Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

201–210 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#201

Earlier quoted context omitted.

For me personally it is much more important to hide my DNS traffic from my ISP instead of Google, etc., even though I don't live in the US. I pay them to access the internet, every further information they gather about my internet activity does not mean any benefit for me.

This does not make sense. Either people are not concerned about hiding their traffic or if they are it follows they would be equally if not much more concerned about Google that can track them across devices and build far more indepth invasive profiles than the ISP. Aside it's strange https everywhere has been pushed aggressively by many here under the bogeyman of ISP adware and spying while completely ignoring the m…

Most fears of ISPs have been stoked primarily by tech companies, who invest a lot more money into marketing than the ISPs do.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#202

DNS-over-HTTPS doesn’t make as much sense to me as DNS-over-TLS. They are effectively the same thing, but HTTPS has the added overhead of the HTTP headers per request. If you look at the currently in progress RFC, https://tools.ietf.org/html/draft-ietf-doh-dns-over-https-04 , this is quite literally the only difference. The DNS request is encoded as a standard serialized DNS packet. The article mentions QUIC as being…

One of the use cases for DNS-over-HTTPS given in the draft was to allow web applications access to DNS directly via existing browser APIs.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#203

Earlier quoted context omitted.

>"Now, audits are generally not worth very much (even, perhaps even especially, from a Big Four group like KPMG)" Indeed, see the recent KPMG scandal: https://www.marketwatch.com/story/kpmg-indictment-suggests-m...

Seems we need an auditor auditor.

Quis custodiet ipsos custodes?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#204

My FAI, Orange in France, seems to block/redirect acces to https://1.1.1.1 , i see great irony here. Chrome security warning when i try to access it, ping <1ms when ping ip adress.

It's very likely that they have 1.1.1.1 in their "bogons" list and have for a very long time.

Bogons are a list of prefixes that most ISPs blackhole as there is usually never any legitimate traffic bound for those destinations. RFC1918 addresses, for example.

I can't reach 1.1.1.1 either, but 1.0.0.1 works fine. Maybe try that.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#205
post #3

This is the Cloudflare resolver, right? What's the "privacy-first" part about? It's just another third party DNS host. They haven't changed the protocol to be uninspectable and AFAIK haven't made any guarantees about logging or whatnot that would enhance privacy vs. using whatever you are now. This just means you're trusting Cloudflare instead of Comcast or Google or whoever.

"We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say." Now, audits are generally not worth very much (even, perhaps even especially, from a Big Four group like KPMG), but for this type of thing (verifying that a company isn't doing something they promised they would not do) th…

Worth noting they have already edited the article (less than 2hours later) and taken out the "We will never log your IP" bit...

"We committed to never writing the querying IP addresses to disk and wiping all logs within 24 hours."

"While we need some logging to prevent abuse and debug issues, we couldn't imagine any situation where we'd need that information longer than 24 hours. And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would."

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#206
post #170

Earlier quoted context omitted.

You're just trying to make Australians jealous aren't you? ping 1.1.1.1 Reply from 1.1.1.1: bytes=32 time=366ms TTL=58 Reply from 1.1.1.1: bytes=32 time=366ms TTL=58 Reply from 1.1.1.1: bytes=32 time=365ms TTL=58 Reply from 1.1.1.1: bytes=32 time=365ms TTL=58 ping 8.8.8.8 Reply from 8.8.8.8: bytes=32 time=402ms TTL=59 Reply from 8.8.8.8: bytes=32 time=373ms TTL=59 Reply from 8.8.8.8: bytes=32 time=373ms TTL=59 Reply…

I'm getting ~40-50ms on both on Internode from Brisbane.

Australia, LOL.

You guys are 100ms from anywhere cool.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#207

DNS-over-HTTPS doesn’t make as much sense to me as DNS-over-TLS. They are effectively the same thing, but HTTPS has the added overhead of the HTTP headers per request. If you look at the currently in progress RFC, https://tools.ietf.org/html/draft-ietf-doh-dns-over-https-04 , this is quite literally the only difference. The DNS request is encoded as a standard serialized DNS packet. The article mentions QUIC as being…

rfc 8336. h2 coalescing. h2 push. caching. it starts to add up to a very interesting story.

Thank you for responding, Patrick. As one of the authors of the RFC, your views on this are a great contribution to the conversation.

> rfc 8336

I'll have to read up on this, thanks for the link.

> h2 coalescing

DNS is already capable of using TCP/TLS (and by it's nature UDP) for multiple DNS requests at a time. Is there some additional benefit we get here?

> h2 push

This one is interesting, but DNS already has optimizations built in for things like CNAME and SRV record lookups, where the IP is implicitly resolved when available and sent back with the original request. Is this adding something additional to those optimizations?

> caching

DNS has caching built-in, TTLs on each record. Is there something this is providing over that innate caching built into the protocol?

> it starts to add up to a very interesting story.

I'd love to read about that story, if someone has written something, do you have a link?

Also, a question that occurred to me, are we talking about the actual website you're connecting to being capable of preemptively passing DNS resolution to web clients over the same connection?

Thanks!

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#209

DNS-over-HTTPS doesn’t make as much sense to me as DNS-over-TLS. They are effectively the same thing, but HTTPS has the added overhead of the HTTP headers per request. If you look at the currently in progress RFC, https://tools.ietf.org/html/draft-ietf-doh-dns-over-https-04 , this is quite literally the only difference. The DNS request is encoded as a standard serialized DNS packet. The article mentions QUIC as being…

1.1.1.1 does support DNS-over-TLS as well: https://developers.cloudflare.com/1.1.1.1/dns-over-tls/

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#210
post #179

Earlier quoted context omitted.

Hiding DNS traffic from your ISP is pointless when you have to give them the IP that gets resolved anyway for them to route your traffic.

Not really. Typically the query includes much more information (the site you want to visit) than the response (an IP potentially shared by thousands or millions of sites).

You're still leaking that information due to SNI.
Post reply on HN