Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

591–600 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#591
Very impressed so far. I wonder if Cloudflare already has or is going to provide an IP address lookup service too, like OpenDNS and Google have? I find it quite useful to be able to just do something like:

dig -4 +short myip.opendns.com a @resolver1.opendns.com

dig -6 +short myip.opendns.com aaaa @resolver1.ipv6-sandbox.opendns.com

dig -4 +short o-o.myaddr.l.google.com txt @8.8.8.8

dig -6 +short o-o.myaddr.l.google.com txt @2001:4860:4860::8888

to get back my IPv4/IPv6 addresses; especially if Cloudflare can do it faster. Does anyone know if they already have something like this?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#592

Earlier quoted context omitted.

Australia :( 64 bytes from 1.1.1.1: icmp_seq=0 ttl=57 time=17.580 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=57 time=18.025 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=57 time=17.780 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=57 time=18.231 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=57 time=17.906 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=57 time=18.447 ms

Cambodia - crappy office wifi PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=59 time=22.806 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=59 time=23.321 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=59 time=24.379 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=59 time=25.869 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=59 time=24.485 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=59 time=24.165 ms PING 8.8.8.8 (8.…

Johannesburg, South Africa. 100mb/s home fibre:

  ping 1.1.1.1
  PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data.
  64 bytes from 1.1.1.1: icmp_seq=1 ttl=58 time=1.36 ms
  64 bytes from 1.1.1.1: icmp_seq=2 ttl=58 time=1.32 ms
  64 bytes from 1.1.1.1: icmp_seq=3 ttl=58 time=1.34 ms
  64 bytes from 1.1.1.1: icmp_seq=4 ttl=58 time=1.38 ms
  64 bytes from 1.1.1.1: icmp_seq=5 ttl=58 time=1.37 ms

  ping 8.8.8.8
  PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
  64 bytes from 8.8.8.8: icmp_seq=1 ttl=56 time=1.33 ms
  64 bytes from 8.8.8.8: icmp_seq=2 ttl=56 time=1.38 ms
  64 bytes from 8.8.8.8: icmp_seq=3 ttl=56 time=1.35 ms
  64 bytes from 8.8.8.8: icmp_seq=4 ttl=56 time=1.36 ms
  64 bytes from 8.8.8.8: icmp_seq=5 ttl=56 time=1.35 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#593

EDIT: Looks like this might be an issue w/ my AT&T-provided CPE, sorry! (more details at the bottom) From my vantage point, 1.1.1.1 is inaccessible, while 1.0.0.1 seems to work just fine. Comments on the blog post blame this on "various reasons" but, at least in my case, this seems to be a Cloudflare issue: $ ping -c 5 -q 1.0.0.1 PING 1.0.0.1 (1.0.0.1) 56(84) bytes of data. --- 1.0.0.1 ping statistics --- 5 packets t…

I have the same Pace box and can replicate. Pinging 1.1.1.1 from my OpenWrt router fails.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#594
post #430

Earlier quoted context omitted.

I'm guessing Google's resolvers are a little busier than Cloudflare's right now, because pretty much nobody not on HN right now is hitting them. Will be a more interesting comparison in 6 months.

I'd be surprised if increased load has a negative effect on 1.1.1.1's performance. We run a homogeneous architecture -- that is, every machine in our fleet is capable of handling every type of request. The same machines that currently handle 10% of all HTTP requests on the internet, and handle authoritative DNS for our customers, and serve the DNS F root server, are now handling recursive DNS at 1.1.1.1. These machin…

> In fact, in this kind of architecture, a little-used service is actually likely to be penalized in terms of performance because it's spread so thin that it loses cache efficiency

This is exactly what I'm seeing with the small amount of testing I'm doing against google to compare vs cloudflare.

Sometimes google will respond in 30ms (cache hit), more often than not it has to do at least a partial lookup (160ms), and sometimes even go further to (400ms.)

The worst I'm encountering on 1.1.1.1 is around 200ms for a cache miss.

Basically, what it looks like is that google is load balancing my queries and I'm getting poor performance because of it - I'm guessing they simply need to kill some of their capacity to see increased cache hits.

Anecdotally I'm at least seeing better performance out of 1.1.1.1 than my ISP's (internode) which has consistently done better than 8.8.8.8 in the past.

Also anecdotally, my short 1-2 month trial of using systemd-resolved is now coming to a failed conclusion, I suspect I'll be going back to my pdnsd setup because it just works better.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#595
post #488

Earlier quoted context omitted.

>It's worth pointing out that KPMG was Wells Fargo's independent auditor while the bank recently committed fraud on a massive scale by creating more than a million fake deposit accounts and 560,000 credit card applications for customers without their knowledge or approval.[1] Why is it worth point out? Please detail the work you've done in establilshing that KPMG had access to the data and willfully ignored it.

An auditing company is pointless if they can't find fraud on such a massive scale or recognize that something is being hidden from them.

Thats like saying Linux is a useless project because of giant security holes that stay hidden for decades. I prefer to live in the real world, which is a lot more nuanced, and my question still stands.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#596

Earlier quoted context omitted.

Where are you testing from? I'm going to guess: a datacenter. Residential customers won't see anything this fast. I'm in a small town in Kansas, connected by 1 Gbit ATT fiber. I'm getting ~26ms to 1.1.1.1 and ~19ms to my private DNS resolver that I host in a datacenter in Dallas. Google DNS comes in around 19ms. I suspect that Cloudflare and Google DNS both have POPs in Dallas, which accounts for the similar numbers…

Ping from University of Rochester, over wifi: Cloudflare: 64 bytes from 1.1.1.1: icmp_seq=0 ttl=128 time=2 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=128 time=2 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=128 time=2 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=128 time=9 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=128 time=2 ms Google: 64 bytes from 8.8.8.8: icmp_seq=0 ttl=54 time=12 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=54 t…

From Tokyo, Japan:

$ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=58 time=111.781 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=58 time=102.982 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=58 time=102.206 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=58 time=110.135 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=58 time=110.085 ms

$ ping 8.8.8.8 PING 8.8.8.8 (8.8.8.8): 56 data bytes 64 bytes from 8.8.8.8: icmp_seq=0 ttl=58 time=6.886 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=58 time=5.475 ms 64 bytes from 8.8.8.8: icmp_seq=2 ttl=58 time=5.674 ms 64 bytes from 8.8.8.8: icmp_seq=3 ttl=58 time=5.557 ms 64 bytes from 8.8.8.8: icmp_seq=4 ttl=58 time=7.066 ms

$ ping 9.9.9.9 PING 9.9.9.9 (9.9.9.9): 56 data bytes 64 bytes from 9.9.9.9: icmp_seq=0 ttl=58 time=5.880 ms 64 bytes from 9.9.9.9: icmp_seq=1 ttl=58 time=5.534 ms 64 bytes from 9.9.9.9: icmp_seq=2 ttl=58 time=5.251 ms 64 bytes from 9.9.9.9: icmp_seq=3 ttl=58 time=5.194 ms 64 bytes from 9.9.9.9: icmp_seq=4 ttl=58 time=5.698 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#598

So, one thing I'd love to see clarified: APNIC was interested in studying the junk traffic to 1.1.1.1. Cloudflare's DNS will not log or track. So what is logged and tracked for APNIC's research purposes? Everything but DNS? Everything but DNS and HTTPS requests directly to 1.1.1.1 (presumably people looking for details on Cloudflare DNS?). What's being studied? Fun fact: CCNA classes regularly use 1.1.1.1 as a router…

Some previous study on the space with an APNIC loan:

https://www.youtube.com/watch?v=RBOPcLpQZ8w

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#599
post #3

This is the Cloudflare resolver, right? What's the "privacy-first" part about? It's just another third party DNS host. They haven't changed the protocol to be uninspectable and AFAIK haven't made any guarantees about logging or whatnot that would enhance privacy vs. using whatever you are now. This just means you're trusting Cloudflare instead of Comcast or Google or whoever.

"We will never log your IP address (the way other companies identify you). And we’re not just saying that. We’ve retained KPMG to audit our systems annually to ensure that we're doing what we say." Now, audits are generally not worth very much (even, perhaps even especially, from a Big Four group like KPMG), but for this type of thing (verifying that a company isn't doing something they promised they would not do) th…

How do we know they are not lying (or forced to lie, they are a US company after all)?
Post reply on HN