Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

161–170 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#161

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Thanks for the explanation. One more reason to keep using you instead of anything else.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#162
post #123

Earlier quoted context omitted.

Or you know you Piss off CloudFare CEO and he directs them to censor a site... Which has happened in the past

Can you cite any source on this?

It's a reference to https://www.businessinsider.com/the-daily-stormer-got-pushed...

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#163

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Alternatively: Cloudflare simply is making a subversive play against their competitor CDNs. Client subnet of a DNS request is used for initial rough mapping by Cloudflare competitors such as Akamai (definitely) and I believe Fastly ( and probably others) . Stripping it easily adds at least a few milliseconds to the time to first byte and most likely results a request re-routing on the second or third request. After a…

As this is related to CDN, I am gonna leave it here.

The irony is one.one.one.one is marketed as getaway to faster internet, while making CDNs that use GeoDNS slower.

All it takes is a bad route to a far away cloudflare POP to make your internet really slower. Case in point. [1]

I really don't find why no EDNS is considered private, as it only sends the IP subnet.[2] And on IPv6 the IP is far more protected.

If you care that much about privacy, you should be using a VPN.

[1] https://pastebin.com/raw/QnbWXU1a

[2] https://tools.ietf.org/html/rfc7871#section-11.1

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#164

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Encrypting dns is bad for end users. Please cut this shit out. You are acting like you are defending against the NSA, but in reality we will have a bunch of shitty IoT phoning data to indecipherable IP addresses without any meaningful defense of consumer privacy. It is hostile to customers who want to troubleshoot wtf apps are doing.

In my country, government/ISP blocks websites and changes the DNS results of 8.8.8.8 since it is not encrypted. If ISP can create a valid certificate, that browsers trust [1], they may be able to access my Gmail or Github account.

[1] https://www.zdnet.com/article/mozilla-to-chinas-wosign-well-...

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#165

Earlier quoted context omitted.

Does anyone know why archive.is would block Cloudflare? Is it a technical issue, or does the owner of archive.is have some kind of grudge against them?

Cloudflare uses "privacy" and "caring about users" as excuses to sabotage competing CDNs (including whatever CDN is used by archive.is). Most recursive DNS severs on Internet can be categorized in two groups: local DNS servers, offered by Internet providers to their users, and enormous "generic" DNS like Google's 8.8.8.8. When someone makes a DNS request to those servers, they will in turn forward it to DNS servers o…

I think your accusations are factually incorrect. EDNS was created back in 1999 (RFC2671[0]) waaaaay before Google's 8.8.8.8 in 2009.

And Cloudflare is EDNS-compliant. They simply choose not to enable the optional EDNS extension released in 2016 for sending the client subnet for privacy reasons.

Here's what RFC7871 – Client Subnet in DNS Queries[1] says about itself (emphasis mine):

This document defines an EDNS0 [RFC6891] option to convey network information that is relevant to the DNS message. It will carry sufficient network information about the originator for the Authoritative Nameserver to tailor responses. It will also provide for the Authoritative Nameserver to indicate the scope of network addresses for which the tailored answer is intended. This EDNS0 option is intended for those Recursive Resolvers and Authoritative Nameservers that would benefit from the extension and not for general purpose deployment. This is completely optional and can safely be ignored by servers that choose not to implement or enable it.

As far as I know, the standard practice, before this optional EDNS extension was to do GeoDNS based on the resolver's IP. This works just fine, including in the case of Cloudflare, since they've got 150+ POPs with each resolving on their own. That's higher density than most CDNs.

[0]: https://tools.ietf.org/html/rfc2671

[1]: https://tools.ietf.org/html/rfc7871

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#166
post #39

Earlier quoted context omitted.

Are there any other known sites that don't work with 1.1.1.1 but work fine on other resolvers?

I (random HN user) happen to know of lancaster.ac.uk (there was a comment thread a while back where this was mentioned).

In what way doesn't it work? This is with my ISP's DNS (using which I can visit https://www.lancaster.ac.uk/ in a browser):

  $ host -t a lancaster.ac.uk
  lancaster.ac.uk has address 148.88.65.80
and this is with Cloudflare's:

  $ host -t a lancaster.ac.uk 1.1.1.1
  Using domain server:
  Name: 1.1.1.1
  Address: 1.1.1.1#53
  Aliases: 
  
  lancaster.ac.uk has address 148.88.65.80
Looks the same to me.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#167
post #126

Earlier quoted context omitted.

This is amusing, They Banned the DailyStormer which I why I will never support them. While I disagree 100% with the DailyStormer it is not up to cloudflare to decide who can and can not speak, who can and can not access the internet. The concept of Free Speech is the most important right we have as humanity, while I may not agree with some peoples words I will fight for their right to say those words And do not even…

I think you're being downvoted because of the bit about regulation. At least, that is what I choose to believe, because imagine our state of affairs if you are being downvoted because of your comments about the idea of free speech.

Then you are new to HN...

Silicon Valley is full of Authoritarians that believe the Tech Companies should be our overlords and be allowed to choose what "truth" is, and who can revel that "truth" to you

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#168
post #126

Earlier quoted context omitted.

This is amusing, They Banned the DailyStormer which I why I will never support them. While I disagree 100% with the DailyStormer it is not up to cloudflare to decide who can and can not speak, who can and can not access the internet. The concept of Free Speech is the most important right we have as humanity, while I may not agree with some peoples words I will fight for their right to say those words And do not even…

race, sex, age, etc. Where does daily stormer fall in the “etc.” part?

Never said it did, etc was in reference to other protected classes in the list which vary by state.

Many states, including California, have political ideology has a protected class as well.

IMO companies run a foul of that when they start banning people for subjective ideology based reasons like "hate speech" which is not illegal in the US, and is every much based in political ideology to make the determination as to what is "hate".

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#169
post #123

Earlier quoted context omitted.

Or you know you Piss off CloudFare CEO and he directs them to censor a site... Which has happened in the past

Can you cite any source on this?

https://blog.cloudflare.com/why-we-terminated-daily-stormer/

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#170
post #146
post #126

Earlier quoted context omitted.

This is amusing, They Banned the DailyStormer which I why I will never support them. While I disagree 100% with the DailyStormer it is not up to cloudflare to decide who can and can not speak, who can and can not access the internet. The concept of Free Speech is the most important right we have as humanity, while I may not agree with some peoples words I will fight for their right to say those words And do not even…

Yes, I want them to censor lies and misleading speech. People or services that feed the public dangerous misinformation should be silenced. I realize that’s a slippery slope, but I just don’t trust the public to filter for themselves any more.

So who should be the arbitrator of truth? You do understand that I can cite many many many many many examples though out history where actual truth was suppressed, actual advancement was suppressed by those in power.

Free Speech is the most powerful tool Minorities and oppressed people through out the world have to end their oppression, and you just want to strip it away because of fear...

How can you not see how utterly dangerous this idea is, how can you ignore all of human history to believe it is a good idea to suppress speech.

It is not a slippery slope at all, is termination of basic human rights, is the the return to the dark ages, to Totalitarianism.

You hope that be installing a regime of censorship and speech control you will end "lies" and/or "hate" when in reality you will ensure its continued existence and growth while taking away peoples power to challenge it in the open light of public debate

Post reply on HN