Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

61–70 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#61

Earlier quoted context omitted.

DNS traffic, no. Random garbage traffic misdirected to 1.1.1.1, APNIC is studying.

Does all this garbage traffic affect the performance of Cloudflare's servers? There must be some cost (performance and $$$) to filter this traffic. Was that a consideration when deciding whether to use 1.1.1.1 instead of some other IP address? :)

Cloudflare is anycast announcing the space from something like 30 to 50 unique POPs worldwide, so the volume of shit traffic is significantly decentralized. It's not like 40 Gbps is hitting one location.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#62
post #59

Earlier quoted context omitted.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

I think everyone's concern should be that Cloudflare or Google might just replace each IP in their 24h logs with a random UUID and call it anonymized. Both companies can potentially store enough information to correlate DNS requests with regular traffic logs. It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www…

We're not storing the source IP addresses in any form. Not raw, not "transformed", not anonymized, not hashed. They are not being stored.

Our business is not about tracking people; it's about selling our service to businesses to make their web sites/APIs/applications faster and more secure.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#63
post #39

Earlier quoted context omitted.

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS directed towards any number you want, and also be able to send out texts originating from that number. Anyone who relies on SMS for any type of authentication should stop.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#64
post #16

> AT&T Gigapower using 1.1.1.1 on an internal interface on at least one model of router-gateway, the Pace 5268AC Yup. I can't use 1.1.1.1 because my AT&T router is responding to it.

"Whatever just use 1.1.1.1! Nobody will ever use that address!"

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#65

Earlier quoted context omitted.

Hello, Are the gigabytes of junk billions of tiny requests or are there large requests as well? Are you finding it more difficult than expected to manage the data? I'm a 1.1.1.1 customer since you launched, thanks a lot for it.

Nope. We have a lot of excess capacity. Doesn’t increase our costs. But, that’s a longer conversation…

Neteng here: without seeing the traffic charts for individual interfaces and aggregations, I would bet cloudflare has a shitload of excess inbound capacity. They are a content pushing CDN. I would bet that at a major IX where they have one 100Gbps port that their out:in ratio is 90:10 or greater. So if they only have 6-9 Gbps of traffic inbound on a 100GbE port to a fabric consisting of 80+ bgp peers, they have a lot of extra capacity to absorb unwanted inbound traffic before it becomes an operational concern.

Have seen edge traffic charts for major porn hosting companies and the out:in traffic ratio is like 97:3

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#66

Awesome, the worlds biggest honeypot? There is literally a finite amount of bandwidth in the existance, let Cloudflare have as much cruft as it wants.

I have no idea where you get the idea there is a finite amount of bandwidth available. It is not coal or molybdenum. ISPs are continually being expanded.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#67
post #63

Earlier quoted context omitted.

It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS dir…

SS7 was designed in an era of huge Monopoly telecoms that all trusted each other. Worked fine. Needs to be burnt to the ground, the ashes stomped around on a bit, and rebuilt with the same level of thought that has gone into the development of TLS1.3 for modern use. Won't happen though due to the sheerly massive installed base of telecom gear worldwide.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#68
post #8

I worked with my ISP, htcinc.net to fix routing to 1.1.1.1 this week -- Not sure how they had their core router mis-configured, but it was dropping the traffic.

Most likely had an old copied-pasted bogon filter in place for a huge chunk of previously unannounced APNIC IP space.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#69

Earlier quoted context omitted.

As an ex-Comcast employee. Seeing stuff like that happen really doesn't surprise me When Comcast first rolled out that data cap nation wide, I started prodding at it one night out of morbid curiosity Turned out that it would silently slurp all HTTP traffic! Once you hit some arbitrary measurement (EG: 50%) it'll immediately start hijacking all HTTP websites you visit and inject a ton of Javascript to put a message ov…

And people wonder why https everywhere is such a necessity now. It should not be necessary to treat your last mile ISP as a hostile entity , but sadly, it often is.

I canceled my decade old COX account last time that happened. Even asked nicely not to "help" by editing traffic, the runaround was fun. At the end they offered to take my ~$90/mo to ~$70; re-confirming they had no idea what I was unhappy about.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#70
post #3

Houston has run a study on the traffic being directed towards 1/8 before. http://www.potaroo.net/studies/1slash8/1slash8.html

Very interesting how the volume of shit traffic to /24s which were not in the "typical" example/documentation ranges like 1.1.1.0/24 was much lower. When they announced the whole /8 and plotted the traffic only a few /24 receive huge volumes of shit, while others receive (relatively) little, like 8Mbps.
Post reply on HN