Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

111–120 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#111
post #65
post #62

Earlier quoted context omitted.

I don't know of any particular popular concrete instance, but why is it hard to believe? It's trivial to implement and would be brought to you by the same people who think serving ads for NXDOMAIN is a good idea. https://www.dnsleaktest.com/what-is-transparent-dns-proxy.ht...

That link was useful, thank you. I don't find it hard to believe technically, but it strikes me as a fundamentally different practice than what I'd head of before. If I request for traffic to go to a certain IP, I expect it to be sent to that IP. MITMing and manipulating that traffic is bad, but not delivering it at all is qualitatively different. I suspect it could be grounds for a serious civil or criminal action.

I can confirm we run across transparent dns proxying with customers at DNSFilter all the time. Mobile carriers are the worst for doing this.

A few days ago it was a customers compromised router doing it.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#113
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

I’m curious. What DNS server do you use? Or do you just memorize the IPs of the websites you want to visit? :P

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#114

In Firefox I'm using DNS over HTTPS ( https://mozilla.cloudflare-dns.com/dns-query ) and there is no issue accessing archive.is. Actually I wanted to query archive.is manually but I don't know how to do it in DoH.

Firefox is likely falling back to your local resolver (the default) when it can't find a domain.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#115
Archive.is is very interesting. I was checking and they block (by responding back with 127.0.0.3):

- 1.1.1.1

- Neustar DNS

- AdGuard DNS

But they don't block Quad9 or CleanBrowsing that also do not send the EDNS subnet. Very curious way of blocking itself out of the Internet. OpenDNS blocks it (sends to their block page):

https://dnsblacklist.org/?domain=archive.is

Would love to hear from someone from archive.is what is going on.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#116

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

If the govt of your jurisdiction (American I assume?) commanded you to censor a certain domain or block of IPs with a court order, what exactly happens? I'm not sure if this has been done on the DNS level before but do you guys have a plan in case it ever does happen?

Jurisdiction would include every place where they have a business presence. Their page https://www.cloudflare.com/en-au/about-overview/ lists quite a few international phone numbers, which may or may not correspond with offices and subsidiary companies in those locations.

I assume they'd just have to go along with such legal demands, or withdraw from the relevant country, unless the penalty for not complying was very small.

It will probably become an issue some day. In Australia, for example, courts can issue DNS bans of particular sites to individual ISPs. You can avoid these bans entirely by using a service like Cloudfare DNS.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#117
post #93

Earlier quoted context omitted.

I just added an entry for archive.is in my etc/hosts.

How do I do that on my iPhone?

It's possible using DNSCloak, under Advanced Options > Enable Cloaking.

You'll need to add a hosts file to your iCloud Drive.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#119
post #92

archive.org works fine with 1^4. What is the advantage of using archive.is?

Because you usually want to use the service that has the snapshot you want to view. And that isn't always archive.org. But it is my first place to go as well.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#120

We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…

The experience for the user is that the page just keeps loading indefinitely, while showing a blank page. Is there nothing Cloudflare could do to inform the browser about the situation, so that the browser can show some kind of a message to the user? As it stands, to the user it just looks like their connection died.

[deleted]
Post reply on HN