Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

31–40 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#31
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

[deleted]

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#32
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

Hello,

Are the gigabytes of junk billions of tiny requests or are there large requests as well?

Are you finding it more difficult than expected to manage the data?

I'm a 1.1.1.1 customer since you launched, thanks a lot for it.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#33

Earlier quoted context omitted.

"The service" is the DNS service. If you send random garbage to random IP addresses I think you waive the right to privacy.

>APNIC gets to see the noise as well as the DNS traffic >Huston emphasised that APNIC intends to protect users' privacy. "DNS is remarkably informative about what users do, if you inspect it closely, and none of us are interested in doing that," he said. Maybe it is reasonable to take them at their word as they seem trustworthy, but we should at least consider the fact that at least some of this DNS traffic is indeed…

No, wait.

Users of the DNS service get the privacy guarantee.

Non-users do not. If you floodping 1.1.1.1 you are not a user of the DNS service and the privacy terms don't apply to you. Rather you're a member of the Misconfiguration Club, and the site you're pinging has the usual right to analyse your pings.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#34
post #27

A German podcaster who has been working on networks for decades once said that he owns a large chunk of public IP addresses in the 192.68.0.0/16 subnet and it's impossible for him to use it because once he activates it he basically gets a DDOS of misdirected traffic. So many misconfigured networks out there...

[deleted]

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#35
post #19

Earlier quoted context omitted.

But that's just a Cloudflare policy, isn't it? Or are you arguing that even Cloudflare couldn't get raw DNS traffic?

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

Oh, I didn't realize that you're a CloudFlare cofounder.

I don't mean to question CloudFlare's integrity.

It's just that, for claims about privacy, I'd rather depend on more than trusting any one party.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#36
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

>they can’t query anything on a specific user.

What exactly do you mean by "user"? Can they query DNS traffic by IP address / subnet? Exactly what are all of the restrictions there?

EDIT: Is there a whitelist of things they can query by or do you simply trust them to be good citizens, have a binding legal agreement, all of the above?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#37
post #23

Earlier quoted context omitted.

I expect that no human from APNIC or Cloudflare will ever look at raw data from 1.1.1.1, nor will any of it be recorded, or used in aggregated data that retains any personal information. As personal information count full IP addresses, the content of requests, or any set of data that can be used to recover these. That is what "we respect your privacy" means.

Neither we nor APNIC can query “what” or “how many” requests from any IP have been made. We can query things like: 1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers? If you have specific concerns, please raise them here.

What's in it for you guys? How do you make money off of 1.1.1.1? Thanks!

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#38
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

From https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...:

"Specifically, APNIC will be permitted to access query names, query types, resolver location and other metadata via a Cloudflare API, that will allow APNIC to study topics like the volume of DDoS attacks launched on the Internet and adoption of IPv6."

I interpret "query names" as some values obtained from DNS queries hitting 1.1.1.1, e.g. "foo.example.com".

Is your answer to "What data do you provide to APNIC?" complete in the statement above?

Thanks for clarifying.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#39
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#40
post #39
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

You have no idea
Post reply on HN