Live data from Hacker News

DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

medium.com

41–50 of 364 posts

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#41
I feel like people forgot about how CloudFlare, Google, et. al. can new effectively censor content they don't agree with:

https://fightthefuture.org/article/the-new-era-of-corporate-...

..and even though CloudFlare back pedaled on that particular decision somewhat, it still happened.

If you really want something fast and secure, run your own caching DNS that uses root DNS servers.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#42
post #35
post #28

9.9.9.9 does not seem to be geographically-aware. Here are the resolutions for the same domain name (CNAME referring to the hopefully closest edge server), from France. % dig [domain] @8.8.8.8 +short [id].kxcdn.com. p-frpa00.kxcdn.com. # France % dig [domain] @9.9.9.9 +short [id].kxcdn.com. s-us-ca00.kvcdn.com. # America p-ussj00.kxcdn.com. % dig [domain] @1.1.1.1 +short [id].kxcdn.com. p-frpa00.kxcdn.com. # France %…

9.9.9.9 does not pass along EDNS client subnet resulting in wrong geo-located responses. It is their "feature".

According to the FAQ[1], they also offer 9.9.9.10, which passes client subnet at the cost of other features.

[1] https://www.quad9.net/faq

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#43
post #32

I presume that Google uses this as part of it's surveillance operation.

Yes, they aren’t providing 8.8.8.8 out of the goodness of their black hearts

And I wanted to add a similar comment, why on earth would any privacy-oriented person would use Google's 8.8.8.8 when there are other options out there?

Oh, and I definitely don't buy this for Google: "The Privacy option above is based on the providers promise to do not log or share your DNS requests."

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#44

I presume that Google uses this as part of it's surveillance operation.

Google has a separate, stricter, privacy policy for Google Public DNS: https://developers.google.com/speed/public-dns/privacy

Basically there are two log files kept:

- One for up to 48 hours which contains IP addresses, which is used for handling abuse.

- One is permanent which doesn't contain any personal identifying information (eg IP addresses), which is used for things like internal performance monitoring, load testing, and tracking frequency of longer term abuse etc.

Google provides Google public DNS because if you see the internet as being slow because of poor DNS performance, then you don't use websearch as much. Google doesn't need to use Google Public DNS to track users, and would rather not have the information (as it makes it available for government requests etc which are a major pain to deal with). But running a large scale recursive DNS server tends to attract a _lot_ of abuse, both intentional, and unintentional as I'm sure 9.9.9.9 and 1.1.1.1 are discovering.

Google provides Google Public DNS because a lot of ISPs provide extremely poor default recursive nameservers (having tiny caches, dropping queries due to overload, not implementing IPv6, DNSSEC validation, EDNS0 payload size, or other important modern DNS features. Some ISPs also hijack domains for their own purposes, or "stretching" DNS TTLs etc) so providing a better alternative to improve overall Internet use is clearly in Google's best interest.

Having other public resolvers, with different trade offs is clearly better for everyone, including Google as long as they are reliable, trustworthy, and provide low latency responses.

Good luck to everyone who's joining in the fun of running a planet scale recursive DNS server.

(Disclaimer: I have previously worked on Google Public DNS, but no longer do)

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#45

I presume that Google uses this as part of it's surveillance operation.

You've got any proof, indication or even slight hint for this? Aggregate data is indeed used for all kinds of analytics, but individual IP addresses aren't tracked nor kept for more than 48 hours - to combat abuse.

(Disclaimer: I'm a Google corporate shill)

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#46
I wonder how well 4.2.2.x compares...

Then again, a few ms of difference is unlikely to make any noticeable effect in real-world use cases where clients already have local DNS caching and the bulk of the time is data transfer, not DNS lookups.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#47
post #28

9.9.9.9 does not seem to be geographically-aware. Here are the resolutions for the same domain name (CNAME referring to the hopefully closest edge server), from France. % dig [domain] @8.8.8.8 +short [id].kxcdn.com. p-frpa00.kxcdn.com. # France % dig [domain] @9.9.9.9 +short [id].kxcdn.com. s-us-ca00.kvcdn.com. # America p-ussj00.kxcdn.com. % dig [domain] @1.1.1.1 +short [id].kxcdn.com. p-frpa00.kxcdn.com. # France %…

A more comprehensive benchmark would also measure a ping or HTTP request to each resolved IP take to this into account. Actual browser performance is very skewed now without it.

And throughput to the content as well - RTT (even time to first byte) by itself does not a benchmark make.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#48

You can run a benchmark of your own using namebench. I recommend you uncheck the options for the included nameservers or it will take a very long time to run and enter only the DNS servers you want to test manually. It can use your Firefox browsing history as a source for domains to resolve. Ignore the "incorrect" and "hijacked" warnings, I think the program has hardcoded, outdated IP ranges for popular services whic…

for the curious arch user, it's on AUR

ps: namebench is quite extensive. thousands of queries and a nice and long report. enjoy it

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#49

I feel like people forgot about how CloudFlare, Google, et. al. can new effectively censor content they don't agree with: https://fightthefuture.org/article/the-new-era-of-corporate-... ..and even though CloudFlare back pedaled on that particular decision somewhat, it still happened. If you really want something fast and secure, run your own caching DNS that uses root DNS servers.

This is the most alarming thing about this trend that has been happening for the last few years

The Internet should be DECENTRALIZED yet it seems we are attempting to do everything in our power to ensure only a handful of companies control access to all information. For what to save 3 ms off a ping time?

Facebook is in hot water over privacy issues, but that is just the tip of the ice berg

Google, AWS, Cloudflare are IMO are larger threat then facebook ever could be.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#50

I feel like people forgot about how CloudFlare, Google, et. al. can new effectively censor content they don't agree with: https://fightthefuture.org/article/the-new-era-of-corporate-... ..and even though CloudFlare back pedaled on that particular decision somewhat, it still happened. If you really want something fast and secure, run your own caching DNS that uses root DNS servers.

> If you really want something fast and secure, run your own caching DNS that uses root DNS servers.

is there a good tutorial for this somewhere?

Post reply on HN