Live data from Hacker News

Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

jarv.is

121–128 of 128 posts

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#121
post #78
post #70

Earlier quoted context omitted.

Source?

https://blog.archive.today/post/623568857709395968/i-from-th... There was another answer I could not find quickly where that is named here "another free dns service" was named Amazon.

Amazon doesn't make any sense as the "another free DNS service" since they're described as free and "much smaller than Cloudflare", and Amazon is neither of those things.

And in any case, if I assume that Cloudflare is indeed proxying all DNS queries for Archive.today through some shitty EC2 instance that causes Archive.today to not have any geo information, it's a completely self-inflicted wound. They could've gotten geographical data from 1.1.1.1 to the accuracy of the edge nodes but decided to just outright block 1.1.1.1.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#122
post #121
post #78

Earlier quoted context omitted.

https://blog.archive.today/post/623568857709395968/i-from-th... There was another answer I could not find quickly where that is named here "another free dns service" was named Amazon.

Amazon doesn't make any sense as the "another free DNS service" since they're described as free and "much smaller than Cloudflare", and Amazon is neither of those things. And in any case, if I assume that Cloudflare is indeed proxying all DNS queries for Archive.today through some shitty EC2 instance that causes Archive.today to not have any geo information, it's a completely self-inflicted wound. They could've gotte…

To add, I can't find any other evidence of this. This community post was posted on the same day as that blog entry, and archive.is still isn't loading: https://community.cloudflare.com/t/getting-servfail-for-some...

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#123
post #112
post #109

Earlier quoted context omitted.

I appreciate that you’ve moved from assuming what Cloudflare is doing to assuming what I understand. I think this thread has run its course.

I concluded that from sentences like "they don’t owe you optional features because you really want to see user IP data" which reveal misunderstanding on who is sending queries and who decides what to answer to those queries. From your text it looks like webmasters are sending requests to CloudFlare to get user's IP. This is totally wrong. It is CloudFlare wants to see server IP and in the query it has to explain how…

> to which region they will forward my server IP.

They're not forwarding it at all. A request from LA will come from the LAX Cloudflare DC, and thus plugging in the requesting IP address into some geoip service will show Los Angeles, California. All you have to do to get this working is to fallback to the incoming IP if ECS is absent.

Or time travel to 2010 and try to respond to DNS queries while no servers are sending ECS.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#124
post #121
post #78

Earlier quoted context omitted.

https://blog.archive.today/post/623568857709395968/i-from-th... There was another answer I could not find quickly where that is named here "another free dns service" was named Amazon.

Amazon doesn't make any sense as the "another free DNS service" since they're described as free and "much smaller than Cloudflare", and Amazon is neither of those things. And in any case, if I assume that Cloudflare is indeed proxying all DNS queries for Archive.today through some shitty EC2 instance that causes Archive.today to not have any geo information, it's a completely self-inflicted wound. They could've gotte…

Amazon is indeed not a "another free DNS service", that should have to be in different points of time. Overloaded a "free DNS service" they launched an EC2 instance, or vice versa.

> They could've gotten geographical data from 1.1.1.1 to the accuracy of the edge nodes but decided to just outright block 1.1.1.1.

Yes.

But they cannot get back in time to getting information from the edges simple by unblocking.

Since CloudFlare sends queries not from the edges.

So there is a deadlock atm.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#125
post #112

Earlier quoted context omitted.

I concluded that from sentences like "they don’t owe you optional features because you really want to see user IP data" which reveal misunderstanding on who is sending queries and who decides what to answer to those queries. From your text it looks like webmasters are sending requests to CloudFlare to get user's IP. This is totally wrong. It is CloudFlare wants to see server IP and in the query it has to explain how…

> to which region they will forward my server IP. They're not forwarding it at all. A request from LA will come from the LAX Cloudflare DC, and thus plugging in the requesting IP address into some geoip service will show Los Angeles, California. All you have to do to get this working is to fallback to the incoming IP if ECS is absent. Or time travel to 2010 and try to respond to DNS queries while no servers are sendi…

> They're not forwarding it at all.

They indeed are, "for your privacy".

And our topic started exactly out of this:

From: https://webapps.stackexchange.com/questions/135222/why-does-...

``` Official Statement

archive.today had this to say about the issue:

https://twitter.com/archiveis/status/1017902875949793285

    2018-07-13T1545: yes, unlike other public DNS services, 1.1.1.1 does not support EDNS Client Subnet
https://twitter.com/archiveis/status/1018691421182791680

    2018-07-15T1958: "Having to do" is not so direct here. Absence of EDNS and massive mismatch (not only on AS/Country, but even on the continent level) of where DNS and related HTTP requests come from causes so many troubles so I consider EDNS-less requests from Cloudflare as invalid.
 
```

> Or time travel to 2010 and try to respond to DNS queries while no servers are sending ECS.

That is exactly what `archive.{*}` does.

It responses to

[+] requests from IPs with geo-information (as in 2010, and it seems to be the most of requests still)

[+] AND to requests from public global resolvers with EDNS, which supply information to which region the server IP will be forwarded (as in 2015)

[-] But not requests from a public global resolver which conceal the source region (as it does a single privacy minded megacorp in 2019)

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#126
post #69

I have long hated Cloudflare, so it's hard to be on their side here. They MitM large parts of the web and often trap you in long or even infinite loops with their horrendous checker that some sites unfortunately use. It's especially bad on less common browsers. In two cases I had to spoof my useragent or it would literally never pass the check, locking me out of several sites. Even if the block was without reason, I…

CloudFlare DNS is not the part that gives you the annoying anti bot checks. Those are from website operators who have opted in to the CDN and anti-DDoS services that CloudFlare offers.

Re: Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)

#128

Earlier quoted context omitted.

Archiving the Internet is not stealing the history books. It’s writing them.

I don't think we need metaphors to grasp what it is. Its importance is so obvious, even the people that wrote copyright law created an exemption for. That exemption includes an opt-out provision. And while I could see how ignoring such requests could be in the public interest in some cases, ignoring them wholesale is fundamentally incompatible with any view of morality that condemns "doxing".

I condemn doxing in principle. But if it’s out there once, it’s out there. To try to stuff the genie back only harms those who lack the information, regardless of intent.

I understand you don’t care for metaphors but I can’t help wondering who you mean by “we”? Perhaps “we” are not the intended audience. Please let “we” know “we” are free to ignore.

Post reply on HN