Live data from Hacker News

DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

medium.com

191–200 of 364 posts

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#191

Earlier quoted context omitted.

Timing in general isn’t the issue here, there isn’t a way to my knowledge to get just the DNS portion (specifically across an arbitrary set of DNS providers) of the network timing in JS. Just like there isn’t a way to test the timing of a single packet really either.

You can get the DNS-over-HTTP(s) though. Not as ideal as a perfect DNS request/response over UDP, of course.

See original context, it is clearly about evaluating DNS providers with real end users via a web app. Considering a majority of providers don’t support it, seems it’ll be a very limited evaluation if it followed your proposal.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#192

Earlier quoted context omitted.

we don't keep personally identifiable information We all know what that means. "Anonymous" user IDs that can trivially be traced when combined with another database.

Except that if you click the link, that's not what this means.

I read the policy before quoting it...

How can I verify that's not what it means? It's all about subtlety in language. It's just a fact that centralized DNS servers are a bad idea and cannot be trusted, regardless of what it very carefully says on a policy page or whatever speed gains you could get. It's a broken system and I have no reason to trust Google with even more data.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#193

Earlier quoted context omitted.

Read the announcement: https://blog.cloudflare.com/announcing-1111/ "APNIC's research group held the IP addresses 1.1.1.1 and 1.0.0.1. While the addresses were valid, so many people had entered them into various random systems that they were continuously overwhelmed by a flood of garbage traffic. APNIC wanted to study this garbage traffic but any time they'd tried to announce the IPs, the flood would overwhelm any co…

Have they discussed what this means in terms of the privacy promises? What "garbage traffic" does APNIC have access to in order to study?

HA failover pings that get routed rather than being sent to their peer, captive portal requests that no longer exist. Things of that nature.

There is a lot of documentation, Cisco being one of the primary at-fault companies, that uses 1.1.1.1 for all kinds of various internal configuration.

Given hundreds of thousands of devices configured with 1.1.1.1, even a simple misconfiguration on just 10% of those is a lot of garbage traffic.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#194
post #163

Earlier quoted context omitted.

Quad9 is a consortium of 3 founding companies, none of which is the London Police Department. Additionally nowhere in your link is either Quad9, IBM, PCH or GCA mentioned. Please stop spreading and disinformation and FUD. See: https://www.quad9.net/about/

I never said it's London PD, it's City of London, these are two different things, have different mayors and budget etc. https://www.youtube.com/watch?v=LrObZ_HZZUc http://news.cityoflondon.police.uk/r/945/ibm__packet_clearin... https://www.cityoflondon.police.uk/advice-and-support/cyberc...

Whether its the City of London's Police Department or the Greater London Police is splitting hairs. Your comment suggests that the Quad9 was funded by a municipal police force. And that's patently untrue.

If you dug a little deeper on one of your own links you would find that the NYC DA and City of London Police Department donated money to establish a 501(c)3 non-profit to combat cyber crime. That 5013C is but one member of a consortium of 3 companies behind Quad9.

"Knowing the potential that an organisation like GCA could have, the DA committed $25 million in criminal asset forfeiture proceeds to fund this critical work over a five-year period. The Center for Internet Security and City of London Police also made significant contributions in providing space, funding, staff, and assistance with building strategic partnerships."[1]

[1] https://www.globalcyberalliance.org/about.html#history

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#195

Pushed a shell script to compare all of them from your location: https://github.com/cleanbrowsing/dnsperftest $ sh ./dnstest.sh |sort -k 22 -n test1 test2 test3 test4 test5 test6 test7 test8 test9 test10 Average cloudflare 1 ms 1 ms 1 ms 4 ms 1 ms 1 ms 1 ms 1 ms 1 ms 1 ms 1.30 norton 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2.00 neustar 2 ms 2 ms 2 ms 2 ms 1 ms 2 ms 2 ms 2 ms 2 ms 22 ms 3.90 cleanbrowsing 11…

Welp glad to know I was trying to dig www.pornhub.com on my work network.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#196

Earlier quoted context omitted.

That’s quite a bold claim. Got any data to back it up? Source: I've yet to see this on any ISP I've used anywhere , sans free airport wifis. Travelled pretty much every continent on earth.

CenturyLink, major telecom in 37 US states. DNS requests for all nonexistent domains go to a server that delivers a dumb "search" page to web requests. They're currently the sole fiber-to-the-home provider in my neighborhood, and Comcast is the only broadband alternative.

So one or two ISPs in one country out of 300+ worldwide.

Hardly “most” ISPs as claimed in the post I replied to. Not even a fraction.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#197
post #49

Earlier quoted context omitted.

This is the most alarming thing about this trend that has been happening for the last few years The Internet should be DECENTRALIZED yet it seems we are attempting to do everything in our power to ensure only a handful of companies control access to all information. For what to save 3 ms off a ping time? Facebook is in hot water over privacy issues, but that is just the tip of the ice berg Google, AWS, Cloudflare are…

You're barking up the wrong tree here. DNS is already an inherently centralized service -- using one company's resolvers instead of another doesn't change that.

Yes and No

the problem with Cloudflare is not simply the fact that DNS is centralized, it is a combination of all their services that is concerning for Cloudflare,

between the DDOS Proxy, the CDN, the Other Services, and now DNS that is a lot of services in a single basket, so while it is true that dns is some what centralized, having all traffic and all services dependent upon a single company seems to be a bad idea to me

But clearly everyone sees not issue with it provided they "claim" to providing a "privacy first" service for free (ya riiiiiggghhhhttttt and Facebook cares about their users privacy as well) and they have better performance, who cares what the long term effects are...

We should be working to make DNS less centralized, or replace it with something less centralized, not moving to DNS over HTTP to a few "cloud" providers who also control all of the content...

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#198
post #86

Earlier quoted context omitted.

It is common for ISP to host instances of the Google Global Cache (GGC, see https://peering.google.com/ ) which are used for many Google services, most importantly YouTube. In fact, in many cases Google itself "suggests" to ISP that they host a few GGC servers. They are directly monitored by Google, and the ISP has basically no say in how they are run. Capacity is managed by Google directly.

Yep, Virgin Media did this in the UK and messed it up badly. Every day at 6pm YouTube would stop working until the following morning. It appeared to work by inspecting DNS packets and replying with overrides if necessary. I didn’t like it but I could understand that. What I did not agree with was the fact that this also happened for other DNS services. Google DNS and OpenDNS both experienced the same issue, as did a…

Again, it's probably _not_ Virgin's fault or responsibility. Capacity planning is handled by Google directly.

Also, I think that virtually every ISP with more than a few tens of thousands users is hosting a GGC instance nowadays (and a Netflix OpenCache, etc. etc.).

Nowadays, the vast majority of the transit&peering of ISPs is not going to the Internet, but to a few racks of local caching servers managed by OTT operators.

Bandwidth-wise, at least in prime time, the Internet is much less connected/realtime than people think :)

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#199

Earlier quoted context omitted.

That’s quite a bold claim. Got any data to back it up? Source: I've yet to see this on any ISP I've used anywhere , sans free airport wifis. Travelled pretty much every continent on earth.

Time Warner (Now Spectrum) in Texas does this on residential as well as "business class"

So this is a US problem and therefore “most” ISPs worldwide does this?

That’s hardly evidence if any.

Re: DNS Performance compared: CloudFlare 1.1.1.1 x Google 8.8.8.8 x Quad9 x OpenDNS

#200

Pushed a shell script to compare all of them from your location: https://github.com/cleanbrowsing/dnsperftest $ sh ./dnstest.sh |sort -k 22 -n test1 test2 test3 test4 test5 test6 test7 test8 test9 test10 Average cloudflare 1 ms 1 ms 1 ms 4 ms 1 ms 1 ms 1 ms 1 ms 1 ms 1 ms 1.30 norton 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2 ms 2.00 neustar 2 ms 2 ms 2 ms 2 ms 1 ms 2 ms 2 ms 2 ms 2 ms 22 ms 3.90 cleanbrowsing 11…

Welp glad to know I was trying to dig www.pornhub.com on my work network.

Good point. Removed it from the default tested domains.
Post reply on HN