25 ms·
Issues with 1.1.1.1 public resolver and WARP
- denysvitali 3y agoDuplicate: https://news.ycombinator.com/item?id=37762227 https://news.ycombinator.com/item?id=37762227
- T3OU-736 3y ago(Unaffected by this). Found it the reverse chronological order (with timestamps being a smaller/lighter font, at least on mobile) to have caused extra thinking, which, for a status, seems undesireable. I get wanting to expose the latest thing first, but the "top-posting" style seems intuitive. Perhaps, as a compromise, a status page would have a "Latest" block at the top, with the timestamp prominent, where the latest known status would be placed by whatever makes the updates, but the updates themselves are in the chronological order?
- deleted 3y ago[deleted]
- lucgagan 3y agoCrazy how many things a single thing breaking takes down with it
- luuurker 3y agoAnd that's why we all use more than one DNS server. Right? :-P
- diggan 3y agoNot sure how crazy it is when that single thing's whole business objective is to be between what you're trying to reach and yourself.
- ornornor 3y agoWait until you learn about what happens when the electricity stops working
- sillysaurusx 3y agoNote that if you use 1.1.1.1, you apparently can't visit archive.is links. I'm not sure why, but around a dozen people on HN have confirmed this. (At least as of a couple months ago.) I think the world could use more alternatives to 8.8.8.8. Hopefully 1.1.1.1 will become more reliable as the years tick by. (Do you use something besides 8.8.8.8 or 1.1.1.1? If so, post it here! Collecting reliable DNS servers might be a niche hobby, but it's a fun one. I was going to suggest 9.9.9.9 aka Quad9, but apparently it comes with strings attached. https://news.ycombinator.com/item?id=16728214 https://news.ycombinator.com/item?id=16728214)
- frankjr 3y ago> Note that if you use 1.1.1.1, you apparently can't visit archive.is links. I'm not sure why, but around a dozen people on HN have confirmed this. (At least as of a couple months ago.) https://news.ycombinator.com/item?id=19828702 https://news.ycombinator.com/item?id=19828702
- lxgr 3y agoThe operators of archive.* have a peculiar problem with eDNS, or rather Cloudflare’s lack of support thereof. Some details here: https://community.cloudflare.com/t/archive-today-works-again-on-1-1-1-1-and-archive-ph-is-li-vn-fo-md/387566 https://community.cloudflare.com/t/archive-today-works-again...
- 542458 3y agoCloudflare supports EDNS, they just don't support the optional EDNS Client Subnet extension.
- iamdbtoo 3y agoThe reason has been known for a while now. https://news.ycombinator.com/item?id=19828317 https://news.ycombinator.com/item?id=19828317
- depr 3y agoand https://news.ycombinator.com/item?id=36971650 https://news.ycombinator.com/item?id=36971650
- dintech 3y agoI’ve just started using Warp+ and it has been excellent for my specific use case: better peering to my Plex server while in another continent. Plex was unusable and now it’s not. Overall very happy despite this brief outage.
- zozos 3y agoI did not know you can use wrap+ like this. I will try it out as well. Plex has been unusable between continents.
- jshier 3y agoYou can't use Warp+ to control your egress point, unlike many other VPN services, so you can't use it to bypass geographic blocks. However, since Warp+ (not Warp) routes you within Cloudflare's network (using their Argo routing from participating datacenters), I'd guess GP gets a more stable and faster connection to their server than the public internet would provide.
- quesera 3y agoJust a reminder for anyone on the fence, or who has not considered it previously... Running your own DNS resolver is super easy. It probably has the highest ROI of any self-hosted service, because it is so easy and inexpensive to do. I recommend Unbound: https://nlnetlabs.nl/projects/unbound https://nlnetlabs.nl/projects/unbound
- lantry 3y agoPlus you can do fun things like block ads across your whole network with tools like pihole.
- AnonC 3y agoCan you disable the blocking on each device as and when needed (for a little while) and enable it back again (on iOS)? That would be a killer feature for running a DNS server and pi-hole at home.
- snailmailman 3y agoIt has a pretty easy “toggle for 5 mins” button on the dashboard if I encounter issues. It has a few preset time options. I think you can set rules per device in Pihole? I haven’t tried personally. I’ve only had set a few (3-4) sites manually allowed through the blocklists.
- hsdropout 3y agoCan be done with a combination of client groups, like this: https://discourse.pi-hole.net/t/client-group-management-how-does-it-work/39554 https://discourse.pi-hole.net/t/client-group-management-how-...
- RockRobotRock 3y agoHow slow is running your own recursive DNS?
- 3y ago
- lopkeny12ko 3y agoWhat's the point of having a secondary endpoint 1.0.0.1 if an outage breaks both that and 1.1.1.1? Are these two servers not running in physically isolated regions with independent code deploys?
- SSLy 3y agoDNS servers are run anycast from each cloudflare POP. Why are the two addresses' fault domains not separated otherwise is the proper question.
- silverwind 3y agoWill DNS clients actually try the other if one of them returns SERVFAIL?
- ArchOversight 3y agoYes.
- AndyMcConachie 3y agorouting redundancy
- jshier 3y agoThey've posted their incident report: https://blog.cloudflare.com/1-1-1-1-lookup-failures-on-october-4th-2023/ https://blog.cloudflare.com/1-1-1-1-lookup-failures-on-octob...