Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

41–50 of 171 posts

Re: 1.1.1.1 for Families

#41

I had to stop using 1.1.1.1 because I am getting rate limited when using their “cloudflared” dns-over-https proxy. My pretty modest home network and the various services running make 20-25k queries per day and I get a lot of REFUSED responses. Google on the other hand has no problem serving all of them. I even set a local cache to bypass the dns TTL but the problem is that sometimes 10 or more queries arrive at the s…

> 10 or more queries arrive at the same moment from a service.

I suspect you hit some sub-second ratelimit.

Re: 1.1.1.1 for Families

#42
post #7

Earlier quoted context omitted.

Yeah, I would also love to get NextDNS-style offering fro CloudFlare. I'm currently have multiple malware/spyware/adds/annoyances filters enabled and I need them on DNS level because having uBlock Origin in my browser doesn't help me, for example, to prevent spying by my smart TV or phone apps.

Hate to break it to you, but DNS level blocking won't help you either. Lots of this kind of spying is done through fixed IP addresses.

Please define "lots" and provide source.

Re: 1.1.1.1 for Families

#43
I was happy to set up 1.1.1.1 for my daughter on her Iphone7 but it never seemed to work well with Mobile Data (Freedom Mobile Canada). Internet would always be spotty/non-existent. The app being used was Google Classroom. In the end we turned off 1.1.1.1 and Google Classroom started working. Anyone experience anything similar?

Re: 1.1.1.1 for Families

#45
post #40
post #37

All providers are in on this "free" public DNS scam for the same reason, and it makes me wonder why anyone would voluntarily donate their entire home's click analytics to a super-aggregator free of charge. Did I miss the link to the payment page? Cisco at least release some low frequency summaries of the data they are able to collect: https://s3-us-west-1.amazonaws.com/umbrella-static/index.htm...

Cloudflare's public DNS's privacy promises are audited by KPMG https://www.bleepingcomputer.com/news/security/cloudflares-1...

That is almost 2 years old, and does not seem to cover aggregate processing applied before the logs are deleted. FWIW stripping the last octet is the same as happens in EDNS, it is far from anonymous.

Re: 1.1.1.1 for Families

#46
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

> ...so right now I don't see a good reason for using Cloudflare over Quad9.

If you care about performance there is a pretty significant gap between them [0].

[0] https://www.dnsperf.com/#!dns-resolvers

Re: 1.1.1.1 for Families

#47

Earlier quoted context omitted.

This is irrelevant, no one using a VPN is also configuring a 'family-friendly' DNS resolver.

Why not? I use a VPN to give my half-Danish children access to Danish TV from outside Denmark, and I also have, well, children who I might want to protect against evil content such as nipples. I don't do the latter but that has little to do with the fact that I use a VPN sometimes and more to do with the fact that we're not American and American ideas of what's "family friendly" feel extremely alien to us. In fact, g…

How cool would it be to be able to only allow malware but not nipples? :D

Re: 1.1.1.1 for Families

#49

I was happy to set up 1.1.1.1 for my daughter on her Iphone7 but it never seemed to work well with Mobile Data (Freedom Mobile Canada). Internet would always be spotty/non-existent. The app being used was Google Classroom. In the end we turned off 1.1.1.1 and Google Classroom started working. Anyone experience anything similar?

One thing I can think of is: perhaps some sections (all?) of their network is IPv6 only, and the carrier does XLAT64. In which case they would provide custom dns servers which resolve IPv4 dns records to IPv6 addresses. Custom DNS servers would not do that, therefore IPv4-only services would not work.

May well have been something else though.

Re: 1.1.1.1 for Families

#50
post #26

Earlier quoted context omitted.

So if archive.is decided to also return garbage DNS results to Quad9 you would stop using them too? I get your sentiment, but allowing one single webpage on the internet to dictate who you are allowed to use for DNS is going too far in the other direction, IMHO

It's a little ironic complaining about a single webpage on the internet, when you're suggesting that we use a single resolver on the internet instead of a distributed resolver system that we have otherwise. FWIIW, I use the resolver of my ISP, and 100% happy with the results. If your ISP provides incorrect and fake data to make extra money on advertising, maybe you should vote with your wallet and change the ISP.

Millions of people in the US can't change their ISP. I live in a major city and would have to drop my speed by 90% if I switched to my other option. I have two options total.
Post reply on HN