Live data from Hacker News

Cloudflare 1.1.1.1 Incident on July 14, 2025

blog.cloudflare.com

361–370 of 391 posts

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#361
post #358

Earlier quoted context omitted.

A better recommendation is to use Cloudflare for one of your DNS servers and a completely different company for the other.

Just wondering, how do y'all manage wifi portals and manually setting DNS services? I used to use cf and google's but it was so annoying to disable and re-enable that every time I use a public wifi network.

DNS is just a look up service. You can filter it or not but in the end it is just a "source of truth".

What are you trying to do on your wifi?

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#362

Earlier quoted context omitted.

I don't consider these interchangeable. They have different priorities and policies. If anything I'd choose one and use my ISP default as fallback.

Agreed in principle, but has anyone seen any practical difference between these DNS services? What would be a more detailed downside for using these in parallel instead of the ISP default as a fallback?

Some of them are so privacy-preserving they block sending your own location to the original DNS server, which makes anycast not work, so you get slower connections to the site.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#363
post #224

Earlier quoted context omitted.

They are not all in the US.

Well that's the experience I had. Obviously caching was enabled (unbound), but most DNS keepalive times are so short as to be fairly useless for a single user. Even if a root server wasn't in the US, it will still be pretty slow for me. Europe is far worse. Most of Asia has bad paths to me, except for Japan and Singapore which are marginally better than the US. Maybe Aus has one...?

Cloudflare actually runs one of the root servers (https://blog.cloudflare.com/f-root/).

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#364

Earlier quoted context omitted.

Cloudflare is a for-profit company in the US. Their privacy claims can't be believed. Even if we did believe them, we have no idea if rsolution data isn't taken by US TLA agencies.

It seems we have a lot of Cloudflare fanbois and apologists here. This is not unexpected. But is anything I'm writing untrue, or just unpopular? Does anyone who's downvoting me care to point out any inaccuracies about what I've written?

It's illegal for a US company to lie to their investors, so if you believe they're lying to you, you should sue them for securities fraud.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#365
post #71

> For many users, not being able to resolve names using the 1.1.1.1 Resolver meant that basically all Internet services were unavailable. Don't you normally have 2 DnS servers listed on any device. So was the second also down, if not why didn't it go to that.

Listing two is better than nothing, but it's not great. If one goes down, there's nothing that tracks which one is working, so you usually see long hangs and intermittent issues.

Unless you do something fancy with a local caching dns proxy with more than one upstream.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#366
post #327

> The way that Cloudflare manages service topologies has been refined over time and currently consist of a combination of a legacy and a strategic system that are synced. This writing is just brilliant. Clear to technical and non-technical readers. Makes the in-progress migration sound way more exciting than it probably is! > We are sorry for the disruption this incident caused for our customers. We are actively maki…

I can't tell if you are being sarcastic, but "legacy" is a term most often used by technical people whereas "strategic" is a term most often used by marketing and non-technical leadership. Mixing them together annoys both kinds of readers.

[deleted]

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#367
post #358

Earlier quoted context omitted.

Just wondering, how do y'all manage wifi portals and manually setting DNS services? I used to use cf and google's but it was so annoying to disable and re-enable that every time I use a public wifi network.

DNS is just a look up service. You can filter it or not but in the end it is just a "source of truth". What are you trying to do on your wifi?

Many wifi networks redirect non-encrypted http traffic to their captive portal. For the redirect to work, your DNS needs to be the default one provided by the router so that http://neverssl.com resolves to the wifi's "Please accept our ToS to get online" page.

If you aren't using their DNS, then your network requests just get dropped (as you're not approved yet). You need their DNS to learn how to access their captive host so they can whitelist your mac address.

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#368
post #280
post #209

Earlier quoted context omitted.

I became a bit disillusioned with quad9 when they started refusing to resolve my website. It's like wetransfer but supporting wget and without the AI scanning or interstitials. A user had uploaded malware and presumably sent the link to a malware scanner. Instead of reporting the malicious upload or blocking the specific URL¹, the whole domain is now blocked on a DNS level. The competing wetransfer.com resolves just…

What is your ticket #? Let's see if we can get this resolved for you.

Oh hey, didn't expect this to actually be seen by many people, let alone you guys!

There was no ticket number yet because I was mainly trying to resolve it upstream (whoever made it get into uBlock's default block list, Quad9, and probably other places) and then today when I checked your site specifically, the link in "False Positive? " (when you do a lookup for a blocked domain) just links back to itself so I couldn't open a case there either. Now that I look at the page again, with the advice in mind from a sibling comment to just email you, I now see that maybe this is supposed to go to the generic contact form and I needn't go through this domain status page. Opening the contact page now, I see that removal from blocklist is a selectable option so I'll use that :)

The ticket number I just submitted is 41905. Not that I'd want you to now apply preferential treatment, I didn't expect my post above to be seen by many people though I very much appreciate that you've reached out here. Makes me think you're actually interested in resolving this type of issue for small website operators, where the complete block without so much as a heads up felt a bit, well, like that might not get me anywhere. If the process just works as it normally should, that's good enough for me! Thanks for encouraging me to actually open a ticket!

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#369
post #275
post #209

Earlier quoted context omitted.

I became a bit disillusioned with quad9 when they started refusing to resolve my website. It's like wetransfer but supporting wget and without the AI scanning or interstitials. A user had uploaded malware and presumably sent the link to a malware scanner. Instead of reporting the malicious upload or blocking the specific URL¹, the whole domain is now blocked on a DNS level. The competing wetransfer.com resolves just…

I've been the victim of similar abuse before, for my mail servers and one of my community forums that I used to run. It's frustrating when you try to do everything right but you're at the mercy of a cold and uncompromising rules engine. You just convinced me to ditch quad9.

In the ticket I just opened (see sibling thread), I asked which blocklist my domain was on. Maybe let's see what comes out of it, perhaps they can improve the process (e.g. drop that blocklist, or notify the abuse record of domains which they're blocking so that domain owners are at least aware of where they can go to fix things)

I don't see contact info on your profile or website/blog, but I can post here what the outcome is

Edit: I love your blog's theme btw!

Re: Cloudflare 1.1.1.1 Incident on July 14, 2025

#370

Earlier quoted context omitted.

That sounds good in principle, but is there a more private configuration that doesnt send DNS resolutions to cloudfare, google et al. ie. avoid BigTech tracking, and not wanting DOH. dnsmasq with a list of smaller trusted DNS providers sounds perfect, as long as it is not considered bad etiquette to spam multiple DNS providers for every resolution? But where to find a trusted list of privacy focused DNS resolvers. Th…

NextDNS. Generous free tier, very affordable paid tier. Happy customer for several years and I've never noticed an outage.

Likewise; they make it easy to use across my devices, each with bespoke configuration.
Post reply on HN