I wonder how much ICMP is going to those IPs. I ping 1.0.0.1 ("ping 1.1") as a quick check to ensure my internet is working a lot, far quicker and less stretching than typing ping 8.8.8.8. When I'm tracing a fault I'll ping 1.1.1.x as I can then tcpdump on a spanport against that IP and be fairly confident any traffic is from my test point and not from another device. I'm sure I'm not the only one.
Setting Up 1.1.1.1 for Families on a Pi-Hole
61–70 of 82 posts
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#62I wonder how much ICMP is going to those IPs. I ping 1.0.0.1 ("ping 1.1") as a quick check to ensure my internet is working a lot, far quicker and less stretching than typing ping 8.8.8.8. When I'm tracing a fault I'll ping 1.1.1.x as I can then tcpdump on a spanport against that IP and be fairly confident any traffic is from my test point and not from another device. I'm sure I'm not the only one.
I even remember them once writing about having such an unusually high volume of ICMP traffic that they had to divert that traffic to a dedicated box at some point.
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#63When 1.1.1.1 for Families launched, it blocked access to GLADD's site because Cloudflare didn't do a good enough job testing any of this stuff and they just pulled in filters from other parental companies, some of which turned out to be anti-gay. Cloudflare apologized, pushed a couple of fixes, but never actually took a step back and asked how this happened. In the meantime, 1.1.1.1 for Families launched without blocking access to sites like Stormfront. Cloudlfare didn't think it was appropriate for them to make a determination over whether that site was safe for kids.
I think that our society is just generally a lot less thoughtful about filtering adult content than it is about filtering other forms of content like political speech, and we don't think about adult content filters as having a downside, or being real censorship. So when 1.1.1.1 for Families was released, I came up with a challenge: https://danshumway.com/blog/sex-censorship-is-censorship/
I do think there are scenarios where it's completely appropriate to block content for children, and I do think families should always able to make these kinds of determinations. People and communities have a fundamental Right to Filter (https://anewdigitalmanifesto.com/#right-to-filter). However, adult content isn't the only content that falls into the category of being harmful to children. It is utter hypocrisy for Cloudflare to launch a service that blocks adult content but not hate speech; both forms of content are legitimate for parents to want off of their networks.
My challenge is, if Cloudflare is frightened of the implications of being the company that decides what is and isn't hate speech, then why isn't it also frightened of being the company that decides what is and isn't adult material? Why do we view accidental censorship of LGBTQ+ informational materials as less of an existential free speech risk than accidental censorship of political ideas or extremist groups? Cloudflare still, over a year later, doesn't really have clear documentation I can find anywhere about what specific criteria they use to make filtering decisions on 1.1.1.3 beyond that they "aim to imitate" Google Safe Search. Would people tolerate that kind of fuzziness if they were filtering hate speech or political extremism?
There is a reasonable debate people can have about whether or not it's appropriate for Cloudflare to be the company that carves out sections of the Internet that are inappropriate, even as an opt-in filter. I think both sides of that debate can make some good points, and reasonable people could go in either direction. But for me, the biggest question isn't really whether Cloudflare is the right company to build and maintain Internet filters. For me, the biggest question is about which subjects Cloudflare views as OK to moderate, and which communities Cloudflare is OK offloading the externalities of their moderation onto.
Because frankly, in free speech communities we do have a lot of hypocrisy about this. There's no argument to be made that extremist hate sites aren't just as dangerous to kids as pornography is. We should try to have more consistency about stuff like this. Are we OK with content moderation or not?
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#64I still think this is a business that Cloudflare shouldn't be involved in. There are very legitimate reasons for parents to filter Internet content. But Cloudflare is in a unique position here, they have a brand as a company that cares about free speech, and specifically because of who they are, they really shouldn't be making determinations about what is and isn't inappropriate content for kids. When 1.1.1.1 for Fam…
1.1.1.1 for Families is an awful, dangerous, harmful product. You should not use it.
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#65Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.
Parents have a responsibility to teach, guide, and educate their children to prepare them for adulthood. Today a vast amount of your "life" is online (much more than a decade ago). It only makes sense for parents to "parent" their children online. > "Horrendously invasive" Children do not have a right to privacy from their parents. Privacy (from parents) is a privileged that is earned and can be taken away. If you fo…
No, they really don't thankfully.
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#66Earlier quoted context omitted.
The DNS approach helps more for malware than it does for adult content and the like. Twitter, Reddit, Tumblr, Google/Bing image search etc all have adult content easily within reach and DNS can't do anything about that. It doesn't make sense on a technical level so it doesn't even matter if it makes sense on a philosophical level.
Using 1.1.1.3 blocks adult content on search engines like Google - it’s obviously not hard to find adult content through other means, but it avoids accidents. https://one.one.one.one/family/
Those sorts of "accidents."
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#67Earlier quoted context omitted.
>Why aren't they just called infrequently used domains then? You could call them "infrequent" but "long-tail" is also a common description to convey a Power Law distribution: https://en.wikipedia.org/wiki/Long_tail I think in this case about DNS caching, "long tail" is better than "infrequent". In the wikipedia graph, some of the domain lookups in yellow may be "frequent" (absolute sense) but simultaneously but much…
DNS is essentially a cache. I've never once in my life heard of infrequently accessed cache items as "long-tail". This is definitely a dumb phrase that should be avoided.
The parent poster wrote "long tail _domains_" and not cache items: https://news.ycombinator.com/item?id=29036188
You also used the word "domains" when you asked about "infrequently used domains" and that's the context I was responding to. I didn't say that cache items are labeled "long tail".
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#68I still think this is a business that Cloudflare shouldn't be involved in. There are very legitimate reasons for parents to filter Internet content. But Cloudflare is in a unique position here, they have a brand as a company that cares about free speech, and specifically because of who they are, they really shouldn't be making determinations about what is and isn't inappropriate content for kids. When 1.1.1.1 for Fam…
1.1.1.3 (or 2) is a tool in the tool chest. Some people may find it too aggressive and don’t need to implement it, some may find it too conservative and implement more. No tool will be perfect for everyone, and if you don’t find it hits the right balance you don’t have to use it. No one has to use it, and cloudflare can literally release any free block list they want and call it parental blocking. It’s free, it’s a best effort product that doesn’t drive revenue, and it is up to each network owner to determine which blocks they want.
It would be a totally different story if the company was determining blocking for the US or people were forced to use it. But they aren’t.
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#69Earlier quoted context omitted.
Interesting, but what are long tail domain?
I think the idea is that you take a list of all domains and then count the number of DNS lookups that are done for each over the course of some time period (e.g. 1 year). Then sort them from high to low number of lookups. At the start of the list you'll probably find only a few domains with many billions of lookups. As you go down the list you'll find many domains with very few lookups, the "long tail". It's a bit co…
Perhaps 1/frequency.
Re: Setting Up 1.1.1.1 for Families on a Pi-Hole
#70Why do parents feel the need to control what their children do online? I had unrestricted internet access as a child and turned out fine. Although I must say, a DNS based approach is more benign than some of the horrendously invasive alternatives.
We figured it would be better to train and guide them around the "search for pussy pictures" results than to let them grow up in a sheltered internet at home and get confronted with the "less desirable results" when connected to the open networks of friends & neighbours.