Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

21–30 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#21
post #6

So, the traffic is being sniffed and analyzed, and that service was advertised as privacy-oriented?

DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.

Does all this garbage traffic affect the performance of Cloudflare's servers? There must be some cost (performance and $$$) to filter this traffic. Was that a consideration when deciding whether to use 1.1.1.1 instead of some other IP address? :)

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#22
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

How do you know where the requests came from without IP addresses? Do you log ASN or something?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#23
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

I expect that no human from APNIC or Cloudflare will ever look at raw data from 1.1.1.1, nor will any of it be recorded, or used in aggregated data that retains any personal information.

As personal information count full IP addresses, the content of requests, or any set of data that can be used to recover these.

That is what "we respect your privacy" means.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#24
post #19

Earlier quoted context omitted.

They don’t get raw DNS traffic. Ever.

But that's just a Cloudflare policy, isn't it? Or are you arguing that even Cloudflare couldn't get raw DNS traffic?

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#25

Earlier quoted context omitted.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

How do you know where the requests came from without IP addresses? Do you log ASN or something?

We keep IPs in memory to help stop abuse and debugging ng other issue, but we promise to purge all logs within 24 hours or less.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#26
post #23

Earlier quoted context omitted.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

I expect that no human from APNIC or Cloudflare will ever look at raw data from 1.1.1.1, nor will any of it be recorded, or used in aggregated data that retains any personal information. As personal information count full IP addresses, the content of requests, or any set of data that can be used to recover these. That is what "we respect your privacy" means.

Neither we nor APNIC can query “what” or “how many” requests from any IP have been made.

We can query things like:

1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers?

If you have specific concerns, please raise them here.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#27
A German podcaster who has been working on networks for decades once said that he owns a large chunk of public IP addresses in the 192.68.0.0/16 subnet and it's impossible for him to use it because once he activates it he basically gets a DDOS of misdirected traffic. So many misconfigured networks out there...

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#28
post #19

Earlier quoted context omitted.

But that's just a Cloudflare policy, isn't it? Or are you arguing that even Cloudflare couldn't get raw DNS traffic?

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

you could hire auditors who aren't currently facing criminal charges for corruption? like it's not even been 2 years...

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#30

Earlier quoted context omitted.

DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.

Does all this garbage traffic affect the performance of Cloudflare's servers? There must be some cost (performance and $$$) to filter this traffic. Was that a consideration when deciding whether to use 1.1.1.1 instead of some other IP address? :)

Vendors like Cloudflare have usually really easy to use and cheap measures to drop traffic otherwise they would not be able to provide DDOS protection. Usually they have BGP or other means to propagate blacklisted IP ranges to peers meaning that not even their peers will route the garbage towards them. This is how you can survive DDOS that is bigger than your pipe while serving legit traffic (coming from different ranges than the ones you blacklisted).
Post reply on HN