Earlier quoted context omitted.
Well no, CloudFlare doesn't get to talk about not "violating the integrity of DNS" after you stopped responding to "any" queries in violation of the standard. You started by doing your own thing and then proposed a change to the standard to fit your business decision. [0] [0] https://www.rfc-editor.org/info/rfc8482
There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.
Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
171–180 of 210 posts
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#172Earlier quoted context omitted.
There's a difference between changing results (or adding) and not supporting a feature that is dangerous and rarely used. Kind-of like banning handguns vs. providing unknownly modified guns.
Wait, but both of these are horrible ideas. Horrible analogy; theres no need to bring politics into this.
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#173Earlier quoted context omitted.
This is no different than any 3rd party DNS service. If the resolving DNS server you hit doesn't have a cached response, it reaches out to the upstream resolver. It doesn't pass your IP along to the upstream resolver
Did I say something that was untruthful?
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#174Earlier quoted context omitted.
Honestly, Cloudflare choosing not to hastily slap a band-aid on a problem like this just makes me feel more compelled to continue using 1.1.1.1. I hesitate to compare this to Apple calling themselves “courageous” when removing the headphone jack, but in this case, I think the word is appropriate. I’ll happily stand behind you guys if you take some PR hits while forcing the rest of the industry to make DNS safer – sin…
For the moment, I also do trust CloudFlare's intentions, but it's wrong to classify this as some kind of stoic resolve in not "slapping a band-aid on a problem" since that's exactly what they did after their business decision about not responding to "any" queries.
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#175We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…
Honestly, Cloudflare choosing not to hastily slap a band-aid on a problem like this just makes me feel more compelled to continue using 1.1.1.1. I hesitate to compare this to Apple calling themselves “courageous” when removing the headphone jack, but in this case, I think the word is appropriate. I’ll happily stand behind you guys if you take some PR hits while forcing the rest of the industry to make DNS safer – sin…
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#176We don’t block archive.is or any other domain via 1.1.1.1. Doing so, we believe, would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service. Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the…
The operator of archive.is claims that they suffer from a "massive mismatch" between those query IPs and actual traffic. Any idea why? [Is that claim wrong? Is archive.is to blame? Is cloudflare to blame? Are ISPs badly routing the DNS queries?]
Do you have stats on how well the geolocation works in practice?
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#177Earlier quoted context omitted.
Or you know you Piss off CloudFare CEO and he directs them to censor a site... Which has happened in the past
Exactly. If it's not "the right kind" of content behind a domain, it doesn't even take a court order for CloudFlare to censor it.
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#178Earlier quoted context omitted.
> That assumes that the nameserver and the actual server are run by the same party which quite often is not the case. Cloudflare can check if nameserver and the actual server are run by different parties, and if so omit subnet information from EDNS response. It is not hard to implement — Google and OpenDNS used to require manual whitelisting to receive EDNS subnet responses (not sure if they still do). Cloudflare's C…
> Cloudflare's CDN leaks user's full online identity to Google via reCaptcha, especially when you use Tor. How?
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#179Earlier quoted context omitted.
Exactly. If it's not "the right kind" of content behind a domain, it doesn't even take a court order for CloudFlare to censor it.
that is not censorship.
Re: Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
#180Earlier quoted context omitted.
It's possible your ISP is intercepting all traffic for port 53 and sending it to their own nameservers (which do send client subset) instead of you actually taking to cloudflare's 1.1.1.1 at all.
Links for documented instances of this practice?
I couldn't figure out if this was plain incompetency, an attempt to enforce DNS-based website blocking, or some programmer willfully implementing the latter with the former so that it would be reasonably easy to circumvent.
Also Italian residential providers really, really like to mess with NXDOMAIN instead returning a helpful error page with affiliate links instead. You might think you can imagine how much shit this breaks; you probably don't.