Live data from Hacker News

Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

jarv.is

71–80 of 128 posts

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#71
There are a lot of emotions in the comments here today. CloudFlare provides a clear response and it has merit. Archive.is surely is not 100 reliant on this single mechanism to load share or determine correct routing to cache locations, I agree with the poster - I can't see a reason why they would block this via Cloudflare when so many other mechanisms they should already be deploying to satisfy their requirements across multiple layers in the stack exist. Edit: The position makes or made no sense and smells fishy.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#72
post #64
post #4

Archive.is is unironically one of the most important websites in the world. I hope this mess gets fixed but I am not holding my breath because we are in the same position for years now. Interesting read on the probable owner of the site : https://webapps.stackexchange.com/a/149405

"Archive.is is unironically one of the most important websites in the world" Are you sure you're not confusing it with the internet archive https://www.archive.org/

I am not talking about archive.org

Archive.is is faster and does not respect robots.txt. It is recommended by Wikipedia and is widely used by journalists worldwide.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#73
post #65
post #60

Earlier quoted context omitted.

Cloudflare (Matthew Prince personally, here on Hacker News few months ago) said that they do reverse that their global stance for Netflix and some other megacorps. So this is a super-premium feature unavailable to small players. CloudFlare just changed how DNS behaved and charge corps to make it work as it worked before CloudFlare entered the stage.

Do you have a citation for that? Sourcing from https://news.ycombinator.com/item?id=19828702 , they don’t reverse their global stance for large providers. Their stance is ~”Including client IP via EDNS violates our goal of maximizing user data privacy”, and what they’re working on with other large-scale providers is a way to improve geo-resolution without weakening user privacy.

Exactly on your link, just ctrl-F for "Netflix":

"We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation".

Well, I might be inaccurate in saying "exactly the same protocol as before", but it is clear that what was available to every webmaster via EDNS, now available only to members of a closed club, via good old EDNS or a proprietary alternative. The latter is more likely, not because of privacy-caring, but because they could now charge it as license fee for using private protocol.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#74

Earlier quoted context omitted.

Can we not call literally everything "anticompetitive"? archive.is isn't a competitor of Cloudflare. Cloudflare doesn't treat them differently from any other site, they're not doing anything "to keep them down", their DNS product just has a focus that isn't compatible with archive.is' hunger for data. That you might connect to archive.is directly isn't of any concern. You might also not do that, and they've decided t…

> Cloudflare doesn't treat them differently from any other site Did we read the same article? Cloudflare is treating them, and anybody else that makes the same choices wrt EDNS, differently from the rest of the Internet.

Cloudflare treats everybody the same: they never include client subnet in the EDNS field.

Archive.is is manually having their nameservers respond w/ junk records when queried by Cloudflare’s resolvers.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#75
post #27

Out of curiosity - not defending the behavior - what kind of problems could omitting EDNS cause? What is the steelman case for Archive.is here? The author says Archive.is's claim that it causes problems is "questionable", but he doesn't mention what those purported problems are or address why they're illegitimate, so it's hard to evaluate whether that's accurate.

To add, apparently another reason is that he believes using Cloudflare as your recursive resolver could lead to phishing[0]:

> the same entity which answers your DNS queries is able to issue SSL certs for any domain, so using CloudFlare DNS you never know whether you access the original website or a fishing one

Generally this is protected via certificate transparency+CAA records. If CF's CA were to issue a bad certificate, it'd be blocked by the browser and, should it get out, jeopardize the entire company, likely DigiCert as well given they cross-signed Cloudflare's issuing CA.

0: https://blog.archive.today/post/634795612966125568/when-will...

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#76
post #73
post #65

Earlier quoted context omitted.

Do you have a citation for that? Sourcing from https://news.ycombinator.com/item?id=19828702 , they don’t reverse their global stance for large providers. Their stance is ~”Including client IP via EDNS violates our goal of maximizing user data privacy”, and what they’re working on with other large-scale providers is a way to improve geo-resolution without weakening user privacy.

Exactly on your link, just ctrl-F for "Netflix": "We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation". Well, I might be inaccurate in saying "exactly the same protocol as before", but it is clear that what was available to ever…

EDNS is an optional field. Client subnet is an optional part of that optional field. It’s relatively new compared to DNS as a whole, and most “webmasters” don’t make active use of it.

The quote you pulled is about Cloudflare’s efforts to build a better standard. They’re talking to the people with the expertise and interest to build that standard. You’ve inferred “proprietary” and “closed club”, and a ton of motive besides, and you’ve copy-pasted that speculation as if it were fact into multiple comment trees.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#77
post #16

Earlier quoted context omitted.

Cloudflare has worked providers to make sure they can efficiently route. If you find case where this isn’t the case please let us know.

Cloudflare DNS does not route efficiently with AWS CloudFront anycast DNS. I tracked down insanely slow `rustup update` downloads to incorrect selection of ideal routes to the AWS resources caused by using CF to resolve the DNS. Switching to a different resolver that works with anycast and EDNS fixed it. CF saying “we break standard DNS geo routing but work with providers to route things right” isn’t very inspiring.

> Cloudflare DNS does not route efficiently with AWS CloudFront anycast DNS. I tracked down insanely slow `rustup update` downloads to incorrect selection of ideal routes to the AWS resources caused by using CF to resolve the DNS.

Please send me details (silverlock at cloudflare) here - AWS has our geofeed.

If you can include resolution details - e.g. dig @1.1.1.1 +nsid - with the incorrect CF results, we can provide them to AWS.

Folks did geo-routing with DNS long before ECS was included, and there’s a privacy trade-off to be had. We’re exploring ways to make this better but there is no free lunch.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#78
post #70
post #67

Earlier quoted context omitted.

>> 1.1.1.1 is delivered across Cloudflare’s entire network that today spans 180 cities. We publish the geolocation information of the IPs that we query from. That allows any network with less density than we have to properly return DNS-targeted results. Cloudflare makes an exception to this rule for Archive.{today,is,...} domains. All queries for this domains come from Amazon EC2 in the U.S., not the 180 edges of Clo…

Source?

https://blog.archive.today/post/623568857709395968/i-from-th...

There was another answer I could not find quickly where that is named here "another free dns service" was named Amazon.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#79
post #73
post #65

Earlier quoted context omitted.

Do you have a citation for that? Sourcing from https://news.ycombinator.com/item?id=19828702 , they don’t reverse their global stance for large providers. Their stance is ~”Including client IP via EDNS violates our goal of maximizing user data privacy”, and what they’re working on with other large-scale providers is a way to improve geo-resolution without weakening user privacy.

Exactly on your link, just ctrl-F for "Netflix": "We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation". Well, I might be inaccurate in saying "exactly the same protocol as before", but it is clear that what was available to ever…

[deleted]

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#80
post #76
post #73

Earlier quoted context omitted.

Exactly on your link, just ctrl-F for "Netflix": "We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation". Well, I might be inaccurate in saying "exactly the same protocol as before", but it is clear that what was available to ever…

EDNS is an optional field. Client subnet is an optional part of that optional field. It’s relatively new compared to DNS as a whole, and most “webmasters” don’t make active use of it. The quote you pulled is about Cloudflare’s efforts to build a better standard. They’re talking to the people with the expertise and interest to build that standard. You’ve inferred “proprietary” and “closed club”, and a ton of motive be…

1. EDNS is needless when you are using your provider DNS. It is needed for public DNS servers. So it is optional, as is needless most of the time. Before launching Cloudflare DNS, the biggest public DNS service was Googles, who developed and implemented EDNS. Then comes Cloudflare and "the people with the expertise and interest" to rethink that.

2. I assume that commercial companies are here to make money, not "a better future" (besides the better future for the shareholders). If they implement something, the first question is how do they make money with it.

Post reply on HN