Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

671–680 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#671
post #595

Earlier quoted context omitted.

Thats like saying Linux is a useless project because of giant security holes that stay hidden for decades. I prefer to live in the real world, which is a lot more nuanced, and my question still stands.

That's a bad analogy because the Linux project isn't dedicated to auditing the Linux project. It's like calling a home security system pointless if it doesn't detect any forced entries.

I think its a perfect analogy.

>because the Linux project isn't dedicated to auditing the Linux project.

Huh? Code Review? Testing? The entire point of open source especially w.r.t security is to have millions of eyes on the source. Heck with the entire world being able to audit and review the source code, people still find bugs that were introduced decades ago.

>It's like calling a home security system pointless if it doesn't detect any forced entries.

I'm afraid that didn't make much sense to me.

Anyway, why are we focusing on irrelevant minutia or language anyway. I simply asked a commentor to show the work they've done for basing their opinion.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#672
post #283

Earlier quoted context omitted.

Having dealt with KPMG recently (which I do at least once a year...), I would not expect to see the report. KPMG's risk department - the lawyers' lawyers - appears to be violently allergic to their customers disclosing any report to outside parties. Based on my experience you can get a copy, but first you and the primary customer need to submit some paperwork. And among the conditions you need to agree with is that y…

> KPMG's risk department - the lawyers' lawyers - appears to be violently allergic to their customers disclosing any report to outside parties. Isn't that the entire point of such an audit? To be able to present it to outside third-parties? For examples, Mozilla (CA/B) requires audits for root CAs. The CA must provide a link to the audit on the auditor's public web site -- forwarding a copy or hosting it on their own…

Auditors will confirm the result of the audit but usually not disclose the content of the audit report.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#673

Not accessible from Buenos Aires, Argentina on Fibertel. ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes Request timeout for icmp_seq 0 Request timeout for icmp_seq 1

Same here (timeout), Shanghai, China on China Unicom. Pinging 1.1.1.1 with 32 bytes of data: Request timed out. Request timed out. Request timed out. Request timed out. Ping statistics for 1.1.1.1: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

Found out via Twitter you can also use 1.0.0.1 which is another of their resolvers and works for me in Argentina.

Although 1.1.1.1 is accessible for me know so I suspect it was a propagation issue.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#674
post #452

Earlier quoted context omitted.

Wonder if this will pave the way for other protocols over HTTPS.

Hopefully not. One needs to stop working around crappy setups from crappy networks. Which X-over-HTTPS really is all about.

It seems like crappy networks are the norm nowadays, and the preference of the ISPs is to offer the web only. You need a middle box just to access the internet at-large (e.g Tor). Masquerading traffic as web traffic appears to be a good tactic, though inefficient/sloppy.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#675

Earlier quoted context omitted.

My tendency would be to ask for some sort of proof, though I realize asking for proof of nonexistence of evidence is near impossible. I'm inclined at present to place more trust in Cloudflare's word at this point, but I try to keep an open mind. It's always good to know both sides' stories.

Well, you have the CloudFlare blog where Prince states "The tipping point for us making this decision was that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology."[0] So, all that is necessary is to find this statement. I won't link to it but the Daily Stormer has been active on the clear web for most of the time intervening the seizure of their domain and now. Prince neve…

You seem to know an awful lot about this specific case, and I'll defer to you on that. I know about the general case, technically speaking (though merely a DNS hobbyist).

However, having a business relationship with another organization is not a right. Hate speakers are not a protected class.

DNS does not operate in the same manner nor with the same assumptions. One can obviously run their own DNS resolver as has been pointed out repeatedly in this thread.

Please list the, "pro-pedophilia and ISIS web sites." hosted by Cloudflare?

Edit: There's probably a business opportunity for a registrar/DNS provider/host that operates under 'free speech purism,' though it's hard to say it won't go the way of usenet in that regard.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#676

Earlier quoted context omitted.

Fastest Bigpipe residential connection available in the middle of Auckland: $ ping -c 4 1.1.1.1 PING 1.1.1.1 (1.1.1.1) 56(84) bytes of data. 64 bytes from 1.1.1.1: icmp_seq=1 ttl=56 time=29.0 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=56 time=27.7 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=56 time=30.5 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=56 time=28.6 ms --- 1.1.1.1 ping statistics --- 4 packets transmitted, 4 receiv…

BigPipe, Spark, Skinny and Vodafone don't believe in peering and thus don't peer with Cloudflare at APE. If you wanted the best performance then 2degrees, Orcon, Voyager or Slingshot are the best for this since they peer.

Vodafone have come to the party and are on AKL-IX now.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#677
post #452

Earlier quoted context omitted.

Wonder if this will pave the way for other protocols over HTTPS.

Hopefully not. One needs to stop working around crappy setups from crappy networks. Which X-over-HTTPS really is all about.

Yeah, but once everything is tunneled over HTTP it will finally fix the network operator problem once and for all since you can't filter applications using ports.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#678

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

From Hyderabad, India

Cloudflare:

Reply from 1.0.0.1: bytes=32 time=119ms TTL=56

Reply from 1.0.0.1: bytes=32 time=74ms TTL=56

Reply from 1.0.0.1: bytes=32 time=74ms TTL=56

Reply from 1.0.0.1: bytes=32 time=74ms TTL=56

Reply from 1.0.0.1: bytes=32 time=74ms TTL=56

GoogleDNS:

Reply from 8.8.8.8: bytes=32 time=44ms TTL=55

Reply from 8.8.8.8: bytes=32 time=43ms TTL=55

Reply from 8.8.8.8: bytes=32 time=43ms TTL=55

Reply from 8.8.8.8: bytes=32 time=43ms TTL=55

Reply from 8.8.8.8: bytes=32 time=44ms TTL=55

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#679
post #671

Earlier quoted context omitted.

That's a bad analogy because the Linux project isn't dedicated to auditing the Linux project. It's like calling a home security system pointless if it doesn't detect any forced entries.

I think its a perfect analogy. >because the Linux project isn't dedicated to auditing the Linux project. Huh? Code Review? Testing? The entire point of open source especially w.r.t security is to have millions of eyes on the source. Heck with the entire world being able to audit and review the source code, people still find bugs that were introduced decades ago. >It's like calling a home security system pointless if…

>Heck with the entire world being able to audit and review the source code

That's irrelevant when we are talking about a company being paid specifically to audit something. The entire world is able to send me food as well, but I don't get mad when it doesn't except for when I pay someone to do it.

>I simply asked a commentor to show the work they've done

And it was a dumb question. An auditing company that failed to detect massive fraud either willfully ignored it to sellout or was too incompetent to recognize it.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#680

Earlier quoted context omitted.

I am not allowed to share that information. I now work for a Infosec/Intel company. I've worked on IBM/Watson's days systems, and before that I worked at another Intel Agency. I have terribly worked with Packet Forensics, FBI, Secret Service, and yes... Cloudflare. Don't be daft.

He asked for evidence , not more unverifiable claims. I'm not a huge fan of Cloudflare and do not use any of their services but you can't just go around making shit up and then refuse to back up your claims.

Actually, I have every right to share information that I have.

People can complain and ask for information that I can't provide. That's your right.

I have the same responsibility to provide proof as you do to believe me, even if I provided "proof".

Bother someone else.

Post reply on HN