Live data from Hacker News

Google DNS at 010.010.010.010

8.8.8.8

111–120 of 132 posts

Re: Google DNS at 010.010.010.010

#111
post #103

Earlier quoted context omitted.

>The practical benefit is that some ISPs run bad DNS servers that e.g. automatically redirect nxdomains to their spam pages. If you use Google or Cloudflare you can bypass this particular anti-feature. As I discussed here[0], my goto DNS server is 192.168.xxx.91. Which is to say I run my own recursive resolver. This avoids ISP DNS server issues as well as other issues (like these[1][2]). Also, Google/Cloudflare/whoev…

Since ISPs generally see DNS queries from the gateway and not individual hosts, wouldn't your ISP still be able to see those requests? AFAIK, the only way to prevent your ISP from collecting the domains you visit is if you use something like dns over https. Even then, you're tls connection leaks the domain via sni (hopefully this hole will get plugged by tls 1.3).

>Since ISPs generally see DNS queries from the gateway and not individual hosts, wouldn't your ISP still be able to see those requests?

Of course. Just as they can see every other packet that comes out of my network.

>AFAIK, the only way to prevent your ISP from collecting the domains you visit is if you use something like dns over https. Even then, you're tls connection leaks the domain via sni (hopefully this hole will get plugged by tls 1.3).

Actually, they can capture or log all your network traffic if they want, not just DNS traffic.

As for DoH/DoT, that's a huge can of worms that I dislike immensely. Why? Because it uses tcp/443. As such, any device that I don't roll myself (roku, fire stick, etc.) could (and with wider adoption, will) perform their own DoH/DoT requests that I can't intercept with my network-based ad/tracking/spying blocker (e.g., Pi-Hole).

That means that blocking ads/tracking is going to become enormously more difficult, unless I block tcp/443, limiting my ability to connect to pretty much any website these days.

And I am much more concerned about that than I am about my ISP logging netflow[0] data, or even capturing all my packets.

What's more, they are extremely unlikely to do the latter. Even with cheap storage, capturing all my packets (and even just the hundreds of other customers that connect to my head-end, let alone the millions of customers they have) isn't economically (or likely even physically) viable.

That said, if you're afraid that your ISP might be doing so, I suggest using a VPN. Then they only see the envelope of the encrypted VPN traffic and that's it.

Given that most data is going to be encrypted anyway (https, ssh, etc.), the fact that they can see where I'm going (which they need to know anyway to route the packets) doesn't really concern me.

As such, if my ISP really wants to capture all my DNS queries and other network connections (assuming they do so for all their customers, as I'm not anyone state-level actors are interested in), they're going to need some ginormous data centers for all that data storage.

Yes, NSA has their ginormous data center in Utah, but they're pulling data from Tier 1 peering points and nothing I do will impact that -- not even using a VPN.

As I said, I'm much more concerned with ads/tracking/spyware, as that's much more likely to be tied to me personally, as those folks want to maintain the fiction that they can effectively "target" advertising at me so they can keep charging the advertisers more and more.

So unless you're someone who some state actor wants to mess with (in which case, you're hosed anyway), blocking the corporate ad spies is more useful than worrying about your ISP. I'd note that Google is one of the biggest of those spies too.

As such, I'm going to focus on a real threat to my privacy that I can actually do something about (which includes doing my own recursive DNS queries), rather than worrying about stuff over which I have no control.

I'm not telling you what to do, just what I do.

[0] https://en.wikipedia.org/wiki/NetFlow

Edit: Added the missing link.

Re: Google DNS at 010.010.010.010

#112
post #14

It's also at 010.010.2056 or 0x8080808 or 01002004010. I made a little tool a while ago that iterates over all the options that I know of: https://lucb1e.com/randomprojects/php/funnip.php?ip=8.8.8.8 The variant found by OP is apparently the very last option that my tool generates. These days, Firefox is a bit boring (okay, okay, I'll admit it's a good choice for security) and translates these at the first opportunity…

Octal is a great way to mislead both human beings and software, and I kind of hope it gets removed by browsers as a result of this new attention. It’s one of those things that isn’t productive or useful in any way in our modern era and serves only to complicate with no benefit in return.

Probably useless in the browser, but who uses octal in general? I assume it's still important in some areas (networking?) but I don't actually know.

Only thing I can think of personally is UNIX file permissions.

Re: Google DNS at 010.010.010.010

#113
post #75

Earlier quoted context omitted.

Doesn’t this just highlight that php development ecosystem doesn’t value quality much? What even is a “file” in context of a web request? What about dependencies or logic defined in other files? This is just bizarre, I can’t see a sane codebase where this would be preferable to going on GitHub and pressing “.”

On the contrary, doesn't it highlight that the PHP development ecosystem values simplicity? That is, a simple application (which this is) can be contained within one file, rather than something requiring several folders, dependencies, and an 'init' command? I don't understand your criticism and I suggest you might not either.

The irony of thinking files and folders are too much for simple app and also praising a feature that is in direct relation to php’s MO of conflating codebase folder structure with requests’ path.

Edit: this reminds me, I was like this too at the beginning of my dev career, I also was completely in favor of this supposed “simplicity” of php, only much later, thanks to hickey’s nice talk I realized that I was confusing simplicity with ease.

https://www.infoq.com/presentations/Simple-Made-Easy/

Re: Google DNS at 010.010.010.010

#114
post #55

Earlier quoted context omitted.

Have you used malicious ISP DNS resolution?!

Not every ISP has malicious DNS resolution. For many people outside the US, their ISP DNS server is a superior option to Google DNS.

Possibly, but not in Australia. Among other things our government has a secret blacklist it forces ISPs to implement. https://en.wikipedia.org/wiki/Internet_censorship_in_Austral...

The usual reasons are given - protecting children and preventing other illegal activity, which is all well and good and commendable in theory. However there have been instances where the filter has been used to silence opposing political opinions, as well as prevent access to materials on subjective moral grounds (ie "hardcore" pornography, online gambling, discussion of suicides, etc) where the government has decided Aussies shouldn't do that sort of thing, which seems a bit puritanical and mildly thought police-y.

It's not like we're in an "actual dictatorship", by and large the representative democracy trundles along as best these things do, and the life and freedoms we enjoy in Australia make us incredibly privileged compared to much of the world. But this whole online censorship and thought policing our government seems fond of is something I disagree with. In addition to banning certain forms of speech and text, they're now pushing through an act that sets the stage for de-anonymising all users online with a government-issued "Digital ID", the next step presumably being making it illegal to provide and use anonymous web services in Australia. That has broad implications for things like Reporters Without Borders, corporate and government whistleblowers, etc.

Coupled with a historical record of every blocked or "suspect" DNS attempt, and these trends paint a dire picture for individuals who may have legitimate interests or even just curiosity about something like "how are drugs made." Handing this information to the federal government seems risky to me because I don't know what they're going to decide to make illegal to read and write about in the future. Our government has talked seriously about banning encryption many times over the years, and are currently at war against social media, so who knows what they'll do.

That doesn't mean I agree that people should get away with heinous acts or organised crime, but it's why I personally avoid using my ISP's DNS resolution in Australia. I don't exactly trust Google either, but I'd rather they deal with my DNS lookup than our technophobe government.

Sorry for the long rant, probably could have just left it at my first sentence, but it all touches on the one subject in Australian politics that really rubs me the wrong way, and most people I talk to here are of the mind "if you're not doing something wrong, there's nothing to worry about." Just, gah!

Re: Google DNS at 010.010.010.010

#116
post #75

Earlier quoted context omitted.

Doesn’t this just highlight that php development ecosystem doesn’t value quality much? What even is a “file” in context of a web request? What about dependencies or logic defined in other files? This is just bizarre, I can’t see a sane codebase where this would be preferable to going on GitHub and pressing “.”

> Doesn’t this just highlight that php development ecosystem doesn’t value quality much? As opposed to which web development ecosystem exactly? The only web development ecosystem with overall decent quality software that I could come up with is Java, and their understanding of quality is... enterprise-y. Give me a mature PHP framework over a NPM dependency tree, python web framework, or ruby on rails any day. At leas…

Which PHP frameworks do you have in mind?

Re: Google DNS at 010.010.010.010

#117

I found this quite amusing as it seems as if Google is trying to impersonate Cloudflare's 1.1.1.1, whereas 010.010.010.010 is indeed the octal representation of 8.8.8.8. Credit: IPv4 addresses are silly, inet_aton(3) doubly so. https://www.netmeister.org/blog/inet_aton.html

For clarity - 8.8.8.8 has been around as a free public DNS for a good bit longer than 1.1.1.1 has I think you probably know that already, but there are at least a couple of ways to interpret what you wrote. https://en.wikipedia.org/wiki/Google_Public_DNS https://en.wikipedia.org/wiki/1.1.1.1

Also, for those who don't know - you can use 1.1.1.2 which blocks all known Malware domains, and 1.1.1.3 to also block all adult content.

There's also always dns.adguard.com to block Ads (which is what I use on my phone).

Re: Google DNS at 010.010.010.010

#118
post #116

Earlier quoted context omitted.

> Doesn’t this just highlight that php development ecosystem doesn’t value quality much? As opposed to which web development ecosystem exactly? The only web development ecosystem with overall decent quality software that I could come up with is Java, and their understanding of quality is... enterprise-y. Give me a mature PHP framework over a NPM dependency tree, python web framework, or ruby on rails any day. At leas…

Which PHP frameworks do you have in mind?

Laravel, or any Symphony based framework is a great choice.

PHP is a very modern and mature language at this point. If the first thing you think of is Wordpress, then you’re behind.

Re: Google DNS at 010.010.010.010

#119
post #116

Earlier quoted context omitted.

Which PHP frameworks do you have in mind?

Laravel, or any Symphony based framework is a great choice. PHP is a very modern and mature language at this point. If the first thing you think of is Wordpress, then you’re behind.

And how relevant do you think highlight_file is for symphony or laravel?

Re: Google DNS at 010.010.010.010

#120
post #116

Earlier quoted context omitted.

Which PHP frameworks do you have in mind?

Laravel, or any Symphony based framework is a great choice. PHP is a very modern and mature language at this point. If the first thing you think of is Wordpress, then you’re behind.

I agree with these points although going back to the grandparent comment, the value of being able to show the source code of a controller with these frameworks by appending a query string is close to zero.
Post reply on HN