So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?
Cloudflare's new DNS attracting 'gigabits per second' of rubbish
11–20 of 206 posts
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#12So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#13So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#14So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?
DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.
If you want privacy, you never do DNS queries from an ISP-assigned IP address. Tor exits do DNS queries on behalf of clients. Decent VPN services also handle DNS queries for clients.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#15Earlier quoted context omitted.
DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.
Sure, but they could also study DNS traffic if they wanted to. Or at least, with Cloudflare's cooperation. If you want privacy, you never do DNS queries from an ISP-assigned IP address. Tor exits do DNS queries on behalf of clients. Decent VPN services also handle DNS queries for clients.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#16Yup. I can't use 1.1.1.1 because my AT&T router is responding to it.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#17I used to play a game where each kingdom had an address (kingdom:island) if you where on kingdom one on island one (1:1) you would get attacked all the time no matter how much defense you had. If you landed on 1:1 you where basically doomed.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#18So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?
It was reworded enough times to make their promise vague and not well defined.
I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them.
What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from?
For DNS users of 1.1.1.1, we never provide APNIC any identifying information. We don’t upload any data to them. While they can query for questions like: “How many queries came from India in the last 24 hours?” they can’t query anything on a specific user.
If you have concerns, ask them here. I’ll answer.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#19Earlier quoted context omitted.
Sure, but they could also study DNS traffic if they wanted to. Or at least, with Cloudflare's cooperation. If you want privacy, you never do DNS queries from an ISP-assigned IP address. Tor exits do DNS queries on behalf of clients. Decent VPN services also handle DNS queries for clients.
They don’t get raw DNS traffic. Ever.
Or are you arguing that even Cloudflare couldn't get raw DNS traffic?
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#20So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?
"The service" is the DNS service. If you send random garbage to random IP addresses I think you waive the right to privacy.
>Huston emphasised that APNIC intends to protect users' privacy. "DNS is remarkably informative about what users do, if you inspect it closely, and none of us are interested in doing that," he said.
Maybe it is reasonable to take them at their word as they seem trustworthy, but we should at least consider the fact that at least some of this DNS traffic is indeed being analyzed.