Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

151–160 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#151

From Shenzhen, China 1.1.1.1/1.0.0.1 rtt min/avg/max/mdev = 198.036/199.739/202.978/2.319 ms 8.8.8.8/8.8.4.4 rtt min/avg/max/mdev = 12.798/13.681/14.408/0.673 ms 114.114.114.114/114.114.115.115 rtt min/avg/max/mdev = 15.508/25.381/38.815/9.842 ms

Not surprising: Google despite being blocked in China a lot of presumably expensive paid transit from the big 3 mainland china telcos in and out of the mainland to Hong Kong.

Cloudflare serves sites visited from China that aren't using their China-requires-an-ICP-license service from their west coast USA location where the big 3 Chinese telcos will peer for free.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#152
post #45

Earlier quoted context omitted.

Both encrypted extensions are of course inspectable at the end-point, which is the privacy model being discussed. What is intriguing to me is why Cloudflare are offering this. Perhaps it is to provide data on traffic that is 'invisible' to them, as in it doesn't currently touch their networks. Possibly as a sales-lead generator. Or is the plan to become dominant and then use DNS blackholing to shutdown malware that i…

Im probably being naive, but maybe altruism? At least if you buy into their making the internet better rhetoric

Cloudflare is already a significant enough player in handling Internet traffic. Maybe the company does want to do good for the sake of doing good, but I’m wary of companies taking over in this manner and making the Internet more like a monolith than a distributed system.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#153

From Shenzhen, China 1.1.1.1/1.0.0.1 rtt min/avg/max/mdev = 198.036/199.739/202.978/2.319 ms 8.8.8.8/8.8.4.4 rtt min/avg/max/mdev = 12.798/13.681/14.408/0.673 ms 114.114.114.114/114.114.115.115 rtt min/avg/max/mdev = 15.508/25.381/38.815/9.842 ms

True...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#154
post #14

Earlier quoted context omitted.

Cloudflare is making a public pronouncement that they're not going to sell your DNS data nor track your IP address, with the implication that they will also not use the usage data to upsell you services. That's about the only additional "privacy" edge they offer. In the same breath, they insinuate that Google both sells and uses DNS usage from their 8.8.8.8 and 8.8.4.4 resolvers.

They are NOT saying Google is lying and collecting the data. They are saying the business model of Google inherently provides such incentive. Cloudflare is somewhat right: Means, Motive and Opportunity - but for a conviction you have to prove someone acted on the Opportunity. The Motive of Google is tampered with severe risk for loosing trust. Cloudflare can make an argument they are fundamentally better positioned a…

>"They are NOT saying Google is lying and collecting the data."

The OP did not say that cloudflare is "saying" that. The OP very clearly said they are "insinuating" it. And yes under the heading "DNS's Privacy Problem" the post mentions:

"With all the concern over the data that companies like Facebook and Google are collecting on you,..."

I think that juxtaposition of this statement under a bolded heading of "DNS's Privacy Problem" is very much insinuating that.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#155

TIL you can also use 1.1 and it will expand to 1.0.0.1 $> ping 1.1 PING 1.1 (1.0.0.1) 56(84) bytes of data. 64 bytes from 1.0.0.1: icmp_seq=1 ttl=55 time=28.3 ms 64 bytes from 1.0.0.1: icmp_seq=2 ttl=55 time=33.0 ms 64 bytes from 1.0.0.1: icmp_seq=3 ttl=55 time=43.6 ms 64 bytes from 1.0.0.1: icmp_seq=4 ttl=55 time=41.7 ms 64 bytes from 1.0.0.1: icmp_seq=5 ttl=55 time=56.5 ms 64 bytes from 1.0.0.1: icmp_seq=6 ttl=55 t…

Interesting question related to this : https://superuser.com/questions/486788/why-does-pinging-192-...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#156
post #19

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…

[deleted]

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#157
post #145

I'm probably gonna switch my PiHole over from Google DNS. I trust Cloudflare more than Google to uphold my privacy. Not that I trust either very much. Benchmarking Results for the interested: (sorted worst first, P value is bottom-X-percent) 1.1.1.1: P00.5=48.2ms (55.8ms VPN) P50.0=32.8ms (37.0ms VPN) P95.0=29.1ms (33.0ms VPN) P99.5=29.1ms (32.7ms VPN) 8.8.8.8: P00.5=225.4ms (71.5ms VPN) P50.0=48.0ms (53.6ms VPN) P95…

Why isn't your pihole a stand-alone DNS resolver instead on relying on 3rd-party services ?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#158
post #112

Earlier quoted context omitted.

And since it's cloudflare if some site's politics don't align with the owner's politics they'll just block it arbitrarily.

Any examples of this besides the KKK?

So, you're implying things here that I'll address with an H. L. Mencken quote,

>"The trouble with fighting for human freedom is that one spends most of one's time defending scoundrels. For it is against scoundrels that oppressive laws are first aimed, and oppression must be stopped at the beginning if it is to be stopped at all."

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#159
post #19

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=47 time=214.866 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=47 time=173.416 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=45 time=256.007 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=45 time=196.638 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=45 time=294.694 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=45 time=314.883 ms 64 bytes from 1.1.1.1: ic…

[deleted]

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#160
> We committed to never writing the querying IP addresses to disk and wiping all logs within 24 hours.

> Cloudflare's business has never been built around tracking users or selling advertising. We don't see personal data as an asset; we see it as a toxic asset. While we need some logging to prevent abuse and debug issues, we couldn't imagine any situation where we'd need that information longer than 24 hours.

How about aggregate stats? Will CloudFlare be keeping track of any long term usage statistics per domain?

I'm not talking about tracking the person making the request. I'm referring to tracking the hostnames that are being resolved. Given the near 1:1 mapping between user's accessing a website and DNS resolution for that website[1], wide scale usage of something like this gives decent analytics on net usage of any website even if it's not served by CloudFlare.

[1]: Assuming the DNS response cache times are low enough that a new user session to a website would require a fresh DNS request to resolve the website's IP.

Post reply on HN