Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

41–50 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#41
post #27

A German podcaster who has been working on networks for decades once said that he owns a large chunk of public IP addresses in the 192.68.0.0/16 subnet and it's impossible for him to use it because once he activates it he basically gets a DDOS of misdirected traffic. So many misconfigured networks out there...

Freakshow \o/

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#43

Earlier quoted context omitted.

DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.

Does all this garbage traffic affect the performance of Cloudflare's servers? There must be some cost (performance and $$$) to filter this traffic. Was that a consideration when deciding whether to use 1.1.1.1 instead of some other IP address? :)

No. We have a lot of capacity. A lot.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#44
post #35

Earlier quoted context omitted.

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

Oh, I didn't realize that you're a CloudFlare cofounder. I don't mean to question CloudFlare's integrity. It's just that, for claims about privacy, I'd rather depend on more than trusting any one party.

Great. Use 1.1.1.1 and 8.8.8.8. You don’t depend on one party now?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#45
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

Are you aware that your public resolvers are actively breaking DNS-based GeoIP (striping EDNS0-ECN and not using source IPs geo-localized as the requester would be)? and if so, what is the rationale for it?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#46

Earlier quoted context omitted.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

>they can’t query anything on a specific user. What exactly do you mean by "user"? Can they query DNS traffic by IP address / subnet? Exactly what are all of the restrictions there? EDIT: Is there a whitelist of things they can query by or do you simply trust them to be good citizens, have a binding legal agreement, all of the above?

No. We have a legally binding agreement. And, more importantly, we don’t store or give them access to IPs or anything else that may be associated with any individual. Look at a DNS query, look at what could be identifying — let us know where concerns are. My hunch is we’ve thought of it. If not, we will fix. We don’t want personally identifiably info. It creates a legal risk for us. We purge it as quickly as we can.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#47
post #39
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

It's even easier to steal a phone number.

Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#48

I noticed an issue with several public WiFi hotspots after setting 1.1.1.1 as my primary DNS: The login/"landing" page when connecting to these hotspots would not load. Changing back to 8.8.8.8 fixed the problem.

That means they're intercepting requests to 8.8.8.8 (even if only before login), probably because of its popularity. It's a shame we still have to use these hacks to login; there's a solution for that in RFC7710 (which sends the captive portal information in DHCP), but who knows if and when it'll be adopted by most hotspots.

https://tools.ietf.org/html/rfc7710

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#49

Earlier quoted context omitted.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

From https://developers.cloudflare.com/1.1.1.1/commitment-to-priv... : "Specifically, APNIC will be permitted to access query names, query types, resolver location and other metadata via a Cloudflare API, that will allow APNIC to study topics like the volume of DDoS attacks launched on the Internet and adoption of IPv6." I interpret "query names" as some values obtained from DNS queries hitting 1.1.1.1, e.g. "foo.exa…

No querying IPs, ever. Nothing personally identifiable. APNIC can query things like: how many DNS queries come from the UK? How many query for google.com?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#50
post #35

Earlier quoted context omitted.

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

Oh, I didn't realize that you're a CloudFlare cofounder. I don't mean to question CloudFlare's integrity. It's just that, for claims about privacy, I'd rather depend on more than trusting any one party.

Even if you just use 1.1.1.1 you know you have 2 parties, cloudflare and their auditor.
Post reply on HN