Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

481–490 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#481
My main problem with these DNS services is that they often break gated wifi networks that require a login page to access. It's horrible that it has become standard practice to take over DNS to redirect to a access gate — but as users, your choices are either: suck it up, or no internet.

Does anyone have a better solution for this?

(Also — why no IPv6 DNS?)

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#482
post #429

Earlier quoted context omitted.

Agreed. Anecdotal but... We have had to supply information to KPMG “IT Auditors” at a client due to some software we wrote. In most cases the auditors are young grads who have never worked in an actual IT/software dev team. So they have very naive view and never ask the right questions. If one wanted to hide something it would be super easy.

Audits provide reasonable assurance, not total. When auditors test access controls for a homegrown application for example, it is unreasonable to ask that a full code review is done to check 100% that checking the box next to Admin confers that, and that checking Read Only restricts it always. In my experiences performing these tests (as a young grad who had never worked on a software dev team), we would ask what the…

The audit checks your documented procedures, not your actual practices.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#483

Earlier quoted context omitted.

So, you're implying things here that I'll address with an H. L. Mencken quote, >"The trouble with fighting for human freedom is that one spends most of one's time defending scoundrels. For it is against scoundrels that oppressive laws are first aimed, and oppression must be stopped at the beginning if it is to be stopped at all."

"A witty saying proves nothing." - Voltaire Universal free speech is not laudable, it's suicidal. If your free speech doesn't protect you from those who want to take it away, they will win, on a long enough time horizon. They only need to win once.

Wow. I can't tell if you're trying to be funny by being meta or you just don't realize what you just said applies to your very argument. Lets break it down.

You want to protect free speech by taking it away because if you don't then someone might use free speech to take away free speech.

First, speech is not an action that can violate your rights. Sticks and stones, etc. And no, just because communication can help organize your political opposition does not mean the speech itself is violating your rights. Actions and legislation do that.

Second, deciding that some things are allowed and some aren't and then enforcing those arbitrary decisions through violence by the state certainly can violate those rights. And and gets easier and more every time.

I suppose you think that limited free speech is a thing that can persist. I strongly disagree. The idea of universe free speech is because any attempt to regulate leads to the loss of all of it fairly quickly if not instantly; they only need to win once. It exists to protect opinions that are disliked by most if not all.

I see your argument is basically that if free speech allows for speech that supports the idea of not allowing free speech then it will fail. And that may be true. That's why constant villigance is required even, especially, when they try to use people who's opinion almost everyone hates to justify it. There is no final solution.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#484

>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…

> to audit our code and practices annually and publish a public report confirming we're doing what we said we would

Some exec to developer: Hey John, KPMG wrote to us that they will be here on friday to make an audit, lets just remove those 10 lines that until audit finishes.

I don't want to imply anything about Cloudflare here, just a comment about how useful that kind of private audits are generally.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#485

Earlier quoted context omitted.

>"Fees earned for the bank were accidental and usually nonexistent," "Approximately 85,000 of the accounts opened incurred fees, totaling $2 million. Customers' credit scores were also likely hurt by the fake accounts.[43] The bank was able to prevent customers from pursuing legal action as the opening of an account mandated customers enter into private arbitration with the bank." "The bank paid $110 million to consu…

I'm pretty confident that when 85,000 out of "more than a million" accounts earn fees, it's fair to say that fees are "usually nonexistent". You're talking about accounts that Wells Fargo didn't want and fees that it assessed by mistake. By a normal analysis, that wouldn't be a scandal of any kind, and it would call for no more than returning the accidental fees, without a 55x punitive damages award. > "The bank was…

The arbitration clause is an overarching thing. The customer agrees to it when they legitimately open an account. It covers the entire banking relationship between that customer and the bank. Which is why Wells was able to use it to prevent litigation from their existing customer over the fraudulent accounts.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#486

"Visit https://1.1.1.1/ from any device to get started with the Internet's fastest, privacy-first DNS service." When I try, my browser tells me: Bad cert ident from 1.1.1.1: dNSName=*.cloudflare-dns.com cloudf: accept? (y or n)

I get ERR_CONNECTION_REFUSED

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#487

Earlier quoted context omitted.

Some ISPs block outbound DNS from customers to anywhere but their resolvers, filtering based on target port. This is a particularly common trick in countries that attempt to censor the internet. It's a lot harder to do that with DNS-over-HTTPS because it looks like normal traffic. That said, in this case ISPs can just null route the IP address of the obvious main resolvers such as 1.1.1.1. I imagine most of the benef…

I suppose there is also domain fronting [1], but it won't be fast or an easy-to-remember IP address anymore. And if you need that, you might need a VPN anyway? [1] https://en.wikipedia.org/wiki/Domain_fronting

It's amazing that governments haven't shut down shared domains to prevent domain-frontong.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#488

>"And we wanted to put our money where our mouth was, so we committed to retaining KPMG, the well-respected auditing firm, to audit our code and practices annually and publish a public report confirming we're doing what we said we would." It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accou…

>It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accounts and 560,000 credit card applications for customers without their knowledge or approval.[1]

Why is it worth point out? Please detail the work you've done in establilshing that KPMG had access to the data and willfully ignored it.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#489

Earlier quoted context omitted.

Genuinely asking, what are some companies that would be a good choice for this sort of thing?

Many privacy activists believe that the best proof of a no-logging assertion is for a court to order a provider to turn over logs and for the company to be unable to do so.

Isn't the court system mostly powered by the threat of serious jail time if you're found to be lying, and penalties for your lawyers, too?

If you say "We don't have those logs," and you swear to it and a lawyer puts their name on the filing, it's not like Judge Alsup will start pentesting your company to find the one employee who accidentally has Dropbox pointed at an sftp mount of some production server.

Post reply on HN