Earlier quoted context omitted.
I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…
Hello, Are the gigabytes of junk billions of tiny requests or are there large requests as well? Are you finding it more difficult than expected to manage the data? I'm a 1.1.1.1 customer since you launched, thanks a lot for it.
Cloudflare's new DNS attracting 'gigabits per second' of rubbish
51–60 of 206 posts
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#52Earlier quoted context omitted.
Neither we nor APNIC can query “what” or “how many” requests from any IP have been made. We can query things like: 1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers? If you have specific concerns, please raise them here.
What's in it for you guys? How do you make money off of 1.1.1.1? Thanks!
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#53I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…
When Comcast first rolled out that data cap nation wide, I started prodding at it one night out of morbid curiosity
Turned out that it would silently slurp all HTTP traffic! Once you hit some arbitrary measurement (EG: 50%) it'll immediately start hijacking all HTTP websites you visit and inject a ton of Javascript to put a message over the web page forcing you to acknowledge your cap
Nmapping the server they used caused the messages to immediately disappear. As well as the server to seemingly vanish. Turned out the firewall was just blanket banning the entire IP range when it saw a portscan!
The upside being that Comcast would stop MITM'ing HTTP traffic for about 72 hours
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#54Earlier quoted context omitted.
Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.
It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.
When it came out. If you wanted to "borrow" someone's phone number. All you had to do was clone the MAC address of the VoIP (EMTA) port
If someone called the number. Both you and the victims phones would ring
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#55Earlier quoted context omitted.
Neither we nor APNIC can query “what” or “how many” requests from any IP have been made. We can query things like: 1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers? If you have specific concerns, please raise them here.
What's in it for you guys? How do you make money off of 1.1.1.1? Thanks!
Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it.
Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often because employees believe in our mission. 1.1.1.1 helps with that.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#56I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…
As an ex-Comcast employee. Seeing stuff like that happen really doesn't surprise me When Comcast first rolled out that data cap nation wide, I started prodding at it one night out of morbid curiosity Turned out that it would silently slurp all HTTP traffic! Once you hit some arbitrary measurement (EG: 50%) it'll immediately start hijacking all HTTP websites you visit and inject a ton of Javascript to put a message ov…
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#57I used to play a game where each kingdom had an address (kingdom:island) if you where on kingdom one on island one (1:1) you would get attacked all the time no matter how much defense you had. If you landed on 1:1 you where basically doomed.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#58A German podcaster who has been working on networks for decades once said that he owns a large chunk of public IP addresses in the 192.68.0.0/16 subnet and it's impossible for him to use it because once he activates it he basically gets a DDOS of misdirected traffic. So many misconfigured networks out there...
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#59Earlier quoted context omitted.
It was reworded enough times to make their promise vague and not well defined.
I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…
It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www.example.com at the same location a few milliseconds later.
Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish
#60I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…
Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.
If our upstreams were clueless or negligent, it would be possible to get into a situation such as when a Pakistani telecom announced a huge chunk of V4 space that is YouTube, effectively DDoSing their international submarine links and also taking down YouTube for some users worldwide.