Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

361–370 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#361

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

Keep in mind that ping time isn't the only factor in DNS lookup speed. For me (sonic.net in Palo Alto): ping 1.1.1.1: ~22ms ping 8.8.8.8: ~19ms dig @1.1.1.1: ~45ms dig @8.8.8.8: ~70ms Disclaimer: Eyeballed averages over a few samples. A more rigorous test of DNS lookup times would be cool to see. Disclosure: I work for Cloudflare, but not on DNS.

So logging accounts for 25ms ;)

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#363

Earlier quoted context omitted.

That does not change the the fact that Cloudflare is insinuating something something about Google's DNS.

Is the suggestion that a company whose main business is targeting ads based on collecting data about you might be collecting data about you an unfair insinuation?

Please follow the thread - the question of whether an insinuation if "fair" is not what's being discussed. What's being discussed is whether or not Cloudflare said or insinuated that there were privacy concerns with using 8.8.8.8.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#364

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

Keep in mind that ping time isn't the only factor in DNS lookup speed. For me (sonic.net in Palo Alto): ping 1.1.1.1: ~22ms ping 8.8.8.8: ~19ms dig @1.1.1.1: ~45ms dig @8.8.8.8: ~70ms Disclaimer: Eyeballed averages over a few samples. A more rigorous test of DNS lookup times would be cool to see. Disclosure: I work for Cloudflare, but not on DNS.

how are you pinging 8.8.8.8?

EDIT: nevermind - mistake on my end!

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#365

This is bad, bad, bad advice. You don't set the DNS on your local machine. That breaks things. The DNS needs to be set at the gateway. If you change your PC/mac's DNS to an external service, you won't be able to resolve any addresses on the local network. Come on, CloudFlare. You guys know better than that. Please stop breaking the (local) internet.

Why not just use avahi-daemon?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#366

Thought this was an April Fool joke at first. Queries are jumping anywhere from 10ms to 138ms compared to a flat 6ms on Google and OpenDNS in Australia. Maybe unexpected traffic?

I thought so too, especially the emphasis on April 1. But I'm not sure what the joke is.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#368
post #242

Earlier quoted context omitted.

No it wouldn't. They're both encrypted with the same method so they can't tell whether http is used or not.

Sorry, confused. Https requests are prolific, while encrypted DNS requests aren't. Why isn't the former less hard to detect?

Perhaps if the attacker filters traffic first by protocol, it's harder but not at all impossible. I'd guess that DNS-over-HTTPS packets won't be hard to identify by other means.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#369

My FAI, Orange in France, seems to block/redirect acces to https://1.1.1.1 , i see great irony here. Chrome security warning when i try to access it, ping <1ms when ping ip adress.

My AT&T fiber is blocking 1.1.1.1, too. But 1.0.0.1 is working.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#370

Earlier quoted context omitted.

Ordinary users don't have anything that resolves to local IPs, so this is a non-issue for just about anybody. Plus, many if not most ISP-provided modem-router-AP-boxes don't let you configure the DNS server they use, making your recommendation impossible to follow for most users. Someone who runs services on their local network likely knows enough to do as you say, but for 99% of people, these instructions are exactl…

Most people own printers and other devices that use local DNS. Don’t presume that joe public is a simpleton. Millions of people are not.

Zeroconf (Avahi/Bonjour) takes care of making that wireless printer work regardless of which DNS server you’re using.

I’m not insinuating that “joe public” is dumb. He just doesn’t need to care about DNS on his local network, there’s software that handles it for him.

Post reply on HN