Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

561–570 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#561
post #212

Earlier quoted context omitted.

Even with https, the name of the site is sent in clear when the connection to the site is established (this is SNI).

Back when they chose this design for SNI, I’m sure someone argued that it was fine because DNS had already leaked the hostname anyway :)

A load balancer can chose the correct backend by using the SNI. So there is a use for being unencrypted.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#562
post #548

Earlier quoted context omitted.

what happens if you go to https://1.1.1.1 in a browser? It should have a valid TLS cert and have a big banner that says, among other things, "Introducing 1.1.1.1". If your ISP's CPE or anything else is fucking with traffic to that IP, it wont load/display that

I just get connection refused.

Call your ISP and ask them why they're blocking access to some websites. Ask them if there are any other websites they're blocking. Tweet about it. Etc

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#563
post #176

I wish that they talked a bit more about their stance regarding censorship. They have a small paragraph talking about the problem, but they don't talk about the "solution". While Cloudflare has been pretty neutral about censoring sites in the past (notably, pirate sites), the Daily Stormer incident put them in a though spot[1]. They talk a bit about Project Galileo (the link is broken BTW, it should be https://www.cl…

There's a pretty big difference between terminating a business relationship (which is what Cloudflare did to Daily Stormer, and which Google also did a couple days before Cloudflare did) and refusing to answer DNS queries for third-party domains with which there is no business relationship. It's hard to imagine how the former could be used as precedent to compel the latter. Cloudflare has no interest in censorship --…

[deleted]

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#564

Earlier quoted context omitted.

There is no DNS involved when you're connecting directly to an IP address

Unless you tell it not to, ping will try a reverse lookup on the IP you are pinging in order to display that to you in the output. It's a good idea to keep that in mind when you ping something, especially if you notice the first ping is abnormally slow.

That reverse lookup time is not counted in the first ping.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#565
From Comcast in San Francisco, I'm seeing that CloudFlare is the slowest of Google Public DNS, OpenDNS, Level 3, and Comcast's resolver.

Definitely not what I was expecting...

CloudFlare:

  $ ping -c 240 -i 0.25 1.1.1.1
  ...
  --- 1.1.1.1 ping statistics ---
  240 packets transmitted, 240 packets received, 0.0% packet loss
  round-trip min/avg/max/stddev = 16.271/17.286/25.105/1.236 ms
Google Public DNS:

  $ ping -c 240 -i 0.25 8.8.8.8
  ...
  --- 8.8.8.8 ping statistics ---
  240 packets transmitted, 240 packets received, 0.0% packet loss
  round-trip min/avg/max/stddev = 5.092/10.083/35.949/2.426 ms
OpenDNS:

  $ ping -c 240 -i 0.25 208.67.222.222
  ...
  --- 208.67.222.222 ping statistics ---
  240 packets transmitted, 240 packets received, 0.0% packet loss
  round-trip min/avg/max/stddev = 8.596/9.847/25.898/1.788 ms
Level 3:

  $ ping -c 240 -i 0.25 4.2.2.2
  ...
  --- 4.2.2.2 ping statistics ---
  240 packets transmitted, 240 packets received, 0.0% packet loss
  round-trip min/avg/max/stddev = 8.479/9.563/18.971/1.336 ms
Comcast's Resolver:

  $ ping -c 240 -i 0.25 75.75.75.75
  ...
  --- 75.75.75.75 ping statistics ---
  240 packets transmitted, 240 packets received, 0.0% packet loss
  round-trip min/avg/max/stddev = 8.410/9.717/19.428/1.487 ms
It even looks like OpenDNS and Level 3 are better than Google Public DNS in terms of latency.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#566

Earlier quoted context omitted.

It's a private organization with no monopoly and lots of competition. Free speech doesn't apply here. Also Cloudflare gets vastly more negative opinions that they don't check enough and serve too many unsavory sites so it seems there's no way to win with the HN crowd.

It set the precedent that they do filtering. It is now being used in legal cases against Cloudflare by companies suing them to force them to filter other things. Any censorship immediately leads to massive censorship even if they don't want to expand it. That's why it has to be stopped at the start; not done at all. Dumb pipe or censorship pipe.

No business is completely a dumb pipe, the DMCA provisions are very specific and are increasingly overruled once enough (copyrighted) content is in place.

Cloudflare also specifically removed that site for a stated reason that they claimed CF was helping them. That is outside the bounds of the site content itself and is a perfectly fine argument to stop doing business based on libel and misrepresentation.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#567

Earlier quoted context omitted.

If you are on ethernet, I am able to get 1-2ms pings. On same AT&T Fiber Gigabit. Wifi ruins both bandwidth and latency for me.

AT&T Fiber Gigabit in Nashville TN. iMac ~ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=64 time=0.688 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=64 time=0.814 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=64 time=1.153 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=64 time=0.752 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=64 time=0.755 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=64 time=0.789…

haha, I knew that was you when I read Nashville, nodesocket

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#568

Timeout from Shanghai, China on China Unicom. Pinging 1.1.1.1 with 32 bytes of data: Request timed out. Request timed out. Request timed out. Request timed out. Ping statistics for 1.1.1.1: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

In Shanghai, Jing'an with China Telecom Fiber

  PING 1.1.1.1 (1.1.1.1): 56 data bytes
  64 bytes from 1.1.1.1: icmp_seq=0 ttl=53 time=188.730 ms
  64 bytes from 1.1.1.1: icmp_seq=1 ttl=53 time=178.453 ms
  64 bytes from 1.1.1.1: icmp_seq=2 ttl=53 time=179.869 ms
  64 bytes from 1.1.1.1: icmp_seq=3 ttl=53 time=177.808 ms
Google :

  PING 8.8.8.8 (8.8.8.8): 56 data bytes
  Request timeout for icmp_seq 0
  64 bytes from 8.8.8.8: icmp_seq=1 ttl=42 time=58.368 ms
  Request timeout for icmp_seq 2
  Request timeout for icmp_seq 3
  Request timeout for icmp_seq 4
  64 bytes from 8.8.8.8: icmp_seq=5 ttl=42 time=51.636 ms
  64 bytes from 8.8.8.8: icmp_seq=6 ttl=42 time=55.772 ms
  Request timeout for icmp_seq 7
  64 bytes from 8.8.8.8: icmp_seq=8 ttl=42 time=42.365 ms
  64 bytes from 8.8.8.8: icmp_seq=9 ttl=42 time=45.782 ms
Cloudflare seems more stable here

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#569
post #548

Earlier quoted context omitted.

what happens if you go to https://1.1.1.1 in a browser? It should have a valid TLS cert and have a big banner that says, among other things, "Introducing 1.1.1.1". If your ISP's CPE or anything else is fucking with traffic to that IP, it wont load/display that

I just get connection refused.

I'm getting this on Comcast in Knoxville. https://1.0.0.1 works fine, and https://1.1.1.1 works on my phone if I turn off wifi.
Post reply on HN