Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

111–120 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#111

Earlier quoted context omitted.

A $12/hour call center customer retention worker in rural TN has no idea what you're complaining about, their job is simply to meet some retention metrics on a weekly basis. Even if you can actually reach the people who run the ASN of your ISPs, if it something big like Cox, charter, Shaw, etc, they'll be politically unable to confirm or deny anything, and won't want to talk to you. You might get a straight answer if…

Such are the joys of modern "customer support" -- human beings don't scale, because they need to sleep and can only talk to one other human at a time. So you hire the cheapest ones you can find, and instruct them to be minimally helpful. Even better, make them all "managers," so "can I please speak to your manager" will just take you to another minimum-wage employee. If you want actual customer support these days, yo…

In cases without competition. I live in an area with three gigabit-capable ISPs and the difference in support quality is unbelievable, even for the Comcast and Verizon customers – just calling from a competitive neighborhood gets your call processed differently.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#112

Earlier quoted context omitted.

What's in it for you guys? How do you make money off of 1.1.1.1? Thanks!

Brand. How much would you pay if you were us to associate your brand with privacy/security and speed? Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it. Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often becau…

> Our mission is to help build a better Internet.

I've been working a lot with open data and I have huge problem with Cloudflare ruining open internet with bot protection and such. The issue I have is that public data is public, be it bot or human.

I'm having real issue with you guys saying that your mission is to better the internet when you break shitton of floss apps that are essentially harmless and people who want to do harm, crawl at huge rates for commercial purposes break your systems like it's made of twigs. I'm saying this as a person who works on both sides and can't help but call you out.

So sorry unless you turn to non-profit I'm really not buying your "helping the internet" song.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#113

Earlier quoted context omitted.

I'm not a networking guy, but I'd like to try this. Can you explain how you would do it? (which tools, or a link to some docs would be nice)

Using radvd [1] is the easiest way with Linux. Or you can get it done using ICS on Windows. Personally I used burner laptop, with live distribution and runned radvd. Or if you like details, you can use Python Scapy on Linux to send RA packets. [1] http://www.litech.org/radvd/

Thanks. I'm on Linux, so I'll check out radvd.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#114

Earlier quoted context omitted.

"The service" is the DNS service. If you send random garbage to random IP addresses I think you waive the right to privacy.

>APNIC gets to see the noise as well as the DNS traffic >Huston emphasised that APNIC intends to protect users' privacy. "DNS is remarkably informative about what users do, if you inspect it closely, and none of us are interested in doing that," he said. Maybe it is reasonable to take them at their word as they seem trustworthy, but we should at least consider the fact that at least some of this DNS traffic is indeed…

I'm pretty sure that all the traffic is being analyzed. The only thing they publicly committed to is not saving your Ip address.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#115
post #96
post #33

Earlier quoted context omitted.

No, wait. Users of the DNS service get the privacy guarantee. Non-users do not. If you floodping 1.1.1.1 you are not a user of the DNS service and the privacy terms don't apply to you. Rather you're a member of the Misconfiguration Club, and the site you're pinging has the usual right to analyse your pings.

What if somebody has a bad DNS resolver and what he qualifies as a valid DNS request, researchers do not. I get the general idea, but having "user-privacy oriented" and "we collect everything and make it available to many researchers" services under the same IP may lead to some issues.

Oh, in that case you can apply those issues to all of Cloudflare. They serve many thousands of websites from each node. God only knows how many different privacy policies may apply depending on which bytes you send to TCP port 80.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#116

Earlier quoted context omitted.

No. We have a lot of capacity. A lot.

For ordinary singlehomed users who don't get the "a lot". As an example cloudflare has 40Gbps of capacity to the SIX in Seattle. I would guess that they also have direct, at minimum, 10Gbps PNI peering sessions with other huge ISPs in the Pacific Northwest which never see the SIX fabric. So probably add another 20 individual 10GbE circuits at bare minimum to that 40 figure. All of which helps spread the traffic load…

I don’t know the exact number, but you’re off by about an order of magnitude roughly. Cloudflare peering is in the terabits/sec range globally.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#117

Earlier quoted context omitted.

For ordinary singlehomed users who don't get the "a lot". As an example cloudflare has 40Gbps of capacity to the SIX in Seattle. I would guess that they also have direct, at minimum, 10Gbps PNI peering sessions with other huge ISPs in the Pacific Northwest which never see the SIX fabric. So probably add another 20 individual 10GbE circuits at bare minimum to that 40 figure. All of which helps spread the traffic load…

I don’t know the exact number, but you’re off by about an order of magnitude roughly. Cloudflare peering is in the terabits/sec range globally.

At many non profit IXes the interface size to the fabric is public data and published by both the IX and on peeringdb. Such as at the SIX. They have not yet upgraded to 1x100GbE.

Another regional example, they have 20Gbps to the VANIX.

What is opaque is the size and scale of their PNI peering, which parties generally don't share. For example in a mid sized city where Comcast is the cable monopoly they almost certainly use a 100GbE interface direct to Comcast for just that isp.

Yes the scale is terabits globally. But it is highly decentralized.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#118
post #111

Earlier quoted context omitted.

Such are the joys of modern "customer support" -- human beings don't scale, because they need to sleep and can only talk to one other human at a time. So you hire the cheapest ones you can find, and instruct them to be minimally helpful. Even better, make them all "managers," so "can I please speak to your manager" will just take you to another minimum-wage employee. If you want actual customer support these days, yo…

In cases without competition. I live in an area with three gigabit-capable ISPs and the difference in support quality is unbelievable, even for the Comcast and Verizon customers – just calling from a competitive neighborhood gets your call processed differently.

Which city?

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#119
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

Even for regular IPv4s you often get upwards of 20-40k SSH probes per day trying common passwords against root. IPv6 largely makes this go away since it's too big to brute force scan.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#120

Earlier quoted context omitted.

It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

PacketCable (VoIP over Cable internet) is even worse When it came out. If you wanted to "borrow" someone's phone number. All you had to do was clone the MAC address of the VoIP (EMTA) port If someone called the number. Both you and the victims phones would ring

Same with CDMA. Just had to copy the phone number and ESN. Boom whichever phone was closest to the tower would ring, if both phones wear pinging with near freq then both could receive the same SMS and call, but only one could be on a call at a time. No actual interception.

Things got a bit different with MDN and MIN were different to ESN pair. Calls still came but you couldn't auth or call out for data services.

It's all a bit old now, but look up QPST, QXDM for the past decade and 20 years ago look up Oki900.

Post reply on HN