Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

31–40 of 171 posts

Re: 1.1.1.1 for Families

#31
post #7

Earlier quoted context omitted.

Yeah, I would also love to get NextDNS-style offering fro CloudFlare. I'm currently have multiple malware/spyware/adds/annoyances filters enabled and I need them on DNS level because having uBlock Origin in my browser doesn't help me, for example, to prevent spying by my smart TV or phone apps.

Hate to break it to you, but DNS level blocking won't help you either. Lots of this kind of spying is done through fixed IP addresses.

What do you suggest instead?

Re: 1.1.1.1 for Families

#32
post #24

DNS filters are a joke, too easy to bypass.

If your 12 year old is getting a malicious link via whatsapp on their tablet it can make a difference. (e.g. they'll ask you why this doesn't work and you might explain malware etc)

It's certainly not something for every circumstance, but given that most people (including family members) are just end users makes sense.

Re: 1.1.1.1 for Families

#33
post #26

Earlier quoted context omitted.

So if archive.is decided to also return garbage DNS results to Quad9 you would stop using them too? I get your sentiment, but allowing one single webpage on the internet to dictate who you are allowed to use for DNS is going too far in the other direction, IMHO

It's a little ironic complaining about a single webpage on the internet, when you're suggesting that we use a single resolver on the internet instead of a distributed resolver system that we have otherwise. FWIIW, I use the resolver of my ISP, and 100% happy with the results. If your ISP provides incorrect and fake data to make extra money on advertising, maybe you should vote with your wallet and change the ISP.

ISP's regularly resell subscriber data, including DNS requests. They're also more likely to "play ball" with authorities.

> we use a single resolver

Cloudflare is still doing BGP like your ISP.

Re: 1.1.1.1 for Families

#34

One should use DNS servers offered by one's VPN provider. Otherwise, it leaks to both VPN provider and DNS provider.

This is irrelevant, no one using a VPN is also configuring a 'family-friendly' DNS resolver.

Why not?

I use a VPN to give my half-Danish children access to Danish TV from outside Denmark, and I also have, well, children who I might want to protect against evil content such as nipples. I don't do the latter but that has little to do with the fact that I use a VPN sometimes and more to do with the fact that we're not American and American ideas of what's "family friendly" feel extremely alien to us.

In fact, given that they have an option that blocks malware but not nipples, I might actually use this.

Re: 1.1.1.1 for Families

#35
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

> I also don't care much for family "protection", so right now I don't see a good reason for using Cloudflare

It seems like you don’t fit the target audience for this service at all.

Re: 1.1.1.1 for Families

#36
post #26

Earlier quoted context omitted.

It's a little ironic complaining about a single webpage on the internet, when you're suggesting that we use a single resolver on the internet instead of a distributed resolver system that we have otherwise. FWIIW, I use the resolver of my ISP, and 100% happy with the results. If your ISP provides incorrect and fake data to make extra money on advertising, maybe you should vote with your wallet and change the ISP.

ISP's regularly resell subscriber data, including DNS requests. They're also more likely to "play ball" with authorities. > we use a single resolver Cloudflare is still doing BGP like your ISP.

This is simply unsubstantiated — there's absolutely no reason to believe Cloudflare won't play ball with authorities.

If anything, ISP DNS being a distributed system with independent ISPs all across the world, it would be much more difficult for the major agencies to control all the individual ISPs than it would be to simply control a single global entity with a US HQ and offices and POPs worldwide — Cloudflare.

Re: 1.1.1.1 for Families

#37
All providers are in on this "free" public DNS scam for the same reason, and it makes me wonder why anyone would voluntarily donate their entire home's click analytics to a super-aggregator free of charge. Did I miss the link to the payment page?

Cisco at least release some low frequency summaries of the data they are able to collect: https://s3-us-west-1.amazonaws.com/umbrella-static/index.htm...

Re: 1.1.1.1 for Families

#39
Why is this here? It was launched last year?

Also, people should really be using Dnscrypt-proxy/DoH/DoT. Otherwise it's really easy for your ISP just to read/capture your DNS requests.

Re: 1.1.1.1 for Families

#40
post #37

All providers are in on this "free" public DNS scam for the same reason, and it makes me wonder why anyone would voluntarily donate their entire home's click analytics to a super-aggregator free of charge. Did I miss the link to the payment page? Cisco at least release some low frequency summaries of the data they are able to collect: https://s3-us-west-1.amazonaws.com/umbrella-static/index.htm...

Cloudflare's public DNS's privacy promises are audited by KPMG https://www.bleepingcomputer.com/news/security/cloudflares-1...
Post reply on HN