For the Cloudflare folks hanging around: Please, please, please add some basic "features" (like Google does) that will help when troubleshooting resolution! For example, the following will show the unicast IP address of the server you're hitting when using 8.8.8.8: $ dig @8.8.8.8 txt o-o.myaddr.l.google.com. +short Additionally, with one other DNS query, we can get a list of what netblocks are being used (for Google…
1.1.1.1: Fast, privacy-first consumer DNS service
401–410 of 695 posts
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#402Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#403Earlier quoted context omitted.
"We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say." Now, audits are generally not worth very much (even, perhaps even especially, from a Big Four group like KPMG), but for this type of thing (verifying that a company isn't doing something they promised they would not do) th…
Worth noting they have already edited the article (less than 2hours later) and taken out the "We will never log your IP" bit... "We committed to never writing the querying IP addresses to disk and wiping all logs within 24 hours." "While we need some logging to prevent abuse and debug issues, we couldn't imagine any situation where we'd need that information longer than 24 hours. And we wanted to put our money where…
[1] https://blog.cloudflare.com/announcing-1111/ [2] https://1.1.1.1
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#404 PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
64 bytes from 1.1.1.1: icmp_seq=1 ttl=57 time=11.6 ms
64 bytes from 1.1.1.1: icmp_seq=2 ttl=57 time=11.2 ms
64 bytes from 1.1.1.1: icmp_seq=3 ttl=57 time=10.8 ms
64 bytes from 1.1.1.1: icmp_seq=4 ttl=57 time=11.1 ms
64 bytes from 1.1.1.1: icmp_seq=5 ttl=57 time=10.9 ms
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=57 time=15.0 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=57 time=15.9 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=57 time=15.1 ms
64 bytes from 8.8.8.8: icmp_seq=4 ttl=57 time=15.0 ms
64 bytes from 8.8.8.8: icmp_seq=5 ttl=57 time=15.1 ms
FTTC, southern EU.Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#405>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#406And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#407And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…
Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…
$ ping 1.1.1.1
PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
64 bytes from 1.1.1.1: icmp_seq=1 ttl=56 time=10.8 ms
64 bytes from 1.1.1.1: icmp_seq=2 ttl=56 time=11.3 ms
64 bytes from 1.1.1.1: icmp_seq=3 ttl=56 time=10.7 ms
64 bytes from 1.1.1.1: icmp_seq=4 ttl=56 time=10.9 ms
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=60 time=10.7 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=60 time=11.3 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=60 time=11.1 ms
64 bytes from 8.8.8.8: icmp_seq=4 ttl=60 time=10.5 msRe: 1.1.1.1: Fast, privacy-first consumer DNS service
#408>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…
Suppose you were a Wells Fargo depositor and a Wells Fargo teller opened a fake account in your name without consulting you. What harm did you suffer?
How massive is this fraud if you measure it in a more useful way than "number of accounts"?
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#409Earlier quoted context omitted.
Not surprising: Google despite being blocked in China a lot of presumably expensive paid transit from the big 3 mainland china telcos in and out of the mainland to Hong Kong. Cloudflare serves sites visited from China that aren't using their China-requires-an-ICP-license service from their west coast USA location where the big 3 Chinese telcos will peer for free.
Peer for free? Anything to back that up because I doubt that highly? Maybe DTAG and UPC will peer for free in mighty LA as well. /s
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#410EDIT: Looks like this might be an issue w/ my AT&T-provided CPE, sorry! (more details at the bottom) From my vantage point, 1.1.1.1 is inaccessible, while 1.0.0.1 seems to work just fine. Comments on the blog post blame this on "various reasons" but, at least in my case, this seems to be a Cloudflare issue: $ ping -c 5 -q 1.0.0.1 PING 1.0.0.1 (1.0.0.1) 56(84) bytes of data. --- 1.0.0.1 ping statistics --- 5 packets t…
I have ATT and seeing the same issues, but my tracert is different. tracert 1.1.1.1 Tracing route to 1dot1dot1dot1.cloudflare-dns.com [1.1.1.1] over a maximum of 30 hops: 1 1 ms 1 ms 1 ms 1dot1dot1dot1.cloudflare-dns.com [1.1.1.1] tracert 1.0.0.1 Tracing route to 1dot1dot1dot1.cloudflare-dns.com [1.0.0.1] over a maximum of 30 hops: 1 3 ms [12.122.132.121] 8 27 ms 24 ms 28 ms ae16.cr7-chi1.ip4.gtt.net [173.241.128.29]…
Yep, exactly. Using 1.0.0.1, everything works. Using 1.1.1.1, nothing (ping, DNS, HTTPS) does.
EDIT: See earlier comment; looks like an issue w/ the AT&T-provided CPE (5268AC).