Live data from Hacker News

1.1.1.1: Fast, privacy-first consumer DNS service

blog.cloudflare.com

681–690 of 695 posts

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#681
post #671

Earlier quoted context omitted.

I think its a perfect analogy. >because the Linux project isn't dedicated to auditing the Linux project. Huh? Code Review? Testing? The entire point of open source especially w.r.t security is to have millions of eyes on the source. Heck with the entire world being able to audit and review the source code, people still find bugs that were introduced decades ago. >It's like calling a home security system pointless if…

>Heck with the entire world being able to audit and review the source code That's irrelevant when we are talking about a company being paid specifically to audit something. The entire world is able to send me food as well, but I don't get mad when it doesn't except for when I pay someone to do it. >I simply asked a commentor to show the work they've done And it was a dumb question. An auditing company that failed to…

>That's irrelevant when we are talking about a company being paid specifically to audit something. The entire world is able to send me food as well, but I don't get mad when it doesn't except for when I pay someone to do it.

Linux is developed almost exclusively by people who get paid for their work. Billions of dollars of real money has been poured by IBM, Intel, RH, etc. You are thoroughly confused my friend. Lets stick with the original point.

> An auditing company that failed to detect massive fraud either willfully ignored it to sellout or was too incompetent to recognize it.

So explain how they audited the firm, explain which data they had access to and how they were incompetent

You can't define your way out of providing evidence. An auditor does X. They couldn't do X, therefore they were incompetent. That schoolyard logic doesn't work. People will ask you to backup your opinion. Its completely fine to say I don't know...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#682
post #15
post #5

If everyone* just ran a full recursing resolver would that cause undue load on the root-servers? Seems like a sane way to decentralise. * Actually only ~1% of internet users, the kind of people that install openwrt

Root servers get basically no traffic anyway. It's basically all cached by recursors.

That's not in fact true. There are quite a lot of cache misses in the normal course of affairs, to start with.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#683

Earlier quoted context omitted.

Bear in mind, they dropped Daily Stormer because they were claiming Cloudflare agreed with their ideology. Which someone in the previous discussion pointed out was a Terms of Service violation. DNS resolving offers no such terms and no such reason to make such a claim. I don't see that playing here. And bear in mind, when the CEO did it, he wrote about how dangerous it was that companies had that power. I don't feel…

Cloudflare is a private company and they're free to do what they want but their reasoning for the Daily Stormer termination felt like a convenient excuse to me. I'm sure that it was the best business decision for them but when I read a blog post touting 1.1.1.1 as being anti-censorship, I roll my eyes. Anti-censorship so long as Matthew Prince doesn't have a bad morning. I run my own DNS-over-TLS resolver at a truste…

Running your own root content DNS server isn't particularly hard, note. The public root content DNS server operators are not interested in serving up dummy answers for all sorts of internal stuff that leaks out to the root content DNS servers any more than you are interested in sending it to them. (-:

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#684
post #681

Earlier quoted context omitted.

>Heck with the entire world being able to audit and review the source code That's irrelevant when we are talking about a company being paid specifically to audit something. The entire world is able to send me food as well, but I don't get mad when it doesn't except for when I pay someone to do it. >I simply asked a commentor to show the work they've done And it was a dumb question. An auditing company that failed to…

>That's irrelevant when we are talking about a company being paid specifically to audit something. The entire world is able to send me food as well, but I don't get mad when it doesn't except for when I pay someone to do it. Linux is developed almost exclusively by people who get paid for their work. Billions of dollars of real money has been poured by IBM, Intel, RH, etc. You are thoroughly confused my friend. Lets…

>Linux is developed almost exclusively by people who get paid for their work. Billions of dollars of real money has been poured by IBM, Intel, RH, etc. You are thoroughly confused my friend. Lets stick with the original point.

What aren't you getting? Developing is not auditing. KPMG wasn't paid to do banking, they were just paid to audit.

>So explain how they audited the firm, explain which data they had access to and how they were incompetent

As an auditing firm you either demand enough data to do a real audit or you walk away from the deal. So either they didn't have enough data or they were sell-outs rubber stamping it. That's just how auditing works.

>People will ask you to backup your opinion. Its completely fine to say I don't know...

It's not an opinion. It's literally what they are paid to do. If I pay for a hamburger and someone just gives me a pile of sand, any bystander can tell that the seller didn't do their job.

If you want more evidence of KPMG incompetence, check out this: https://seekingalpha.com/news/3344058-ge-urged-proxy-advisor...

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#685

Earlier quoted context omitted.

Why not use a VPN like PIA?

> Why not use a VPN like PIA? A VPN gives you little protection against browser fingerprinting, which may alone leak enough information about you to identify you. Also privacy-by-policy is in no way near privacy-by-design. If you want privacy, use the Tor Browser.

What a bunch of false security you're providing. NSA had broken the TOR traffic quite a while back. Worthless.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#686

My FAI, Orange in France, seems to block/redirect acces to https://1.1.1.1 , i see great irony here. Chrome security warning when i try to access it, ping <1ms when ping ip adress.

It's very likely that they have 1.1.1.1 in their "bogons" list and have for a very long time. Bogons are a list of prefixes that most ISPs blackhole as there is usually never any legitimate traffic bound for those destinations. RFC1918 addresses, for example. I can't reach 1.1.1.1 either, but 1.0.0.1 works fine. Maybe try that.

Could it be that 1.1.1.1 is blocked because it uses a secure protocol as opposed to 1.0.0.1 which is unsecure. This would be for the sake of monitoring traffic.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#687

Earlier quoted context omitted.

AT&T Fiber Gigabit in Nashville TN. iMac ~ ping 1.1.1.1 PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: icmp_seq=0 ttl=64 time=0.688 ms 64 bytes from 1.1.1.1: icmp_seq=1 ttl=64 time=0.814 ms 64 bytes from 1.1.1.1: icmp_seq=2 ttl=64 time=1.153 ms 64 bytes from 1.1.1.1: icmp_seq=3 ttl=64 time=0.752 ms 64 bytes from 1.1.1.1: icmp_seq=4 ttl=64 time=0.755 ms 64 bytes from 1.1.1.1: icmp_seq=5 ttl=64 time=0.789…

That's probably because AT&T is using 1.1.1.1 for something internal and breaking the public internet for it's users: you get a really fast ping on 1.1.1.1, but it's not the 1.1.1.1 you are trying to reach.

Seems AT&T uses 1.1.1.1 inside of their modems. Oops!

Using 1.0.0.1 works.

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#688
post #678

And look at these ping times: CloudFlare Google DNS Quad9 OpenDNS NewYork 2 msec 1 msec 2 msec 19 msec Toronto 2 msec 28 msec 17 msec 27 msec Atlanta 1 msec 2 msec 1 msec 19 msec Dallas 1 msec 9 msec 1 msec 7 msec San Francisco 3 msec 21 msec 15 msec 20 msec London 1 msec 12 msec 1 msec 14 msec Amsterdam 2 msec 6 msec 1 msec 6 msec Frankfurt 1 msec 9 msec 2 msec 9 msec Tokyo 2 msec 2 msec 81 msec 77 msec Singapore 2…

From Hyderabad, India Cloudflare: Reply from 1.0.0.1: bytes=32 time=119ms TTL=56 Reply from 1.0.0.1: bytes=32 time=74ms TTL=56 Reply from 1.0.0.1: bytes=32 time=74ms TTL=56 Reply from 1.0.0.1: bytes=32 time=74ms TTL=56 Reply from 1.0.0.1: bytes=32 time=74ms TTL=56 GoogleDNS: Reply from 8.8.8.8: bytes=32 time=44ms TTL=55 Reply from 8.8.8.8: bytes=32 time=43ms TTL=55 Reply from 8.8.8.8: bytes=32 time=43ms TTL=55 Reply…

From Hyderabad, another ISP

Pinging 1.1.1.1 with 32 bytes of data: Reply from 1.1.1.1: bytes=32 time=45ms TTL=53 Reply from 1.1.1.1: bytes=32 time=45ms TTL=53 Reply from 1.1.1.1: bytes=32 time=45ms TTL=53 Reply from 1.1.1.1: bytes=32 time=45ms TTL=53

Ping statistics for 1.1.1.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 45ms, Maximum = 45ms, Average = 45ms

Pinging 1.0.0.1 with 32 bytes of data: Reply from 1.0.0.1: bytes=32 time=46ms TTL=54 Reply from 1.0.0.1: bytes=32 time=46ms TTL=54 Reply from 1.0.0.1: bytes=32 time=46ms TTL=54 Reply from 1.0.0.1: bytes=32 time=46ms TTL=54

Ping statistics for 1.0.0.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 46ms, Maximum = 46ms, Average = 46ms

Pinging 8.8.4.4 with 32 bytes of data: Reply from 8.8.4.4: bytes=32 time=29ms TTL=56 Reply from 8.8.4.4: bytes=32 time=29ms TTL=56 Reply from 8.8.4.4: bytes=32 time=29ms TTL=56 Reply from 8.8.4.4: bytes=32 time=29ms TTL=56

Ping statistics for 8.8.4.4: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 29ms, Maximum = 29ms, Average = 29ms

Pinging 8.8.8.8 with 32 bytes of data: Reply from 8.8.8.8: bytes=32 time=21ms TTL=56 Reply from 8.8.8.8: bytes=32 time=21ms TTL=56 Reply from 8.8.8.8: bytes=32 time=21ms TTL=56 Reply from 8.8.8.8: bytes=32 time=21ms TTL=56

Ping statistics for 8.8.8.8: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 21ms, Maximum = 21ms, Average = 21ms

Pinging 208.67.220.220 with 32 bytes of data: Reply from 208.67.220.220: bytes=32 time=45ms TTL=54 Reply from 208.67.220.220: bytes=32 time=46ms TTL=54 Reply from 208.67.220.220: bytes=32 time=45ms TTL=54 Reply from 208.67.220.220: bytes=32 time=50ms TTL=54

Ping statistics for 208.67.220.220: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 45ms, Maximum = 50ms, Average = 46ms

Pinging 208.67.222.222 with 32 bytes of data: Reply from 208.67.222.222: bytes=32 time=61ms TTL=54 Reply from 208.67.222.222: bytes=32 time=61ms TTL=54 Reply from 208.67.222.222: bytes=32 time=61ms TTL=54 Reply from 208.67.222.222: bytes=32 time=61ms TTL=54

Ping statistics for 208.67.222.222: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 61ms, Maximum = 61ms, Average = 61ms

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#689
post #289
post #170

Earlier quoted context omitted.

I'm getting ~40-50ms on both on Internode from Brisbane.

What do you get to internode from there? (@192.231.203.132) I'm halfway up to newcastle getting ~10ms across the board, 1.1.1.1, 8.8.8.8, and 192.231.203.132. Of course performance on each is a different matter. 1.1.1.1 is giving the best response times @ 8-11ms. Internode's is giving decent @ 10-14ms 8.8.8.8 is a bit wonky, sometimes I hit a 10ms route once they cache it, but propagation is very slow and most respon…

Sorry for the late response: to Internode (192.231.203.132) I get 36 ms. This is all on (rather terrible) ADSL 2+

Re: 1.1.1.1: Fast, privacy-first consumer DNS service

#690

Is Cloudflare overriding TTLs on RRs? If I send a request to 1.0.0.1 for a specific RR that I'm 99.9% certain isn't cached (although I didn't check the query logs on the authoritative DNS servers to verify a request actually came in), the response contains the (expected) TTL of 14400. If I then send the same request to 1.1.1.1, I get a response that is identical except with a TTL of 3591 seconds. According to the tim…

Yes, there's a cap on both negative and positive cache lifetime. The reason is reducing the blast radius as accidents happen, and it hurts especially on long infrastructure records (mistake during repointing NSs, bad glue, expired DS etc.) We're going to be looking into making the cap more dynamic over time.

I do this at home as well, using Unbound DNS to set a min and max TTL. It's taboo on public DNS recursors, but totally makes sense. Some folks try to use DNS as real time load balancers and will set crazy low TTL's like 1 second or even 0 (which violates RFC's)
Post reply on HN