Live data from Hacker News

Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

radar.cloudflare.com

171–180 of 351 posts

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#171

Earlier quoted context omitted.

I'm just curious, given all the other options that respect your privacy and don't put data collection at the center of their business model, why do you use Cloudflare on your pi-hole?

what is the vector here? dns traffic is practically anonymous, there would have to be some very specific and purposeful trickery going on to link dns traffic to an identity. It sounds like something more hypothetical than a tangible threat model

> A Cloudflare Ray ID is an identifier given to every request that goes through Cloudflare.

https://developers.cloudflare.com/fundamentals/reference/clo...

if you think a little creatively about how this information could be used by an organization that was created at the insistence of the United States Department of Homeland Security, then you're on the right track.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#172
post #31

Earlier quoted context omitted.

The linked blog contains a story about who funds archive today and they presumably don’t like being exposed.

[flagged]

Archive today being free doesn’t excuse them using their audience to DDoS someone they don’t like or excuse them from modifying archive content. Also documenting who funds a service is in the public interest.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#173
post #155

Earlier quoted context omitted.

Because that would be subject to the whim of the provider, who subject to court orders would have to oblige to continue operating as US entity.

How does that differ from Quad9? You’re subject to Swiss laws, so there’s still a government involved? And you’re now hosted in an area where the US government has far fewer limitations on what they can attempt.

Quad9 is based in Switzerland, but the three founders-sponsors are US-based [0], so I’m not sure if it can be considered 100% safe from US government intervention.

[0] https://quad9.net/about/sponsors/

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#174
post #155

Earlier quoted context omitted.

How does that differ from Quad9? You’re subject to Swiss laws, so there’s still a government involved? And you’re now hosted in an area where the US government has far fewer limitations on what they can attempt.

Quad9 is based in Switzerland, but the three founders-sponsors are US-based [0], so I’m not sure if it can be considered 100% safe from US government intervention. [0] https://quad9.net/about/sponsors/

Also a quick search suggests that Switzerland has made Internet providers in-country block DNS results in the past.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#175

Earlier quoted context omitted.

what is the vector here? dns traffic is practically anonymous, there would have to be some very specific and purposeful trickery going on to link dns traffic to an identity. It sounds like something more hypothetical than a tangible threat model

It isn't anonymous. DNS server resolve, IP addresses by hostnames. It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit. Since ISP know your identity, and all it takes is to (request and get) the DNS logs and ISP servitude for all sort of questionable information, you as an identity are giving away all sites domains you visit.

> It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit.

Correction: they can log host names/IPs, not URLs. The path of any given URL is part of the HTTP header, invisible to onlookers (assuming HTTP and assuming HTTPS is uncracked).

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#176
post #152
post #144

Earlier quoted context omitted.

Relevant because Cloudflare manipulated the DNS using a false reasoning

1.1.1.2 blocks malware, and archive.today performs DDOS. Where's the false reasoning?

It‘s not a C&C/Botnet

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#177
post #176
post #152

Earlier quoted context omitted.

1.1.1.2 blocks malware, and archive.today performs DDOS. Where's the false reasoning?

It‘s not a C&C/Botnet

It is C&C -- it instructs their site visitors to DOS a specific site.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#178
post #155

Earlier quoted context omitted.

How does that differ from Quad9? You’re subject to Swiss laws, so there’s still a government involved? And you’re now hosted in an area where the US government has far fewer limitations on what they can attempt.

Quad9 is based in Switzerland, but the three founders-sponsors are US-based [0], so I’m not sure if it can be considered 100% safe from US government intervention. [0] https://quad9.net/about/sponsors/

The ASN and stuff is also operated by a US entity it seems like:

  ASHandle:       AS19281
  Street:         CleanerDNS Inc. dba Quad9
  Street:         1442A Walnut Street, Suite 501
  City:           Berkeley
  State/Prov:     CA
  Country:        US
They also have servers in the US, so that's yet another reason not to consider them "100% safe from US government intervention"

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#179
post #172

Earlier quoted context omitted.

[flagged]

Archive today being free doesn’t excuse them using their audience to DDoS someone they don’t like or excuse them from modifying archive content. Also documenting who funds a service is in the public interest.

>Also documenting who funds a service is in the public interest.

Not really, no. It's not unlikely to result in the service ceasing to exist.

Re: Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2

#180

Earlier quoted context omitted.

I'm just curious, given all the other options that respect your privacy and don't put data collection at the center of their business model, why do you use Cloudflare on your pi-hole?

Which options respect your privacy?

The ones where you don't send a single company all of your queries
Post reply on HN