14 ms·
Cloudflare 1.1.1.1 iOS app
- MordodeMaru 8y agoWorks like a charm.
- sjroot 8y agoYep. Doesn’t get more simple than a toggle switch.
- Mistri 8y agoAlso on the Google Play store: https://play.google.com/store/apps/details?id=com.cloudflare.onedotonedotonedotone https://play.google.com/store/apps/details?id=com.cloudflare...
- sourcesmith 8y agoThere are also generic apps that allow you to use cloudflare or another provider, such as: https://play.google.com/store/apps/details?id=com.frostnerd.dnschanger https://play.google.com/store/apps/details?id=com.frostnerd....
- blinkingled 8y agoBtw, you don't need the App if you the 1% of Android - Pie introduced a system setting for this under Private DNS.
- ptrinh 8y agoI can just add 1.1.1.1 as the DNS server in iOS Settings. What's the difference?
- philliphaydon 8y agoHow do you do that for non wifi??
- cjensen 8y agoConfiguring with iOS settings sends unencrypted DNS requests to 1.1.1.1 and, as a result, the sites you access can be seen in your internet traffic by people like your Mobile provider (when using mobile internet) or the local cafe (when using their WiFi) or your home ISP (when using your home WiFi). This app enables your DNS requests to be encrypted. Your requests are still seen by Cloudflare, of course.
- zackbloom 8y agoWe try to hold on to as few logs as possible, the goal of the project is improving privacy. You can read the full policy here: https://developers.cloudflare.com/1.1.1.1/commitment-to-privacy/privacy-policy/privacy-policy/ https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
- rabboRubble 8y agoGot a follow up question for you... have you guys integrated the IOS into Apple's "Shortcuts" app? This app was created by a 3rd party used to be called Workflow. Apple bought the app 2 years ago or so. Reason I ask... I have a one-tap shortcut to turn off WIFI and Bluetooth for leaving home. Would be awesome to turn off WIFI / Bluetooth / turn on Cloudfare with a single tap as I head out the door. I don't need the battery drain from VPN usage while sitting at home, and already have my DNS routed away from my ISP.
- zackbloom 8y agoThanks for the suggestion, we'll look into integrating. There shouldn't be notable battery drain from the app though, it's not a VPN in the traditional sense.
- rabboRubble 8y agoVery cool. Thanks. Yeah, in addition to the battery issue (which sounds a nonissue based on your reply) there is the simply issue of me not remembering to turn on / off.
- tuananh 8y agodns over https as well
- deleted 8y ago[deleted]
- rabboRubble 8y agoThat setting change only changes DNS while on Wifi. IOS offers no direct method of changing DNS while on cellular. Without something like Terminal on an iPhone, pretty difficult to tell which DNS is being used by the iPhone unless the phone is jailbroke. I use an app called Net Analyzer to check various networking configs. I'm not sure even the Cloudflare app is actually changing DNS. Need to do a bit more poking about to figure out what exactly is going on. Edit: After playing around a bit, with the CloudFlare app alongside Net Analyzer, DNS on cellular appears to modified from my cell provider to what I think is the CloudFlare VPN profile on the device with IP addresses 192.0.2.2, 192.0.2.3, 192.0.2.4.
- zackbloom 8y agoIt installs a VPN policy to do it, that's the only viable method on non-managed devices. There is another big difference as well, the app enables DNS-over-HTTPS which encrypts your DNS traffic.
- toomuchtodo 8y agoIs there a performance hit vs using native carrier DNS?
- zackbloom 8y agoYour carrier's DNS may or may not be fast depending on how it is set up and who you use. In general 1.1.1.1 is faster than any of the other public DNS resolvers, and does a lot of preemptive caching that it's likely your ISP does not. Of course, it also doesn't sell your data which is a bonus.
- rabboRubble 8y agoThanks! Good info. Yeah, was able to confirm that the Cloudflare app defaulted to DNS over https. That's an improvement over my previous attempts to excise cellular DNS traffic away from my carrier. Is Cloudflare also servicing internet requests or are requests still being serviced by the cellular providers after DNS is resolved?
- dnh44 8y agoYou can’t specify your DNS server at all on iOS when you’re not on WiFi.
- hendry 8y agoYay! Centralisation
- AckSyn 8y agoit's just a service you can run your own easily just connect to roots
- saagarjha 8y agoIt's cute that the time in the screenshots is 11:11.
- lenocinor 8y agoI get the joke, but I wonder if some folks will believe it's for a different reason: https://en.wikipedia.org/wiki/11:11_(numerology) https://en.wikipedia.org/wiki/11:11_(numerology)
- johnklos 8y agoI'm not quite so sure why everyone is happy to just blindly trust Cloudflare. These are the people who play games when Adobe Flash "updater" sites which are clearly, obviously and unambiguously hosting Trojans are hosted via their services. I don't trust them one tiny bit.
- whorleater 8y agoYou shouldn't, but there's some vague notion that giant corporations have taken over the net and fighting against it is actively harming your privacy more than it helps. Is cloudflare better than your {ISP, self hosted, Google, etc} DNS servers? That's probably for an individual to decide.
- eridius 8y agoWhat do you mean, you don’t trust them? Cloudflare provides services to scummy websites, yes. But Cloudflare isn’t doing anything to promote these websites, trick users into visiting them, or otherwise aide them in any way other than providing the exact same services they provide to everybody else. I fully understand disagreeing with Cloudflare’s decision to turn a blind eye towards what their customers are doing. I just don’t understand why this behavior means you “don’t trust them”. What do you think Cloudflare is going to do?
- slededit 8y agoIts just weird they are willing to censor legal speech but not illegal things like malware.
- untog 8y agoHave they said they won't? Or is it just more difficult to stamp out? The malware sites can use any URL, so I imagine it's difficult to stamp out automatically.
- eridius 8y agoCloudflare explicitly takes a hands-off approach. They said they'll provide their basic services to anyone and everyone as long as it's not violating the law (which basically means they won't protect child pornography sites), and they explicitly don't police the content of the sites. AIUI their rationale is that it's so easy to DDoS sites these days that everyone deserves to have access to basic DDoS protection no matter who they are or what they believe.
- tomschlick 8y agoBeen using this since the beta on testflight and it has beeen awesome. The only thing it needs IMO is the ability to whitelist WiFi networks not to run it on. I run a PiHole instance at home that does DoH through CF already so I have to remember to turn it off/on all the time to get the ad blocking.
- krispbyte 8y agoOn Android I use DNS66 [0], it creates a VPN server in my phone, redirects DNS traffics through it and filters it. This way I get adblock all the time even if I don't have a PiHole. Edit: I see now this app by CloudFlare does the same. However DNS66 let's you choose your own hosts filters and your own DNS servers. [0] https://f-droid.org/en/packages/org.jak_linux.dns66/ https://f-droid.org/en/packages/org.jak_linux.dns66/
- tomschlick 8y agoYeah iPhone user here so thats probably a no go. I've considered just creating a VPN back to my gigabit connection at home (running R715 in a homelab rack) but not super keen about the data making a round trip back home first, especially when travelling.
- voltagex_ 8y agoHeh, if you're using global roaming on your SIM, the data is making a round trip anyway.
- oarsinsync 8y agoDefinitely not. Simple services like ipchicken.com will show you're using an IP address local to the roaming provider that you're using. If you're travelling far enough, you can try accessing local services vs home-country-services and compare loading times. Or better still, just ping various services that are local or in your home and compare the actual latencies.
- bart3r 8y agoIf you install this on iOS, you'll see a little 'VPN' icon in the top bar of your phone. Not sure if you can hide that though.
- dividuum 8y agoSame on Android. It's also implemented as a VPN.
- deleted 8y ago[deleted]
- asasidh 8y agoTrust us, not them?
- jonny_eh 8y agoI'd trust one organization that I trust a bit (Cloudflare), rather than random wifi hotspots or my cell & ISP providers which have proven themselves untrustworthy.
- ashishb4u 8y agoFrom their play store description: "Best of all: No upsells, no in-app purchases, and free for life. Website owners pay us to make your Internet faster so you don’t have to." That sounds totally against net neutrality to me. Unless website owners are not getting preferential speed up.
- eridius 8y agoThe description does not mean website owners are paying so that users of this app can get a faster connection to them. It just means website owners pay Cloudflare already, Cloudflare’s business model is selling services to website owners, and so this dinky app for consumers has no need to make money and therefore is free.
- brians 8y agoWellll.... paying Cf customers will get lower latency service using this, just as Cloudfront gives better service to AWS users. That’s part of why this app is in CF’s interests.
- eridius 8y agoThis app only redirects DNS, it does not tunnel any other networking. The DNS speedup someone will get by using this app applies to all domains, not just those of websites that pay for Cloudflare.
- nyolfen 8y agoso, it's a vpn -- the other vpn app i use is local hosts file adblocker that apple removed from the app store last year for the following reason: >According to Apple, Future Mind's AdBlock app violates section 4.2 of the App Store Review Guidelines, which dictates that apps must be useful, unique, and "app-like." ‾\_(ツ)_/‾
- rconti 8y agoIt's not a VPN. Unless you mean "it's a VPN for your DNS traffic only". Which is an odd distinction.
- ebeip90 8y agoIt's implemented on iOS as a VPN, of which you can only have one active at a time. Some Ad Blockers are implemented as VPNs. This is unfortunate, and they should use the Safari Content Blockers interface instead. Content Blockers cannot intercept or sell your content, since the code is sandboxed and doesn't get network access. NeverAds seems to work well for me.
- scarface74 8y agoWell, VPN software is one place you don’t have to use Apple’s “walled garden”. They could sell thier service outside of the App Store and publish instructions on how to set it up within settings on the iPhone.
- sigjuice 8y agoNot quite. iPhone VPN settings are limited to the protocols that Apple has built into iOS (primarily IPsec). If you want something different like WireGuard, you need a separate app.
- scarface74 8y agoIf you are marketing a VPN solution to iOS users, and you want to sell outside of the App Store, how is it an onerous requirement to implement industry standards?
- dschuetz 8y agoDon't use that. Don't use 1.1.1.1 or 8.8.8.8 or any other DNS service which have clear conflicts of interest on both sides. Don't ever trust DNS servers you don't have any control over.
- Gaelan 8y agoAny specific thing that either of them are doing wrong, or just hypothetical? Not a huge fan of a lot of things Google does, but they do seem to run 8.8.8.8 quite responsibly. (I don't have much against Cloudflare, and they also seem to good a job.)
- foota 8y agoWhat? Who has complete control over their DNS?
- judge2020 8y agoYep. Too untrustworthy. My isp's DNS which shows me Yahoo ads instead of a NXDOMAIN error is much safer.
- jrockway 8y agoI don't have control over the root domain name servers, so I guess I shouldn't use DNS?
- Down_n_Out 8y agoOn IOS there's also DNSCloak[0], which goes even further and has the option to choose for ad-filtering (eg, via PiHole) in combination with no-logging and using 1.1.1.1 as DNS. [0] https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client/id1330471557 https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client...
- Mistri 8y agoDoes it encrypt DNS queries like the 1.1.1.1 app though?
- ripdog 8y agoThe URL includes 'doh', which means 'dns over https'. That is the encryption layer which 1.1.1.1 uses.
- roboyoshi 8y agoCloudflare also has DNS over TLS that you can enable in the Settings, which is probably what everyone should be using anyway.
- elithrar 8y agoWhat drives that suggestion? I prefer DNS over HTTPS as some networks intercept DNS traffic, fail to parse the TLS-wrapped DNS payloads, and fail. DoH exists because DoTLS is prone to more interference.
- Down_n_Out 8y agoAs others have replied already, it does, depending on which solution you pick out of the list. I'm a happy user of this app, no affiliation at all in case someone was wondering.
- jedisct1 8y agoYes, DNSClock only supports encrypted DNS.
- gt640k 8y agoHow do I test this is working correctly?
- social_quotient 8y agoConnect your phone to desktop via adhoc network and run Wireshark. You’ll see the dns lookups and be able to confirm the tcp traffic afterwards. This SO post seemed to give a lot of details if you need it https://stackoverflow.com/questions/9555403/capturing-mobile-phone-traffic-on-wireshark https://stackoverflow.com/questions/9555403/capturing-mobile... Good luck!
- jen729w 8y agoSo the app shows you your DNS logs, without any sort of protection. I imagine this is a trivially simple way of snooping on an unsuspecting target. Let’s say you don’t trust your spouse. You install this app – showing them the security benefits as advertised by the application, letting them do their own research if necessary – then a day later come back and scroll through their DNS logs looking for cheatonmypartner.com.
- seanp2k2 8y agophysical access = device owned in almost every case
- laumars 8y agoThis app changes nothing. If you've got access to install software on someones handset then there isn't much they can do to prevent you from installing tracking tools - aside having to trust that you wouldn't.
- jen729w 8y agoAll good points in response, I hadn't thought this through. - You need to be able to unlock their device without their knowledge to view the DNS logs. - Therefore you know their PIN or have your fingerprint loaded (as I do on my partner's phone and vice versa). - Therefore you can just install [any other tracking malware] and hide the icon in a folder somewhere. And now you don't have a VPN icon in the toolbar. But does [any other tracking malware] actually exist for iOS?
- m45t3r 8y ago> But does [any other tracking malware] actually exist for iOS? Much easier would be to install a router with OpenWRT, set a DNS server (that your DHCP points to) and look at the logs. Or even running Wireshark in your own network should do the trick. As long the DNS requests are not encrypt, you should got the information you want.
- benbristow 8y ago
- imagetic 8y agoIt's super slow for me. I'm on AT&T fiber at home. Which I can't even set my DNS to without taking everything down. But when using the Cloudfare app it appears to work, but it's 10+ seconds to load a page.
- Mistri 8y agoI've actually had a noticeable increase in speed, not sure why that's happening to you.
- imagetic 8y agoI'm jealous. It's still incredibly slow for me. I assume it's an AT&T thing since I'm on wifi working from home. I am unable to use 1.1.1.1 with AT&T at all still. So I use Google's 8.8.8.8 until they fix the issue. But it's been 6 months and I doubt it will ever be resolved at this point.
- EZ-E 8y agoThis app works by connecting to a VPN. From experience, user experience on these kind of apps using a VPN is pretty poor (for example, ad blockers) I believe keeping VPN connected drains the battery because some of the device's chips cannot "sleep" A VPN-based app also disconnects when going from Wi-FI to cellular. Worse, when going from cellular to WiFi (ie: going back home) with a VPN on, the iPhone just keeps using the mobile network until the VPN is disconnected These apps usually try to auto-connect to VPN but when your connection is spotty, it becomes a very annoying, you have to kill the app, disconnect the vpn manually etc As user you're left manually putting the VPN on/off constantly if you're on the move It's definitively not a "set and forget thing". I wish Apple could give a way for ad-blockers and this kind of apps to function normally without using a VPN as a crutch
- Gaelan 8y agoIt’s not a “real” VPN. I’m not sure exactly how much it does, but everything but the actual DNS queries happen on-device, with other network connections not touching CloudFlare servers.
- dzek69 8y agoIt just acts as both server and client. The issues described still apply
- elithrar 8y agoNot quite. There’s no VPN tunnel - no IPSec tunnel is being set up, even on loopback. The reason the “VPN” icon appears is because VPN profiles are how you override iOS network settings on unmanaged devices: which can include just DNS. Any time a profile is ‘active’, the icon appears. You could generate your own unsigned profile to do the same, if you were so inclined.
- nothrabannosir 8y agoI’ve been using openvpn on iOS for about a year, and this 1.1.1.1 app for a day now, and I can guarantee that most of the connectivity issues described are not true. [edit: for me, of course. sorry, didn't mean to discredit parent comment like that. just wanted to add my perspective.] - it automatically switches networks, both to and from WiFi - it does not disconnect when switching - the 1.1.1.1 app does not make anything more spotty or unreliable; it’s just DNS. Openvpn yes, but this app clearly not. As for the battery issue: could very well be true, I have no idea how to test it. The difference between this app and an actual VPN are clear from using it.
- odedregev 8y agoCan someone please help me understand something please? I understand that the main feature of 1.1.1. is privacy from the ISP, however, after the DNS resolution when my device will actually go to the destination, lets say to www.example.com domain - my ISP will know about this too, so what exactly am I hiding here?
- Gaelan 8y agoMany sites these days are hosted on cloud services not owned by the company owning the site, and in these cases it can fairly hard to find the actual domain from the IP address. In other cases, however, you’re right—the ISP can still figure out where you’re going.
- homero 8y agoEncrypted sni will add some plausible deniability
- nly 8y agoIIRC, a prerequisite for the confidentiality of eSNI is in fact secure DNS.
- tialaramex 8y agoYou need that your adversary can't snoop your DNS queries (which DoH and other DPRIVE offerings provide) and if the adversary is active you also need DNSSEC with validation so that the adversary can't lie to your DNS provider and say eSNI isn't available. Cloudflare do both
- dingaling 8y agoI think this is mainly a USian mindset. I trust my UK ISPs ( Goscomb, AA.net ) to whom I pay a monthly fee for service more than I do some US-based company who wants to provide me a critical service for 'free'. And yet which at other times prevents me reaching websites with a 'One more step...' blocker page.
- kasey_junk 8y ago
- z3t4 8y agoISP DNS servers will always be closer, eg have less latency then third party DNS servers. And after one query, the result will be stored locally, eg no DNS servers will be used for following lookups. The thing with expensive DNS solutions is they only speed up the very first lookup, which might be cached on your ISP anyway. DNS is already a distributed system, which is much larger then any single private entity. Some third party DNS services might also sacrifice resiliency for performance, they will for example not try secondary DNS if primary is down. The reason why private organizations want you to use their DNS service is because they want to know every site you visit, then sell that information.
- growse 8y agoThis is a perfect line of reasoning, assuming: a) your ISP can competently run a secure DNS service correctly (latency is not the whole story of 'performance') b) it's acting entirely in your interests and not attempting to hijack your DNS service to insert ads etc. Personally, I've had ISPs where neither of these things have been true.
- kasey_junk 8y agoCloudflare is on record saying they will not sell the information. You can trust that or not but your ISP is almost certainly selling it if it is one of the major US ISP. Verizon owns Oath, Att owns App Nexus, Comcast has a whole suite of adtech companies & owns gigantic publishers. Time Warner literally started out in the sell side of advertising.
- scarface74 8y agoCloudFlare can say anything and have all the good intentions in the world. But, on Android, they are using a third party bug tracking software that they don’t have source control for (Instabug). That third party binary blob requests camera and microphone access.
- z3t4 8y agoI think ISP selling user data is outrageous and should be illegal. Thankfully where I live (EU) I got 20 ISP's to choose from, allowing me to vote with my wallet.
- vegardx 8y agoI imagine they don't want anyone to find the app with that name, given how notoriously bad AppStore search is.
- blablabla123 8y agoI still need to understand how that is going to be faster and more private
- natch 8y agoWill they rent/lease/lend/share my data out to partners/non partners/anyone? I understand they clearly state they won’t sell the data or use it (themselves) for ad targeting, but their wording doesn’t cover rental to others.
- CoryG89 8y agoMaybe I'm a little naive, but to me, "renting" data sounds a lot like just selling data.
- natch 8y agoRight... but it’s a known dark pattern for companies to make deceptive-but-technically-true assurances, so I’m not so sure. They do it because it works, as evidenced by what you say. I do tend to trust Cloudflare to do what they say, but they should say it with full clarity.
- zackbloom 8y agoNo. We (Cloudflare) barely even store the data, we get rid of it as fast as we can.
- natch 8y agoOK, that's great. Just as feedback to the company, if you're able to pass it on to someone, as a potential user I would feel more confident in the service if they would clarify the wording (not just from a Hacker News account, I mean). From a user's perspective outside the company it's hard to distinguish between weasel words, and the mere appearance of weasel words.
- kevinSuttle 8y agoAccording to a comment on ProductHunt: > “Cloudflare will never sell your data or use it to target ads. Period.". https://www.producthunt.com/posts/the-1-1-1-1-app#comment-693735 https://www.producthunt.com/posts/the-1-1-1-1-app#comment-69...
- jedisct1 8y agoFor something with way more features, check out DNSCloak, probably the best DNS app for mobile devices: https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client/id1330471557?mt=8 https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client... DNSCloak supports Cloudflare (among many other options), and has since day one. It will also let you choose how to steer DNS traffic, what domains to block and when, has a built-in cache to reduce latency, and more.
- elithrar 8y agoIs there a trustworthy third-party review of DNSCloak? Short of installing & packet sniffing myself, or breaking apart the package; neither of which I have time to do. (edit: to be clear, I’d love more options, including one that allows me to use Google’s DoH DNS, but I won’t blindly instal an app that intercepts my traffic, even if ‘just’ DNS)
- deleted 8y ago[deleted]
- chrisweekly 8y agoRelated tangent: does this (or any other similar app or service) provide a straightforward way to bind a static IP address to outbound HTTP requests? Use case: persistent IP address that can be whitelisted by a secured endpoint.
- gigatexal 8y agoIt’s not a real VPN from what I think of a VPN in that my IP is still from my ISP (checked at whatismyip.com) just the DNS requests are encrypted. Still cool though.
- cntlzw 8y agoFor what it's worth I think this is a beautifully designed app. The usability and user experience is great. Yes, it does just one simple thing but it does so in a smooth and elegant way.
- kevinSuttle 8y agoI want to believe this is a good thing, but I can’t get that whole “we block Tor users” campaign out of my mind.
- kodablah 8y agoI'm quite the opposite as I appreciate the work towards supporting Tor with easy-to-setup onion fronts as alt-svc's and their work towards limiting their DDOS mitigation for Tor users. These are usually thankless efforts that don't affect their bottom line, or maybe even are a net negative depending upon the level of effort they expend.
- znpy 8y ago33.6 MB? to change the dns ?
- Klonoar 8y agoSounds like a React Native app (and feels like one, sadly?). I could be wrong, though, since the NetworkExtension would have to be written in Swift, so I don't see why they wouldn't just write the rest in Swift and/or ObjC... would be happy to be wrong actually.
- auslander 8y agoIt is a bad idea for several reasons. 1. You won't be able to configure real VPN, iOS allows only one VPN profile. Get a real VPN for native IKEv2 client you have. 2. It gives CF golden mine of your browsing history. It already has your traffic to many sites in plaintext, emails and passwords included 3. You trust the third-party app without the source code, probaly with access all your traffic