Live data from Hacker News

1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

webcache.googleusercontent.com

161–170 of 253 posts

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#161
post #139

Earlier quoted context omitted.

Where did you get China Telecom from? The IANA released 1.0.0.0/8 to APNIC in 2010 and 1.1.1.0/24 was assigned to APNIC-LABS. The IRR Netname is actually still APNIC-LABS too. See: https://stat.ripe.net/1.1.1.1#tabId=at-a-glance

The IANA released 1.0.0.0/8 to APNIC, and APNIC subsequently sold parts of it to China Telecom. I deduct this because neighboring IP ranges ( https://stat.ripe.net/1.1.0.0#tabId=at-a-glance and https://stat.ripe.net/1.1.2.0#tabId=at-a-glance ) belong to China Telecom. So 1.1.1.0 likely did too. I think the whois information may have reflected the China Telecom ownership before it was updated. APNIC-LABS is probably j…

No. 1.1.1.0/24 was not allocated because idiots poisoned it. For a long time address ranges like these were left unused because it wasn't worth anybody's time handling the problems but since IPv4 is now full we may as well do what we can with them.

So China Telecom will never have been given 1.1.1.0/24

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#162
post #118

Earlier quoted context omitted.

nope -- as stated, up to the website owner. They can whitelist Tor if they'd like to. Entirely the website owner's decision to make.

Cloudflare is responsible for even providing such a "feature". They aren't off the hook here.

Indeed, our security service allows our customer (the website owner) the option to adequately protect their website.

I'm not sure you actually made a point other than to confirm that we allow website owners to fully whitelist Tor if they'd like to.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#164
post #14

Well crap. I was used to going to 1.1.1.1 on my cellphone when on wireless APs that tried to redirect you an agreement page. Now there is a valid cert/website at that address. Guess I'll have to pick a new one.

Switch to an example.com bookmark.

Never had any issue and there's an extremely low, almost infinitely zero, chance of the domain dropping and being taken over by squatters (re: neverssl)

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#165
post #145

Earlier quoted context omitted.

I wonder if, given that we now have a number of reasonably decent DNS services, if we can make software better to obscure/divide up our DNS use. Take your 1.1.1.1, 8.8.8.8, 9.9.9.9, maybe your ISP DNS, etc., check against them randomly to try and avoid giving any one of them all of your DNS request traffic, maybe look up the same address on two of them to confirm that you're getting the same destination from both?

I'm waiting for Facebook to get 6.6.6.6. That's a DNS service everyone would love to use, right?

If you are Chinese, you would. 1, 6 and 8 are lucky numbers to Chinese.

I suspect that the whole reason why 8.8.8.8 is a Google DNS server is that they were originally only 4.4.4.4 until someone Chinese pointed out that 4 is an unlucky number. :)

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#166
post #139

Earlier quoted context omitted.

The IANA released 1.0.0.0/8 to APNIC, and APNIC subsequently sold parts of it to China Telecom. I deduct this because neighboring IP ranges ( https://stat.ripe.net/1.1.0.0#tabId=at-a-glance and https://stat.ripe.net/1.1.2.0#tabId=at-a-glance ) belong to China Telecom. So 1.1.1.0 likely did too. I think the whois information may have reflected the China Telecom ownership before it was updated. APNIC-LABS is probably j…

No. 1.1.1.0/24 was not allocated because idiots poisoned it. For a long time address ranges like these were left unused because it wasn't worth anybody's time handling the problems but since IPv4 is now full we may as well do what we can with them. So China Telecom will never have been given 1.1.1.0/24

Indeed, and there was always great worry about how polluted that IP space might be. I posted this link elsewhere:

https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pd...

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#167
post #12

The concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast…

What about akamai? They are a much larger CDN (no one talks about it on HN because they are not a startup). I agree with your assertion that it will become a single point of failure with many web properties but also I think that HN has a sort of filter bubble on startups (for obvious reasons) and I'm not sure cloudflare is as big as people make it out to be. Also, Google has 8.8.8.8 which could be for the same thing…

CloudFlare publishes their pricing. Akamai doesn't.

Dealing with salespeople is a massive PITA. They're not going to tell me anything that's not in the docs or support forums and I don't want to spend a week negotiating. I've seen many others make this point on HN over the years.

Maybe Akamai only focuses on large enterprise customers while CloudFlare also goes for the SMB market. IDK. The HN crowd seems to work at SMBs (startups included) or at companies big enough to operate their own CDN.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#169

Earlier quoted context omitted.

(Removed.)

Use dnscrypt-proxy 2.x -- The 1.x branch has reached end of life. Cloudflare's resolvers have been supported by dnscrypt-proxy for quite some time and are even present in the example configuration.

Thanks.

Re: 1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?

#170
post #131

Earlier quoted context omitted.

There is quad9 - 9.9.9.9 :)

Highly recommend Quad9. Their privacy policy is absolutely no identifying data logging, period. They're also the few providers offering DNS over TLS. Google, on the other hand, keeps identifying logs for 24-48 hours.

Just watch out for them if you're not in the US - any DNS-based CDNs will send you to an American node rather than your closest, it could slow things down a little

  dig @9.9.9.9 icnerd-1e5f.kxcdn.com
  icnerd-1e5f.kxcdn.com.	3600	IN	CNAME	s-us-ca00.kvcdn.com.
  s-us-ca00.kvcdn.com.	55	IN	CNAME	p-ussj00.kxcdn.com.
  p-ussj00.kxcdn.com.	55	IN	A	209.58.129.70

  dig @8.8.8.8 icnerd-1e5f.kxcdn.com
  icnerd-1e5f.kxcdn.com.	21599	IN	CNAME	p-uklo00.kxcdn.com.
  p-uklo00.kxcdn.com.	59	IN	A	217.146.91.55
Post reply on HN