Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

71–80 of 171 posts

Re: 1.1.1.1 for Families

#71
post #36

Earlier quoted context omitted.

ISP's regularly resell subscriber data, including DNS requests. They're also more likely to "play ball" with authorities. > we use a single resolver Cloudflare is still doing BGP like your ISP.

This is simply unsubstantiated — there's absolutely no reason to believe Cloudflare won't play ball with authorities. If anything, ISP DNS being a distributed system with independent ISPs all across the world, it would be much more difficult for the major agencies to control all the individual ISPs than it would be to simply control a single global entity with a US HQ and offices and POPs worldwide — Cloudflare.

They certainly make better privacy commitments and have more transparency than my ISP.

Cloudflare DNS supports DNS-over-HTTPS and DNS-over-TLS.

Cloudflare DNS claims to anonymize IPs in logs and only retain anonymized logs for 25 hours.[1]

Cloudflare has warrant canaries[2] and publishes transparency reports[3].

Many (most?) of us do not have more than one to two choices for an ISP. Voting with our wallet is not possible and doesn't even make sense for DNS.

I agree that centralizing under Cloudflare is unideal and I would gladly switch back to my ISP's DNS servers if they provided the same level of service and made similar commitments.

[1] https://blog.cloudflare.com/announcing-the-results-of-the-1-...

[2] https://www.cloudflare.com/learning/privacy/what-is-warrant-...

[3] https://www.cloudflare.com/transparency/

Re: 1.1.1.1 for Families

#72
post #30
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

CloudFlare is in the right. This is for privacy. Just put the IPs on your hosts file, it's easy. https://dns.google/query?name=archive.is 54.37.18.234 archive.today 54.37.18.234 archive.is While there try a hosts blocklist http://someonewhocares.org/hosts/ https://github.com/jmdugan/blocklists/tree/master/corporatio... etc

> Just put the IPs on your hosts file, it's easy.

Just wanted to say: Thank you for posting an actual solution!

Re: 1.1.1.1 for Families

#74
post #39

Why is this here? It was launched last year? Also, people should really be using Dnscrypt-proxy/DoH/DoT. Otherwise it's really easy for your ISP just to read/capture your DNS requests.

> Why is this here? It was launched last year?

FWIW, I'm one of today's lucky 10,000 and am thankful to have seen it.

Re: 1.1.1.1 for Families

#75

Earlier quoted context omitted.

> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/

Thank you! This is incredibly informative on the situation and makes sense. It also makes me happy with clouflare's choice

They also blocked all of Finland a few years ago for pretty dubious reasons:

https://en.wikipedia.org/wiki/Archive.today#Finland

Re: 1.1.1.1 for Families

#76

Looks like a great alternative to NextDNS if you can do without any special configuration. For me, NextDNS is still better. I can setup separate DNS zones for adults, children, IOT, etc. and it works across networks (unlike Pihole/AdguardHome). I can also setup DNS forwards for each zone.

NextDNS is fantastic. I love the level of control and flexibility it gives me to set network wide controls and then simple bypasses for the grown ups in the house.

Re: 1.1.1.1 for Families

#77
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

If you run a pi-hole create a config file in /etc/dnsmasq.d such as 02-archive.is.conf with the following

    server=/archive.is/8.8.8.8 
    server=/archive.is/8.8.4.4 
    server=/archive.li/8.8.8.8 
    server=/archive.li/8.8.4.4 
    server=/archive.to/8.8.8.8 
    server=/archive.to/8.8.4.4 
    server=/archive.today/8.8.8.8 
    server=/archive.today/8.8.4.4
And restart dnsmasq (or just reboot the pi)

This will resolve the common archive.is domains using Google's DNS service rather than 1.1.1.1 but everything else via 1.1.1.1 as normal.

Re: 1.1.1.1 for Families

#78
post #64
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

Cloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error message. I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. [0] https://community.spotify.com/t5/Desktop-Windows/Random-Stop...

>I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away.

Since you're already using a pi-hole, why not just roll your own recursive DNS server.

The additional network traffic to do so is insignificant.

That way, you don't have to rely on someone else to resolve your DNS queries -- or deal with spats like that.

I've been meaning to do so for a while, but life has interrupted. As I'm going through an ISP change ATM, I will do so soon.

And I won't ever look back.

Edit: Since your post got me thinking about it, I just now went ahead and set up my recursive resolver and pointed my pi-hole at it. Took about 10 minutes on an existing VM.

Re: 1.1.1.1 for Families

#79

Earlier quoted context omitted.

> I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is. It does resolve archive.is, it’s just the archive.is nameservers return garbage if the source if CloudFlare. CloudFlare could simply fix this their end if they wanted but haven’t done so out of integrity. This looks good for CloudFlare and bad for archive.is from where I’m sitting.

Is there any non-conspiratorial reason for archive.is's position on this?

Latency optimization.

There's an argument that CF benefits if that DNS extension is not in widespread usage. (Because CF sells a CDN but if sites can "just implement" that with DNS, then there's "nothing for them to sell".)

Re: 1.1.1.1 for Families

#80

Earlier quoted context omitted.

> I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is. It does resolve archive.is, it’s just the archive.is nameservers return garbage if the source if CloudFlare. CloudFlare could simply fix this their end if they wanted but haven’t done so out of integrity. This looks good for CloudFlare and bad for archive.is from where I’m sitting.

Is there any non-conspiratorial reason for archive.is's position on this?

It leads to further centralization of the internet where a few have more data to make better decisions (and more money) and the smaller players are left out.
Post reply on HN