Live data from Hacker News

Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

news.ycombinator.com

151–160 of 210 posts

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#151
post #123

Earlier quoted context omitted.

If the govt of your jurisdiction (American I assume?) commanded you to censor a certain domain or block of IPs with a court order, what exactly happens? I'm not sure if this has been done on the DNS level before but do you guys have a plan in case it ever does happen?

Or you know you Piss off CloudFare CEO and he directs them to censor a site... Which has happened in the past

Can you cite any source on this?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#152
post #34
post #33

Earlier quoted context omitted.

This diverges pretty hard from your earlier comparison, between this scenario and the Linux kernel breaking userspace. If a dev updates their code so it won’t run unless an kernel flag is enabled, the kernel hasn’t broken userspace, and kernel devs are unlikely to add a “fake-enabled-flag” to trick the userspace program, even if it’s popular. Likewise, I don’t expect my DNS resolver to add in custom behavior if upstr…

If every other resolver works, then I expect Cloudflare to work. The kernel hardcodes plenty of hacky things to get specific hardware to work.

When the Linux Kernel hardcodes an "acceptable DNS resolver" list into net/, then that argument might be valid, but for now, it isn't.

Archive.is operators are throwing a temper tantrum. It isn't in Cloud Flare or anyone else's best interest to appease them.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#153

Earlier quoted context omitted.

Alternatively: Cloudflare simply is making a subversive play against their competitor CDNs. Client subnet of a DNS request is used for initial rough mapping by Cloudflare competitors such as Akamai (definitely) and I believe Fastly ( and probably others) . Stripping it easily adds at least a few milliseconds to the time to first byte and most likely results a request re-routing on the second or third request. After a…

Google has its own public DNS and CDN, I'm pretty sure that counts.

Isn't Google CDN a public beta or did it just exit a public beta into a GA? If so, it is a non-entity for at least a year long contracts that the other CDNs have with its customers. Probably a non-entity for years to come.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#154
post #92

archive.org works fine with 1^4. What is the advantage of using archive.is?

Archive.org, the Internet Archive, and archive.is, a webpage capture service that seems to have a primary name of "Archive.today", are wholly separate concerns, offerring different services.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#155

Earlier quoted context omitted.

Well no, CloudFlare doesn't get to talk about not "violating the integrity of DNS" after you stopped responding to "any" queries in violation of the standard. You started by doing your own thing and then proposed a change to the standard to fit your business decision. [0] [0] https://www.rfc-editor.org/info/rfc8482

There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.

Wait, but both of these are horrible ideas. Horrible analogy; theres no need to bring politics into this.

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#156

Earlier quoted context omitted.

@eastdakota what about just failing without response on archive.is calls so the second resolver address configured in the client will be used? I understand this is also a DNS integrity violation, however the result for the end user would be either the same if they don’t have a second resolver configured or enhanced if they do. The current effect is I stop using 1.1.1.1 when I need archive.is (often) and set it back t…

DNS either has integrity or it doesn’t. We get a response from an Authoritative server and, as a Resolver, we believe our responsibility is to return it. If we start making exceptions because of bad PR, how can you trust us to do the right thing when the stakes are even higher (e.g., nationstate pressure)? As an aside, I used to think that when Emerson said that “a foolish consistency is the hobgoblin of little minds…

I would recommend you leave exegesis of Emerson to the experts. What he meant is much closer to "pave the cowpaths" than "break things that currently work by enforcing arbitrary standards".

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#157

Earlier quoted context omitted.

> Say you remove/don't proxy the ECS information, and I get some generic, non-geo-location aware response back. In the majority of cases, wouldn't my next step be to open a TCP connection to the IP in the response, and immediately leak my full IP address to the other end? That assumes that the nameserver and the actual server are run by the same party which quite often is not the case.

> That assumes that the nameserver and the actual server are run by the same party which quite often is not the case. Cloudflare can check if nameserver and the actual server are run by different parties, and if so omit subnet information from EDNS response. It is not hard to implement — Google and OpenDNS used to require manual whitelisting to receive EDNS subnet responses (not sure if they still do). Cloudflare's C…

> Cloudflare's CDN leaks user's full online identity to Google via reCaptcha, especially when you use Tor.

How?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#158
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

Because what you get is often faster, more accurate and more resilient compared to the junk DNS run by most ISPs.

And because most site visits start with a Google search anyway.

And finally, because I am comfortable with their privacy statement : https://developers.google.com/speed/public-dns/privacy

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#159
post #107
post #97

Earlier quoted context omitted.

Its preventing the DNS authority to know the IP of who is making the request. CloudFlare decided its DNS should be the authority to the end user and Archive.is's DNS should be the authority only to CloudFlare. CloudFlare is breaking the bond between the end user and the Service provider. What CloudFlare is doing is centralizing authority to itself rather allowing authority to be distributed to all owners of the domai…

This is no different than any 3rd party DNS service. If the resolving DNS server you hit doesn't have a cached response, it reaches out to the upstream resolver. It doesn't pass your IP along to the upstream resolver

Did I say something that was untruthful?

Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)

#160
post #158
post #90

I don't get why people use 1.1.1.1 8.8.8.8 etc, for more then debugging. Why tell Google et.al about every site you visit !? And get slightly slower, less accurate and less resilient DNS lookups ...

Because what you get is often faster, more accurate and more resilient compared to the junk DNS run by most ISPs. And because most site visits start with a Google search anyway. And finally, because I am comfortable with their privacy statement : https://developers.google.com/speed/public-dns/privacy

I live in New Zealand where all the ISPs and mobile carriers provide fast and reliable DNS resolvers. I've looked into switching to alterntive DNS providers but every one of them are slower than my ISP's resolver. I'm aware that the sitation is quite different in the US and certan other countries, but I wish more Americans were aware that junk ISP-provided DNS servers seem to be an issue exclusive to certain countries (such as the US). I think it would be an intrerestin exercise to figure out why they occur in certain countries and not in other countries.
Post reply on HN