Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

91–100 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#91
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

> I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk.

Is there a guarantee that this will always be the case? Might there, in theory, be a point in the future where users' IPs are collected and stored?

Loving 1.1.1.1, btw.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#92
post #69

Earlier quoted context omitted.

I canceled my decade old COX account last time that happened. Even asked nicely not to "help" by editing traffic, the runaround was fun. At the end they offered to take my ~$90/mo to ~$70; re-confirming they had no idea what I was unhappy about.

A $12/hour call center customer retention worker in rural TN has no idea what you're complaining about, their job is simply to meet some retention metrics on a weekly basis. Even if you can actually reach the people who run the ASN of your ISPs, if it something big like Cox, charter, Shaw, etc, they'll be politically unable to confirm or deny anything, and won't want to talk to you. You might get a straight answer if…

Such are the joys of modern "customer support" -- human beings don't scale, because they need to sleep and can only talk to one other human at a time. So you hire the cheapest ones you can find, and instruct them to be minimally helpful. Even better, make them all "managers," so "can I please speak to your manager" will just take you to another minimum-wage employee.

If you want actual customer support these days, your best bet is to create a PR problem for the company via social media, because PR flacks are paid enough to matter.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#93
post #27

A German podcaster who has been working on networks for decades once said that he owns a large chunk of public IP addresses in the 192.68.0.0/16 subnet and it's impossible for him to use it because once he activates it he basically gets a DDOS of misdirected traffic. So many misconfigured networks out there...

Freakshow \o/

I can understand why this comment was downvoted without any further context, but yes, the podcaster's name is Clemens Schrimpe and he probably mentioned that fact in the German podcast "Freak Show": https://freakshow.fm/

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#94
post #19

Earlier quoted context omitted.

But that's just a Cloudflare policy, isn't it? Or are you arguing that even Cloudflare couldn't get raw DNS traffic?

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

Will these auditors guarantee that you won't wake up one morning after a troublesome sleep and start monitoring this to protect us against Nazis? Because that might be good to ensure we believe your word.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#95
post #87

From a marketing point of view, I think it was a brilliant move from Cloudflare to get the 1.1.1.1 address. Clearly better than 8.8.8.8! But from a user perspective, why couldn't they have just let that address be... So many things are going to break just because Cloudflare wants a pretty IP. Sure, the things that break were using a hack, but in my opinion that doesn't automatically make it okay to break it. Now I'm…

example.com (and other example.*) is reserved for documentation purposes, i.e. you can't buy it.

Like blocks 192.0.2.0/24 (TEST-NET-1), 198.51.100.0/24 (TEST-NET-2) and 203.0.113.0/24 (TEST-NET-3) from rfc5737? Or is it to new, maybe 192.0.2.0/24 from rfc2119 is better? There is a few test-nets for documentation, just like example.com.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#96
post #33

Earlier quoted context omitted.

>APNIC gets to see the noise as well as the DNS traffic >Huston emphasised that APNIC intends to protect users' privacy. "DNS is remarkably informative about what users do, if you inspect it closely, and none of us are interested in doing that," he said. Maybe it is reasonable to take them at their word as they seem trustworthy, but we should at least consider the fact that at least some of this DNS traffic is indeed…

No, wait. Users of the DNS service get the privacy guarantee. Non-users do not. If you floodping 1.1.1.1 you are not a user of the DNS service and the privacy terms don't apply to you. Rather you're a member of the Misconfiguration Club, and the site you're pinging has the usual right to analyse your pings.

What if somebody has a bad DNS resolver and what he qualifies as a valid DNS request, researchers do not.

I get the general idea, but having "user-privacy oriented" and "we collect everything and make it available to many researchers" services under the same IP may lead to some issues.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#97

Earlier quoted context omitted.

That’s our policy and we’ve hired outside auditors to ensure we’re honoring it. If you have suggestions of what else we can do to prove we’re a company of our word, LMK.

Will these auditors guarantee that you won't wake up one morning after a troublesome sleep and start monitoring this to protect us against Nazis? Because that might be good to ensure we believe your word.

I have a problem with these comments because they're basically a false dichotomy. No, CloudFlare can't ensure they play fair. Can your ISP? Who can?

Because these sorts of comments read to me as "yeah, you're the best right now, but are you perfect? No.". Nobody claimed perfection, and there's value in being the best.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#98

From a marketing point of view, I think it was a brilliant move from Cloudflare to get the 1.1.1.1 address. Clearly better than 8.8.8.8! But from a user perspective, why couldn't they have just let that address be... So many things are going to break just because Cloudflare wants a pretty IP. Sure, the things that break were using a hack, but in my opinion that doesn't automatically make it okay to break it. Now I'm…

8.8.8.8 goes pretty well in the Chinese market. (8 being a popular number.) I think 1.1.1.1 is not such a hit.

Fa.Fa.Fa.Fa

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#99

If your ISP doesn't support IPv6, just try sending RA packets upstream and see what happens. If they're doing it wrong using blacklist instead of whitelist, then it might well leak. It's good to notice, that this doesn't affect IPv4 networking in any way.

I'm not a networking guy, but I'd like to try this. Can you explain how you would do it? (which tools, or a link to some docs would be nice)

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#100

Earlier quoted context omitted.

Will these auditors guarantee that you won't wake up one morning after a troublesome sleep and start monitoring this to protect us against Nazis? Because that might be good to ensure we believe your word.

I have a problem with these comments because they're basically a false dichotomy. No, CloudFlare can't ensure they play fair. Can your ISP? Who can? Because these sorts of comments read to me as "yeah, you're the best right now, but are you perfect? No.". Nobody claimed perfection, and there's value in being the best.

Cloudfares CEO was guaranteeing that they have an external auditors to ensure the company keeps its word. I'm asking whether the same auditors can ensure that the CEO himself won't decide one morning to go against this word wrt this topic. In the same way that a ToS might state "we will never sell your data to third parties" and a CEO can't break that promise, what guarantee beyond "some external people are looking at what we do" and "oh, just trust me" do we actually have? Im asking if the auditors will also guarantee the CEOs word.

This is relevant as the CEO has previously woken up one morning after a troublesome sleep and it has been argued, gone against his word (for good and anti nazi reasons). Many argue that he was entirely within his right to do so, and he was! So in this case, would he be entirely within his right to start monitoring all that data. As he asks, paraphrasing: "what more can I do to ensure my word is good."

Post reply on HN