Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

181–190 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#181

Earlier quoted context omitted.

Will these auditors guarantee that you won't wake up one morning after a troublesome sleep and start monitoring this to protect us against Nazis? Because that might be good to ensure we believe your word.

I have a problem with these comments because they're basically a false dichotomy. No, CloudFlare can't ensure they play fair. Can your ISP? Who can? Because these sorts of comments read to me as "yeah, you're the best right now, but are you perfect? No.". Nobody claimed perfection, and there's value in being the best.

Precisely. There's no perfect. OK, so I use IVPN. I've known a principal for many years. I write stuff for them. And I trust them to protect my privacy. More than any other VPN service. I also trust a few others, almost as much. And way more than I trust my ISP.

But I never depend on any one of them. I use nested chains. That's my no means perfect, because routes are relatively static, unlike Tor with its frequently changing circuits. But the basic idea is the same. Compromise would depend on collusion, perhaps forced, of multiple parties. Or some serious traffic analysis.

Here, there's CloudFlare, its auditors, and perhaps Google. So maybe there is distributed trust in that. But still, I'm happier to put more independent parties between me and them. Tor, or at least a nested VPN chain.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#182

Awesome, the worlds biggest honeypot? There is literally a finite amount of bandwidth in the existance, let Cloudflare have as much cruft as it wants.

Ignoring the Finite, but years ago, I was introduced to a company that basically did not use a whole routed and public /8 except for... honeypot research. Was a blast to see some of it and the warstories about how they where able to do some early warnings of nasties that where about to wreak havoc. Gave them a good insentive to actually design a pretty good toolingset, that never made it past "On Demand Innovation Se…

It seems you grasped my poorly worded comment. I think Cloudflare knows what they are doing, and I am happy they are taking a lot of the focus towards themselves, this good for everyone. And I hope they learn alot about dealing with nefarious traffic.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#183

Awesome, the worlds biggest honeypot? There is literally a finite amount of bandwidth in the existance, let Cloudflare have as much cruft as it wants.

I have no idea where you get the idea there is a finite amount of bandwidth available. It is not coal or molybdenum. ISPs are continually being expanded.

Well my comment got completely misunderstood.

There are only so many criminals in the world, period. They only have so much bandwidth, either through stealing it or buying it.

Also, I am happy Cloudflare is doing this, they are, at the very least, taking resources away from the criminals that could be attacking others and doing real harm.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#184
post #35

Earlier quoted context omitted.

Oh, I didn't realize that you're a CloudFlare cofounder. I don't mean to question CloudFlare's integrity. It's just that, for claims about privacy, I'd rather depend on more than trusting any one party.

Great. Use 1.1.1.1 and 8.8.8.8. You don’t depend on one party now?

Yes, thanks.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#185
post #35

Earlier quoted context omitted.

Oh, I didn't realize that you're a CloudFlare cofounder. I don't mean to question CloudFlare's integrity. It's just that, for claims about privacy, I'd rather depend on more than trusting any one party.

Even if you just use 1.1.1.1 you know you have 2 parties, cloudflare and their auditor.

There is that argument. But both are likely vulnerable to coercion from some adversaries. And of course, that's always a risk.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#186

Earlier quoted context omitted.

I solidly feel it’s a cop out for an ISP to not filter their traffic to block spoofed IPs. In my eyes, there’s zero legitimate reason that this guy should get flooded, but alas, our industry gets lazier and more careless each year.

There is no spoofing involved there. We're talking about typos of 192.168 (private space) typed as 192.68 which is "real" space. It is not like ISPs are leaking rfc1918 IP space.

Very true that it is a typo, which I had noticed, and thanks for calling out. Still doesn’t invalidate my point though. My theory is that a lot of that traffic is likely coming from spoofed IPs as I doubt there would be substantial sustained legitimate, but improperly directed, traffic. My guess is a lot of it is shoddily written malicious traffic.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#187

Earlier quoted context omitted.

I don’t know the exact number, but you’re off by about an order of magnitude roughly. Cloudflare peering is in the terabits/sec range globally.

At many non profit IXes the interface size to the fabric is public data and published by both the IX and on peeringdb. Such as at the SIX. They have not yet upgraded to 1x100GbE. Another regional example, they have 20Gbps to the VANIX. What is opaque is the size and scale of their PNI peering, which parties generally don't share. For example in a mid sized city where Comcast is the cable monopoly they almost certainl…

> But it is highly decentralized

Isn’t that the entire point of a CDN, to have decentralized POPs scattered globally?

Yes, they may max out at 100gb per public IX in most cases, but they still have lots of 100gb peers all over the globe.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#188

Earlier quoted context omitted.

At many non profit IXes the interface size to the fabric is public data and published by both the IX and on peeringdb. Such as at the SIX. They have not yet upgraded to 1x100GbE. Another regional example, they have 20Gbps to the VANIX. What is opaque is the size and scale of their PNI peering, which parties generally don't share. For example in a mid sized city where Comcast is the cable monopoly they almost certainl…

> But it is highly decentralized Isn’t that the entire point of a CDN, to have decentralized POPs scattered globally? Yes, they may max out at 100gb per public IX in most cases, but they still have lots of 100gb peers all over the globe.

Yes, it's exactly the point. What I was saying is I am not off by an order of magnitude, I know exactly how big they are. Two ASes I do engineering work for peer directly with cloudflare.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#189
post #39

Earlier quoted context omitted.

Wow I’m surprised. That is such a low barrier to doing your own BGP hijackig.

It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

As someone who has tried to port about 1,100 phone numbers last year, this couldn't be further from the truth. Getting numbers ported is a GIGANTIC pain in the ass with ANY small detail being wrong will reject the entire batch. Since the slamming problem in the 90s it's been increasingly hard to port phone numbers without every T crossed and every I dotted exactly right.
Post reply on HN