Live data from Hacker News

Cloudflare 1.1.1.1 Incident on July 14, 2025

blog.cloudflare.com

341–350 of 391 posts

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#341

Earlier quoted context omitted.

I think just setting up Unbound is even less trouble. Servers come and go. Getting rid of the dependency altogether is better than having to worry who operates the DNS-servers and how long it's going to be available.

i am 95% certain i run unbound in a datacenter, and i have pihole local, my PC connects to pihole first, and if that's down, it connects to my DC; pihole connects to the DC and one of the filtered DNS providers (don't remember which) and GTEi's old server, that still works and has never let me down. No, not that one, the other one. i have musknet, though, so i can't edit the DNS providers on the router without buying…

Having a 2nd trustworthy router consumes extra energy, but maybe it's worth it. More than once my router made an update and silently disabled the pi-hole.

Having a fully configured spare pi-hole in a box also helps. Another time my pi-hole refused to boot after a power outage.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#342

Earlier quoted context omitted.

That sounds good in principle, but is there a more private configuration that doesnt send DNS resolutions to cloudfare, google et al. ie. avoid BigTech tracking, and not wanting DOH. dnsmasq with a list of smaller trusted DNS providers sounds perfect, as long as it is not considered bad etiquette to spam multiple DNS providers for every resolution? But where to find a trusted list of privacy focused DNS resolvers. Th…

NextDNS. Generous free tier, very affordable paid tier. Happy customer for several years and I've never noticed an outage.

This

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#343

Interesting to see that they probably lost 20% of 1.1.1.1 usage from a roughly 20 minute incident. Not sure how cloudflare keeps struggling with issues like these, this isn't the first (and probably won't be the last) time they have these 'simple', 'deprecated', 'legacy' issues occuring. 8.8.8.8+8.8.4.4 hasn't had a global(1) second of downtime for almost a decade. 1: localized issues did exist, but that's really the…

Yes, I honestly switched back to 8.8.8.8 and 8.8.4.4 google DNS. 100% stable, no filtering, fast in the EU.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#344
post #280

Earlier quoted context omitted.

What is your ticket #? Let's see if we can get this resolved for you.

Why not address the REAL issue: > I haven't been able to find any recourse. [...] there seems to be no way to clear my name.

From the parent comment the path of recourse is a ticket. Does not help if hn is needed to have it looked at.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#345

I’m surprised at the delay in impact detection: it took their internal health service more than five minutes to notice (or at least alert) that their main protocol’s traffic had abruptly dropped to around 10% of expected and was staying there. Without ever having been involved in monitoring at that kind of scale, I’d have pictured alarms firing for something that extreme within a minute. I’m curious for description o…

This is one of those graphs that would have been on the giant wall in the NOC in the old days - someone would glance up and see it had dropped and say “that’s not right” and start scrambling.

That's how I picture it. Is that not how it is? Everyone working from home and the big chart is on the TV but someone in the family changed channels?

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#346

Earlier quoted context omitted.

Please don’t. It doesn’t make sense, doesn’t help, doesn’t improve anything and is just waste of money, time, power and people. Now without crying: I saw multiple, big companies getting rid of NOC and replacing that with on duties in multiple, focused teams. Instead of 12 people sitting 24/7 in group of 4 and doing some basic analysis and steps before calling others - you page correct people in 3-5 minutes, with exac…

24/7 on-call is basically mandatory at any major network, which cloudflare is. Your contractual relations with other networks will require it.

The question is, which is better: 24/7 shift work (so that someone is always at work to respond, with disrupted sleep schedules at regular planned intervals) or 24/7 on-call (with monitoring and alerting that results in random intermittent disruptions to sleep, sometimes for false positives)?

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#347
post #127

Earlier quoted context omitted.

There's more to DNS than just availability (granted, it's very important). There's also speed and privacy. European users might prefer one of the alternatives listed at https://european-alternatives.eu/category/public-dns over US corporations subject to the CLOUD act.

HN users might prefer to run their own. It's a low maintenance service. It's not like running a mail server.

Running your own and being the sole user is the exact same thing as using a dns server (you need to obtain nameservers for any given domain which you have to contact a dns server for).

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#349

How does Cloudflare compare with OpenDNS?

Cloudflare is a for-profit company in the US. Their privacy claims can't be believed. Even if we did believe them, we have no idea if rsolution data isn't taken by US TLA agencies.

It seems we have a lot of Cloudflare fanbois and apologists here. This is not unexpected. But is anything I'm writing untrue, or just unpopular? Does anyone who's downvoting me care to point out any inaccuracies about what I've written?

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#350

Earlier quoted context omitted.

That sounds good in principle, but is there a more private configuration that doesnt send DNS resolutions to cloudfare, google et al. ie. avoid BigTech tracking, and not wanting DOH. dnsmasq with a list of smaller trusted DNS providers sounds perfect, as long as it is not considered bad etiquette to spam multiple DNS providers for every resolution? But where to find a trusted list of privacy focused DNS resolvers. Th…

There are no good private DNS configurations, but if you don't trust the big caching recursive resolvers then I'd consider just running your own at home. Unbound is easy to set up and you'll probably never notice a speed difference.

I trust my isp far more than I trust cloudflare and google
Post reply on HN