I thought: I ask dns server about domain, they return an IP address. I connect to IP address and they in turn can see mine.
So why does cloud flare need to a) query domain for IP address on my behalf? Can’t they just do it on their own behalf and cache the results?
B) why do they need to hide my IP address information from the domain? Aren’t I going to visit the destination regardless?
Privacy isn’t an absolute pass/fail. Giving authoritative nameservers my IP via EDNS leaks my IP. Sure, other things also leak my IP, but that doesn’t mean we should throw in the towel and accept any new way to leak user data. In many cases, DNS logs aren’t going to the same place as web server logs, so this keeps my data in fewer log files owned by fewer people.
It isn’t the actual IP, it is the subnet. Leaks some info, but unless you own the entire subnet it won’t give up your identity. https://en.wikipedia.org/wiki/EDNS_Client_Subnet
The entire point of ECS is to give the location, not the actual origin IP, which might be something you'd like to avoid giving away. The main point is that every resolver or network switch in the chain gets the ECS and would be able to combine it with the domain being requested. If you don't only visit Facebook/Google, your ipv4 /24 in combination with some obscure domain only you visit is very likely to give up your identity should an IX or resolver be watching for requests to such domain.
I don't fully understand how archive.is operates. They don't remove copyrighted content (which I like, since it provides a useful service), they must have probably terabytes upon terabytes of data in some datacenter somewhere, yet they never seem to be shut down by the govt or their datacenter/cloud provider. Am I just naive to be surprised by this? How does all this work exactly?
I don't fully understand how archive.is operates. They don't remove copyrighted content (which I like, since it provides a useful service), they must have probably terabytes upon terabytes of data in some datacenter somewhere, yet they never seem to be shut down by the govt or their datacenter/cloud provider. Am I just naive to be surprised by this? How does all this work exactly?
"Archive.is is unironically one of the most important websites in the world" Are you sure you're not confusing it with the internet archive https://www.archive.org/
I am not talking about archive.org Archive.is is faster and does not respect robots.txt. It is recommended by Wikipedia and is widely used by journalists worldwide.
Both sites are important, used by Wikipedia editors, and used by journalists worldwide.
EDNS is an optional field. Client subnet is an optional part of that optional field. It’s relatively new compared to DNS as a whole, and most “webmasters” don’t make active use of it. The quote you pulled is about Cloudflare’s efforts to build a better standard. They’re talking to the people with the expertise and interest to build that standard. You’ve inferred “proprietary” and “closed club”, and a ton of motive be…
1. EDNS is needless when you are using your provider DNS. It is needed for public DNS servers. So it is optional, as is needless most of the time. Before launching Cloudflare DNS, the biggest public DNS service was Googles, who developed and implemented EDNS. Then comes Cloudflare and "the people with the expertise and interest" to rethink that. 2. I assume that commercial companies are here to make money, not "a bet…
I’m not going to debate your stance on how you assess someone’s motivations, but it does seem like you shouldn’t attempt to present your speculation as fact.
Do you have a citation for that? Sourcing from https://news.ycombinator.com/item?id=19828702 , they don’t reverse their global stance for large providers. Their stance is ~”Including client IP via EDNS violates our goal of maximizing user data privacy”, and what they’re working on with other large-scale providers is a way to improve geo-resolution without weakening user privacy.
Exactly on your link, just ctrl-F for "Netflix": "We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation". Well, I might be inaccurate in saying "exactly the same protocol as before", but it is clear that what was available to ever…
I think they mean they're working on an alternative standard, not anywhere near "we give you an API to match DNS requests to origin city". These talks might have been as simple as "we'll give you [and everyone] geoip information for the datacenters we request from based on IP, and you can load balance off that".
I don't fully understand how archive.is operates. They don't remove copyrighted content (which I like, since it provides a useful service), they must have probably terabytes upon terabytes of data in some datacenter somewhere, yet they never seem to be shut down by the govt or their datacenter/cloud provider. Am I just naive to be surprised by this? How does all this work exactly?
It’s pretty shadowy for sure.
There’s basically no information on the web site about the company, how they operate, who finances them, what their privacy policy is, or even how to contact them. Their “blog” is an anonymous Tumblr site.
The operator of archive.is is circumventing copyright law in close to every country on earth, including all the democratic ones. Its unique selling point is that they do not comply with site owners' requests not to archive content or to delete content archived in the past. While that doesn't exclude them from the protection of law, my conviction is slightly weaker when it comes to arbitrary standards of behaviour peo…
Archiving the Internet is not stealing the history books. It’s writing them.
I don't think we need metaphors to grasp what it is. Its importance is so obvious, even the people that wrote copyright law created an exemption for.
That exemption includes an opt-out provision. And while I could see how ignoring such requests could be in the public interest in some cases, ignoring them wholesale is fundamentally incompatible with any view of morality that condemns "doxing".