Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

471–480 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#472
post #283

Earlier quoted context omitted.

Having dealt with KPMG recently (which I do at least once a year...), I would not expect to see the report. KPMG's risk department - the lawyers' lawyers - appears to be violently allergic to their customers disclosing any report to outside parties. Based on my experience you can get a copy, but first you and the primary customer need to submit some paperwork. And among the conditions you need to agree with is that y…

> KPMG's risk department - the lawyers' lawyers - appears to be violently allergic to their customers disclosing any report to outside parties. Isn't that the entire point of such an audit? To be able to present it to outside third-parties? For examples, Mozilla (CA/B) requires audits for root CAs. The CA must provide a link to the audit on the auditor's public web site -- forwarding a copy or hosting it on their own…

You'd think, but it's surprisingly difficult to get the real full audit report. Mozilla's root policy _does_ require that they be shown the report, and has a bunch of extra requirements in there to ensure they're more detail, rather than some summary or overview document the auditors were persuaded to produce for this purpose. But the CA/B rules would allow just an audit letter which basically almost always says "Yes, we did an audit, and everything is fine" unless the auditors weren't comfortable writing "everything is fine". And almost always they feel that a footnote on a sub-paragraph buried in a detailed report is enough to leave "everything is fine" as the headline in the letter...

If you've ever been audited for some other reason, you'll know they find lots of things, and then you fix them, and that's "fine". But well, is it fine? Or, should we acknowledge that they found lots of things and what those things were, even if you subsequently fixed them? The CA/B says you have several months to hand over your letter after the audit period. Guess what those months are spent doing...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#473

Earlier quoted context omitted.

If you are on ethernet, I am able to get 1-2ms pings. On same AT&T Fiber Gigabit. Wifi ruins both bandwidth and latency for me.

You should invest in some better wifi gear, it sounds like! On a Unifi nano hd, with moderate signal, my latency only goes up 1ms. Getting ~3.5 ms on wifi to 1.1.1.1, ~2.5ms ethernet

Out of curiosity, what is your complete Unifi / network setup?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#474

Earlier quoted context omitted.

I'm on Ethernet and fiber all the way. This may have to do more with how AT&T has constructed their fiber in this region. Where do you live? https://chrissnell.com/hn/traceroute-1.1.1.1.png

How did you get that beautiful traceroute output?

The GP is using mtr:

https://en.m.wikipedia.org/wiki/MTR_(software)

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#477
post #457

Earlier quoted context omitted.

Comcast in Northern NJ USA about 45 MI from NYC $ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data. 64 bytes from 1.1.1.1: icmp_seq=1 ttl=56 time=10.8 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=56 time=11.3 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=56 time=10.7 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=56 time=10.9 ms PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data. 64 bytes from 8.8.8.8: icmp_seq=1 ttl=60 time=10.7…

From a residential connection in New Zealand: $ ping 1.1.1.1 Pinging 1.1.1.1 with 32 bytes of data: Reply from 1.1.1.1: bytes=32 time=4ms TTL=60 Reply from 1.1.1.1: bytes=32 time=4ms TTL=60 Reply from 1.1.1.1: bytes=32 time=4ms TTL=60 Reply from 1.1.1.1: bytes=32 time=4ms TTL=60 $ ping 8.8.8.8 Pinging 8.8.8.8 with 32 bytes of data: Reply from 8.8.8.8: bytes=32 time=27ms TTL=60 Reply from 8.8.8.8: bytes=32 time=27ms T…

Four! I'm getting 14 from fibre in Wellington. Google are 35 ish.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#478

Earlier quoted context omitted.

This does not make sense. Either people are not concerned about hiding their traffic or if they are it follows they would be equally if not much more concerned about Google that can track them across devices and build far more indepth invasive profiles than the ISP. Aside it's strange https everywhere has been pushed aggressively by many here under the bogeyman of ISP adware and spying while completely ignoring the m…

Most fears of ISPs have been stoked primarily by tech companies, who invest a lot more money into marketing than the ISPs do.

I can only really discuss the UK, since that's the only place where I've bought home ISP service.

Only a handful of small specialist firms actually just move bits in the UK. Every single UK ISP big enough to advertise on television is signed up to filter traffic and block things for being "illegal" or maybe if Hollywood doesn't like them, or if they have "naughty" words mentioned, or just because somebody slipped. If you're thinking "Not mine" and it runs TV adverts then, oops, nope, you're wrong about that and have had your Internet censored without realising it. I wonder how ISPs got their bad reputation...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#479
"Cloudflare's 1.1.1.1 DNS will respond very fast, but the big sites you access, the whole reason for resolving DNS, will be SLOWER ∵ no edns-client-subnet support, so no geolocation of results." - https://twitter.com/philpennock/status/980561009961299968

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#480
post #418

>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…

This has not been the only incident of them having turned a “blind eye” or doing things that were questionable. 1. They looked the other way when 100+ million of public money was laundered out of South Africa. 2. The scheme literally stole money destined to uplift poor rural communities 3. To top it off, a portion of the money was used to write of an extravagant wedding as a business expense. 4. When a junior auditor…

Auditors are never "independent". They work for someone. If that someone is government or a client, great. If the auditor works for management, maybe OK for finding employee malfeasance, but no good for management malfeasance.

And of course, like tests, no audit can prove correctness, only can find flaws.

Post reply on HN