Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

51–60 of 171 posts

Re: 1.1.1.1 for Families

#51
post #26

Earlier quoted context omitted.

So if archive.is decided to also return garbage DNS results to Quad9 you would stop using them too? I get your sentiment, but allowing one single webpage on the internet to dictate who you are allowed to use for DNS is going too far in the other direction, IMHO

It's a little ironic complaining about a single webpage on the internet, when you're suggesting that we use a single resolver on the internet instead of a distributed resolver system that we have otherwise. FWIIW, I use the resolver of my ISP, and 100% happy with the results. If your ISP provides incorrect and fake data to make extra money on advertising, maybe you should vote with your wallet and change the ISP.

> maybe you should vote with your wallet and change the ISP.

Not a lot an option for many, most of my life I've lived in areas that only have a single choice.

Re: 1.1.1.1 for Families

#52

Earlier quoted context omitted.

> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/

Thank you! This is incredibly informative on the situation and makes sense. It also makes me happy with clouflare's choice

It doesn't have the owner's side on it, though, which is not as evil as the article makes it sound. I can post more information when I'm home, but he basically uses that info to thwart attacks.

Re: 1.1.1.1 for Families

#53

Launched last year. Was incredibly abusive against sexual minorities then, and is still the same. A product anyone who built it should be genuinely ashamed of.

Can you please expand on this, I'm not familiar with the controversy and don't understand what you mean

Re: 1.1.1.1 for Families

#55

I was happy to set up 1.1.1.1 for my daughter on her Iphone7 but it never seemed to work well with Mobile Data (Freedom Mobile Canada). Internet would always be spotty/non-existent. The app being used was Google Classroom. In the end we turned off 1.1.1.1 and Google Classroom started working. Anyone experience anything similar?

Did you set up both 1.1.1.3/1.0.0.3 and also 2606:4700:4700::1113/2606:4700:4700::1003? Maybe there was some IPv6 issues.

https://developers.cloudflare.com/1.1.1.1/1.1.1.1-for-famili...

Re: 1.1.1.1 for Families

#56

I had to stop using 1.1.1.1 because I am getting rate limited when using their “cloudflared” dns-over-https proxy. My pretty modest home network and the various services running make 20-25k queries per day and I get a lot of REFUSED responses. Google on the other hand has no problem serving all of them. I even set a local cache to bypass the dns TTL but the problem is that sometimes 10 or more queries arrive at the s…

Did you talk to someone at Cloudflare about this? That sounds... odd.

As John says - sounds odd - but please drop me an email with more details - silverlock at cloudflare

Understanding the # of unique names, peak QPS, % of response types, etc will help.

I consider it a “bug” if you can take the same profile of DNS queries to another resolver and see no issues ;-)

Re: 1.1.1.1 for Families

#57
post #36

Earlier quoted context omitted.

ISP's regularly resell subscriber data, including DNS requests. They're also more likely to "play ball" with authorities. > we use a single resolver Cloudflare is still doing BGP like your ISP.

This is simply unsubstantiated — there's absolutely no reason to believe Cloudflare won't play ball with authorities. If anything, ISP DNS being a distributed system with independent ISPs all across the world, it would be much more difficult for the major agencies to control all the individual ISPs than it would be to simply control a single global entity with a US HQ and offices and POPs worldwide — Cloudflare.

DNS is distributed, by design. Your ISP operates no differently than Cloudflare, and receives routing information from peers in the exact same way. There is nothing special or unique about consumer ISP-provided DNS. A DNS provider is either the definitive source and the buck stops there for a lookup, or it forwards to a peer for resolution.

Cloudflare is not a telecom, which comes with regulation baggage that can be enforced. This matters a lot to a subpoena.

Re: 1.1.1.1 for Families

#58
post #37

All providers are in on this "free" public DNS scam for the same reason, and it makes me wonder why anyone would voluntarily donate their entire home's click analytics to a super-aggregator free of charge. Did I miss the link to the payment page? Cisco at least release some low frequency summaries of the data they are able to collect: https://s3-us-west-1.amazonaws.com/umbrella-static/index.htm...

Use a DoH/DoT oblivious proxy? I have no idea if anyone commercializes that.

https://try.popho.be/doh-proxy.html

Re: 1.1.1.1 for Families

#59
post #53

Launched last year. Was incredibly abusive against sexual minorities then, and is still the same. A product anyone who built it should be genuinely ashamed of.

Can you please expand on this, I'm not familiar with the controversy and don't understand what you mean

If I recall, some sites providing help and information on certain things were flagged as adult content and blocked which made a bunch of people mad.

Cloudflare I think corrected a bunch, came out with a fairly reasonable explanation why, and then even showed how to setup special rules to override it.

Post reply on HN