Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

101–110 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#101
post #72

Earlier quoted context omitted.

So, what he claims is that state actors monitor traffic at certain locations, extract subnet information from DNS packets that only large centralized DNS resolvers include when query some authoritative servers that where probed to support that feature. That subnet is not a subnet of an end user IP address, but an IP address of a recursive resolver of that user's ISP. They have to correlate that information with a con…

1.1.1.1 supports dns/https. It is entirely possible to make a request to 1.1.1.1 for an ip and have nobody be able to know what you made the request for. There is no guarantee the name server they are querying is the same as the server in the A result, and the idea is to reduce the number of points where people other than the A result and the client know that they plan to talk to each other. It's not bullshit.

> There is no guarantee the name server they are querying is the same as the server in the A result

That's ok. Let me try to explain a bit more:

Queries to 1.1.1.1 are going over public internet. And even though they are encrypted, they also carry metadata with them, including IP addresses of who is doing them, precise time, rough size, various OS specific stuff, etc. And packets going out to authoritative servers from 1.1.1.1 are in clear text. There is a very tiny window of possible queries out of 1.1.1.1 for encrypted data coming in from some IP address and therefore only a tiny number of possible responses from authoritative servers. Given that and enough intercepted data all over the world it is easy to correlate clear text DNS responses with IP addresses or who got responses from cache and on which popular website ended up, etc.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#102
post #72

Earlier quoted context omitted.

See the CEO's comment: https://news.ycombinator.com/item?id=19828702 > We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1. So it's not just "Cloudflare benefits from pushing anycast" (even if that's part of it).

So, what he claims is that state actors monitor traffic at certain locations, extract subnet information from DNS packets that only large centralized DNS resolvers include when query some authoritative servers that where probed to support that feature. That subnet is not a subnet of an end user IP address, but an IP address of a recursive resolver of that user's ISP. They have to correlate that information with a con…

[deleted]

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#103
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

Because in certain countries the ISP has to respect the legal regulations and so the DNS server provided/defined by each provider will block/redirect certain web sites. These could be torrent trackers, subtitle distribution sites, political and/or religious sites and so on... In some parts of the world alternate DNS servers allow people to access all sites :-)

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#104
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

Many people are otherwise using their ISP's DNS servers, which are often even worse with regards to performance and reliability. Long ago I did tech support for an ISP, and I'd say that 9/10ths of our "outages" were due to our overworked ancient DNS servers failing. I'd go off-script when I took calls during those kinds of outages, and just help people set 4.2.2.2 in their router's DNS settings the moment I saw a strong signal in the line test and hosts not resolving. Managers made snide comments about that not being the official procedure and "not displaying confidence in $ISP", but it fixed the problem.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#105

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

Encrypting dns is bad for end users. Please cut this shit out. You are acting like you are defending against the NSA, but in reality we will have a bunch of shitty IoT phoning data to indecipherable IP addresses without any meaningful defense of consumer privacy. It is hostile to customers who want to troubleshoot wtf apps are doing.

Normal DNS queries aren't encrypted. It's normal queries on port 53.

Users/programs/IoT can choose to use DNS-over-TLS or DNS-over-HTTPS, but that's not Cloudflare's fault.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#106
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

Because in certain countries the ISP has to respect the legal regulations and so the DNS server provided/defined by each provider will block/redirect certain web sites. These could be torrent trackers, subtitle distribution sites, political and/or religious sites and so on... In some parts of the world alternate DNS servers allow people to access all sites :-)

Not to mention that some ISPs redirect users to pages full of ads when a domain doesn't exist or use DNS to MITM users and inject ads into pages.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#107
post #97
post #67

Earlier quoted context omitted.

Thank you for your comment. Since HTTPS traffic already reveals communicating IPs to nation-state actors, could you clarify what attack vector removing user IP info from authoritative DNS queries protects against? In what way does Cloudflare publish its PoP geolocation? Is it a Cloudflare-specific API? Why not fake EDNS subnet info by providing the PoP’s? I notice of course that Google, Facebook, and Netflix still wo…

Its preventing the DNS authority to know the IP of who is making the request. CloudFlare decided its DNS should be the authority to the end user and Archive.is's DNS should be the authority only to CloudFlare. CloudFlare is breaking the bond between the end user and the Service provider. What CloudFlare is doing is centralizing authority to itself rather allowing authority to be distributed to all owners of the domai…

This is no different than any 3rd party DNS service. If the resolving DNS server you hit doesn't have a cached response, it reaches out to the upstream resolver. It doesn't pass your IP along to the upstream resolver

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#108
post #24
post #13

Earlier quoted context omitted.

It doesn’t really seem to be the resolvers “using a protocol that [archive.is] doesn’t support”; it seems that archive.is responds to queries from Cloudflare’s systems with an incorrect response. How is Cloudflare meant to work around that kind of behavior?

>"it seems that archive.is responds to queries from Cloudflare’s systems with an incorrect response." What makes the response incorrect? I was under the impression that DNS implementations were under no "practical" obligation to return consistent queries to differing requester IP addresses (hence stuff like split-horizon DNS and EDNS: https://developers.google.com/speed/public-dns/docs/ecs )

It is deliberately invalid.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#109
post #73

Earlier quoted context omitted.

True. Copying the information would be possible, but given they’re working on other efforts to replace the functionality of EDNS ECS in a standard way, it seems like a hacky bandaid.

EDNS is a working system today, doesn't seem that hacky to use it until a new system is actually ready (which doesn't seem to be anytime soon anyway).

It works if you don't care about privacy

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#110
post #93

Earlier quoted context omitted.

I just added an entry for archive.is in my etc/hosts.

How do I do that on my iPhone?

Without jailbreaking, I don't think you do. You can do it at the router level with dnsmasq, but then you'd always have to be VPN-ed into that network when you are out and about.

Although, I believe Cloudflare DNS app on iphone uses a VPN iOS API to do it's thing, so it should be possible to put dnsmasq-like functionality into an iOS app. I don't know if this exists already.

Post reply on HN