in the DNS hierarchy, or…

Using an ip instead of a domain name like this allows the possibility of dns rebinding attacks, right?

What would be rebound to what?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#102

9.9.9.9 [1] has been praised by a bunch of people in the thread from a couple days ago [2]. How do those two compare? [1] https://www.quad9.net/ [2] https://news.ycombinator.com/item?id=16716606

Logging: https://www.quad9.net/privacy/

Anonymized logging to improve the service and security. Is this different from Cloudflare?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#103

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

AFAIK the only data is domain name, record and the incoming ip. I don't care if they store the first two. Do you have any actual points against or are you just trying to nitpick? And do you have anything better?

Fair point and (maybe) you are right, I am nitpicking but not ashamed to do so. Could have been stronger to say "We won't store your data" rather than "We won't sell your data". And frankly, "we will never log your IP address (the way other companies identify you)", like really? Talking very naively, what if they just store a hashcode or some other derivative of the IP instead, is that counted as logging the IP? And what about the timestamp, geoIP, reverse hostname and other factors, can deep intelligence be used to associate with other behavior?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#104

I am getting ERR_CERT_AUTHORITY_INVALID because my ISP-provided router is intercepting the connection and trying to show me a "helpful" configuration wizard. No Cloudflare DNS for me. To be explicit: This is not Cloudflare's fault and we should blame the manufacturer of the router, or the ISP for deploying their custom "friendly" settings. But it is what it is.

Same problem here. It would be nice if Cloudflare created an alias to 1.1.1.1, because I can't access it at all. Edit: 1.0.0.1 also takes me to the router configuration screen. And there's no configuration setting for it. :(

https://cloudflare-dns.com/ works, however it redirects to https://1.1.1.1/

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#105

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

"I can't be arsed to pay $3/mo for a VPS that I can tunnel my DNS requests through, so I'm gonna nitpick on hackernews about a company trying their best to offer it to /everyone/ for free"

No that's not fair. Everything is open to criticism.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#107
I'm curious to read the reports from the garbage traffic they get at their 1.x.x.x addresses. Must be a ton of computers sending traffic that way. On the other hand, there's probably quite a few networks where 1.x.x.x is unreachable or routed to a local captive network access server, too.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#108
post #55

Earlier quoted context omitted.

Tokyo, Japan: [mason@iMac-Pro-No-5 fubastardo (master)]$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=56 time=2.310 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=56 time=2.287 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=56 time=2.103 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=56 time=2.785 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=56 time=2.276 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl…

You're just trying to make Australians jealous aren't you? ping 1.1.1.1 Reply from 1.1.1.1: bytes=32 time=366ms TTL=58 Reply from 1.1.1.1: bytes=32 time=366ms TTL=58 Reply from 1.1.1.1: bytes=32 time=365ms TTL=58 Reply from 1.1.1.1: bytes=32 time=365ms TTL=58 ping 8.8.8.8 Reply from 8.8.8.8: bytes=32 time=402ms TTL=59 Reply from 8.8.8.8: bytes=32 time=373ms TTL=59 Reply from 8.8.8.8: bytes=32 time=373ms TTL=59 Reply…

I'm getting ~60 and ~50 from Canberra.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#109

This is bad, bad, bad advice. You don't set the DNS on your local machine. That breaks things. The DNS needs to be set at the gateway. If you change your PC/mac's DNS to an external service, you won't be able to resolve any addresses on the local network. Come on, CloudFlare. You guys know better than that. Please stop breaking the (local) internet.

How many people have local DNS at home? Not many, I'd wager. How many know how to access their router? Also not many. Besides, "In your router’s configuration page, locate the DNS server settings."

I've been running my own DNS servers since 1996, when I had my first dedicated connection (an ISDN line.) I never use my ISP's DNS.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#110
post #19

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…

From Belgium, not much of a difference

        [:~] % ping 1.1.1.1
        PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
        64 bytes from 1.1.1.1: icmp_seq=1 ttl=59 time=22.0 ms
        64 bytes from 1.1.1.1: icmp_seq=2 ttl=59 time=21.1 ms
        64 bytes from 1.1.1.1: icmp_seq=3 ttl=59 time=21.8 ms
        64 bytes from 1.1.1.1: icmp_seq=4 ttl=59 time=21.0 ms
        64 bytes from 1.1.1.1: icmp_seq=5 ttl=59 time=21.8 ms
        64 bytes from 1.1.1.1: icmp_seq=6 ttl=59 time=21.2 ms
        ^C
        --- 1.1.1.1 ping statistics ---
        6 packets transmitted, 6 received, 0% packet loss, time 5009ms
        rtt min/avg/max/mdev = 21.023/21.509/22.031/0.399 ms
        [:~] % ping 8.8.8.8
        PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
        64 bytes from 8.8.8.8: icmp_seq=1 ttl=59 time=26.4 ms
        64 bytes from 8.8.8.8: icmp_seq=2 ttl=59 time=26.6 ms
        64 bytes from 8.8.8.8: icmp_seq=3 ttl=59 time=26.7 ms
        64 bytes from 8.8.8.8: icmp_seq=4 ttl=59 time=26.4 ms
        64 bytes from 8.8.8.8: icmp_seq=5 ttl=59 time=26.7 ms
        64 bytes from 8.8.8.8: icmp_seq=6 ttl=59 time=25.9 ms
        ^C
        --- 8.8.8.8 ping statistics ---
        6 packets transmitted, 6 received, 0% packet loss, time 5010ms
        rtt min/avg/max/mdev = 25.925/26.501/26.790/0.344 ms
Post reply on HN