Live data from Hacker News

DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

medium.com

161–170 of 364 posts

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#161
post #29
post #24

Earlier quoted context omitted.

But your DNS will have to query other DNS providers so if you’re the only one using it, it won’t be private.

There is 2 main different ways, one which does what you say - the other i'd say is pretty much OK. If your local DNS server is merely querying an upstream resolver (like 1.1.1.1 / 8.8.8.8) on your behalf, then yes - it is no different. If however, you query the root nameservers for the glue record for a domain and query the domain's own nameservers directly, then it is pretty good... As you are neither querying your…

They don't need to be doing DNS proxying, they can just inspect port 53 traffic -- unless the site you're visiting supports DNS over TLS, then you're not hiding anything from your ISP, since they'll see the DNS query packet hitting the www.porn-site.com nameserver.

However, if have a local TLS nameserver, you can set it up to query 1.1.1.1 over TLS, then your ISP can't see any of your DNS queries.

So you need to decide who you trust more -- your ISP or a DNS provider (or a VPN provider).

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#162
post #49

I feel like people forgot about how CloudFlare, Google, et. al. can new effectively censor content they don't agree with: https://fightthefuture.org/article/the-new-era-of-corporate-... ..and even though CloudFlare back pedaled on that particular decision somewhat, it still happened. If you really want something fast and secure, run your own caching DNS that uses root DNS servers.

This is the most alarming thing about this trend that has been happening for the last few years The Internet should be DECENTRALIZED yet it seems we are attempting to do everything in our power to ensure only a handful of companies control access to all information. For what to save 3 ms off a ping time? Facebook is in hot water over privacy issues, but that is just the tip of the ice berg Google, AWS, Cloudflare are…

You're barking up the wrong tree here. DNS is already an inherently centralized service -- using one company's resolvers instead of another doesn't change that.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#163
post #7

Earlier quoted context omitted.

Quad9 is supported/funded by City Of London Police, the same police that cooperates with ad companies to track people online. https://www.theguardian.com/media-network/media-network-blog... Keep away from this.

Quad9 is a consortium of 3 founding companies, none of which is the London Police Department. Additionally nowhere in your link is either Quad9, IBM, PCH or GCA mentioned. Please stop spreading and disinformation and FUD. See: https://www.quad9.net/about/

I never said it's London PD, it's City of London, these are two different things, have different mayors and budget etc.

https://www.youtube.com/watch?v=LrObZ_HZZUc

http://news.cityoflondon.police.uk/r/945/ibm__packet_clearin...

https://www.cityoflondon.police.uk/advice-and-support/cyberc...

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#165
post #56

Which ISPs are so bad that you want to use external services, which are further in distance than your ISP, for speed? When I test with my ISP, they beat all of these services (both IPv4 and IPv6). They're simply closer to me in terms of hops. My router is another story though. The Fritzbox (>200eur router) adds 6ms of latency, and that's what is advertised over DHCP. (Might still be fine, since cached queries are fas…

I run a local caching server on my network 192.168.1.22, from there I now forward to cloudflare, then to opendns on misses. This makes DNS resolution blazing fast for things we frequent.

I use my ASUS router's DHCP to teach all my dynamically configured network devices how to find the bind9 DNS caching server.

All the statically configured ones just have 192.168.1.22 hard coded with 1.1.1.1 as backup.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#166

Earlier quoted context omitted.

> only the domain nameserver owner knows what queries you made (and you are probably hitting that domain in a moment anyway!) But these are different people, with different incentives. The NS owner may be logging everything, without the domain owner's knowledge, and the NS owner won't even be in the wrong, because they likely made no promise to not log. With a single resolver, I can verify that they're trustworthy en…

> With a single resolver, I can verify that they're trustworthy enough [for me], just once, and direct all my traffic to it. Apply this deceptively simple principle to every need you have on our wonderfully decentralized Internet and see where that gets us. Oh snap. Not so decentralized anymore.

I'm talking about DNS and nothing else.

Okay, say, 1 year from now, somehow, 95% of internet users are sending their DNS queries to Cloudflare. What can go wrong? Malicious or not. Not rhetorical, actually curious.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#167
post #58
post #29

Earlier quoted context omitted.

There is 2 main different ways, one which does what you say - the other i'd say is pretty much OK. If your local DNS server is merely querying an upstream resolver (like 1.1.1.1 / 8.8.8.8) on your behalf, then yes - it is no different. If however, you query the root nameservers for the glue record for a domain and query the domain's own nameservers directly, then it is pretty good... As you are neither querying your…

> (The caveat is that some ISP's do transparent DNS proxying.. in which case, you have much larger trust issues with your ISP and need to take greater measures!) I once had an ISP which did transparent http proxying. You could theoretically query an external DNS server and get back the correct result, but it would intercept your http connection, discard the ip address you were trying to connect to then do a new DNS l…

Virgin Media in the UK appear to do this for sites they are ordered to block. Even if you get the right DNS response, you get forwarded to http://assets.virginmedia.com/site-blocked.html (HTTPS requests get a connection reset).

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#168
post #74

Earlier quoted context omitted.

I wonder how much Cloudflare paid/pays for the 1.1.1.1

Read the announcement: https://blog.cloudflare.com/announcing-1111/ "APNIC's research group held the IP addresses 1.1.1.1 and 1.0.0.1. While the addresses were valid, so many people had entered them into various random systems that they were continuously overwhelmed by a flood of garbage traffic. APNIC wanted to study this garbage traffic but any time they'd tried to announce the IPs, the flood would overwhelm any co…

Have they discussed what this means in terms of the privacy promises? What "garbage traffic" does APNIC have access to in order to study?

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#170

Safari barfs on visiting https://1.1.1.1 as linked in the article. Certificate invalid (though it looks fine). Rather unfortunate regarding perception; it's an interesting service!

Works for me; Safari 11.0.3 on High Sierra. (I'm surprised it works at all though... I wouldn't have thought you could have an HTTPS certificate for an IP address? You learn something new every day.)

The actual domain name is https://cloudflare-dns.com/ (found by inspecting the cert)

Before SNI, every cert had to go to a static public IP address. Everything between you and the TLS terminator had to handle this. As a side-effect, you didn't actually need to know the domain name to get the tunnel, because everything handling the packets was running on the destination IP.

tl;dr: Trickery based on dated TLS quirks.

Post reply on HN