7 ms·
It was reworded enough times to make their promise vague and not well defined.
by _eht 9y ago
It was reworded enough times to make their promise vague and not well defined.
- eastdakota 9y agoI’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never provide APNIC any identifying information. We don’t upload any data to them. While they can query for questions like: “How many queries came from India in the last 24 hours?” they can’t query anything on a specific user. If you have concerns, ask them here. I’ll answer.
- lulmerchant 9y agoHow do you know where the requests came from without IP addresses? Do you log ASN or something?
- eastdakota 9y agoWe keep IPs in memory to help stop abuse and debugging ng other issue, but we promise to purge all logs within 24 hours or less.
- kuschku 9y agoI expect that no human from APNIC or Cloudflare will ever look at raw data from 1.1.1.1, nor will any of it be recorded, or used in aggregated data that retains any personal information. As personal information count full IP addresses, the content of requests, or any set of data that can be used to recover these. That is what "we respect your privacy" means.
- eastdakota 9y agoNeither we nor APNIC can query “what” or “how many” requests from any IP have been made. We can query things like: 1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers? If you have specific concerns, please raise them here.
- tannercollin 9y agoWhat's in it for you guys? How do you make money off of 1.1.1.1? Thanks!
- celticninja 9y agoI guess they don't, they just make a better internet, which helps their customers of their other services, and the rest of us. Seems like so good old fashioned altruism to me.
- eastdakota 9y agoBrand. How much would you pay if you were us to associate your brand with privacy/security and speed? Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it. Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often because employees believe in our mission. 1.1.1.1 helps with that.
- kabacha 9y ago> Our mission is to help build a better Internet. I've been working a lot with open data and I have huge problem with Cloudflare ruining open internet with bot protection and such. The issue I have is that public data is public, be it bot or human. I'm having real issue with you guys saying that your mission is to better the internet when you break shitton of floss apps that are essentially harmless and people who want to do harm, crawl at huge rates for commercial purposes break your systems like it's made of twigs. I'm saying this as a person who works on both sides and can't help but call you out. So sorry unless you turn to non-profit I'm really not buying your "helping the internet" song.
- deleted 9y ago[deleted]
- thinkloop 9y agoHello, Are the gigabytes of junk billions of tiny requests or are there large requests as well? Are you finding it more difficult than expected to manage the data? I'm a 1.1.1.1 customer since you launched, thanks a lot for it.
- eastdakota 9y agoNope. We have a lot of excess capacity. Doesn’t increase our costs. But, that’s a longer conversation…
- walrus01 9y agoNeteng here: without seeing the traffic charts for individual interfaces and aggregations, I would bet cloudflare has a shitload of excess inbound capacity. They are a content pushing CDN. I would bet that at a major IX where they have one 100Gbps port that their out:in ratio is 90:10 or greater. So if they only have 6-9 Gbps of traffic inbound on a 100GbE port to a fabric consisting of 80+ bgp peers, they have a lot of extra capacity to absorb unwanted inbound traffic before it becomes an operational concern. Have seen edge traffic charts for major porn hosting companies and the out:in traffic ratio is like 97:3
- decisiveness 9y ago>they can’t query anything on a specific user. What exactly do you mean by "user"? Can they query DNS traffic by IP address / subnet? Exactly what are all of the restrictions there? EDIT: Is there a whitelist of things they can query by or do you simply trust them to be good citizens, have a binding legal agreement, all of the above?
- eastdakota 9y agoNo. We have a legally binding agreement. And, more importantly, we don’t store or give them access to IPs or anything else that may be associated with any individual. Look at a DNS query, look at what could be identifying — let us know where concerns are. My hunch is we’ve thought of it. If not, we will fix. We don’t want personally identifiably info. It creates a legal risk for us. We purge it as quickly as we can.
- davrosthedalek 9y agoWe don’t want personally identifiably info. It creates a legal risk for us. We purge it as quickly as we can. Ding ding ding, we have a winner. If more people would realize this, we would have less data breaches. To get there, a data breach must become more costly for the companies.
- chinathrow 9y agoFrom https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/privacy-policy/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...: "Specifically, APNIC will be permitted to access query names, query types, resolver location and other metadata via a Cloudflare API, that will allow APNIC to study topics like the volume of DDoS attacks launched on the Internet and adoption of IPv6." I interpret "query names" as some values obtained from DNS queries hitting 1.1.1.1, e.g. "foo.example.com". Is your answer to "What data do you provide to APNIC?" complete in the statement above? Thanks for clarifying.
- eastdakota 9y agoNo querying IPs, ever. Nothing personally identifiable. APNIC can query things like: how many DNS queries come from the UK? How many query for google.com?
- nextgens 9y agoAre you aware that your public resolvers are actively breaking DNS-based GeoIP (striping EDNS0-ECN and not using source IPs geo-localized as the requester would be)? and if so, what is the rationale for it?
- lathiat 9y agoYeah I tested it out and switched back, it made performance to Twitch in particular quite bad for me. I don't get that issue with Google DNS though.
- nextgens 9y agoGoogle's take good care of it... and they explain precisely what they do on the topic... https://developers.google.com/speed/public-dns/docs/ecs https://developers.google.com/speed/public-dns/docs/ecs https://developers.google.com/speed/public-dns/faq#locations https://developers.google.com/speed/public-dns/faq#locations (when EDNS0/ECS isn't supported) The tin foil hat brigade might suggest that this is deliberate to ensure that only what's served by cloudflare gets to be fast...
- acct1771 9y agoWhy is healthy speculation now considered "tin foil hat brigade"? Conspiracy theory isn't a dirty word. Speculation keeps people informed and alive.
- zuzun 9y agoI think everyone's concern should be that Cloudflare or Google might just replace each IP in their 24h logs with a random UUID and call it anonymized. Both companies can potentially store enough information to correlate DNS requests with regular traffic logs. It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www.example.com at the same location a few milliseconds later.
- jgrahamc 9y agoWe're not storing the source IP addresses in any form. Not raw, not "transformed", not anonymized, not hashed. They are not being stored. Our business is not about tracking people; it's about selling our service to businesses to make their web sites/APIs/applications faster and more secure.
- GunlogAlm 9y ago> I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. Is there a guarantee that this will always be the case? Might there, in theory, be a point in the future where users' IPs are collected and stored? Loving 1.1.1.1, btw.
- cesarb 9y agoDoes APNIC get a sample of the raw packets of non-DNS and non-HTTP/HTTPS/QUIC protocols, so they can figure out what they actually are and why they're being sent towards that network?
- JackC 9y agoIs there personal data in the domain names queried, as opposed to the IP addresses querying? I think there probably is. For example, consider the bug in iTerm2 that ran a dns query for any text cmd-clicked on. To protect against that, could you commit not to log to disk any queries that come from fewer than N ips in 24 hours, and not to expose rare queries to APNIC or internally? (Not a demand, just brainstorming mitigation.) It might also be fun to give an internal team access to the data you consider safe, and challenge them to dig up personal data from it.
- dx034 9y agoDo you plan to publish usage statistics over the coming weeks? I'd be keen to know what kind of (valid DNS) volumes you've seen since the announcement. And if there are any obvious patterns of ASNs or countries using it a lot (unless you don't want to disclose that to avoid being blocked there).