Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

91–100 of 171 posts

Re: 1.1.1.1 for Families

#91

Earlier quoted context omitted.

> I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is. It does resolve archive.is, it’s just the archive.is nameservers return garbage if the source if CloudFlare. CloudFlare could simply fix this their end if they wanted but haven’t done so out of integrity. This looks good for CloudFlare and bad for archive.is from where I’m sitting.

Is there any non-conspiratorial reason for archive.is's position on this?

[deleted]

Re: 1.1.1.1 for Families

#92
post #52

Earlier quoted context omitted.

Thank you! This is incredibly informative on the situation and makes sense. It also makes me happy with clouflare's choice

It doesn't have the owner's side on it, though, which is not as evil as the article makes it sound. I can post more information when I'm home, but he basically uses that info to thwart attacks.

This has come up a few times. Mostly the owner is set in their ways and are mad at CF for not providing the DNS flags that allow outside CDNs to figure out what IP you are closest to. From a 2019 thread about this:

The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifices the privacy of users. This is especially problematic as we work to encrypt more DNS traffic since the request from Resolver to Authoritative DNS is typically unencrypted. We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1.

https://news.ycombinator.com/item?id=19828317

Re: 1.1.1.1 for Families

#94
post #62
post #50

Earlier quoted context omitted.

Millions of people in the US can't change their ISP. I live in a major city and would have to drop my speed by 90% if I switched to my other option. I have two options total.

Doesn't T-Mobile US offer home internet over 4G and 5G in most of the US now? I've actually been using tethering for home internet, and it's often faster and cheaper than landline alternatives. Easily get 100Mbps in my location over 4G LTE on an old phone.

I don't think I could make do with less than 1 Gb/s (currently gave 1.3).

I have a ton of home automation, a few HD cameras, and household members who stream video (or play games) basically 24/7.

Re: 1.1.1.1 for Families

#95
post #64

Earlier quoted context omitted.

Cloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error message. I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. [0] https://community.spotify.com/t5/Desktop-Windows/Random-Stop...

>I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. Since you're already using a pi-hole, why not just roll your own recursive DNS server. The additional network traffic to do so is insignificant. That way, you don't have to rely on someone else to resolve your DNS queries -- or deal with spats like that. I've been…

I use Pi-Hole + Unbound forwarding to Cloudflare/Quad9 over TLS.

It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted.

Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.

Re: 1.1.1.1 for Families

#96
post #45
post #40

Earlier quoted context omitted.

Cloudflare's public DNS's privacy promises are audited by KPMG https://www.bleepingcomputer.com/news/security/cloudflares-1...

That is almost 2 years old, and does not seem to cover aggregate processing applied before the logs are deleted. FWIW stripping the last octet is the same as happens in EDNS, it is far from anonymous.

The current product page still states that "a big four accounting firm" audits the service's privacy policy on a yearly retainer https://one.one.one.one/dns/

Re: 1.1.1.1 for Families

#97

I had to stop using 1.1.1.1 because I am getting rate limited when using their “cloudflared” dns-over-https proxy. My pretty modest home network and the various services running make 20-25k queries per day and I get a lot of REFUSED responses. Google on the other hand has no problem serving all of them. I even set a local cache to bypass the dns TTL but the problem is that sometimes 10 or more queries arrive at the s…

That's not too many requests, but running any form of a home network would still benefit moderately from a local DNS server. You could even install something like dnsmasq on the most heavy-using boxes to cache lookups locally. Granted, I'm saying this as yet another home-network admin who hasn't quite... ahem... gotten around to installing a DNS server. ^_^; I'm mostly sharing this here in case someone else has a sim…

I am running a pihole and I have set a minimum TTL of 40 minutes for the local cache, my setup is pihole --> local DoH proxy --> 1.1.1.1 as described here https://docs.pi-hole.net/guides/dns/cloudflared/

Re: 1.1.1.1 for Families

#98
post #81

Earlier quoted context omitted.

> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/

Is archive.is the only major site using that line of reasoning?

That I’m aware of, yes.

Re: 1.1.1.1 for Families

#99
Any updates from Cloudflare on their replacement for EDNS that they are making with Google/Facebook/Netflix etc?

https://news.ycombinator.com/item?id=19828317

``We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation targeting without risking user privacy and security. Those conversations have been productive and are ongoing. If archive.is has suggestions along these lines, we’d be happy to consider them. ``

Re: 1.1.1.1 for Families

#100
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/

From the article above:

> In other words, Archive.is's nameservers throw a hissy fit and return a bogus IP when Cloudflare doesn't leak your geolocation info to them via the optional EDNS client subnet feature. The owner of Archive.is has plainly admitted this with a questionable claim (in my opinion) about the lack of EDNS information causing him "so many troubles."

Not sure how it’s causing him so many troubles.

Post reply on HN