3 ms·
> It's not a lie. Cloudflare is the nameserver, and the CDN. So after resolution the end user still has just a Cloudflare IP. > In 2011 Google wrote an IETF dr
by rydre 6y ago
> It's not a lie. Cloudflare is the nameserver, and the CDN. So after resolution the end user still has just a Cloudflare IP.
> In 2011 Google wrote an IETF draft to send Client IP information using the EDNS0 extension and this is usually called ‘edns-client-subnet’. As a DNS client, it means that a truncated version of your IP address will be added into the DNS request. The DNS server will use this truncated IP address to make a more informed decision in how it responds so that you can be connected to the most optimal server. This standard is promoted by the Faster Internet initiative and already adopted by some leading vendors.
Because it is designed to keep privacy, the sender has the freedom to limit the client IP information. Instead of sending a full IP address, the DNS server is able to send partial information such as /24 only. For instance, if your IP address is 66.214.81.22, the DNS server will only expose the first three octets, so 66–214–81. Armed with the real IP address of the querying device, the DNS server can now come up with a much more accurate response.
With this more intelligent routing, customers have a better Internet experience with lower latency and faster speeds. Best of all, this integration is being done using an open standard that is available for any company to integrate into their own platform.
source: https://engineering.salesforce.com/why-is-edns-important-for-content-delivery-85f5690744ba https://engineering.salesforce.com/why-is-edns-important-for...
Cloudflare 1.1.1.1 for consumers kills EDNS "edns-client-subnet" and instead offers the ip of the nearest cloudflare server to the user even if the website is not using cloudflare. This means your website can not ever serve content faster then cloudflare even if you could potentially be faster.
This is the reason why many internet archives do not allow access to cloudflare client dns (1.1.1.1) users as a form of protest.
BTW, Cloudflare allows you to get informed about the end user's ip via a "x-forwarded-for" header.
- deleted 6y ago[deleted]
- presumably 6y agoThere is only a single "archive" that does not allow access to Cloudflare DNS users - not many. It is also exceedingly unlikely that you have greater density of anycast PoPs than Cloudflare's 200+. In your case, you have zero...
- miyuru 6y agoAkamai has more than 200 pops and do geodns to stear traffic. If I compare cloudflare DNS vs Google DNS, I can see a difference of ~50ms between the Akamai POPs offered. https://pastebin.com/raw/xFQb4pVF https://pastebin.com/raw/xFQb4pVF
- Fej 6y agoEven archive.today has given up on that crusade; I noticed a few days ago that they don't block me anymore (I use Cloudflare DNS) so they have to have stopped within the past couple weeks. So now AFAIK the number of sites that block DNS resolvers which do not forward edns-client-subnet is zero. As it should be.
- dylz 6y agoThey continue to attempt to try to associate your connections/use dns cookies. CtrlF 'pixel' when you are visiting one of their pages (not frontpage) They also attempt to correlate .onion traffic.