Earlier quoted context omitted.
ISP's regularly resell subscriber data, including DNS requests. They're also more likely to "play ball" with authorities. > we use a single resolver Cloudflare is still doing BGP like your ISP.
This is simply unsubstantiated — there's absolutely no reason to believe Cloudflare won't play ball with authorities. If anything, ISP DNS being a distributed system with independent ISPs all across the world, it would be much more difficult for the major agencies to control all the individual ISPs than it would be to simply control a single global entity with a US HQ and offices and POPs worldwide — Cloudflare.
Cloudflare DNS supports DNS-over-HTTPS and DNS-over-TLS.
Cloudflare DNS claims to anonymize IPs in logs and only retain anonymized logs for 25 hours.[1]
Cloudflare has warrant canaries[2] and publishes transparency reports[3].
Many (most?) of us do not have more than one to two choices for an ISP. Voting with our wallet is not possible and doesn't even make sense for DNS.
I agree that centralizing under Cloudflare is unideal and I would gladly switch back to my ISP's DNS servers if they provided the same level of service and made similar commitments.
[1] https://blog.cloudflare.com/announcing-the-results-of-the-1-...
[2] https://www.cloudflare.com/learning/privacy/what-is-warrant-...