Live data from Hacker News

Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

radar.cloudflare.com

151–160 of 351 posts

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#152
post #144

Earlier quoted context omitted.

True, but not relevant.

Relevant because Cloudflare manipulated the DNS using a false reasoning

1.1.1.2 blocks malware, and archive.today performs DDOS. Where's the false reasoning?

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#153

I think there are two angles to look at this. Yes, there’s the attack on the weblog. But there’s also pressure on archive.today, e.g. an FBI investigation [1] and some entity using fictitious CSAM allegations [2]. [1]: https://arstechnica.com/tech-policy/2025/11/fbi-subpoena-tri... [2]: https://adguard-dns.io/en/blog/archive-today-adguard-dns-blo...

I suppose an argument can be made that archive infringes copyright.

Hell I use it to circumvent paywalls.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#154

Earlier quoted context omitted.

I have no idea why anyone would use Cloudflare DNS, much less trust their more filtered versions.

Same thoughts. Cloudflare DNS is noticeably slow to resolve on some of my devices. Switching to literally any other DNS and the same domains resolve instantly. Could be a issue specific to my location or devices, but its been consistent enough that I stopped bothering.

I don't use the public resolvers but here [1] is a script that will show which of those public resolvers is fastest from your location. Add or remove resolvers as you desire. Be sure to scroll down to see a few of the sorting examples. Not my script or repo.

Just as a side note: Something I have done with this in the past as a fun experiment was to set up an Unbound DoT server on assorted VPS nodes in assorted locations around the country, run this script and configure each Unbound to use the 5 to 10 fastest servers on each node and cache results longer. Then I used Tinc (open source VPN) to connect to these VPS nodes from my home's Unbound and distribute the requests among all of them. I save query logs from all of them and use cron to look up all my queries hourly to keep the cache fresh and mess up any analytic patterns for my queries. Just a fun experiment. 99.99% of the time I just query the root DNS servers for what NS servers are authoritative for a given domain or what I call bare-backing the internet.

[1] - https://github.com/cleanbrowsing/dnsperftest

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#155
post #142

Earlier quoted context omitted.

So… why not use 1.1.1.1, cloudflare’s resolver that does not block resolution? 1.1.1.2 and .3 are explicitly offered with filtered responses.

Because that would be subject to the whim of the provider, who subject to court orders would have to oblige to continue operating as US entity.

How does that differ from Quad9? You’re subject to Swiss laws, so there’s still a government involved? And you’re now hosted in an area where the US government has far fewer limitations on what they can attempt.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#156
post #142

Earlier quoted context omitted.

Quad9. Many years ago I used Cloudflare, and more than once I had issues with them blocking websites I wanted to access. I absolutely despise that. I want my DNS to resolve domain names, nothing else. For blocking things I have Pi-Hole, which is under my control for that reason. I can blacklist or whitelist addresses to my needs, not to the whims of a corporation that wants to play gatekeeper to what I can browse.

So… why not use 1.1.1.1, cloudflare’s resolver that does not block resolution? 1.1.1.2 and .3 are explicitly offered with filtered responses.

I used to use 1.1.1.1. I still had issues.

Quad9 behaves exactly as I expect a DNS to work, in the sense that I only remember I use it when the topic of DNS pops up.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#157

Earlier quoted context omitted.

You think DDoS (which is illegal btw) is okay as long as you don't like the target?

Harassment an doxing are both illegal.

Doxxing is illegal? I am against it but if it's republishing public info I don't think it can be illegal in the US unless there is an intent element.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#158
post #79

Earlier quoted context omitted.

Should providing a public service absolve all sins?

So far, the only sin archive.today has been accused of is retaliating against a guy attempting to dox them. That's a pretty small sin in my book. To be written off as wildly unsuccessful but entirely justified self defense. DDoSing gyrovague.com is silly, not evil. The content on gyrovague.com which targets archive.today is evil, plain and simple.

The person who runs archive.today decided to involve me, and every other visitor, in their dispute. They decided to use us to hurt someone else. That's a pretty big sin in my book.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#159

Earlier quoted context omitted.

I'm just curious, given all the other options that respect your privacy and don't put data collection at the center of their business model, why do you use Cloudflare on your pi-hole?

Which options respect your privacy?

I use unbound (recursive resolver), and AdGuard Home as well (just forwards to unbound). Unbound could do ad-blocking itself as well, but it's more cumbersome than in AGH. So I use two tools for the time being.

The upside is there's no single entity receiving all your queries. The downside is there's no encryption (IIRC root servers do not support it), so your ISP sees your queries (but they don't receive them).

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#160
post #142

Earlier quoted context omitted.

So… why not use 1.1.1.1, cloudflare’s resolver that does not block resolution? 1.1.1.2 and .3 are explicitly offered with filtered responses.

I used to use 1.1.1.1. I still had issues. Quad9 behaves exactly as I expect a DNS to work, in the sense that I only remember I use it when the topic of DNS pops up.

Your claim was that 1.1.1.1 was blocking sites.

Are you saying now you just had issues with the quality of service? Or do you want to provide more details to substantiate the claim that they were blocking sites?

Post reply on HN