Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

431–440 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#432

For the Cloudflare folks hanging around: Please, please, please add some basic "features" (like Google does) that will help when troubleshooting resolution! For example, the following will show the unicast IP address of the server you're hitting when using 8.8.8.8: $ dig @8.8.8.8 txt o-o.myaddr.l.google.com. +short Additionally, with one other DNS query, we can get a list of what netblocks are being used (for Google…

[deleted]

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#434
post #285
post #250

Earlier quoted context omitted.

Is there a thing like this for macOS?

This will run fine under Wine on macOS. Steve has said many times on the SN podcast that he tests under Wine to ensure compatibility.

To the downvoters: perhaps a source will placate you: https://www.grc.com/sn/sn-641.htm (search for WINE). I apologize for providing facts that might help someone that wants to run this.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#435

>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…

KPMG was also implicated in the massive South African "state capture" scandal involving the (now fugitive) Gupta family and former president Jacob Zuma.

Among other things, KPMG issued a-later withdrawn-report that was used to undermine the well-respected finance minister, so that a more malleable person could be installed, while also auditing the Guptas during their worst excesses.

Lest we choose to dismiss this as crimes in an insignificant country, KPMG SA has been part of the worldwide group since the 70's, and South Africa's supposedly high auditing standards were a source of national pride.

The story seems to have gone dead after some senior leaders fell on their swords, but six months ago, there was serious talk about the firm being shut down in South Africa.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#436

From someone that takes DNS for granted every day, can someone shed some light on why the current state of DNS has been called archaic and needs to be replaced with something better?

It basically comes down to being insecure. It's all plain-text over UDP. This is easily exploited for various purposes: spoofing (DDoS attacks), surveillance (such as by ISPs), hijacking/tampering, censorship, privacy concerns, and so on. As everything else relies on DNS, the DNS must also be secure.

Are there replacement options being worked on? What about wrapping each request and unwrapping on the other end. Something like how Tor wraps requests in many layers?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#437

Here are instructions for testing DoH (DNS-over-HTTPS) in Firefox Nightly: https://gist.github.com/mcmanus/766a9564a51325b6543644983539...

Unfortunately, enabling DoH in Firefox Nightly causes a 100% reproducible macOS kernel panic for me! :(

https://bugzilla.mozilla.org/show_bug.cgi?id=1450583

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#438

>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…

> the bank recently committed fraud on a massive scale by creating more than a million fake deposit accounts and 560,000 credit card applications for customers without their knowledge or approval. Suppose you were a Wells Fargo depositor and a Wells Fargo teller opened a fake account in your name without consulting you. What harm did you suffer? How massive is this fraud if you measure it in a more useful way than "n…

>"Suppose you were a Wells Fargo depositor and a Wells Fargo teller opened a fake account in your name without consulting you. What harm did you suffer?"

Are you joking? The fake accounts were set up in order to bilk customers out of money in the form of overdrafts fees and penalties.

"Some customers noticed the deception when they were charged unexpected fees, received credit or debit cards in the mail that they did not request, or started hearing from debt collectors about accounts they did not recognize. But most of the sham accounts went unnoticed, as employees would routinely close them shortly after opening them. Wells has agreed to refund about $2.6 million in fees that may have been inappropriately charged."[1]

It also probably impossible to quantify the time customers lost having to deal this. But I think it safe to say it was significant.

>"How massive is this fraud if you measure it in a more useful way than "number of accounts"

OK lets use dollar amounts as a metric - $2.6 million dollars in fees, levied against your own customers? And considering Well Fargo found an additional 1.4 million previously undisclosed fake accounts as recently as August[2] and that the regulatory probe has now widened beyond their retail banking unit and not includes their private wealth division I would say pretty fucking massive.

It's really interesting that you seek to trivialize the scope and severity of a story you seem to know so very little about.

[1] https://www.nytimes.com/2016/09/09/business/dealbook/wells-f...

[2] http://money.cnn.com/2017/08/31/investing/wells-fargo-fake-a...

[3] https://www.barrons.com/articles/federal-probe-expands-to-we...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#440

For the Cloudflare folks hanging around: Please, please, please add some basic "features" (like Google does) that will help when troubleshooting resolution! For example, the following will show the unicast IP address of the server you're hitting when using 8.8.8.8: $ dig @8.8.8.8 txt o-o.myaddr.l.google.com. +short Additionally, with one other DNS query, we can get a list of what netblocks are being used (for Google…

I think i have questions to Google:

  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.8"
  "edns0-client-subnet 92.223.114.166/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.11"
  "edns0-client-subnet 176.36.247.0/24"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.74.3"
  "edns0-client-subnet 94.181.44.185/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.46.8"
  "edns0-client-subnet 92.223.114.166/32"
  [user@v-fed-1 ~]$ dig txt o-o.myaddr.l.google.com @8.8.8.8 +short
  "74.125.74.3"
  "edns0-client-subnet 94.181.44.185/32"
Post reply on HN