8 ms·
In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare
- deadbabe 3y agoIs Cloudflare becoming increasingly powerful?
- geraldhh 3y agofeels like they subjugated half the web, yea
- rafram 3y agoVerisign already controls huge portions of the internet (as a registry and certificate authority) and Cloudflafe controls much of the rest. Giving up .gov does very little to move the needle.
- nkcmr 3y agoNot more than AWS, GCP, or Azure.
- gunapologist99 3y agoNot that I stay up at night worrying about Cloudflare, but Cloudflare is literally the Man In The Middle between the user and the instances running at AWS, GCP, or Azure.
- sophacles 3y agoUnlike AWS, GCP or Azure themselves? You think the people who own the computers you use can't see whats happening on them?
- gunapologist99 3y agoIsn't that the whole value proposition of Cloudflare? Nearly all traffic (in terms of volume) gets swallowed by CloudFlare and never approaches most instances: DDoS attacks swallowed whole, WAF rules block illegitimate traffic (which is, in most cases, the vast majority of traffic to dynamic endpoints or, frequently, non-existent endpoints, if you've ever tailed webserver logs), and Cloudflare-caching handles most of the remainder for static and cacheable files -- leaving those servers with a mostly-sanitized and far lower volume of traffic. If you're using edge workers, even less traffic hits your servers. But, yes, out of the remaining traffic that enters AWS/GCP/Azure's network, they certainly can see what's happening on those machines if they care to look.
- SOLAR_FIELDS 3y agoYeah, that is one of the main value props of Cloudflare. They just slap you with scale. Entire classes of problems like DDOS just become non issues when you front with them. Most people when talking about Cloudflare have few complaints about the actual services they offer. It’s way more often about how they are so good and widespread that you don’t have many other choices and how dangerous that is in the long term.
- tiffanyh 3y agoI can only imagine conspiracy theories flying around about government partnership with Cloudflare.
- supriyo-biswas 3y agoThere doesn’t need to be any conspiracy theories when governments will often use their leveraged positions to get something from companies and punish them severely if they don't comply. If I remember correctly, there was a certain LEA which approached an US ISP for an informal surveillance request, they refused, and the LEA retaliated by cancelling their contract. I’m failing to find it, so I’d be happy if someone can provide a source.
- mook 3y agoThat sounds vaguely like Qwest. https://en.wikipedia.org/wiki/Qwest#Refusal_of_NSA_surveillance_requests https://en.wikipedia.org/wiki/Qwest#Refusal_of_NSA_surveilla...
- supriyo-biswas 3y agoYes, that's the one. Thanks!
- cheekibreeki2 3y agoVerisign IS the conspiracy.
- jmclnx 3y ago[flagged]
- profmonocle 3y agoThey've just taken over authorative DNS. The captchas come from their CDN product.
- randunel 3y agoYou can't use https://esta.cbp.dhs.gov/esta/ https://esta.cbp.dhs.gov/esta/ from my country without an infinity of hcaptchas by CF turnstile.
- profmonocle 3y agoA particular .gov domain using Cloudflare (although from my DNS lookups, that one is not) is unrelated to Cloudflare managing the authoritative DNS servers for the .gov TLD. The fact that only a specific .gov domain - not all of them - has this issue demonstrates that.
- miyuru 3y agoAre you sure about that? esta.cbp.dhs.gov seems to served by akamai at least for me. Also turnstile and hcaptchas are same product(captcha) by 2 different companies.
- acdha 3y agoHere’s what it looks like from India: https://www.webpagetest.org/result/240210_BiDcTM_7TZ/ https://www.webpagetest.org/result/240210_BiDcTM_7TZ/ That’s definitely an Akamai IP. I’d be quite surprised if they were leading address space to a direct competitor.
- rozenmd 3y agoDNS and Turnstile are separate products.
- stefan_ 3y agoDoes this mean every GOV page will now have the "pretend security check" interstitial that litter just about every page now? How do you even describe it, it's like they are vandalising the internet.
- randunel 3y agoYou're getting downvoted, but I guess none of the downvoters tried to apply recently on https://esta.cbp.dhs.gov/esta/ https://esta.cbp.dhs.gov/esta/, I'm getting the infinite turnstile cloudflare hcaptchas. It's probably happening to most people trying to use that website from 3rd world countries.
- acdha 3y agoHe’s getting downvoted for confusing two unrelated services. What you’re both talking about is what happens when someone uses Cloudflare’s CDN, enables their managed CAPTCHA feature, and directs their web traffic through it. This is about DNS, which is a separate service at a lower level. Agencies would have to contract with Cloudflare separately to use the CDN, and each contract is a separate competition where a different part of the government using Cloudflare for a different service would not be considered when reviewing bids.
- cheekibreeki2 3y agoWhat are you on? Site owners choose to enable those rooms.
- overstay8930 3y agoIt is shocking how few people understand how DNS works
- tazjin 3y agoI wasn't sure what you were referring to until reading the other top-level comments. Wow. And that's on a site with a technical audience!
- SOLAR_FIELDS 3y agoIn people’s defense DNS is complicated. Try building a product that uses it and realize there are a ton of edge cases to handle
- dinkleberg 3y agoThey don’t need to know the edge cases to understand the basics of how DNS works. It is a foundational element of how the internet works and any software dev should have at least some fundamental knowledge of it (unless they don’t do anything that ever touched networking which I imagine is rather rare).
- tephra 3y agoWhile there are certainly complex and weird stuff in the DNS world. The basic of how the DNS works is really not that complicated.
- striking 3y agoYeah, but it's not like those comments are making a mistake about how the tech works because they're looking to learn something today. Posting an axe-grinding comment that shows a clear misunderstanding of the technology on a technical forum is an unforced and pretty indefensible error.
- dinkleberg 3y agoIt never fails to amuse. Our world is full of really complex tech which people are eager to learn, yet those same people will seem to be allergic to DNS despite it being very simple (at least the main parts of it).
- 6d6b73 3y ago[flagged]
- Tijdreiziger 3y ago> since Cloudflare is a CIA operation Source for this extraordinary claim?
- phantompeace 3y agoThey were probably exaggerating but it’s well known that American agencies can and will extort whatever they need from any American company and the organisation wouldn’t even be legally allowed to disclose that it even happened through secrecy and gag orders.
- acdha 3y ago“Well known” in conspiracy circles. You’re referring to national security letters and, no, those cannot compel “whatever they need”: it’s limited to release of transactional data, not payload: https://en.wikipedia.org/wiki/National_security_letter https://en.wikipedia.org/wiki/National_security_letter Part of why the news about MUSCULAR was so shocking was that the Buah-era NSA was attacking the fiber connections between American tech companies’ data centers, because they did NOT have a legal way to get that level of information.
- DANmode 3y agoIf that was shocking, put your rubber gloves on for this read: https://en.m.wikipedia.org/wiki/2010s_global_surveillance_disclosures#Timeline https://en.m.wikipedia.org/wiki/2010s_global_surveillance_di...
- acdha 3y agoYeah, that page is one of the places you can read about the program I mentioned. I picked that one because it wasn’t news that the NSA spied on people outside of the United States, but a lot of Americans did not expect them to use the same tactics against American companies on US soil.
- NicoJuicy 3y agoThere's a very interesting document by Cloudflare linked to it that describes why this was not your typical "change nameserver and done" transition: https://indico.dns-oarc.net/event/48/contributions/1038/attachments/1005/1948/gov-transition-nsec-nsec3.pdf https://indico.dns-oarc.net/event/48/contributions/1038/atta...
- blibble 3y agoyet another example of DNSSEC "adding value"
- lambdaone 3y agoBy making it hard just to hijack a crucial TLD and transfer it over to an potential adversary without the cooperation of multiple trusted parties? It seems to me this is DNSSEC working as designed, and being remarkably flexible in doing so. Sometimes things _should_ be difficult to do.
- jpgvm 3y agoYeah I hate that people can't acknowledge that friction is sometimes intentional. Not everything -should- be easy. For example I designed a system at a previous company that used Shamir's Secret Sharing to protect a very very important root key. We used an intermediate of this key for most operations but it came time to rotate it and folks were surprised by the ceremony involved in doing so. i.e the root key was decrypted using X of N members of the SSS group, a new intermediate generated and the special NUC that was designed for this purpose returned to it's safe (which was also using a Yubikey as like a mini-HSM too). Those keys protected very important PII and I deemed this the minimum necessary friction, ideally I would have went further if that was tenable. Some things really should be hard and that hardness should be proportional to how horrible the implications of someone unauthorized doing that thing.
- blibble 3y ago> Not everything -should- be easy. the entirety of .nz probably wouldn't agree with you when they had a 2 day outage due to a slight DNSSEC misconfiguration
- omoikane 3y agoI didn't even know .gov changed operators until this news, but looks like there was an earlier news that said it would happen: https://news.ycombinator.com/item?id=34403055 https://news.ycombinator.com/item?id=34403055 - Verisign Loses Prestige .Gov Contract to Cloudflare (2023-01-16)
- jcsnv 3y agoLooks like it was for ~$7.2mm - https://sam.gov/opp/84b13553be9643f6bd143480a4567352/view https://sam.gov/opp/84b13553be9643f6bd143480a4567352/view
- cheekibreeki2 3y agoVerisign is evil, good for cloudflare.