Live data from Hacker News

Cloudflare 1.1.1.1 Incident on July 14, 2025

blog.cloudflare.com

171–180 of 391 posts

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#171
post #158

Earlier quoted context omitted.

Private DNS on Android refers to 'DNS over HTTPS' and would normally only accept a hostname. Normal DNS can normally be changed in your connection settings for a given connection on most flavours of Android.

No, it is not DNS over HTTPS it is DNS over TLS, which is different.

Android 11 and newer support both DoH and DoT.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#172

Earlier quoted context omitted.

Private DNS on Android refers to 'DNS over HTTPS' and would normally only accept a hostname. Normal DNS can normally be changed in your connection settings for a given connection on most flavours of Android.

Its DNS over TLS. Android does not support DNS over HTTPS except Google's DNS

It does since Android 11.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#173
post #127

Interesting to see that they probably lost 20% of 1.1.1.1 usage from a roughly 20 minute incident. Not sure how cloudflare keeps struggling with issues like these, this isn't the first (and probably won't be the last) time they have these 'simple', 'deprecated', 'legacy' issues occuring. 8.8.8.8+8.8.4.4 hasn't had a global(1) second of downtime for almost a decade. 1: localized issues did exist, but that's really the…

There's more to DNS than just availability (granted, it's very important). There's also speed and privacy. European users might prefer one of the alternatives listed at https://european-alternatives.eu/category/public-dns over US corporations subject to the CLOUD act.

Everyone, European or not, should prefer anything but Cloudflare and Google if they feel that privacy has any value.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#174

Earlier quoted context omitted.

Just pair 1.1.1.1 with 9.9.9.9 (Quad9) so you have fault tolerance in terms of provider as well.

Windows 11 does not allow using this combination

Huh? Did they break the primary/secondary DNS server setup that has been present in all operating systems for decades?

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#175
post #115

Earlier quoted context omitted.

What would be a good reason to switch back from Google DNS?

After trying both several time I since stayed with google due to cloudflare always returning really bad IPs for anything involving CDN. Having users complain stuff take age to load because you got matched to an IP on opposite side of planet is a bit problematic especially when it rarely happen on other dns providers. Maybe there is a way to fix this but I admit I went for the easier option of going back to good old 8…

No, it's deliberately not implemented:

https://developers.cloudflare.com/1.1.1.1/faq/#does-1111-sen...

I've also changed to 9.9.9.9 and 8.8.8.8 after using 1.1.1.1 for several years because connectivity here is not very good, and being connected to the wrong data center means RTT in excess of 300 ms. Makes the web very sluggish.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#177

Earlier quoted context omitted.

Just pair 1.1.1.1 with 9.9.9.9 (Quad9) so you have fault tolerance in terms of provider as well.

Windows 11 does not allow using this combination

How so? Does it reject a secondary DNS server that’s not in the same subnet or something similar?

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#178
post #127

Earlier quoted context omitted.

There's more to DNS than just availability (granted, it's very important). There's also speed and privacy. European users might prefer one of the alternatives listed at https://european-alternatives.eu/category/public-dns over US corporations subject to the CLOUD act.

HN users might prefer to run their own. It's a low maintenance service. It's not like running a mail server.

I think that might be overestimating the technical prowess of HN readers on the whole. Sure, it doesn't require wizardry to set up e.g. Unbound as a catch-all DoT forwarder, but it's not the click'n'play most people require. It should be compared to just changing the system resolvers to dns0, Quad9 etc.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#179
Question: Years ago, back when I used to do networking, Cisco Wireless controllers used 1.1.1.1 internally. They seemed to literally blackhole any comms to that IP in my testing. I assume they changed this when 1.0.0.0/8 started routing on the Internet?
Post reply on HN