Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

201–210 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#201
post #148

Earlier quoted context omitted.

Not quite as easy as when you just have to intercept traffic at one of the intermediate nodes though, it seems. I think that makes the privacy argument a fairly valid thing.

You seem to misunderstand it. There are less points to intercept traffic at with 1.1.1.1, than without it. Much more feasible to spy on a massive scale, much less privacy and usefulness of client subnet EDNS option completely disappears. In 1.1.1.1 case it's literally irrelevant for privacy whether they do it or not. 1.1.1.1 already hurts privacy massively and not passing client subnet only hurts competing CDNs.

This is no longer a factual discussion. You mention two separate issues:

1. Use of EDNS client subnet information harms user privacy, by providing information that would not otherwise be there.

2. Many users on a single global DNS provider lowers the amount of points that needs to be attacked to obtain DNS information.

However, you position your statement as if #2 somehow render #1 moot, which is an entirely subjective evaluation from the perspective of a user, and also not at all relevant to the discussion of #1, as that on its own is not 1.1.1.1 specific.

For an example of why this is very subjective, the user may believe that the security of ISP DNS servers is likely not trustable, and that infiltrating countless ISP DNS services would likely be much less work than infiltrating one of the larger providers, such as 1.1.1.1, with better security practices.

The only things relevant to this discussion is whether or not it is sensible to respond with bogus data to a valid request that does not contain optional fields, and separately whether or not it is sensible for a DNS provider to not contain these fields.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#202
post #167

Earlier quoted context omitted.

I think you're being downvoted because of the bit about regulation. At least, that is what I choose to believe, because imagine our state of affairs if you are being downvoted because of your comments about the idea of free speech.

Then you are new to HN... Silicon Valley is full of Authoritarians that believe the Tech Companies should be our overlords and be allowed to choose what "truth" is, and who can revel that "truth" to you

Actually it's the opposite. It's the newer people that are this way [0], for in my day, most people didn't even trust computers, let alone buying things with a computer, or always carrying an always-connected computer with a microphone and multiple cameras in their pocket.

[0] https://www.pewsocialtrends.org/2019/01/17/generation-z-look...

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#203

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

If you're for integrity of DNS, why did you suspend the free speech of the admittedly bigoted, hateful neonazis on dailystormer? https://blog.cloudflare.com/why-we-terminated-daily-stormer/ "Earlier today, Cloudflare terminated the account of the Daily Stormer. We've stopped proxying their traffic and stopped answering DNS requests for their sites. We've taken measures to ensure that they cannot sign up for Cloudflar…

I don't think this argument is well stated, so I'll give it a shot.

CloudFlare is very basic infrastructure and there are a handful of companies providing such infrastructure, thus a group can be effectively deleted from the Internet if these companies decide or are pressured to do so. (Example of pressuring: Patreon dropped some accounts at the behest of Mastercard.)

So maybe the real question is, "does this notion of the integrity of DNS extend to other basic infrastructure services?"

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#204

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

If you're for integrity of DNS, why did you suspend the free speech of the admittedly bigoted, hateful neonazis on dailystormer? https://blog.cloudflare.com/why-we-terminated-daily-stormer/ "Earlier today, Cloudflare terminated the account of the Daily Stormer. We've stopped proxying their traffic and stopped answering DNS requests for their sites. We've taken measures to ensure that they cannot sign up for Cloudflar…

How does doing this censor them?

The Daily Stormer is free to get their business elsewhere and it's still up on the internet. Cloudflare didn't want to be associated to this kind of content, and thus terminated their business relation.

We don't NEED Cloudflare to keep the internet integrity (if we did, it will go pretty badly...) but we do need DNS to keep the internet integrity.

> I'll keep using non-logging, encrypted OpenNIC servers, since you seem to selectively censor instead of only blocking terrorists and cp.

Why are you censoring Cloudflare? /s

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#205
post #174

Earlier quoted context omitted.

For the moment, I also do trust CloudFlare's intentions, but it's wrong to classify this as some kind of stoic resolve in not "slapping a band-aid on a problem" since that's exactly what they did after their business decision about not responding to "any" queries.

What do you mean with this? Refuse ANY is now a proposed RFC https://datatracker.ietf.org/doc/rfc8482/ How is that a band aid?

Just for another voice in this sub-discussion: I'm an authdns software implementer ( https://github.com/gdnsd/gdnsd ) with no connection to Cloudflare, and I like Refuse ANY. It's maybe hard to see all the issues with traditional ANY clearly unless you're implementing this stuff, but IMHO RFC 8482 is a really good path forward that I'm supportive of and have also implemented.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#206
post #163

Earlier quoted context omitted.

Alternatively: Cloudflare simply is making a subversive play against their competitor CDNs. Client subnet of a DNS request is used for initial rough mapping by Cloudflare competitors such as Akamai (definitely) and I believe Fastly ( and probably others) . Stripping it easily adds at least a few milliseconds to the time to first byte and most likely results a request re-routing on the second or third request. After a…

As this is related to CDN, I am gonna leave it here. The irony is one.one.one.one is marketed as getaway to faster internet, while making CDNs that use GeoDNS slower. All it takes is a bad route to a far away cloudflare POP to make your internet really slower. Case in point. [1] I really don't find why no EDNS is considered private, as it only sends the IP subnet.[2] And on IPv6 the IP is far more protected. If you c…

> If you care that much about privacy, you should be using a VPN.

Another point; if you care about privacy, why use a 3rd party resolver that you have to "trust"?

Use the ISP resolver; they can see all your traffic anyway if they want to.

Alternatively, cut out all the middle men and run your own recursive resolver. It's not complicated to do so, there's other software than Bind for doing so.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#207
post #92

archive.org works fine with 1^4. What is the advantage of using archive.is?

Archive.org, the Internet Archive, and archive.is, a webpage capture service that seems to have a primary name of "Archive.today", are wholly separate concerns, offerring different services.

Interesting, I thought archive.is was an alternate domain of the Internet Archive, but it seems they are completely different people[1].

[1] https://en.wikipedia.org/wiki/Archive.today

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#208

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

tl;dr: Don't use 1.1.1.1 if you use any services that use DNS geolocation to bring you resources from the closest datacentre. These include: Office 365, Netflix, Facebook, Google services, ...

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#209
post #92

archive.org works fine with 1^4. What is the advantage of using archive.is?

Archive.org, the Internet Archive, and archive.is, a webpage capture service that seems to have a primary name of "Archive.today", are wholly separate concerns, offerring different services.

Yes, but what is the difference between the two? That's really my question. Sorry if it wasn't clear.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#210
post #174

Earlier quoted context omitted.

For the moment, I also do trust CloudFlare's intentions, but it's wrong to classify this as some kind of stoic resolve in not "slapping a band-aid on a problem" since that's exactly what they did after their business decision about not responding to "any" queries.

What do you mean with this? Refuse ANY is now a proposed RFC https://datatracker.ietf.org/doc/rfc8482/ How is that a band aid?

Well, I can't say I didn't anticipate it happening exactly like this, with someone from Cloudflare trying to retcon "the ANY query episode" by linking to the proposal drafted after the fact. As though a formal "here is our proposed change" document somehow magically excuses the fact that Cloudflare did "violate the integrity of DNS" in its unilateral decision to abandon parts of the DNS specification in favor of its own modifications in order to cut operating costs by reducing the workload on its servers. [0]

Your boss is talking about not "violating the integrity of DNS" and presents this case where upstream archive.is name servers return unexpected data. He proposes that CloudFlare cannot "just fix it" because doing so "would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service". However, Cloudflare chose to "just fix it" back then by "slapping a bandaid" on something your team saw as a problem instead of abiding by the proper change process. And Cloudflare did so not because of some critical security flaw, but as a cost-cutting measure.

Even if we limit what it means to "violate the integrity of DNS" to the first definition mentioned above (and completely ignore this second definition), Cloudflare "slapped a bandaid" on a PR problem it had a couple of years ago and decided to "just fix it" and "block a domain" by removing the domain and its assets from Cloudflare's infrastructure. [1]

Cloudflare has "violated the integrity of DNS" on more than one occasion using more than one of its own definitions.

Cloudflare "MUST" either adhere to the specification and its change process, or not adhere to the specification and its change process. Cloudflare "CANNOT" choose for both of these statements to be true, and one of them constitutes "violating the integrity of DNS".

[0] https://blog.cloudflare.com/deprecating-dns-any-meta-query-t...

[1] https://blog.cloudflare.com/why-we-terminated-daily-stormer/

Post reply on HN