Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

81–90 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#81

Earlier quoted context omitted.

@eastdakota what about just failing without response on archive.is calls so the second resolver address configured in the client will be used? I understand this is also a DNS integrity violation, however the result for the end user would be either the same if they don’t have a second resolver configured or enhanced if they do. The current effect is I stop using 1.1.1.1 when I need archive.is (often) and set it back t…

Also: it'd be nice if CloudFlare made a secondary DNS resolver (1.1.2.2?) that didn't pass along EDNS information, as a backup for websites like archive.is (and for anyone who cares about privacy).

I think you may have typo’d, but just in case:

1.1.1.1 does not send EDNS ECS data, specifically because of the privacy concern. So the hypothetical secondary resolver would need to send that data, for people who aren’t concerned about the privacy implications / want to get to archive.is.

Given CloudFlare’s stated message of prioritizing privacy, it seems unlikely they’d stand up infrastructure that behaved like 1.1.1.1 except that it leaked more private information.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#82

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

If the govt of your jurisdiction (American I assume?) commanded you to censor a certain domain or block of IPs with a court order, what exactly happens? I'm not sure if this has been done on the DNS level before but do you guys have a plan in case it ever does happen?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#83
post #72

Earlier quoted context omitted.

See the CEO's comment: https://news.ycombinator.com/item?id=19828702 > We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1. So it's not just "Cloudflare benefits from pushing anycast" (even if that's part of it).

So, what he claims is that state actors monitor traffic at certain locations, extract subnet information from DNS packets that only large centralized DNS resolvers include when query some authoritative servers that where probed to support that feature. That subnet is not a subnet of an end user IP address, but an IP address of a recursive resolver of that user's ISP. They have to correlate that information with a con…

1.1.1.1 supports dns/https. It is entirely possible to make a request to 1.1.1.1 for an ip and have nobody be able to know what you made the request for.

There is no guarantee the name server they are querying is the same as the server in the A result, and the idea is to reduce the number of points where people other than the A result and the client know that they plan to talk to each other.

It's not bullshit.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#84

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Encrypting dns is bad for end users. Please cut this shit out. You are acting like you are defending against the NSA, but in reality we will have a bunch of shitty IoT phoning data to indecipherable IP addresses without any meaningful defense of consumer privacy.

It is hostile to customers who want to troubleshoot wtf apps are doing.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#85

Earlier quoted context omitted.

Does anyone know why archive.is would block Cloudflare? Is it a technical issue, or does the owner of archive.is have some kind of grudge against them?

Hard to tell from the outside, but archive.is did blacklist the whole of Finland a while back - due to personal grudge.

Who runs archive.is? Sounds childish without knowing any of the facts.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#86

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

@eastdakota what about just failing without response on archive.is calls so the second resolver address configured in the client will be used? I understand this is also a DNS integrity violation, however the result for the end user would be either the same if they don’t have a second resolver configured or enhanced if they do. The current effect is I stop using 1.1.1.1 when I need archive.is (often) and set it back t…

If you're going to that much trouble I suggest you just hardcode an IP address for archive.is into /etc/hosts. I've only had to change it once in the whole time I've used Cloudflare DNS (i.e. since the first day it was public).

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#87
post #37
post #33

Earlier quoted context omitted.

This diverges pretty hard from your earlier comparison, between this scenario and the Linux kernel breaking userspace. If a dev updates their code so it won’t run unless an kernel flag is enabled, the kernel hasn’t broken userspace, and kernel devs are unlikely to add a “fake-enabled-flag” to trick the userspace program, even if it’s popular. Likewise, I don’t expect my DNS resolver to add in custom behavior if upstr…

Besides, my reading is: Every other resolver supports EDNS Archive.is only works with resolvers that support EDNS Cloudflare decided not to support EDNS That itself is a defendable decision but I do feel for a popular site they could implement some sort of fix.

They need something that works for all sites.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#88
post #14

This has been a known issue for a while. Unfortunately, Archive.is has to fix it from their nameservers and we cannot do anything from our side. You can ready more about it here: https://community.cloudflare.com/t/archive-is-error-1001/182... Disclaimer: I work at Cloudflare

The person or persons running the site have a history of very stubborn behaviour. I do appreciate the service they are running.

One time they blocked the whole Finland because the owner had problems with customs and somehow related the incident with Russia while saying Finnish gov and bur businesses can never be independent.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#89

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Awesome response! Is there already a blog post on this?

Such a post might A) get better SEO than an HN thread for 'cannot access archive.is [or ...]' and B) help change its behaviour.

Post reply on HN