Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

411–420 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#411

Too bad this was announced on 1st of April.

They state why they picked April 1, aka 4/1:

From the article: The only question that remained was when to launch the new service? This is the first consumer product Cloudflare has ever launched, so we wanted to reach a wider audience. At the same time, we're geeks at heart. 1.1.1.1 has 4 1s. So it seemed clear that 4/1 (April 1st) was the date we needed to launch it.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#412
> Through the project we protect groups like LGBTQ organizations targeted in the Middle East, journalists covering political corruption in Africa, human rights workers in Asia, and bloggers on the ground covering the conflict in Crimea.

And in occident? Do they protect MRAs and Christians?

I love how their view of political targeting is limited to what the West wants to impose to all countries. Yet, the organization “A Voice For Men” was flagged as hate speech for funding the movie The Red Pill (2016), the most censored movie of 2017 in occident. If they haven’t identified them as political oppression victims, they don’t know much about Free Speech.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#414

Does Windows/all my devices support DNS-over-HTTPS (or TLS) right now? I.e. if I set everything to use 1.1.1.1, will all my devices know to use the secure protocols, or will it be regular old unsecure DNS?

Your best bet would be to configure your own DNS server (on your router, for example, assuming support) to use DNS-over-(HTTPS|TLS) and then have all of your other devices use your router as their DNS server.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#415

Earlier quoted context omitted.

Yup, the Subject Alternative Name (often misunderstood as an alias, but "Alternative" here is meant in the sense of this is the Internet's _Alternative_ way to name things versus the X.500 series directory hierarchy that the X.509 certificates are originally intended for) can be one of several distinct types, the two relevant for servers are dnsName and ipAddress. dnsName can be any er, name, in the DNS hierarchy, or…

Thanks for the clarification. I did know it was possible when setting up CA's for VPN servers, they can use certificates with DNS and/or IP as identifiers. Somehow I never thought about certificates for public IP addresses.

FWIW, until a few years ago, it was also possible to get certificates for private IP addresses (and "private" hostnames, such as .local).

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#418

>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…

This has not been the only incident of them having turned a “blind eye” or doing things that were questionable.

1. They looked the other way when 100+ million of public money was laundered out of South Africa.

2. The scheme literally stole money destined to uplift poor rural communities

3. To top it off, a portion of the money was used to write of an extravagant wedding as a business expense.

4. When a junior auditor raised his concerns about the audit he was shut down.

http://amabhungane.co.za/article/2017-06-29-guptaleaks-the-d...

http://amabhungane.co.za/article/2017-06-30-guptaleaks-the-d...

http://amabhungane.co.za/article/2017-11-26-guptaleaks-kpmg-...

6. They put out false reports that were partly used as motivation to get rid of ministers fighting corruption.

https://www.timeslive.co.za/politics/2017-09-15-kpmg-cans-sa...

KPMG were not the only multinational firm that were complicit in fleecing the South African tax payer of billions. See

Mckinsey:

http://amabhungane.co.za/article/2017-09-14-how-mckinsey-and...

SAP: http://amabhungane.co.za/article/2017-07-24-guptaleaks-anoth...

T-systems:

http://amabhungane.co.za/article/2017-11-14-exclusive-gupta-...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#419

From someone that takes DNS for granted every day, can someone shed some light on why the current state of DNS has been called archaic and needs to be replaced with something better?

one reason: https://www.ietf.org/proceedings/99/slides/slides-99-maprg-f...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#420

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

I assume a cable modem adds at least 8ms of latency, because I get 8ms of latency to my default router, and about 12-15ms to any of those hosts.
Post reply on HN