$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…
Sorry man :( Things are a bit quicker in the US: 64 bytes from 1.1.1.1: icmp_seq=1 ttl=60 time=0.421 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=58 time=0.645 ms
1.1.1.1: Fast, privacy-first consumer DNS service
131–140 of 695 posts
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#132Earlier quoted context omitted.
Did you read the page? They're supporting DNS over TLS and DNS over HTTPS - both changes to the protocol to make in uninspectable. They've also said they're not logging IP info and they're getting independent auditors in to confirm what they're saying. Sounds trustworthy to me
Both encrypted extensions are of course inspectable at the end-point, which is the privacy model being discussed. What is intriguing to me is why Cloudflare are offering this. Perhaps it is to provide data on traffic that is 'invisible' to them, as in it doesn't currently touch their networks. Possibly as a sales-lead generator. Or is the plan to become dominant and then use DNS blackholing to shutdown malware that i…
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#133When I've seen DNS-over-HTTPS in the past I've always thought it odd that it's setup with a DNS name for the HTTPS address, requiring a plain DNS lookup before it starts using HTTPS. I assumed this was done because they didn't have a valid TLS cert for the IP address. But 1.1.1.1 actually has a valid TLS cert, yet their setup instructions say to use the DNS name cloudflare-dns.com instead of the IP. https://developer…
I suppose I see your point, but since DNS-over-HTTPS only supports HTTPS (not HTTP) and therefore requires a valid certificate for the requested resolver, there's no risk of the protocol being downgraded to HTTP or easily spoofed. So what do you see as the threat profile?
Of course an ISP or nation could block/reroute the IP 1.1.1.1 too, so maybe it doesn't matter. Neither way would allow MITM, I was just thinking about ways oppressive ISPs/nations could stop DNS-over-HTTPS from working.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#134TIL you can also use 1.1 and it will expand to 1.0.0.1 $> ping 1.1 PING 1.1 (1.0.0.1) 56(84) bytes of data. 64 bytes from 1.0.0.1: icmp_seq=1 ttl=55 time=28.3 ms 64 bytes from 1.0.0.1: icmp_seq=2 ttl=55 time=33.0 ms 64 bytes from 1.0.0.1: icmp_seq=3 ttl=55 time=43.6 ms 64 bytes from 1.0.0.1: icmp_seq=4 ttl=55 time=41.7 ms 64 bytes from 1.0.0.1: icmp_seq=5 ttl=55 time=56.5 ms 64 bytes from 1.0.0.1: icmp_seq=6 ttl=55 t…
1.2 -> 1.0.0.2
1.2.3 -> 1.2.0.3
But then, much of software would fail here - Firefox/Chrome for example would both threat that as bareword and redirect to search page.Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#135TIL you can also use 1.1 and it will expand to 1.0.0.1 $> ping 1.1 PING 1.1 (1.0.0.1) 56(84) bytes of data. 64 bytes from 1.0.0.1: icmp_seq=1 ttl=55 time=28.3 ms 64 bytes from 1.0.0.1: icmp_seq=2 ttl=55 time=33.0 ms 64 bytes from 1.0.0.1: icmp_seq=3 ttl=55 time=43.6 ms 64 bytes from 1.0.0.1: icmp_seq=4 ttl=55 time=41.7 ms 64 bytes from 1.0.0.1: icmp_seq=5 ttl=55 time=56.5 ms 64 bytes from 1.0.0.1: icmp_seq=6 ttl=55 t…
You can also use the decimal value of the IP, without the dots: https://16843009
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#136uhm how can you get an ssl cert for an IP?
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#137so is a DHCP server address of 1.1.1.1 still perfectly valid for wireless local area networks? see: http://www.revolutionwifi.net/revolutionwifi/2011/03/explain...
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#138Earlier quoted context omitted.
Logging: https://www.quad9.net/privacy/
Anonymized logging to improve the service and security. Is this different from Cloudflare?
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#139I am getting ERR_CERT_AUTHORITY_INVALID because my ISP-provided router is intercepting the connection and trying to show me a "helpful" configuration wizard. No Cloudflare DNS for me. To be explicit: This is not Cloudflare's fault and we should blame the manufacturer of the router, or the ISP for deploying their custom "friendly" settings. But it is what it is.
Same problem here. It would be nice if Cloudflare created an alias to 1.1.1.1, because I can't access it at all. Edit: 1.0.0.1 also takes me to the router configuration screen. And there's no configuration setting for it. :(
The "good" news is that this isn't being used for anything you really need - imagine if 1.1.1.1 had been delegated and now it was the resolution for www.facebook.com or indeed news.ycombinator.com ...
The bad news is that idiots do not learn from their mistakes, that's Dunning Kruger, the people who built your device don't understand why this was the Wrong Thing™ and won't now seek to do better in future. If we're lucky they'll go out of business, but that's the best we can hope for.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#140Earlier quoted context omitted.
They are NOT saying Google is lying and collecting the data. They are saying the business model of Google inherently provides such incentive. Cloudflare is somewhat right: Means, Motive and Opportunity - but for a conviction you have to prove someone acted on the Opportunity. The Motive of Google is tampered with severe risk for loosing trust. Cloudflare can make an argument they are fundamentally better positioned a…
It's clear what you meant, but for whatever it's worth, I think the word you wanted was "tempered", not "tampered".