Earlier quoted context omitted.
Even with https, the name of the site is sent in clear when the connection to the site is established (this is SNI).
Back when they chose this design for SNI, I’m sure someone argued that it was fine because DNS had already leaked the hostname anyway :)
1.1.1.1: Fast, privacy-first consumer DNS service
561–570 of 695 posts
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#562Earlier quoted context omitted.
what happens if you go to https://1.1.1.1 in a browser? It should have a valid TLS cert and have a big banner that says, among other things, "Introducing 1.1.1.1". If your ISP's CPE or anything else is fucking with traffic to that IP, it wont load/display that
I just get connection refused.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#563I wish that they talked a bit more about their stance regarding censorship. They have a small paragraph talking about the problem, but they don't talk about the "solution". While Cloudflare has been pretty neutral about censoring sites in the past (notably, pirate sites), the Daily Stormer incident put them in a though spot[1]. They talk a bit about Project Galileo (the link is broken BTW, it should be https://www.cl…
There's a pretty big difference between terminating a business relationship (which is what Cloudflare did to Daily Stormer, and which Google also did a couple days before Cloudflare did) and refusing to answer DNS queries for third-party domains with which there is no business relationship. It's hard to imagine how the former could be used as precedent to compel the latter. Cloudflare has no interest in censorship --…
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#564Earlier quoted context omitted.
There is no DNS involved when you're connecting directly to an IP address
Unless you tell it not to, ping will try a reverse lookup on the IP you are pinging in order to display that to you in the output. It's a good idea to keep that in mind when you ping something, especially if you notice the first ping is abnormally slow.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#565Definitely not what I was expecting...
CloudFlare:
$ ping -c 240 -i 0.25 1.1.1.1
...
--- 1.1.1.1 ping statistics ---
240 packets transmitted, 240 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 16.271/17.286/25.105/1.236 ms
Google Public DNS: $ ping -c 240 -i 0.25 8.8.8.8
...
--- 8.8.8.8 ping statistics ---
240 packets transmitted, 240 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 5.092/10.083/35.949/2.426 ms
OpenDNS: $ ping -c 240 -i 0.25 208.67.222.222
...
--- 208.67.222.222 ping statistics ---
240 packets transmitted, 240 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 8.596/9.847/25.898/1.788 ms
Level 3: $ ping -c 240 -i 0.25 4.2.2.2
...
--- 4.2.2.2 ping statistics ---
240 packets transmitted, 240 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 8.479/9.563/18.971/1.336 ms
Comcast's Resolver: $ ping -c 240 -i 0.25 75.75.75.75
...
--- 75.75.75.75 ping statistics ---
240 packets transmitted, 240 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 8.410/9.717/19.428/1.487 ms
It even looks like OpenDNS and Level 3 are better than Google Public DNS in terms of latency.Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#566Earlier quoted context omitted.
It's a private organization with no monopoly and lots of competition. Free speech doesn't apply here. Also Cloudflare gets vastly more negative opinions that they don't check enough and serve too many unsavory sites so it seems there's no way to win with the HN crowd.
It set the precedent that they do filtering. It is now being used in legal cases against Cloudflare by companies suing them to force them to filter other things. Any censorship immediately leads to massive censorship even if they don't want to expand it. That's why it has to be stopped at the start; not done at all. Dumb pipe or censorship pipe.
Cloudflare also specifically removed that site for a stated reason that they claimed CF was helping them. That is outside the bounds of the site content itself and is a perfectly fine argument to stop doing business based on libel and misrepresentation.
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#567Earlier quoted context omitted.
If you are on ethernet, I am able to get 1-2ms pings. On same AT&T Fiber Gigabit. Wifi ruins both bandwidth and latency for me.
AT&T Fiber Gigabit in Nashville TN. iMac ~ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=64 time=0.688 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=64 time=0.814 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=64 time=1.153 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=64 time=0.752 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=64 time=0.755 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=64 time=0.789…
Re: 1.1.1.1: Fast, privacy-first consumer DNS service
#568Timeout from Shanghai, China on China Unicom. Pinging 1.1.1.1 with 32 bytes of data: Request timed out. Request timed out. Request timed out. Request timed out. Ping statistics for 1.1.1.1: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
PING 1.1.1.1 (1.1.1.1): 56 data bytes
64 bytes from 1.1.1.1: icmp_seq=0 ttl=53 time=188.730 ms
64 bytes from 1.1.1.1: icmp_seq=1 ttl=53 time=178.453 ms
64 bytes from 1.1.1.1: icmp_seq=2 ttl=53 time=179.869 ms
64 bytes from 1.1.1.1: icmp_seq=3 ttl=53 time=177.808 ms
Google : PING 8.8.8.8 (8.8.8.8): 56 data bytes
Request timeout for icmp_seq 0
64 bytes from 8.8.8.8: icmp_seq=1 ttl=42 time=58.368 ms
Request timeout for icmp_seq 2
Request timeout for icmp_seq 3
Request timeout for icmp_seq 4
64 bytes from 8.8.8.8: icmp_seq=5 ttl=42 time=51.636 ms
64 bytes from 8.8.8.8: icmp_seq=6 ttl=42 time=55.772 ms
Request timeout for icmp_seq 7
64 bytes from 8.8.8.8: icmp_seq=8 ttl=42 time=42.365 ms
64 bytes from 8.8.8.8: icmp_seq=9 ttl=42 time=45.782 ms
Cloudflare seems more stable hereRe: 1.1.1.1: Fast, privacy-first consumer DNS service
#569Earlier quoted context omitted.
what happens if you go to https://1.1.1.1 in a browser? It should have a valid TLS cert and have a big banner that says, among other things, "Introducing 1.1.1.1". If your ISP's CPE or anything else is fucking with traffic to that IP, it wont load/display that
I just get connection refused.