Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

111–120 of 171 posts

Re: 1.1.1.1 for Families

#111

Earlier quoted context omitted.

Eh, not the GP but I had tried that and switched back to 1.1.1.1 with hosts rules for specific sites to fallback to 8.8.8.8. Running my own DNS just proved to be too much of a troubleshooting headache, since if a site was broken it was one additional step. The pihole itself has been almost no trouble, but the diy DNS would occasionally fail to resolve a site. If I'm at home, the last thing I really want to do in the…

>Running my own DNS just proved to be too much of a troubleshooting headache, since if a site was broken it was one additional step. The pihole itself has been almost no trouble, but the diy DNS would occasionally fail to resolve a site. If I'm at home, the last thing I really want to do in the evening is troubleshoot network issues. A fair point. That said, note the edit on the comment to which you replied. I've bee…

I also run my own DNS servers, both internal caching resolvers and external authoritative, and and have done so since 1996. I run BIND. It takes almost zero maintenance. DNS is one of the easiest services to operate.

Re: 1.1.1.1 for Families

#112

Well one of my domains resolves to some dodgy russian website when using cloudflare's dns. I did everything in my power, including trying to contact them, but it still resolves to the russian host. On any other dns server it resolves correctly to gandi's parking page. Cloudflare did send me an email within 10 seconds to say that no support ticket can/will be logged since I'm not a paying customer (or just customer on…

And the reason why it pissed me off was, I thought my mikrotik router or raspberry pi + pihole got compromised. I spent two hours trying to track down the problem, reset all dns setting on gandi, resetting and updating the router etc... just to find that it worked fine on my phone on MNO's network...then I digged further and found if I switch my dns to anything other than 1.1.1.1, it worked fine. So I don't care what features they are flinging at this point, dns being hijacked is no good.

Re: 1.1.1.1 for Families

#113
post #21

I know they consider "1.1.1.1" to also be a product name, but it's very confusing when the text says 1.1.1.1 50 times, and then there's 2 mentions of "Oh, the service is at 1.1.1.2".

They laid it out pretty simply in the article:

1.1.1.1 - General

1.1.1.2 - No Malware

1.1.1.3 - No adult content

Personally I like how they laid this out, makes it super easy to remember.

Re: 1.1.1.1 for Families

#114
Who bears the brunt of the task of collecting every adult/NSFW domain out there? Doesn't such a list grow by huge numbers each day? What is the name of this list, and where can I get it?

Re: 1.1.1.1 for Families

#115

Looks like a great alternative to NextDNS if you can do without any special configuration. For me, NextDNS is still better. I can setup separate DNS zones for adults, children, IOT, etc. and it works across networks (unlike Pihole/AdguardHome). I can also setup DNS forwards for each zone.

NextDNS is great and all, but it's another third party that could be handing your data over to god knows who. PiHole is local and I don't have to worry about my data being misused.

Re: 1.1.1.1 for Families

#117
post #24

DNS filters are a joke, too easy to bypass.

If my teenager figures out DNS and manages to bypass it, I'd be proud.

That’s always been my rule of thumb, too. I still remember defeating NetNanny on the PC my parents gave me 20 years ago. My dad was proud of me.

Re: 1.1.1.1 for Families

#119
post #21

I know they consider "1.1.1.1" to also be a product name, but it's very confusing when the text says 1.1.1.1 50 times, and then there's 2 mentions of "Oh, the service is at 1.1.1.2".

They laid it out pretty simply in the article: 1.1.1.1 - General 1.1.1.2 - No Malware 1.1.1.3 - No adult content Personally I like how they laid this out, makes it super easy to remember.

1.1.2.1 - General with no ads

1.1.2.2 - No Malware and no ads

1.1.2.3 - No adult content and no ads

This would be amazing if they have the guts to do it. I suspect they will one day when they become huge (they're already handling some 10% of global internet traffic). Today, I want a big corporate pi hole that is managed for me - enough fire power to block shitty ads.

Completely undercut Google, FB, Twitter ad machines. More eggregious are the media companies such as Adobe and their ad-tech.

For businesses ads are super important and we also need to consider the other side of the coin.

Re: 1.1.1.1 for Families

#120
post #110
post #92

Earlier quoted context omitted.

This has come up a few times. Mostly the owner is set in their ways and are mad at CF for not providing the DNS flags that allow outside CDNs to figure out what IP you are closest to. From a 2019 thread about this: The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifi…

Can you explain the attack a bit more? One would (naively) expect that the process of the user connecting to my web server would expose their IP address (associated with their intent) to many more relevant actors (including "nationstate actors") than Cloudflare connecting to my DNS server... is the issue that the specific nationstate actor you have been concerned with is explicitly able to target and achieve surveill…

Because DNS is still largely unencrypted. Nation state actors can read that information and map who is making requests for what domains.

It’s not so much a concern of the site host from getting the users IP, because the user is presumably going to visit it. This is an issue with Archive.is because they host their own DNS, not their web server.

Post reply on HN