Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

131–140 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#131

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

archive.is is a very important tool in online extremism research and you've taken money from far-right extremists, your explanation for why it's inaccessible seems incomplete. This is probably where I get banned from Hn but it has to be said - to posture as if you care about end users while in the same breath taking money from extremists and turning over personal identifiable information to far-right outlets like Dai…

[deleted]

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#132
post #123

Earlier quoted context omitted.

If the govt of your jurisdiction (American I assume?) commanded you to censor a certain domain or block of IPs with a court order, what exactly happens? I'm not sure if this has been done on the DNS level before but do you guys have a plan in case it ever does happen?

Or you know you Piss off CloudFare CEO and he directs them to censor a site... Which has happened in the past

Exactly. If it's not "the right kind" of content behind a domain, it doesn't even take a court order for CloudFlare to censor it.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#133

Earlier quoted context omitted.

@eastdakota what about just failing without response on archive.is calls so the second resolver address configured in the client will be used? I understand this is also a DNS integrity violation, however the result for the end user would be either the same if they don’t have a second resolver configured or enhanced if they do. The current effect is I stop using 1.1.1.1 when I need archive.is (often) and set it back t…

DNS either has integrity or it doesn’t. We get a response from an Authoritative server and, as a Resolver, we believe our responsibility is to return it. If we start making exceptions because of bad PR, how can you trust us to do the right thing when the stakes are even higher (e.g., nationstate pressure)? As an aside, I used to think that when Emerson said that “a foolish consistency is the hobgoblin of little minds…

[deleted]

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#134
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

I use it because I'd rather tell Google than my government, which is not on friendly terms with either US or Google.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#135
post #126

Earlier quoted context omitted.

archive.is is a very important tool in online extremism research and you've taken money from far-right extremists, your explanation for why it's inaccessible seems incomplete. This is probably where I get banned from Hn but it has to be said - to posture as if you care about end users while in the same breath taking money from extremists and turning over personal identifiable information to far-right outlets like Dai…

This is amusing, They Banned the DailyStormer which I why I will never support them. While I disagree 100% with the DailyStormer it is not up to cloudflare to decide who can and can not speak, who can and can not access the internet. The concept of Free Speech is the most important right we have as humanity, while I may not agree with some peoples words I will fight for their right to say those words And do not even…

race, sex, age, etc.

Where does daily stormer fall in the “etc.” part?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#136

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Well no, CloudFlare doesn't get to talk about not "violating the integrity of DNS" after you stopped responding to "any" queries in violation of the standard. You started by doing your own thing and then proposed a change to the standard to fit your business decision. [0] [0] https://www.rfc-editor.org/info/rfc8482

There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#137
post #126

Earlier quoted context omitted.

archive.is is a very important tool in online extremism research and you've taken money from far-right extremists, your explanation for why it's inaccessible seems incomplete. This is probably where I get banned from Hn but it has to be said - to posture as if you care about end users while in the same breath taking money from extremists and turning over personal identifiable information to far-right outlets like Dai…

This is amusing, They Banned the DailyStormer which I why I will never support them. While I disagree 100% with the DailyStormer it is not up to cloudflare to decide who can and can not speak, who can and can not access the internet. The concept of Free Speech is the most important right we have as humanity, while I may not agree with some peoples words I will fight for their right to say those words And do not even…

I think you're being downvoted because of the bit about regulation. At least, that is what I choose to believe, because imagine our state of affairs if you are being downvoted because of your comments about the idea of free speech.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#138
post #81

Earlier quoted context omitted.

Also: it'd be nice if CloudFlare made a secondary DNS resolver (1.1.2.2?) that didn't pass along EDNS information, as a backup for websites like archive.is (and for anyone who cares about privacy).

I think you may have typo’d, but just in case: 1.1.1.1 does not send EDNS ECS data, specifically because of the privacy concern. So the hypothetical secondary resolver would need to send that data, for people who aren’t concerned about the privacy implications / want to get to archive.is. Given CloudFlare’s stated message of prioritizing privacy, it seems unlikely they’d stand up infrastructure that behaved like 1.1.…

My apologies! I misread the OP and thought that CloudFlare was being accused of violating privacy. Instead, it seems that CloudFlare is definitely making the right choice, and I can't see why archive.is has any objection.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#139
post #109

Earlier quoted context omitted.

EDNS is a working system today, doesn't seem that hacky to use it until a new system is actually ready (which doesn't seem to be anytime soon anyway).

It works if you don't care about privacy

The suggestion was to use the EDNS of the datacenter server, how does that ruin privacy?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#140

I remember reading this a while back. It sounded more that archive.is was blocking Cloudflare (or at least not supporting it): https://community.cloudflare.com/t/archive-is-error-1001/182...

Does anyone know why archive.is would block Cloudflare? Is it a technical issue, or does the owner of archive.is have some kind of grudge against them?

Cloudflare uses "privacy" and "caring about users" as excuses to sabotage competing CDNs (including whatever CDN is used by archive.is).

Most recursive DNS severs on Internet can be categorized in two groups: local DNS servers, offered by Internet providers to their users, and enormous "generic" DNS like Google's 8.8.8.8. When someone makes a DNS request to those servers, they will in turn forward it to DNS servers of web page you are requesting. Content Delivery Networks use DNS to determine, which server should serve your request: if your DNS request arrived from Africa, CDN's DNS server will return IP in Africa. Of course, _users_ don't send DNS requests to CDN's server — recursive DNS servers do. In the past almost everyone used DNS, offered by their Internet provider, — CDN's had to use GeoIP or even static lists of providers to determine origin of that request. When world-wide DNS servers like Google's 8.8.8.8 started to gain popularity, that approach was broken, so EDNS was developed.

Cloudflare is a CDN. They are selling their CDN services for money. At the same time they are encouraging end users to use free DNS server, that does not support EDNS on purpose (they admit so on their website). In effect they are creating a situation, when competing CDNs are at disadvantage and can't determine, what country user comes from. Cloudflare itself does not suffer from that disadvantage, because they control both 1.1.1.1 and DNS, used by their clients' websites.

Post reply on HN