Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

51–60 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#51

Earlier quoted context omitted.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

Hello, Are the gigabytes of junk billions of tiny requests or are there large requests as well? Are you finding it more difficult than expected to manage the data? I'm a 1.1.1.1 customer since you launched, thanks a lot for it.

Nope. We have a lot of excess capacity. Doesn’t increase our costs. But, that’s a longer conversation…

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#52

Earlier quoted context omitted.

Neither we nor APNIC can query “what” or “how many” requests from any IP have been made. We can query things like: 1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers? If you have specific concerns, please raise them here.

What's in it for you guys? How do you make money off of 1.1.1.1? Thanks!

I guess they don't, they just make a better internet, which helps their customers of their other services, and the rest of us. Seems like so good old fashioned altruism to me.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#53
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

As an ex-Comcast employee. Seeing stuff like that happen really doesn't surprise me

When Comcast first rolled out that data cap nation wide, I started prodding at it one night out of morbid curiosity

Turned out that it would silently slurp all HTTP traffic! Once you hit some arbitrary measurement (EG: 50%) it'll immediately start hijacking all HTTP websites you visit and inject a ton of Javascript to put a message over the web page forcing you to acknowledge your cap

Nmapping the server they used caused the messages to immediately disappear. As well as the server to seemingly vanish. Turned out the firewall was just blanket banning the entire IP range when it saw a portscan!

The upside being that Comcast would stop MITM'ing HTTP traffic for about 72 hours

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#54
post #39

Earlier quoted context omitted.

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

PacketCable (VoIP over Cable internet) is even worse

When it came out. If you wanted to "borrow" someone's phone number. All you had to do was clone the MAC address of the VoIP (EMTA) port

If someone called the number. Both you and the victims phones would ring

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#55

Earlier quoted context omitted.

Neither we nor APNIC can query “what” or “how many” requests from any IP have been made. We can query things like: 1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers? If you have specific concerns, please raise them here.

What's in it for you guys? How do you make money off of 1.1.1.1? Thanks!

Brand. How much would you pay if you were us to associate your brand with privacy/security and speed?

Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it.

Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often because employees believe in our mission. 1.1.1.1 helps with that.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#56
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

As an ex-Comcast employee. Seeing stuff like that happen really doesn't surprise me When Comcast first rolled out that data cap nation wide, I started prodding at it one night out of morbid curiosity Turned out that it would silently slurp all HTTP traffic! Once you hit some arbitrary measurement (EG: 50%) it'll immediately start hijacking all HTTP websites you visit and inject a ton of Javascript to put a message ov…

And people wonder why https everywhere is such a necessity now. It should not be necessary to treat your last mile ISP as a hostile entity , but sadly, it often is.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#57
post #5

I used to play a game where each kingdom had an address (kingdom:island) if you where on kingdom one on island one (1:1) you would get attacked all the time no matter how much defense you had. If you landed on 1:1 you where basically doomed.

Utopia, right?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#58
post #27

A German podcaster who has been working on networks for decades once said that he owns a large chunk of public IP addresses in the 192.68.0.0/16 subnet and it's impossible for him to use it because once he activates it he basically gets a DDOS of misdirected traffic. So many misconfigured networks out there...

Did he say what the volume was in Gbps? Consideirng the market value of a /16 now for residential use DHCP pools, it could be easily leased via LOA to a huge ISP that would get most of the shit traffic via settlement free peering on N x 10/100Gbps ports, distributed between many cities. If it's like 15Gbps of constant junk I could still find a way to make it useful. Probably would need to nullroute the most common /24s like 192.68.1.0/24 , so you'd lose the equivalent of a /22 to that.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#59
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

I think everyone's concern should be that Cloudflare or Google might just replace each IP in their 24h logs with a random UUID and call it anonymized. Both companies can potentially store enough information to correlate DNS requests with regular traffic logs.

It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www.example.com at the same location a few milliseconds later.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#60
post #39
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

Any sane bgp neighbor has prefix limit ACLs and prefix filters in place on their edge connections to another peer. As an ISP that announces a lot of space and customer space to 2 upstream transits, every time we take on a new downstream customer that brings their own /24 or bigger, we need to have our upstream transit providers update their prefix-list filters.

If our upstreams were clueless or negligent, it would be possible to get into a situation such as when a Pakistani telecom announced a huge chunk of V4 space that is YouTube, effectively DDoSing their international submarine links and also taking down YouTube for some users worldwide.

Post reply on HN