4 ms·
Cloudflare is harmful to independent CDN's. They hide the originating i.p. address (no other does it) to the nameserver in the name of "privacy" so you can only
by rydre 6y ago
Cloudflare is harmful to independent CDN's. They hide the originating i.p. address (no other does it) to the nameserver in the name of "privacy" so you can only have as much granularity as the nearest cloudflare server to user (anti-competitive). That is unless you buy an ipv4 block (because everyone is still on ipv4) and set up anycast.
For non 1.1.1.1 dns users I can just set up varnish and they'll be served via GEO ip lookup so the domain gets pointed to the nearest ip address. This is much cheaper.
I'm not going to buy an ipv4 block just for cloudflare dns users.
Their privacy claim is a lie because your webserver is going to be exposed to the end user i.p. address anyways after resolving from the nameserver.
- DoctorOW 6y agoEDIT: I associated the name Cloudflare with the main product. I forgot the context of this being about DNS and therefore my comment is about Cloudflare CDN not 1.1.1.1 > Cloudflare is harmful to independent CDN's. Cloudflare is a competitor to CDNs. You don't need to use a CDN with Cloudflare, they proxy your content fully and do caching along the way as needed. > Their privacy claim is a lie because your webserver is going to be exposed to the end user i.p. address anyways after resolving from the nameserver. It's not a lie. Cloudflare is the nameserver, and the CDN. So after resolution the end user still has just a Cloudflare IP.
- rydre 6y ago> It's not a lie. Cloudflare is the nameserver, and the CDN. So after resolution the end user still has just a Cloudflare IP. > In 2011 Google wrote an IETF draft to send Client IP information using the EDNS0 extension and this is usually called ‘edns-client-subnet’. As a DNS client, it means that a truncated version of your IP address will be added into the DNS request. The DNS server will use this truncated IP address to make a more informed decision in how it responds so that you can be connected to the most optimal server. This standard is promoted by the Faster Internet initiative and already adopted by some leading vendors. Because it is designed to keep privacy, the sender has the freedom to limit the client IP information. Instead of sending a full IP address, the DNS server is able to send partial information such as /24 only. For instance, if your IP address is 66.214.81.22, the DNS server will only expose the first three octets, so 66–214–81. Armed with the real IP address of the querying device, the DNS server can now come up with a much more accurate response. With this more intelligent routing, customers have a better Internet experience with lower latency and faster speeds. Best of all, this integration is being done using an open standard that is available for any company to integrate into their own platform. source: https://engineering.salesforce.com/why-is-edns-important-for-content-delivery-85f5690744ba https://engineering.salesforce.com/why-is-edns-important-for... Cloudflare 1.1.1.1 for consumers kills EDNS "edns-client-subnet" and instead offers the ip of the nearest cloudflare server to the user even if the website is not using cloudflare. This means your website can not ever serve content faster then cloudflare even if you could potentially be faster. This is the reason why many internet archives do not allow access to cloudflare client dns (1.1.1.1) users as a form of protest. BTW, Cloudflare allows you to get informed about the end user's ip via a "x-forwarded-for" header.
- deleted 6y ago[deleted]
- presumably 6y agoThere is only a single "archive" that does not allow access to Cloudflare DNS users - not many. It is also exceedingly unlikely that you have greater density of anycast PoPs than Cloudflare's 200+. In your case, you have zero...
- miyuru 6y agoAkamai has more than 200 pops and do geodns to stear traffic. If I compare cloudflare DNS vs Google DNS, I can see a difference of ~50ms between the Akamai POPs offered. https://pastebin.com/raw/xFQb4pVF https://pastebin.com/raw/xFQb4pVF
- Fej 6y agoEven archive.today has given up on that crusade; I noticed a few days ago that they don't block me anymore (I use Cloudflare DNS) so they have to have stopped within the past couple weeks. So now AFAIK the number of sites that block DNS resolvers which do not forward edns-client-subnet is zero. As it should be.
- dylz 6y agoThey continue to attempt to try to associate your connections/use dns cookies. CtrlF 'pixel' when you are visiting one of their pages (not frontpage) They also attempt to correlate .onion traffic.
- zaroth 6y agoI think you’re confusing how CloudFlare can hide the server IP from the user (to protect against DDoS) versus how CloudFlare DNS hides the client’s IP from the name server, even though the Client IP is exposed to the web server by Cloudflare, and of course standard Cloudflare is irrelevant if the requested site isn’t using the Cloudflare service in the first place.
- tssva 6y agoNot forwarding EDNS client subnet is a requirement for Mozilla TRR partners. NextDNS also doesn't forward EDNS subnet client since it is a partner and soon Comcast will be joining that list. Although not currently a member of the program Quad9 also by default doesn't forward EDNS subnet info.
- rydre 6y agoI host my name server's myself. If Mozilla is really doing this, they're misguided. All this does is make it impossible to serve requests from nearest webserver. You are getting the ip address anyways, so why do this? This means if I get someone from netherlands I'd have to redirect their requests from www.example.com to nl.example.com or buy an ipv4 block, set up anycast and then serve from the closest ipaddress/server. The end result is same. I'll always get the end user's ip address unless they use a VPN or something. This is a stupid decision by Mozilla. Too bad Firefox users when visiting websites making their own CDN's without anycast/country level redirects will see much slower sites.
- presumably 6y agoWhat you're claiming is false. Cloudflare has over 200 PoPs; in your own name servers, you can use the Cloudflare Resolver's IP (which will be a "close to the user" IP, not 1.1.1.1) to do geotargeting and serve from your closest IP address/server.
- rydre 6y ago>What you're claiming is false. Cloudflare has over 200 PoPs; in your own name servers, you can use the Cloudflare Resolver's IP (which will be a "close to the user" IP, not 1.1.1.1) to do geotargeting and serve from your closest IP address/server. What if my server is closer than cloudflare? Why is cloudflare artificially limiting?
- willcipriano 6y agoI use cloudflare precisely because I don't want clients hitting the server directly. That's its entire purpose. For both caching and anti-ddos reasons.