Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

581–590 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#581
post #506

Earlier quoted context omitted.

My strong impression is that they wouldn't give APNIC any data that can be used to identify users of their DNS service, but I'd definitely love a more detailed answer than what the site currently provides.

Found this: https://labs.apnic.net/?p=1127

An excellent find!

> We will be destroying all “raw” DNS data as soon as we have performed statistical analysis on the data flow. We will not be compiling any form of profiles of activity that could be used to identify individuals, and we will ensure that any retained processed data is sufficiently generic that it will not be susceptible to efforts to reconstruct individual profiles. Furthermore, the access to the primary data feed will be strictly limited to the researchers in APNIC Labs, and we will naturally abide by APNIC’s non-disclosure policies.

So it's a 5 year research program, with options to extend it as a research program. To me, that means they intend to keep DNS data for up to 5 years (or longer) before performing statistical analysis and processing on it. Here is APNIC Labs's privacy policy http://labs.apnic.net/privacy.shtml and APNIC's privacy policy https://www.apnic.net/about-apnic/corporate-documents/docume...

So much for "privacy-first".

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#582
From Sydney

--- 1.1.1.1 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 10.536/13.084/19.910/3.284 ms

--- 8.8.4.4 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 10.931/15.141/32.453/6.498 ms

--- 1.0.0.1 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 10.219/16.709/29.498/6.960 ms

--- 9.9.9.9 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 10.290/22.336/43.267/10.238 ms

--- 208.67.222.222 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 12.985/22.786/46.929/10.036 ms

--- 208.67.220.220 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 16.273/27.225/49.783/10.246 ms

--- 8.8.8.8 ping statistics ---

100 packets transmitted, 100 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 10.581/35.527/125.641/33.204 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#583

Earlier quoted context omitted.

Beijing: PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=52 time=241.529 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=52 time=318.034 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=52 time=337.291 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=52 time=255.748 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=52 time=247.765 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=52 time=235.611 ms 64 bytes from 1.1.1.1: icmp_seq…

Australia :( 64 bytes from 1.1.1.1: icmp_seq=0 ttl=57 time=17.580 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=57 time=18.025 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=57 time=17.780 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=57 time=18.231 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=57 time=17.906 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=57 time=18.447 ms

Cambodia - crappy office wifi

  PING 1.1.1.1 (1.1.1.1): 56 data bytes
  64 bytes from 1.1.1.1: icmp_seq=0 ttl=59 time=22.806 ms
  64 bytes from 1.1.1.1: icmp_seq=1 ttl=59 time=23.321 ms
  64 bytes from 1.1.1.1: icmp_seq=2 ttl=59 time=24.379 ms
  64 bytes from 1.1.1.1: icmp_seq=3 ttl=59 time=25.869 ms
  64 bytes from 1.1.1.1: icmp_seq=4 ttl=59 time=24.485 ms
  64 bytes from 1.1.1.1: icmp_seq=5 ttl=59 time=24.165 ms

  PING 8.8.8.8 (8.8.8.8): 56 data bytes
  64 bytes from 8.8.8.8: icmp_seq=0 ttl=57 time=23.005 ms
  64 bytes from 8.8.8.8: icmp_seq=1 ttl=57 time=22.867 ms
  64 bytes from 8.8.8.8: icmp_seq=2 ttl=57 time=24.461 ms
  64 bytes from 8.8.8.8: icmp_seq=3 ttl=57 time=23.680 ms
  64 bytes from 8.8.8.8: icmp_seq=4 ttl=57 time=35.581 ms
  64 bytes from 8.8.8.8: icmp_seq=5 ttl=57 time=21.033 ms
  64 bytes from 8.8.8.8: icmp_seq=6 ttl=57 time=41.634 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#584
post #371

Earlier quoted context omitted.

What’s your threat model? The latency you’re going to introduce with TOR will make everyday browsing slow

It’s not like I’d be running everything over Tor. DNS requests for newly‐visited domains would slow down, but unbound’s prefetch feature would keep popular frequently‐used domains cached. Adding one of those advertising domain blacklists might help performance too. The point would be to keep Cloudflare from being able to track my DNS requests.

Why not use a VPN like PIA?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#585

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…

I’m getting similar ping times from my Digital Ocean droplet in one of their NYC data centers where my website is hosted:

    PING 1.1.1.1 (1.1.1.1): 56 data bytes

    --- 1.1.1.1 ping statistics ---
    10 packets transmitted, 10 packets received, 0.0% packet loss
    round-trip min/avg/max/stddev = 1.335/1.431/1.517/0.053 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#586

> We will never sell your data or use it to target ads. Period. Won't sell != Won't collect > We will never log your IP address (the way other companies identify you) Never log IP != Never log anything Bonus: The way other companies identify you ~= There are other ways Edit: Looks like many people assume I'm nitpicking. So here are more specific questions: * Is logging a hashcode of the IP considered as "not logging…

I'm fine with nitpicking. Let me try and be clear: We're not logging IPs. We inherently receive them when they connect to the service, but we don't write them to disk and flush them quickly (i.e., seconds or minutes). We're not logging hashes of IPs. We're not logging ASNs of the IPs connecting to the service. We do log the other parts of a DNS query in order to help prevent abuse and debug issues. However, we've com…

"... a crappy data sharing service."

Do you mean OpenDNS?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#587

Earlier quoted context omitted.

Beijing: PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=52 time=241.529 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=52 time=318.034 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=52 time=337.291 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=52 time=255.748 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=52 time=247.765 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=52 time=235.611 ms 64 bytes from 1.1.1.1: icmp_seq…

Australia :( 64 bytes from 1.1.1.1: icmp_seq=0 ttl=57 time=17.580 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=57 time=18.025 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=57 time=17.780 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=57 time=18.231 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=57 time=17.906 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=57 time=18.447 ms

Melbourne, Australia :)

   PING 1.1.1.1 (1.1.1.1): 56 data bytes
   64 bytes from 1.1.1.1: icmp_seq=0 ttl=60 time=5.044 ms
   64 bytes from 1.1.1.1: icmp_seq=1 ttl=60 time=6.447 ms
   64 bytes from 1.1.1.1: icmp_seq=2 ttl=60 time=6.371 ms
   64 bytes from 1.1.1.1: icmp_seq=3 ttl=60 time=6.308 ms
   64 bytes from 1.1.1.1: icmp_seq=4 ttl=60 time=7.317 ms
   64 bytes from 1.1.1.1: icmp_seq=5 ttl=60 time=5.989 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#588

Earlier quoted context omitted.

Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…

Ping from University of Rochester, over wifi: Cloudflare: 64 bytes from 1.1.1.1: icmp_seq=0 ttl=128 time=2 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=128 time=2 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=128 time=2 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=128 time=9 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=128 time=2 ms Google: 64 bytes from 8.8.8.8: icmp_seq=0 ttl=54 time=12 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=54 t…

Something interesting I saw pointed out on the reddit thread about this is the ttl between 1.1.1.1 and 8.8.8.8 is the ttl is way different.

Your pings also have the same thing showing up 128 vs 53. I tried on my laptop and get something simmilar. traceroute to 1.1.1.1 is 1 hop which is wrong. 1.0.0.1 shows a few hops.

`dig google.com @1.1.1.1` doesn't work for me.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#589

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…

> Residential customers won't see anything this fast.

The standard Comcast black-box router/modem I have has a mean ping of ~9ms, and a min of ~3ms, so yeah, I'd have to agree.

(I get ~28ms to 1.1.1.1.)

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#590
post #581
post #506

Earlier quoted context omitted.

Found this: https://labs.apnic.net/?p=1127

An excellent find! > We will be destroying all “raw” DNS data as soon as we have performed statistical analysis on the data flow. We will not be compiling any form of profiles of activity that could be used to identify individuals, and we will ensure that any retained processed data is sufficiently generic that it will not be susceptible to efforts to reconstruct individual profiles. Furthermore, the access to the pr…

Most of those terms relate to APNIC "ad" placement, and it specifies as such. They likely do not apply here, as it seems Cloudflare is not tracking the IP address, and things like browser fingerprinting wouldn't even show up in a DNS request.

The highlight point to me is that they not only say that won't collect data that could be used to identify individuals, but seem to realize even seemingly anonymized data can be traced back to individuals too, hence the further claim.

I'm inclined to give APNIC the benefit of the doubt, they're a nonprofit, and a fundamental part of the Internet's addressing structure, but it'd be nice to get a bit more detail from them on what they :do: collect.

Post reply on HN