Live data from Hacker News

1.1.1.1 for Families

blog.cloudflare.com

121–130 of 171 posts

Re: 1.1.1.1 for Families

#121
post #62
post #50

Earlier quoted context omitted.

Millions of people in the US can't change their ISP. I live in a major city and would have to drop my speed by 90% if I switched to my other option. I have two options total.

Doesn't T-Mobile US offer home internet over 4G and 5G in most of the US now? I've actually been using tethering for home internet, and it's often faster and cheaper than landline alternatives. Easily get 100Mbps in my location over 4G LTE on an old phone.

T-Mobile US is a funny example since they have been caught intercepting traffic for other DNS resolvers and silently responding with their own.

https://esd.io/blog/t-mobile-dns-hijack.html

Re: 1.1.1.1 for Families

#122
I experimented with 1.1.1.3 on a small network segment by configuring DHCP to make 1.1.1.3 the default. I found that they resulted in numerous false-positives that turned out to be a real nuisance. As I went around to various machines and either overrode the DHCP settings with another DNS and/or added lines to the hosts file, I decided that just because you _can_ use DNS for content filtering, doesn't mean it's a particularly effective modality.

Cloudflare does have a tool that allows you to correct false positives... https://radar.cloudflare.com/categorization-feedback/ But I found that the corrections I made were ignored with only one exception. The one I successfully corrected took many attempts over several weeks.

I ended up throwing in the towel on the whole thing and giving up on Cloudflare DNS altogether. That's not to say that others couldn't find value in it. I just found it to be more trouble than it was worth.

Re: 1.1.1.1 for Families

#123

Earlier quoted context omitted.

They laid it out pretty simply in the article: 1.1.1.1 - General 1.1.1.2 - No Malware 1.1.1.3 - No adult content Personally I like how they laid this out, makes it super easy to remember.

1.1.2.1 - General with no ads 1.1.2.2 - No Malware and no ads 1.1.2.3 - No adult content and no ads This would be amazing if they have the guts to do it. I suspect they will one day when they become huge (they're already handling some 10% of global internet traffic). Today, I want a big corporate pi hole that is managed for me - enough fire power to block shitty ads. Completely undercut Google, FB, Twitter ad machine…

I'm not sure I follow why this would be a big deal. There are already ad filtering DNS resolvers and most people are better served by a browser extension.

Re: 1.1.1.1 for Families

#125
post #95

Earlier quoted context omitted.

I use Pi-Hole + Unbound forwarding to Cloudflare/Quad9 over TLS. It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.

>It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. I love DNSSEC, but am not in favor of DoH/DoT. Mostly because I can't control DoH/DoT requests emanating from my network, as they're already encrypted and can't be differentiated from standard HTTPS traffic. That's an issue (and will become a much bigger on…

If you can't control where your device is making DNS requests then it's not your device. It's the manufacturer's surveillance capitalist revenue generator.

We need more devices that actually respect the user.

Re: 1.1.1.1 for Families

#126

Who bears the brunt of the task of collecting every adult/NSFW domain out there? Doesn't such a list grow by huge numbers each day? What is the name of this list, and where can I get it?

Search for block lists, here’s a popular one that is updated regularly.

https://raw.githubusercontent.com/StevenBlack/hosts/master/a...

Re: 1.1.1.1 for Families

#127
post #123

Earlier quoted context omitted.

1.1.2.1 - General with no ads 1.1.2.2 - No Malware and no ads 1.1.2.3 - No adult content and no ads This would be amazing if they have the guts to do it. I suspect they will one day when they become huge (they're already handling some 10% of global internet traffic). Today, I want a big corporate pi hole that is managed for me - enough fire power to block shitty ads. Completely undercut Google, FB, Twitter ad machine…

I'm not sure I follow why this would be a big deal. There are already ad filtering DNS resolvers and most people are better served by a browser extension.

It would be a huge deal. Sort of how Apple has the power to put in place a whole slew of privacy measures on the iPhone. Let Big Tech fight amongst themselves. The opposite would be terrifying.

I consider Cloudflare a formidable player wedging between Big Tech corporations.

Re: 1.1.1.1 for Families

#128
post #123

Earlier quoted context omitted.

1.1.2.1 - General with no ads 1.1.2.2 - No Malware and no ads 1.1.2.3 - No adult content and no ads This would be amazing if they have the guts to do it. I suspect they will one day when they become huge (they're already handling some 10% of global internet traffic). Today, I want a big corporate pi hole that is managed for me - enough fire power to block shitty ads. Completely undercut Google, FB, Twitter ad machine…

I'm not sure I follow why this would be a big deal. There are already ad filtering DNS resolvers and most people are better served by a browser extension.

we have a pi hole and it makes a world of difference. smart devices and iphones are adless in our house.

Re: 1.1.1.1 for Families

#129
post #95

Earlier quoted context omitted.

I use Pi-Hole + Unbound forwarding to Cloudflare/Quad9 over TLS. It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. Post-Snowden revelations I feel pretty confident that DNS requests in the clear are being surveilled. I don't know for sure that requests to Cloudflare or Quad9 are being surveilled.

>It would be nice if all servers supported DoT/DoH + DNSSEC and you could roll your own recursive DNS server and have more trust in traffic not being intercepted. I love DNSSEC, but am not in favor of DoH/DoT. Mostly because I can't control DoH/DoT requests emanating from my network, as they're already encrypted and can't be differentiated from standard HTTPS traffic. That's an issue (and will become a much bigger on…

I don't think my ISP can easily intercept the content of DoT DNS requests.

They would need a valid certificate for 1.1.1.1#cloudflare-dns.com or 9.9.9.9#dns.quad9.net from a trusted (by me) CA, correct?

Now obviously that's not impossible but is a VPN any better in that scenario?

Post reply on HN