1.1.1.1: Fast, privacy-first consumer DNS service
321–330 of 695 posts
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#322Earlier quoted context omitted.
Do you think that ~23ms is going to make any real, perceptible difference to your internet performance? Considering that a) your browser will make any DNS requests it needs in parallel when loading a web page, and b) most DNS requests will be cached anyway.
Yes, absolutely. I'm not sure what you meant in point (a) but, of course, DNS cannot be parallelized with HTTP since the browser doesn't know where to connect until DNS completes. Also, DNS requests for subresources can't start until the referring resource has been loaded. So you could easily see a few serialized DNS requests in the long pole for loading a web site. Also note that the timing above were ping times. An…
I meant that DNS requests are parallelized within the browser. Once it loads the initial resource (html), there might be 10 more dependencies it needs at various different URLs under different domain names. It's usually loading all these dependencies that make up the vast majority of the load time on a complex web page.
Those subsequent DNS requests can of course be made in parallel, so if your DNS latency is 20ms then you're adding ~20ms, not 10 x 20ms.
Even then, DNS is probably making up a small fraction of the overall load time. If a complex page is taking, say, 3000ms to load and render, then adding 20-40ms of DNS time is not going to make a perceptible difference.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#323Earlier quoted context omitted.
There's a pretty big difference between terminating a business relationship (which is what Cloudflare did to Daily Stormer, and which Google also did a couple days before Cloudflare did) and refusing to answer DNS queries for third-party domains with which there is no business relationship. It's hard to imagine how the former could be used as precedent to compel the latter. Cloudflare has no interest in censorship --…
I probably should have made a clearer point instead of linking to TorrentFreak. I did not mean that I was worried that CloudFlare's DNS would start blocking sites whose content they disagree with (although that would also be worrisome). I'm worried that copyright holders might be able to use the Daily Stormer case as a precedent to force CloudFlare to stop offering services to infringing sites. If they are able to do…
I'm not a lawyer, though.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#324Earlier quoted context omitted.
Bear in mind, they dropped Daily Stormer because they were claiming Cloudflare agreed with their ideology. Which someone in the previous discussion pointed out was a Terms of Service violation. DNS resolving offers no such terms and no such reason to make such a claim. I don't see that playing here. And bear in mind, when the CEO did it, he wrote about how dangerous it was that companies had that power. I don't feel…
Cloudflare is a private company and they're free to do what they want but their reasoning for the Daily Stormer termination felt like a convenient excuse to me. I'm sure that it was the best business decision for them but when I read a blog post touting 1.1.1.1 as being anti-censorship, I roll my eyes. Anti-censorship so long as Matthew Prince doesn't have a bad morning. I run my own DNS-over-TLS resolver at a truste…
I think it's great if people are running their own DNS. :) But I'm certainly not mad that Cloudflare's offering yet another public alternative. As I said, more choices is better.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#325Sorry, but I don't trust Cloudflare with anything anymore.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#326Earlier quoted context omitted.
Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…
If you are on ethernet, I am able to get 1-2ms pings. On same AT&T Fiber Gigabit. Wifi ruins both bandwidth and latency for me.
On a Unifi nano hd, with moderate signal, my latency only goes up 1ms.
Getting ~3.5 ms on wifi to 1.1.1.1, ~2.5ms ethernet
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#327Earlier quoted context omitted.
Bear in mind, they dropped Daily Stormer because they were claiming Cloudflare agreed with their ideology. Which someone in the previous discussion pointed out was a Terms of Service violation. DNS resolving offers no such terms and no such reason to make such a claim. I don't see that playing here. And bear in mind, when the CEO did it, he wrote about how dangerous it was that companies had that power. I don't feel…
>because they were claiming Cloudflare agreed with their ideology. That was a lie. It was a commenter on an article.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#328But will it report your DNS lookups to the authorities if Cloudflare's CEO wakes up one morning and decides he doesn't like you? Sorry, but I don't trust Cloudflare with anything anymore.
This doesn't answer whether or not cloudflare will be able to protect against someone intercepting their traffic and recording dns lookups independently, but that's a problem for any dns provider.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#329Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#330Earlier quoted context omitted.
Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…
If you are on ethernet, I am able to get 1-2ms pings. On same AT&T Fiber Gigabit. Wifi ruins both bandwidth and latency for me.