Earlier quoted context omitted.
> I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is. It does resolve archive.is, it’s just the archive.is nameservers return garbage if the source if CloudFlare. CloudFlare could simply fix this their end if they wanted but haven’t done so out of integrity. This looks good for CloudFlare and bad for archive.is from where I’m sitting.
Is there any non-conspiratorial reason for archive.is's position on this?
1.1.1.1 for Families
91–100 of 171 posts
Re: 1.1.1.1 for Families
#92Earlier quoted context omitted.
Thank you! This is incredibly informative on the situation and makes sense. It also makes me happy with clouflare's choice
It doesn't have the owner's side on it, though, which is not as evil as the article makes it sound. I can post more information when I'm home, but he basically uses that info to thwart attacks.
The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifices the privacy of users. This is especially problematic as we work to encrypt more DNS traffic since the request from Resolver to Authoritative DNS is typically unencrypted. We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1.
Re: 1.1.1.1 for Families
#93Are there some DNS services that block ads and trackers (or at least as much ads and trackers as possible) at the DNS level?
Yep! https://nextdns.io And they have a super generous free tier!
Re: 1.1.1.1 for Families
#94Earlier quoted context omitted.
Millions of people in the US can't change their ISP. I live in a major city and would have to drop my speed by 90% if I switched to my other option. I have two options total.
Doesn't T-Mobile US offer home internet over 4G and 5G in most of the US now? I've actually been using tethering for home internet, and it's often faster and cheaper than landline alternatives. Easily get 100Mbps in my location over 4G LTE on an old phone.
I have a ton of home automation, a few HD cameras, and household members who stream video (or play games) basically 24/7.
Re: 1.1.1.1 for Families
#95Earlier quoted context omitted.
Cloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error message. I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. [0] https://community.spotify.com/t5/Desktop-Windows/Random-Stop...
>I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. Since you're already using a pi-hole, why not just roll your own recursive DNS server. The additional network traffic to do so is insignificant. That way, you don't have to rely on someone else to resolve your DNS queries -- or deal with spats like that. I've been…
It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted.
Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.
Re: 1.1.1.1 for Families
#96Earlier quoted context omitted.
Cloudflare's public DNS's privacy promises are audited by KPMG https://www.bleepingcomputer.com/news/security/cloudflares-1...
That is almost 2 years old, and does not seem to cover aggregate processing applied before the logs are deleted. FWIW stripping the last octet is the same as happens in EDNS, it is far from anonymous.
Re: 1.1.1.1 for Families
#97I had to stop using 1.1.1.1 because I am getting rate limited when using their “cloudflared” dns-over-https proxy. My pretty modest home network and the various services running make 20-25k queries per day and I get a lot of REFUSED responses. Google on the other hand has no problem serving all of them. I even set a local cache to bypass the dns TTL but the problem is that sometimes 10 or more queries arrive at the s…
That's not too many requests, but running any form of a home network would still benefit moderately from a local DNS server. You could even install something like dnsmasq on the most heavy-using boxes to cache lookups locally. Granted, I'm saying this as yet another home-network admin who hasn't quite... ahem... gotten around to installing a DNS server. ^_^; I'm mostly sharing this here in case someone else has a sim…
Re: 1.1.1.1 for Families
#98Re: 1.1.1.1 for Families
#99https://news.ycombinator.com/item?id=19828317
``We are working with the small number of networks with a higher network/ISP density than Cloudflare (e.g., Netflix, Facebook, Google/YouTube) to come up with an EDNS IP Subnet alternative that gets them the information they need for geolocation targeting without risking user privacy and security. Those conversations have been productive and are ongoing. If archive.is has suggestions along these lines, we’d be happy to consider them. ``
Re: 1.1.1.1 for Families
#100I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…
> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/
> In other words, Archive.is's nameservers throw a hissy fit and return a bogus IP when Cloudflare doesn't leak your geolocation info to them via the optional EDNS client subnet feature. The owner of Archive.is has plainly admitted this with a questionable claim (in my opinion) about the lack of EDNS information causing him "so many troubles."
Not sure how it’s causing him so many troubles.