Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

101–110 of 171 posts

Re: 1.1.1.1 for Families

#101
post #84

Any tips/ideas for configurations for selective content blocking by device? I'd like to block content on the kids' devices, but not for the adults in the household. I'm not concerned about circumvention at this point. I'm currently using a pi-hole for ad blocking, so I'd like to configure something at that level, unless there's a better way.

Put those devices on a separate subnet would be the easiest way. In order of technical complexity:

* Buy a second router, plug it into your existing one, set the DHCP options to point to 1.1.1.2

* Reconfigure your existing router to add a second subnet (192.168.2.0/24 etc) with its own SSID

* Use DHCP reservations to push 1.1.1.1 to known devices (adults) and 1.1.1.2 to all others; it could be done the other way, but all iPhones/Macs can randomize MAC addresses making evasion very simple

There may be a way to do this inside Pi-Hole, but it would probably be based on IP range rather than MAC address, which is much easier to circumvent.

Re: 1.1.1.1 for Families

#102
post #80

Earlier quoted context omitted.

Is there any non-conspiratorial reason for archive.is's position on this?

It leads to further centralization of the internet where a few have more data to make better decisions (and more money) and the smaller players are left out.

That's a fairly good argument IMO. Today's Cloudflare does not sell data. Tomorrow's, or our children's generation's, could.

As you say, this could become a monopoly and it's cool to see a popular website standing up for a future where littler guys can still make it. It's not clear to me that's the precise argument he's made so I'm just guessing.

When did HN get these new awesome nav buttons? Root, next, ... amazing!

Re: 1.1.1.1 for Families

#103
post #95

Earlier quoted context omitted.

>I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. Since you're already using a pi-hole, why not just roll your own recursive DNS server. The additional network traffic to do so is insignificant. That way, you don't have to rely on someone else to resolve your DNS queries -- or deal with spats like that. I've been…

I use Pi-Hole + Unbound forwarding to Cloudflare/Quad9 over TLS. It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.

>It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted.

I love DNSSEC, but am not in favor of DoH/DoT. Mostly because I can't control DoH/DoT requests emanating from my network, as they're already encrypted and can't be differentiated from standard HTTPS traffic.

That's an issue (and will become a much bigger one as time passes) because vendors can use DoH/DoT to bypass local DNS controls like Pi-Hole, and short of blocking TCP/443, there's nothing you can do about it. Which is, IMNSHO, a big reason why DoT/DoH was developed.

>Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.

Your ISP can surveil whatever they want and there isn't much you can do about it unless you use a VPN.

Re: 1.1.1.1 for Families

#104
post #75

Earlier quoted context omitted.

Thank you! This is incredibly informative on the situation and makes sense. It also makes me happy with clouflare's choice

They also blocked all of Finland a few years ago for pretty dubious reasons: https://en.wikipedia.org/wiki/Archive.today#Finland

"They" refers to archive.is, not Cloudflare.

Re: 1.1.1.1 for Families

#105
post #100

Earlier quoted context omitted.

> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/

From the article above: > In other words, Archive.is's nameservers throw a hissy fit and return a bogus IP when Cloudflare doesn't leak your geolocation info to them via the optional EDNS client subnet feature. The owner of Archive.is has plainly admitted this with a questionable claim (in my opinion) about the lack of EDNS information causing him "so many troubles." Not sure how it’s causing him so many troubles.

This makes me even more willing to use 1.1.1.1.

Re: 1.1.1.1 for Families

#106
post #31
post #7

Earlier quoted context omitted.

Hate to break it to you, but DNS level blocking won't help you either. Lots of this kind of spying is done through fixed IP addresses.

What do you suggest instead?

Blocking traffic to bad IPs entirely, not just blocking DNS resolution to bad IPs.

Re: 1.1.1.1 for Families

#107
post #53

Earlier quoted context omitted.

Can you please expand on this, I'm not familiar with the controversy and don't understand what you mean

If I recall, some sites providing help and information on certain things were flagged as adult content and blocked which made a bunch of people mad. Cloudflare I think corrected a bunch, came out with a fairly reasonable explanation why, and then even showed how to setup special rules to override it.

Cloudflare's explanation: https://blog.cloudflare.com/the-mistake-that-caused-1-1-1-3-...

They said that one of their providers for site-classifications had two feeds called "adult content", one which was a fairly clear porn-blocker, and one which included the LGBTQIA+ stuff as well. Apparently when they launched they flubbed which of those feeds was used because of the name-confusion.

Re: 1.1.1.1 for Families

#108
post #11

I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now…

So you stopped using 1.1.1.1, because the owner of archive.is deliberately broke his domain so it wouldn't work on Cloudflare, specifically so he could mine your geolocation?

You do you, I guess.

Re: 1.1.1.1 for Families

#109
Well one of my domains resolves to some dodgy russian website when using cloudflare's dns. I did everything in my power, including trying to contact them, but it still resolves to the russian host. On any other dns server it resolves correctly to gandi's parking page. Cloudflare did send me an email within 10 seconds to say that no support ticket can/will be logged since I'm not a paying customer (or just customer on their system) and that they case is closed. i get it, but it's still a nasty feeling. And yes I did use their dns flusher, it didn't help.

I switched all my networks back to google's dns.

Re: 1.1.1.1 for Families

#110
post #92
post #52

Earlier quoted context omitted.

It doesn't have the owner's side on it, though, which is not as evil as the article makes it sound. I can post more information when I'm home, but he basically uses that info to thwart attacks.

This has come up a few times. Mostly the owner is set in their ways and are mad at CF for not providing the DNS flags that allow outside CDNs to figure out what IP you are closest to. From a 2019 thread about this: The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifi…

Can you explain the attack a bit more? One would (naively) expect that the process of the user connecting to my web server would expose their IP address (associated with their intent) to many more relevant actors (including "nationstate actors") than Cloudflare connecting to my DNS server... is the issue that the specific nationstate actor you have been concerned with is explicitly able to target and achieve surveillance on Cloudflare's outgoing traffic, but is expected to not be able to surveil the incoming traffic to my infrastructure on the other side (which sees the user's IP address way)?
Post reply on HN