9 ms·
I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., b
by b215826 5y ago
I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is [1]. I don't particularly care what the details are, whose fault it is, etc., but as an end user, I see this a major problem because with 1.1.1.1 if my browser is unable to resolve a domain, I wouldn't know if it's my DNS's fault or if it's the site's without an explicit check. I also don't care much for family "protection", so right now I don't see a good reason for using Cloudflare over Quad9.
[1]: https://news.ycombinator.com/item?id=21155056 https://news.ycombinator.com/item?id=21155056
[2]: https://www.quad9.net/ https://www.quad9.net/
- codetrotter 5y ago> I don't particularly care what the details are, whose fault it is, etc. https://jarv.is/notes/cloudflare-dns-archive-is-blocked/ https://jarv.is/notes/cloudflare-dns-archive-is-blocked/
- netizen-936824 5y agoThank you! This is incredibly informative on the situation and makes sense. It also makes me happy with clouflare's choice
- stavros 5y agoIt doesn't have the owner's side on it, though, which is not as evil as the article makes it sound. I can post more information when I'm home, but he basically uses that info to thwart attacks.
- jrwr 5y agoThis has come up a few times. Mostly the owner is set in their ways and are mad at CF for not providing the DNS flags that allow outside CDNs to figure out what IP you are closest to. From a 2019 thread about this: The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifices the privacy of users. This is especially problematic as we work to encrypt more DNS traffic since the request from Resolver to Authoritative DNS is typically unencrypted. We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1. https://news.ycombinator.com/item?id=19828317 https://news.ycombinator.com/item?id=19828317
- saurik 5y agoCan you explain the attack a bit more? One would (naively) expect that the process of the user connecting to my web server would expose their IP address (associated with their intent) to many more relevant actors (including "nationstate actors") than Cloudflare connecting to my DNS server... is the issue that the specific nationstate actor you have been concerned with is explicitly able to target and achieve surveillance on Cloudflare's outgoing traffic, but is expected to not be able to surveil the incoming traffic to my infrastructure on the other side (which sees the user's IP address way)?
- ViViDboarder 5y agoBecause DNS is still largely unencrypted. Nation state actors can read that information and map who is making requests for what domains. It’s not so much a concern of the site host from getting the users IP, because the user is presumably going to visit it. This is an issue with Archive.is because they host their own DNS, not their web server.
- saurik 5y agoI am sorry, can you explain this to me step by step? My computer makes a DNS request through Cloudflare, which forwards a request to archive.is's DNS server which is apparently going out of its way to carefully prevent anyone from figuring out that I wanted to access archive.is... and then my computer ruins all of that by making a direct connection to archive.is's web server. If you are a "nationstate actor" able to randomly sniff traffic in various places, the DNS request doesn't seem to add any value over the web request. What is the actual attack? Be more specific.
- kenmacd 5y agoThe IP you connect to could host 1000 sites. Leaking which one you're actually accessing could be important.
- fragmede 5y agoThe "attack" is bad implementations revealing the whole IP, leaking that PII, to anybody watching DNS, instead of the query being masked to a /20, or some other subnet. Not all VPNs route DNS queries over the VPN for performance reasons. Thus, knowing that a specific IP is visiting dissident net when that cannot be directly observed is very useful.
- reggegg 5y agoThey also blocked all of Finland a few years ago for pretty dubious reasons: https://en.wikipedia.org/wiki/Archive.today#Finland https://en.wikipedia.org/wiki/Archive.today#Finland
- chmaynard 5y ago"They" refers to archive.is, not Cloudflare.
- kgwxd 5y agoIs archive.is the only major site using that line of reasoning?
- eastdakota 5y agoThat I’m aware of, yes.
- wil421 5y agoFrom the article above: > In other words, Archive.is's nameservers throw a hissy fit and return a bogus IP when Cloudflare doesn't leak your geolocation info to them via the optional EDNS client subnet feature. The owner of Archive.is has plainly admitted this with a questionable claim (in my opinion) about the lack of EDNS information causing him "so many troubles." Not sure how it’s causing him so many troubles.
- q1w2 5y agoThis makes me even more willing to use 1.1.1.1.
- ignoramous 5y ago> Not sure how it’s causing him so many troubles. The allegation is that Cloudflare's in the (anycast) CDN business, hence its customers do not require EDNS (ECS) to be steered to the geographically-nearest server, and so, they naturally want to kill EDNS (ECS) and that privacy's just an excuse. As a consumer, I agree with what Cloudflare's doing (though they could potentially engineer a solution to send fake/blind EDNS (ECS)). Wearing my developer hat, I also agree with archive.is' decision to stage a protest.
- kjaftaedi 5y agoSo if archive.is decided to also return garbage DNS results to Quad9 you would stop using them too? I get your sentiment, but allowing one single webpage on the internet to dictate who you are allowed to use for DNS is going too far in the other direction, IMHO
- cnst 5y agoIt's a little ironic complaining about a single webpage on the internet, when you're suggesting that we use a single resolver on the internet instead of a distributed resolver system that we have otherwise. FWIIW, I use the resolver of my ISP, and 100% happy with the results. If your ISP provides incorrect and fake data to make extra money on advertising, maybe you should vote with your wallet and change the ISP.
- tomnipotent 5y agoISP's regularly resell subscriber data, including DNS requests. They're also more likely to "play ball" with authorities. > we use a single resolver Cloudflare is still doing BGP like your ISP.
- cnst 5y agoThis is simply unsubstantiated — there's absolutely no reason to believe Cloudflare won't play ball with authorities. If anything, ISP DNS being a distributed system with independent ISPs all across the world, it would be much more difficult for the major agencies to control all the individual ISPs than it would be to simply control a single global entity with a US HQ and offices and POPs worldwide — Cloudflare.
- tomnipotent 5y agoDNS is distributed, by design. Your ISP operates no differently than Cloudflare, and receives routing information from peers in the exact same way. There is nothing special or unique about consumer ISP-provided DNS. A DNS provider is either the definitive source and the buck stops there for a lookup, or it forwards to a peer for resolution. Cloudflare is not a telecom, which comes with regulation baggage that can be enforced. This matters a lot to a subpoena.
- beermonster 5y ago> I used to use 1.1.1.1 till the day I realized that it doesn't resolve archive.is. It does resolve archive.is, it’s just the archive.is nameservers return garbage if the source if CloudFlare. CloudFlare could simply fix this their end if they wanted but haven’t done so out of integrity. This looks good for CloudFlare and bad for archive.is from where I’m sitting.
- consumer451 5y agoIs there any non-conspiratorial reason for archive.is's position on this?
- pas 5y agoLatency optimization. There's an argument that CF benefits if that DNS extension is not in widespread usage. (Because CF sells a CDN but if sites can "just implement" that with DNS, then there's "nothing for them to sell".)
- kerng 5y agoIt leads to further centralization of the internet where a few have more data to make better decisions (and more money) and the smaller players are left out.
- unityByFreedom 5y agoThat's a fairly good argument IMO. Today's Cloudflare does not sell data. Tomorrow's, or our children's generation's, could. As you say, this could become a monopoly and it's cool to see a popular website standing up for a future where littler guys can still make it. It's not clear to me that's the precise argument he's made so I'm just guessing. When did HN get these new awesome nav buttons? Root, next, ... amazing!
- deleted 5y ago[deleted]
- fragmede 5y agoYes. From a technical standpoint, archive.is' stance is that it's actually important useful data that, more importantly, isn't a privacy violation. How much you agree with archive.is depends on a very technical understanding of the subject, or barring that, it depends on how much you buy Cloudflare's reasoning. Cloudflare's business would prefer you pay for Cloudflare (at large but specifically their anycast) instead of using an optimization available to you as a Internet business to route clients to a more optimal/closer server. As far as the privacy implications, remember that the site you visit needs to know your IP address in order to respond to your request, so while there are some issues to be aware of, it's kind of hard to see it as a privacy violation and not Cloudflare trying to squash the little guy, imo.
- alecco 5y agoCloudFlare is in the right. This is for privacy. Just put the IPs on your hosts file, it's easy. https://dns.google/query?name=archive.is https://dns.google/query?name=archive.is 54.37.18.234 archive.today 54.37.18.234 archive.is While there try a hosts blocklist http://someonewhocares.org/hosts/ http://someonewhocares.org/hosts/ https://github.com/jmdugan/blocklists/tree/master/corporations https://github.com/jmdugan/blocklists/tree/master/corporatio... etc
- CharlesW 5y ago> Just put the IPs on your hosts file, it's easy. Just wanted to say: Thank you for posting an actual solution!
- Digory 5y ago> I also don't care much for family "protection", so right now I don't see a good reason for using Cloudflare It seems like you don’t fit the target audience for this service at all.
- windexh8er 5y ago> ...so right now I don't see a good reason for using Cloudflare over Quad9. If you care about performance there is a pretty significant gap between them [0]. [0] https://www.dnsperf.com/#!dns-resolvers https://www.dnsperf.com/#!dns-resolvers
- gsa 5y agoCloudflare DNS also broke Spotify for me in a way that took me a while to discover. The Spotify desktop app would randomly stop playing music with no error message. I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. [0] https://community.spotify.com/t5/Desktop-Windows/Random-Stopping-with-CloudFlare-DNS-1-1-1-1/td-p/5190900 https://community.spotify.com/t5/Desktop-Windows/Random-Stop...
- nobody9999 5y ago>I traced the issue back to changing my Pi-Hole upstream DNS to Cloudflare few days earlier. Switching to another DNS provider fixed the issue right away. Since you're already using a pi-hole, why not just roll your own recursive DNS server. The additional network traffic to do so is insignificant. That way, you don't have to rely on someone else to resolve your DNS queries -- or deal with spats like that. I've been meaning to do so for a while, but life has interrupted. As I'm going through an ISP change ATM, I will do so soon. And I won't ever look back. Edit: Since your post got me thinking about it, I just now went ahead and set up my recursive resolver and pointed my pi-hole at it. Took about 10 minutes on an existing VM.
- zrobotics 5y agoEh, not the GP but I had tried that and switched back to 1.1.1.1 with hosts rules for specific sites to fallback to 8.8.8.8. Running my own DNS just proved to be too much of a troubleshooting headache, since if a site was broken it was one additional step. The pihole itself has been almost no trouble, but the diy DNS would occasionally fail to resolve a site. If I'm at home, the last thing I really want to do in the evening is troubleshoot network issues. It was a fun project to setup, and I did learn more than I expected I would. I can recommend it as a weekend project, but not as a long-term solution.
- nobody9999 5y ago>Running my own DNS just proved to be too much of a troubleshooting headache, since if a site was broken it was one additional step. The pihole itself has been almost no trouble, but the diy DNS would occasionally fail to resolve a site. If I'm at home, the last thing I really want to do in the evening is troubleshoot network issues. A fair point. That said, note the edit on the comment to which you replied. I've been running my own authoritative DNS for (personal) domains I own for 15 years or so and have spent very little time managing that. I also run my own internal DNS servers (hybrid BIND/AD DNS) without issue. As such, I don't expect to have many issues with a simple recursive resolver. That said, I understand your point of view and know that managing DNS isn't for everyone. However, I'd rather perform my own DNS lookups rather than relying on my ISP(s), Google or Cloudflare. Yes, my ISP could capture every single recursive query, but I'd rather have them do that than just log every DNS query I make. No, it doesn't significantly add to my privacy, but (IMHO) it's better than the alternative.
- _l4jh 5y agoIf you run a pi-hole create a config file in /etc/dnsmasq.d such as 02-archive.is.conf with the following server=/archive.is/8.8.8.8 server=/archive.is/8.8.4.4 server=/archive.li/8.8.8.8 server=/archive.li/8.8.4.4 server=/archive.to/8.8.8.8 server=/archive.to/8.8.4.4 server=/archive.today/8.8.8.8 server=/archive.today/8.8.4.4 And restart dnsmasq (or just reboot the pi) This will resolve the common archive.is domains using Google's DNS service rather than 1.1.1.1 but everything else via 1.1.1.1 as normal.
- unityByFreedom 5y agoI just installed pi-hole and it says version 4 doesn't use dnsmasq anymore [1]. edit: Nevermind, your configuration worked. I verified after flushing DNS cache that archive.is was at first inaccessible, and now after a pihole reboot it does resolve. Thanks! I wonder if this is another way to set up the same thing with PiHole's "FTL-DNS" [2] [1] https://docs.pi-hole.net/ftldns/dns-resolver/ https://docs.pi-hole.net/ftldns/dns-resolver/ [2] https://docs.pi-hole.net/ftldns/configfile/#pihole_ptr https://docs.pi-hole.net/ftldns/configfile/#pihole_ptr
- RIMR 5y agoSo you stopped using 1.1.1.1, because the owner of archive.is deliberately broke his domain so it wouldn't work on Cloudflare, specifically so he could mine your geolocation? You do you, I guess.
- _nalply 5y agoIt seems that archive.is doesn't want to support 1.1.1.1 requests. Solution: Resolve archive.is yourself if you want to use 1.1.1.1. For example with a host file, pihole, dnmasq, whatever. Look up archive.is once with a different DNS server then create a manual record for archive.is. Whatever. Finally you could write a script to do this automatically in regular intervals to your taste.