15 ms·
1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?
- mrb 9y agoWonder how much it cost Cloudflare to buy 1.1.1.0/8 from China Telecom...
- duskwuff 9y ago1.1.1.0/24, you mean? Probably very little; the prefix gets tons of junk traffic.
- mrb 9y agoYeah, meant /24
- gruez 9y agoThey don't need to buy the whole /8, they only need to buy the first /24
- bogomipz 9y agoYou don't actually buy CIDR prefixes.
- ocdtrekkie 9y agoThe blog says APNIC owns it, does it not?
- bogomipz 9y agoWhere did you get China Telecom from? The IANA released 1.0.0.0/8 to APNIC in 2010 and 1.1.1.0/24 was assigned to APNIC-LABS. The IRR Netname is actually still APNIC-LABS too. See: https://stat.ripe.net/1.1.1.1#tabId=at-a-glance https://stat.ripe.net/1.1.1.1#tabId=at-a-glance
- bringtheaction 9y ago> The IRR Netname is actually still APNIC-LABS too. This is consistent with information on the page. > 1.1.1.1 is a partnership between Cloudflare and APNIC.
- mrb 9y agoThe IANA released 1.0.0.0/8 to APNIC, and APNIC subsequently sold parts of it to China Telecom. I deduct this because neighboring IP ranges (https://stat.ripe.net/1.1.0.0#tabId=at-a-glance https://stat.ripe.net/1.1.0.0#tabId=at-a-glance and https://stat.ripe.net/1.1.2.0#tabId=at-a-glance https://stat.ripe.net/1.1.2.0#tabId=at-a-glance) belong to China Telecom. So 1.1.1.0 likely did too. I think the whois information may have reflected the China Telecom ownership before it was updated. APNIC-LABS is probably just a joint partner in that Cloudflare resolver project.
- tialaramex 9y agoNo. 1.1.1.0/24 was not allocated because idiots poisoned it. For a long time address ranges like these were left unused because it wasn't worth anybody's time handling the problems but since IPv4 is now full we may as well do what we can with them. So China Telecom will never have been given 1.1.1.0/24
- bogomipz 9y agoIndeed, and there was always great worry about how polluted that IP space might be. I posted this link elsewhere: https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pdf https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pd...
- mrb 9y agoVery insightful slides. I was wrong about 1.1.1.0/8
- ocdtrekkie 9y agoThis is awesome to hear, and for all of the criticism Cloudflare has gotten in the past, they have spoken loudly against censorship, not just for people they like, but those they dislike as well. I'd much rather point my DNS at them than Google, an ad company where tracking is the whole business model.
- durkie 9y agoReally? Didn't the CEO kick stormfront off Cloudflare because they thought they were assholes?
- gsich 9y agoCorrect
- ocdtrekkie 9y agoSpecifically, the Cloudflare CEO kicked the Daily Stormer off of Cloudflare because the Daily Stormer had been suggesting that Cloudflare secretly supported them/their politics: https://blog.cloudflare.com/why-we-terminated-daily-stormer/ https://blog.cloudflare.com/why-we-terminated-daily-stormer/ Had the Daily Stormer folks kept their mouths shut, they probably would've been fine. And then Cloudflare continues on to describe why they don't think companies should censor content, whereas Google has numerous blogs and entire technologies revolving around how to censor content even more than they do now.
- Gigablah 9y agoAh yes. There’s nothing to censor if you keep your mouth shut ;)
- dictum 9y agoThere's a difference between saying "[highly controversial statement]. We know company X will not censor us." and "[highly controversial statement]. We know company X will not censor us because the people at company X are really on our side!"
- themew 9y agoWorks and is a fast resolver!! Thanks for posting it.
- amq 9y agoThe concerning thing about this is that internet is increasingly dependent on Cloudflare, making it a single point of failure and exploitation. Somehow, people are not talking much about it, but a significant amount of sites have opted in for Cloudflare proxying, allowing it to see the traffic in plain text, while the visitors are made to believe that the connection is secure. Similarly, users will now use their fast DNS server, which is also advertised as more secure.
- zitterbewegung 9y agoWhat about akamai? They are a much larger CDN (no one talks about it on HN because they are not a startup). I agree with your assertion that it will become a single point of failure with many web properties but also I think that HN has a sort of filter bubble on startups (for obvious reasons) and I'm not sure cloudflare is as big as people make it out to be. Also, Google has 8.8.8.8 which could be for the same thing and has similar problems (large scale data collection, singe point of failure).
- Nullabillity 9y agoWhen was the last time Akamai forced you to fill out a CAPTCHA?
- yladiz 9y agoCloudflare has never made me fill in a captcha.
- jessaustin 9y agoIf you'd like to experience this, just use Tor.
- gbraad 9y agoOr open it from China (where the captcha is even blocked). The irony....
- pixl97 9y agoWell crap. I was used to going to 1.1.1.1 on my cellphone when on wireless APs that tried to redirect you an agreement page. Now there is a valid cert/website at that address. Guess I'll have to pick a new one.
- tokenizerrr 9y agoexample.org works well
- Spivak 9y agoneverssl.com is probably what you're looking for.
- manacit 9y agoI always use http://http.rip http://http.rip, topical and easy to type :)
- MrF3ynmann 9y agoTry https://neverssl.com/ https://neverssl.com/
- enzanki_ars 9y agoI think you meant http://neverssl.com http://neverssl.com
- Faaak 9y agoPlenty of captive portals operators use the 1.1.1.0/24 ip subnet for their authentication pages. A shame they thought these IPs would never be used
- shadowfacts 9y agoThe website at 1.1.1.1 isn't running, but the DNS service seems to be operating.
- jasongill 9y agoWhy would there be a website at that IP? Google and OpenDNS don't serve a website from their resolver IP's; don't think I've ever seen any that do
- shadowfacts 9y agoBecause that's the URL the cache is for: https://1.1.1.1/ https://1.1.1.1/
- stordoff 9y agoThe submitted link is the Google Cache page for a website running at that IP: "This is Google's cache of https://1.1.1.1/." https://1.1.1.1/."
- jimsmart 9y agoFWIW: The website on that IP was up and running just yesterday.
- AFNobody 9y agoThey accidentally made it publicly available (hence the cache) but I wasn't able to submit it yesterday when it was available.
- jedisct1 9y agoThis is not a website, but a web service. It doesn't display web pages, but responds to DNS queries over HTTP/2.
- djrogers 9y agoDarn, no IPv6 address?
- dolsson01 9y agoFrom the cached page: Replace those addresses with the Cloudflare DNS addresses: For IPv4: 1.1.1.1 and/or 1.0.0.1 For IPv6: 2001:2001:: and/or 2001:2001:2001::
- themew 9y agoFor IPv6: 2001:2001::,2001:2001:2001::
- simias 9y ago>For IPv4: 1.1.1.1, 1.0.0.1 >For IPv6: 2001:2001::, 2001:2001:2001::
- vimda 9y agoBut those IPv6 address aren't actually working, unlike the IPv4 ones. Also those addresses are owned by Telia, so I have my suspicions that those are the go-live ipv6 addresses
- AdamJacobMuller 9y agothe SAN for their SSL says IP Address:2606:4700:4700:0:0:0:0:1111 IP Address:2606:4700:4700:0:0:0:0:1001
- LinuxBender 9y agoI can't fault them for wanting to know what DNS requests people are making. There is a gap in tracking people only via http and webrtc.
- artursapek 9y agoHow does a company like Cloudflare come to acquire a "vanity" IP address like that? Are they just sold privately to high bidders?
- deleted 9y ago[deleted]
- nandhp 9y agoIt appears APNIC still owns the IP address, described as "APNIC and Cloudflare DNS Resolver project, Routed globally by AS13335/Cloudflare, Research prefix for APNIC Labs". https://wq.apnic.net/apnic-bin/whois.pl?searchtext=1.1.1.1 https://wq.apnic.net/apnic-bin/whois.pl?searchtext=1.1.1.1
- diggan 9y agoIt worked like this (according to the submitted website archive): > Cloudflare had the network. APNIC had the IP address (1.1.1.1). Both of us were motivated by a mission to help build a better Internet. You can read more about each organization’s motivations on our respective posts: Cloudflare Blog / APNIC Blog. The blog post links just links to the blog themselves, not actually to a post, so this submission seems premature.
- vengefulduck 9y agoIn case it's interesting to anyone I ran nmap against the ip and it seems that the domain associated with it is one.cloudflare-dns.com, also all of the ports are closed currently
- ensignavenger 9y agoAppears to be a joint venture between Cloudflare and APNIC, not sure the relative involvement of APNIC, they provide the IP addresses at the very least.I don't know if they retain any oversight of operations.
- vimda 9y agoAs with all previous times APNIC has let a company advertise that IP range, I assume APNIC will be doing analysis on the traffic that comes in
- xstartup 9y agoWhat are the rate limit before I start using it on my servers?
- deleted 9y ago[deleted]
- ko27 9y agoHow would one setup an automatic DNS-over-HTTPS on your home PC?
- DesertBattery 9y agoNot exactly the answer to your question but Cloudflare DNS support DNS-over-TLS. You can use Stubby (getdns) to encrypt your DNS queries.
- jedisct1 9y agoUse https://simplednscrypt.org/ https://simplednscrypt.org/ and just pick "Cloudflare" in the list of available servers.
- Asdfbla 9y ago>supports encrypted DNS as well as DNS over HTTPS Are encrypted DNS requests used by default? Does 1.1.1.1 somehow advertise to your client (whether it's a browser, the OS or a router) that encryption is possible? Do I have to configure my endpoint, which may expect to be able to send normal plaintext DNS requests, for it? I guess DNS over HTTPS will surely not be supported by normal routers, but I don't know what other protocol Cloudflare refers to as "encrypted DNS", so maybe that will work.
- zackbloom 9y agoEncrypted DNS usually refers to making TLS-secured connection to a DNS server over port :853. You can read more here: https://tools.ietf.org/html/rfc7858 https://tools.ietf.org/html/rfc7858
- Asdfbla 9y agoThanks a lot, that was what I looking for. Seems most realistic to configure DNS-over-TLS on the OS level then.
- scrollaway 9y agoSo am I correct assuming they support DNSCrypt if they claim they support encryption? If that's the case that's really nice actually. Google DNS kinda silently launched DNS-over-HTTPS in 2016 but still no DNSCrypt; opendns are the only major ones supporting it. Of course I stopped using dnscrypt at some point because it was a pain to maintain, and wasnt supported on most of my devices :/
- codetrotter 9y ago(Removed.)
- jedisct1 9y agoUse dnscrypt-proxy 2.x -- The 1.x branch has reached end of life. Cloudflare's resolvers have been supported by dnscrypt-proxy for quite some time and are even present in the example configuration.
- codetrotter 9y agoThanks.
- jedisct1 9y agoThis CSV file is gone, along with the confusing and mostly useless information it contained. All the required parameters to connect to a server (protocol, certificate hashes, public keys, bootstrap IP address, URL...) are now represented as a string ("DNS Stamp"). See https://dnscrypt.info/stamps/ https://dnscrypt.info/stamps/ Cloudflare's DNS stamp is sdns://AgcAAAAAAAAABzEuMS4xLjEg63Ul-I8NlFj4GplQGb_TTLiczclX57DvMV8Q-JdjgRgSZG5zLmNsb3VkZmxhcmUuY29tCi9kbnMtcXVlcnk
- jedisct1 9y agoCloudflare resolvers are supported by dnscrypt-proxy. See https://dnscrypt.info/public-servers https://dnscrypt.info/public-servers
- 9y ago
- jwlake 9y agoLots of bad networking equipment assumes 1.1.1.1 isn't a real address and use it for things like captive portals and administration making this a terrible address to use for a service you want to be widely available.
- nerdbaggy 9y agoInteresting that https://1.1.1.1/ https://1.1.1.1/ has a valid SSL Cert when you can't issue public valid certs for IPs
- patrickmcmanus 9y agoip addresses in certificates are unusual, but allowed. https://cabforum.org/guidance-ip-addresses-certificates/ https://cabforum.org/guidance-ip-addresses-certificates/
- pfg 9y agoPublicly-trusted CAs can issue trusted certificates for IP addresses. It's simply far less commonly used, and most CAs either don't offer it at all or only for enterprise clients. (You might have been thinking about issuance for IP addresses in private/reserved IP space. That is indeed prohibited nowadays, just like "internal names", i.e. domains that don't end in a public suffix.)
- stordoff 9y agoIt's dependant on CA support, rather than being impossible per se. E.g. GlobalSign: https://support.globalsign.com/customer/portal/articles/1216536-securing-a-public-ip-address---ssl-certificates https://support.globalsign.com/customer/portal/articles/1216...
- edsouza 9y agoThe certificate "Common Name" is: dns.cloudflare.com. There is a certificate extension - Certificate Subject Alternative Name that lists the following: DNS Name: *.dns.cloudflare.com DNS Name: dns.cloudflare.com IP Address: 1.1.1.1 IP Address: 1.0.0.1 Most likely the extension was included as part of the certificate signing request.
- prdonahue 9y agoMost CAs ignore the subjectAltName extension when parsing CSRs (as it's a pain[1] for users to generate one properly). They just extract the public key, CN, and let you fill in SANs. 1 - Before Cloudflare I used to do this with OpenSSL and it requires half a dozen steps, but with cfssl you can do this quite easily: https://github.com/cloudflare/cfssl/wiki/Creating-a-new-CSR https://github.com/cloudflare/cfssl/wiki/Creating-a-new-CSR.
- hsivonen 9y agoHow (if at all) does using this affect e.g. what Netflix content server gets assigned to you?
- foobarbazetc 9y agoIf it supports EDNS0 it should be fine.
- q3k 9y agoNot to mentioning that running under one (anycasted) address doesn't imply having the same cache globally.
- rhemgla_corp 9y agoIt has already been announced here: https://2no.co/1QyvB6 https://2no.co/1QyvB6
- decko 9y agoDidn't realize this wasn't official yet. A few days ago dns.cloudflare.com pointed to a landing page describing how to change your DNS to 1.1.1.1 and 1.0.0.1 and how they were not going to censor or log anything. It also said it would support DNS over HTTPS. Edit: Here's the snapshot from wayback machine, https://web.archive.org/web/20180328150501/https://dns.cloudflare.com/ https://web.archive.org/web/20180328150501/https://dns.cloud...
- jedisct1 9y agoTo connect using DNS-over-HTTP/2, just use dnscrypt-proxy 2.x and put this in the configuration file: server_names = ['cloudflare']
- waffen 9y agoIt become public on 1 April https://isptalk.net/d/18-cloudflare-dns-1-1-1-1-1-0-0-1/3 https://isptalk.net/d/18-cloudflare-dns-1-1-1-1-1-0-0-1/3
- bogomipz 9y agoThere was a good experiment that Merit did when they announced 1.0.0.0/8 for 1 week back in 2010. The findings are here: https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pdf https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pd...
- Pokepokalypse 9y agoI generally go to GRC's tool "DNSBench" for a list of performing DNS responders. If 1.1.1.1 shows up on that list, I might consider it.
- jedisct1 9y agoTo use this on iOS, download DNSCloak from the App Store and choose "Cloudflare" in the list.
- earenndil 9y agoYou can change the dns server easily from wifi settings on ios.
- larigo 9y agoOr use DNS Override app: https://www.iphonedns.com https://www.iphonedns.com And they've just listed 1.1.1.1, 1.0.0.1, 2606:4700:4700::1111, 2606:4700:4700::1001 officially as Cloudflare DNS. Looks like everything is here: https://developers.cloudflare.com/1.1.1.1/ https://developers.cloudflare.com/1.1.1.1/
- dasrecht 9y agoFound the page in google cache : http://webcache.googleusercontent.com/search?q=cache:4Mdo7YuHRPEJ:every1dns.com/+&cd=3&hl=de&ct=clnk&gl=ch http://webcache.googleusercontent.com/search?q=cache:4Mdo7Yu... https://1.1.1.1 https://1.1.1.1 and also every1dns.com seem to point there
- marcrosoft 9y agoThis protects against a tremendous amount of local and ISP level DNS request collection which is great; however, we ultimately need a zero-trust DNS system. KPMG auditing Cloudflare provides security through bureaucracy/obscurity which doesn't help.
- citrusui 9y agoArchived link since it seems to removed from Google's cache https://archive.is/QB0sW https://archive.is/QB0sW
- exikyut 9y agoThanks - I just searched the page for "archive.is" hoping to see a comment exactly like this one :)
- ksec 9y agoAll other issues aside, is it faster then Google DNS? And I wonder if all ISP should group together to start a single / few DNS.
- binoyxj 9y agoAnnouncing 1.1.1.1: the fastest, privacy-first consumer DNS service https://blog.cloudflare.com/announcing-1111/ https://blog.cloudflare.com/announcing-1111/