Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

651–660 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#651

Earlier quoted context omitted.

What is your evidence of this?

I am not allowed to share that information. I now work for a Infosec/Intel company. I've worked on IBM/Watson's days systems, and before that I worked at another Intel Agency. I have terribly worked with Packet Forensics, FBI, Secret Service, and yes... Cloudflare. Don't be daft.

He asked for evidence, not more unverifiable claims.

I'm not a huge fan of Cloudflare and do not use any of their services but you can't just go around making shit up and then refuse to back up your claims.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#652

EDIT: Looks like this might be an issue w/ my AT&T-provided CPE, sorry! (more details at the bottom) From my vantage point, 1.1.1.1 is inaccessible, while 1.0.0.1 seems to work just fine. Comments on the blog post blame this on "various reasons" but, at least in my case, this seems to be a Cloudflare issue: $ ping -c 5 -q 1.0.0.1 PING 1.0.0.1 (1.0.0.1) 56(84) bytes of data. --- 1.0.0.1 ping statistics --- 5 packets t…

> When pinging 1.1.1.1 from my (pfSense-based) router sitting directly behind the modem, however, no replies come back from the modem to the router (confirmed via pcap on the upstream-facing interface). Your upstream diagnosis seems to suggest otherwise, but perhaps you have an issue with using pfBlockerNG? If you're using pfSense with pfBlockerNG + DNSBL IP rules, it populates empty firewall alias files with 1.1.1.1…

> ... perhaps you have an issue with using pfBlockerNG?

Thanks, but no, I don't use pfBlockerNG (hadn't even heard of it until now).

As mentioned, this turned out to be an issue w/ my ISP-provided CPE.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#653

Earlier quoted context omitted.

Beijing: PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=52 time=241.529 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=52 time=318.034 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=52 time=337.291 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=52 time=255.748 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=52 time=247.765 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=52 time=235.611 ms 64 bytes from 1.1.1.1: icmp_seq…

Copenhagen: PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=55 time=14.053 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=55 time=12.715 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=55 time=13.615 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=55 time=14.018 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=55 time=12.261 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=55 time=11.428 ms 64 bytes from 1.1.1.1: icmp_seq=6…

Pinging 1.1.1.1 with 32 bytes of data: Reply from 89.228.6.1: Destination net unreachable. Reply from 89.228.6.1: Destination net unreachable. Reply from 89.228.6.1: Destination net unreachable. Reply from 89.228.6.1: Destination net unreachable.

Any idea why my ISP redirects this IP?

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#654

Earlier quoted context omitted.

If you are on ethernet, I am able to get 1-2ms pings. On same AT&T Fiber Gigabit. Wifi ruins both bandwidth and latency for me.

AT&T Fiber Gigabit in Nashville TN. iMac ~ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=64 time=0.688 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=64 time=0.814 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=64 time=1.153 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=64 time=0.752 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=64 time=0.755 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=64 time=0.789…

That's probably because AT&T is using 1.1.1.1 for something internal and breaking the public internet for it's users: you get a really fast ping on 1.1.1.1, but it's not the 1.1.1.1 you are trying to reach.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#655

Earlier quoted context omitted.

That reverse lookup time is not counted in the first ping.

Perhaps that depends on operating system. In the 30 years I have been using ping on Linux, the reverse lookup time is absolutely included in the first ping time.

If true, that's a bug.

Edit: Assuming this is the right file: https://github.com/iputils/iputils/blob/master/ping.c, I don't see the reverse lookup code anywhere. But then I'm not the most proficient in reading linux code.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#656

Earlier quoted context omitted.

AT&T Fiber Gigabit in Nashville TN. iMac ~ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=64 time=0.688 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=64 time=0.814 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=64 time=1.153 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=64 time=0.752 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=64 time=0.755 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=64 time=0.789…

That's probably because AT&T is using 1.1.1.1 for something internal and breaking the public internet for it's users: you get a really fast ping on 1.1.1.1, but it's not the 1.1.1.1 you are trying to reach.

Is this just speculation or can anybody confirm?

    traceroute to 1.1.1.1 (1.1.1.1), 64 hops max, 52 byte packets
     1  1dot1dot1dot1.cloudflare-dns.com (1.1.1.1)  1.117 ms  0.710 ms  0.727 ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#657

Earlier quoted context omitted.

It work as expected if you give it the http://1.2.3 schema prefix. The input bar is a search bar in modern browsers.

Or if you follow it with a trailing slash, for less typing 1.1/

Or if you prefix it with //

  //1.1.1.1
It's one more letter than a suffix, but as a prefix its a bit clearer. I've known companies to post LAN hostname addresses that way, and in written/printed materials it stands out pretty clearly as an address to type.

It follows the URL standards (no schema implies current or default schema). Many auto-linking tools (such as a Markdown, Word) recognize it by default (though sometimes results are unpredictable given schema assumptions). It's also increasingly the recommendation for HTML resources where you do want to help insure same-schema requests (good example cross-server/CDN CSS and JS links now are typically written as //css-host.example.com/some/css/file.css).

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#659
post #402

Earlier quoted context omitted.

Same, ATT Fiber in Charlotte NC

Which AT&T modem do you have? I'm seeing this w/ 5268AC, trying to find others that are affected as well.

If it's not the 5268AC, please let marty at cloudflare dot com know as well. According to a reply on NANOG, he is interested in knowing about other broken CPE.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#660

Earlier quoted context omitted.

How many people have local DNS at home? Not many, I'd wager. How many know how to access their router? Also not many. Besides, "In your router’s configuration page, locate the DNS server settings."

Here in Hacker News: Many.

Exactly. HN is a bubble, and I think people forget they don't represent the average consumer.
Post reply on HN