Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

61–70 of 171 posts

Re: 1.1.1.1 for Families

#61
post #45
post #40

Earlier quoted context omitted.

Cloudflare's public DNS's privacy promises are audited by KPMG https://www.bleepingcomputer.com/news/security/cloudflares-1...

That is almost 2 years old, and does not seem to cover aggregate processing applied before the logs are deleted. FWIW stripping the last octet is the same as happens in EDNS, it is far from anonymous.

So, they basically still collect, log and process the exact same data as Google DNS, but disallow anyone else from having it, breaking legitimate uses of DNS for GeoIP targeting and DoS mitigation? How convenient!

Re: 1.1.1.1 for Families

#62
post #50
post #26

Earlier quoted context omitted.

It's a little ironic complaining about a single webpage on the internet, when you're suggesting that we use a single resolver on the internet instead of a distributed resolver system that we have otherwise. FWIIW, I use the resolver of my ISP, and 100% happy with the results. If your ISP provides incorrect and fake data to make extra money on advertising, maybe you should vote with your wallet and change the ISP.

Millions of people in the US can't change their ISP. I live in a major city and would have to drop my speed by 90% if I switched to my other option. I have two options total.

Doesn't T-Mobile US offer home internet over 4G and 5G in most of the US now?

I've actually been using tethering for home internet, and it's often faster and cheaper than landline alternatives. Easily get 100Mbps in my location over 4G LTE on an old phone.

Re: 1.1.1.1 for Families

#63
post #7

Earlier quoted context omitted.

Yeah, I would also love to get NextDNS-style offering fro CloudFlare. I'm currently have multiple malware/spyware/adds/annoyances filters enabled and I need them on DNS level because having uBlock Origin in my browser doesn't help me, for example, to prevent spying by my smart TV or phone apps.

Hate to break it to you, but DNS level blocking won't help you either. Lots of this kind of spying is done through fixed IP addresses.

It will still help, but it won’t prevent this specific issue, to be clear.

Re: 1.1.1.1 for Families

#64
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

Cloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error message. I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away.

[0] https://community.spotify.com/t5/Desktop-Windows/Random-Stop...

Re: 1.1.1.1 for Families

#66
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

> I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is. It does resolve archive.is, it’s just the archive.is nameservers return garbage if the source if CloudFlare. CloudFlare could simply fix this their end if they wanted but haven’t done so out of integrity. This looks good for CloudFlare and bad for archive.is from where I’m sitting.

Is there any non-conspiratorial reason for archive.is's position on this?

Re: 1.1.1.1 for Families

#67

I had to stop using 1.1.1.1 because I am getting rate limited when using their “cloudflared” dns-over-https proxy. My pretty modest home network and the various services running make 20-25k queries per day and I get a lot of REFUSED responses. Google on the other hand has no problem serving all of them. I even set a local cache to bypass the dns TTL but the problem is that sometimes 10 or more queries arrive at the s…

That's not too many requests, but running any form of a home network would still benefit moderately from a local DNS server. You could even install something like dnsmasq on the most heavy-using boxes to cache lookups locally.

Granted, I'm saying this as yet another home-network admin who hasn't quite... ahem... gotten around to installing a DNS server. ^_^; I'm mostly sharing this here in case someone else has a similar problem and wants a solution.

Re: 1.1.1.1 for Families

#68
post #21

I know they consider "1.1.1.1" to also be a product name, but it's very confusing when the text says 1.1.1.1 50 times, and then there's 2 mentions of "Oh, the service is at 1.1.1.2".

The name they could have used: 1.1.1.2 (1.1.1.1 for families) Or more correct: 1.1.1.3 (1.1.1.1 for families)

It still results in kinda weird readings when the product name is also one of its subproducts but not all of them. Like a coffee shop called "The Big Cup" with a menu "The Big Cup", "The Medium Cup" and "The Small Cup".

Re: 1.1.1.1 for Families

#69
post #61
post #45

Earlier quoted context omitted.

That is almost 2 years old, and does not seem to cover aggregate processing applied before the logs are deleted. FWIW stripping the last octet is the same as happens in EDNS, it is far from anonymous.

So, they basically still collect, log and process the exact same data as Google DNS, but disallow anyone else from having it, breaking legitimate uses of DNS for GeoIP targeting and DoS mitigation? How convenient!

> legitimate uses of DNS for GeoIP targeting and DoS mitigation

What legitimate uses would those be, and how is DNS involved in DoS mitigation?

Re: 1.1.1.1 for Families

#70
post #58
post #37

All providers are in on this "free" public DNS scam for the same reason, and it makes me wonder why anyone would voluntarily donate their entire home's click analytics to a super-aggregator free of charge. Did I miss the link to the payment page? Cisco at least release some low frequency summaries of the data they are able to collect: https://s3-us-west-1.amazonaws.com/umbrella-static/index.htm...

Use a DoH/DoT oblivious proxy? I have no idea if anyone commercializes that. https://try.popho.be/doh-proxy.html

I'd much rather the opposite: an honest public DNS service that offers all data collected to the public, with some premium paid for high frequency data, and free from any conflict of interest. I would happily use a service like this since I could benefit from it.

The business case to collect DNS statistics is clear and imminently useful to numerous people and organizations, it's the complete lack of honesty about why they offer the service that bothers me.

Post reply on HN