Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

111–120 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#111

When I've seen DNS-over-HTTPS in the past I've always thought it odd that it's setup with a DNS name for the HTTPS address, requiring a plain DNS lookup before it starts using HTTPS. I assumed this was done because they didn't have a valid TLS cert for the IP address. But 1.1.1.1 actually has a valid TLS cert, yet their setup instructions say to use the DNS name cloudflare-dns.com instead of the IP. https://developer…

I suppose I see your point, but since DNS-over-HTTPS only supports HTTPS (not HTTP) and therefore requires a valid certificate for the requested resolver, there's no risk of the protocol being downgraded to HTTP or easily spoofed.

So what do you see as the threat profile?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#112

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

And since it's cloudflare if some site's politics don't align with the owner's politics they'll just block it arbitrarily.

Any examples of this besides the KKK?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#113
post #3

This is the Cloudflare resolver, right? What's the "privacy-first" part about? It's just another third party DNS host. They haven't changed the protocol to be uninspectable and AFAIK haven't made any guarantees about logging or whatnot that would enhance privacy vs. using whatever you are now. This just means you're trusting Cloudflare instead of Comcast or Google or whoever.

"We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say." Now, audits are generally not worth very much (even, perhaps even especially, from a Big Four group like KPMG), but for this type of thing (verifying that a company isn't doing something they promised they would not do) th…

>"Now, audits are generally not worth very much (even, perhaps even especially, from a Big Four group like KPMG)"

Indeed, see the recent KPMG scandal:

https://www.marketwatch.com/story/kpmg-indictment-suggests-m...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#114
post #3

This is the Cloudflare resolver, right? What's the "privacy-first" part about? It's just another third party DNS host. They haven't changed the protocol to be uninspectable and AFAIK haven't made any guarantees about logging or whatnot that would enhance privacy vs. using whatever you are now. This just means you're trusting Cloudflare instead of Comcast or Google or whoever.

On the contrary, they've taken 2 big steps that are better than ISPs (not sure about Google): * no logging * DNS over HTTPS

I've switched to cloudflare and none of the dns leak tests are showing my DNS, which I find interesting. They always showed google.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#115

Earlier quoted context omitted.

"I can't be arsed to pay $3/mo for a VPS that I can tunnel my DNS requests through, so I'm gonna nitpick on hackernews about a company trying their best to offer it to /everyone/ for free"

No that's not fair. Everything is open to criticism.

But not every criticism is as high quality as every other criticism. The above for example is just low quality nitpicking.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#116
TIL you can also use 1.1 and it will expand to 1.0.0.1

  $> ping 1.1

  PING 1.1 (1.0.0.1) 56(84) bytes of data.
  64 bytes from 1.0.0.1: icmp_seq=1 ttl=55 time=28.3 ms
  64 bytes from 1.0.0.1: icmp_seq=2 ttl=55 time=33.0 ms
  64 bytes from 1.0.0.1: icmp_seq=3 ttl=55 time=43.6 ms
  64 bytes from 1.0.0.1: icmp_seq=4 ttl=55 time=41.7 ms
  64 bytes from 1.0.0.1: icmp_seq=5 ttl=55 time=56.5 ms
  64 bytes from 1.0.0.1: icmp_seq=6 ttl=55 time=38.4 ms
  64 bytes from 1.0.0.1: icmp_seq=7 ttl=55 time=34.8 ms
  64 bytes from 1.0.0.1: icmp_seq=8 ttl=55 time=45.7 ms
  64 bytes from 1.0.0.1: icmp_seq=9 ttl=55 time=45.2 ms
  64 bytes from 1.0.0.1: icmp_seq=10 ttl=55 time=43.1 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#117

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

Well, the post sort of implies that they log everything for 24 hours, but instead of raw IP addresses they log hashed ones, as they still need to identify everyone. Which, sadly, doesn't affect tracking practices at all.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#118
post #55

Earlier quoted context omitted.

Tokyo, Japan: [mason@iMac-Pro-No-5 fubastardo (master)]$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=56 time=2.310 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=56 time=2.287 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=56 time=2.103 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=56 time=2.785 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=56 time=2.276 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl…

How are you getting those single digit times? I can never get below 15 ms for both Google and CloudFlare. Any tips to improve this or its beyond my control?

Big cities are within half a ms range of various PoPs and IXes on fiber. Makes it possible to go even below 0.5 ms.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#119

Earlier quoted context omitted.

No that's not fair. Everything is open to criticism.

But not every criticism is as high quality as every other criticism. The above for example is just low quality nitpicking.

So what's your take on hashcode of the IP considered as "not logging the IP" (and other stuff edited in comment)?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#120

Earlier quoted context omitted.

Google is one of the first ones using DNS over HTTPS. BTW if you want to use DNS over HTTPS on Linux/Mac I strongly recommend dnscrypt proxy V2 (golang rewrite) https://github.com/jedisct1/dnscrypt-proxy and put e.g. cloudflare in their config toml file to make use of it.

The whole point of encrypting DNS traffic is to hide it from the likes of Google.

For me personally it is much more important to hide my DNS traffic from my ISP instead of Google, etc., even though I don't live in the US.

I pay them to access the internet, every further information they gather about my internet activity does not mean any benefit for me.

Post reply on HN