Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

171–180 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#171

Earlier quoted context omitted.

Well no, CloudFlare doesn't get to talk about not "violating the integrity of DNS" after you stopped responding to "any" queries in violation of the standard. You started by doing your own thing and then proposed a change to the standard to fit your business decision. [0] [0] https://www.rfc-editor.org/info/rfc8482

There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.

They could have allowed "any" only via TCP. Instead Cloudflare told everyone "our software can't handle any, so yours shouldn't either".

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#172

Earlier quoted context omitted.

There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.

Wait, but both of these are horrible ideas. Horrible analogy; theres no need to bring politics into this.

It's a fine analogy: the former is something some people think is a good idea, and others think isn't, whereas about the latter most people agree it should not be done. Which is what OP wanted to express.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#173
post #107

Earlier quoted context omitted.

This is no different than any 3rd party DNS service. If the resolving DNS server you hit doesn't have a cached response, it reaches out to the upstream resolver. It doesn't pass your IP along to the upstream resolver

Did I say something that was untruthful?

Perhaps not untruthful, but bending words to make it look malicious when it wasn’t? In general, your statement was just malicious to the point of “untrustworthy”.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#174

Earlier quoted context omitted.

Honestly, Cloudflare choosing not to hastily slap a band-aid on a problem like this just makes me feel more compelled to continue using 1.1.1.1. I hesitate to compare this to Apple calling themselves “courageous” when removing the headphone jack, but in this case, I think the word is appropriate. I’ll happily stand behind you guys if you take some PR hits while forcing the rest of the industry to make DNS safer – sin…

For the moment, I also do trust CloudFlare's intentions, but it's wrong to classify this as some kind of stoic resolve in not "slapping a band-aid on a problem" since that's exactly what they did after their business decision about not responding to "any" queries.

What do you mean with this? Refuse ANY is now a proposed RFC https://datatracker.ietf.org/doc/rfc8482/ How is that a band aid?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#175

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Honestly, Cloudflare choosing not to hastily slap a band-aid on a problem like this just makes me feel more compelled to continue using 1.1.1.1. I hesitate to compare this to Apple calling themselves “courageous” when removing the headphone jack, but in this case, I think the word is appropriate. I’ll happily stand behind you guys if you take some PR hits while forcing the rest of the industry to make DNS safer – sin…

Please note that incentive to "hastily slap a band-aid" did appear, but was overcome by the team. At least, they deserve praise for honesty.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#176

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

> We publish the geolocation information of the IPs that we query from. That allows any network with less density than we have to properly return DNS-targeted results.

The operator of archive.is claims that they suffer from a "massive mismatch" between those query IPs and actual traffic. Any idea why? [Is that claim wrong? Is archive.is to blame? Is cloudflare to blame? Are ISPs badly routing the DNS queries?]

Do you have stats on how well the geolocation works in practice?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#177
post #123

Earlier quoted context omitted.

Or you know you Piss off CloudFare CEO and he directs them to censor a site... Which has happened in the past

Exactly. If it's not "the right kind" of content behind a domain, it doesn't even take a court order for CloudFlare to censor it.

that is not censorship.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#178

Earlier quoted context omitted.

> That assumes that the nameserver and the actual server are run by the same party which quite often is not the case. Cloudflare can check if nameserver and the actual server are run by different parties, and if so omit subnet information from EDNS response. It is not hard to implement — Google and OpenDNS used to require manual whitelisting to receive EDNS subnet responses (not sure if they still do). Cloudflare's C…

> Cloudflare's CDN leaks user's full online identity to Google via reCaptcha, especially when you use Tor. How?

When cloud flare detects suspicious traffic from an ip, it will get served with a reCaptcha every time. Tor exit nodes always get captchas, not sure how much data that would leak though

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#179
post #177

Earlier quoted context omitted.

Exactly. If it's not "the right kind" of content behind a domain, it doesn't even take a court order for CloudFlare to censor it.

that is not censorship.

No, it's not. However it breaks the trust in the Cloud Flares integrity they so proudly mention in this thread. Once they banned something, how can you trust them to not ban something else, perhaps a bit more silently next time?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#180
post #52
post #35

Earlier quoted context omitted.

It's possible your ISP is intercepting all traffic for port 53 and sending it to their own nameservers (which do send client subset) instead of you actually taking to cloudflare's 1.1.1.1 at all.

Links for documented instances of this practice?

I have personal witnessed this happening with Wind-Infostrada in Italy. DNS spoofing was done through the ISP provided fiber modem/router though, not at the ISP level; if you actually changed the DNS servers on the router than it would send all your queries to those routers instead of the ISP ones.

I couldn't figure out if this was plain incompetency, an attempt to enforce DNS-based website blocking, or some programmer willfully implementing the latter with the former so that it would be reasonably easy to circumvent.

Also Italian residential providers really, really like to mess with NXDOMAIN instead returning a helpful error page with affiliate links instead. You might think you can imagine how much shit this breaks; you probably don't.

Post reply on HN