6 ms·
It's crazy that both 1.1.1.1 and 1.0.0.1 where affected by the same change I guess now we should start using a completely different provider as dns backup Mayb
by CuteDepravity 1y ago
It's crazy that both 1.1.1.1 and 1.0.0.1 where affected by the same change
I guess now we should start using a completely different provider as dns backup
Maybe 8.8.8.8 or 9.9.9.9
- sammy2255 1y ago1.1.1.1 and 1.0.0.1 are served by the same service. It's not advertised as a redundant fully separate backup or anything like that...
- yjftsjthsd-h 1y agoWait, then why does 1.0.0.1 exist? I'll grant I've never seen it advertised/documented as a backup, but I just assumed it must be because why else would you have two? (Given that 1.1.1.1 already isn't actually a single point, so I wouldn't think you need a second IP for load balancing reasons.)
- ta1243 1y agoFar quicker to type ping 1.1 than ping 1.1.1.1 1.0.0.0/24 is a different network than 1.1.1.0/24 too, so can be hosted elsewhere. Indeed right now 1.1.1.1 from my laptop goes via 141.101.71.63 and 1.0.0.1 via 141.101.71.121, which are both hosts on the same LINX/LON1 peer but presumably from different routers, so there is some resilience there. Given DNS is about the easiest thing to avoid a single point of failure on I'm not sure why you would put all your eggs in a single company, but that seems to be the modern internet - centralisation over resilience because resilience is somehow deemed to be hard.
- yjftsjthsd-h 1y ago> Far quicker to type ping 1.1 than ping 1.1.1.1 I guess. I wouldn't have thought it worthwhile for 4 chars, but yes. > 1.0.0.0/24 is a different network than 1.1.1.0/24 too, so can be hosted elsewhere. I thought anycast gave them that on a single IP, though perhaps this is even more resilient?
- darkwater 1y agoNot a network expert but anycast will give you different routes depending on where you are. But having 2 IPs will give you different routes to them from the same location. In this case since the error was BGP related, and they clearly use the same system to announce both IPs, both were affected.
- ta1243 1y agoIn the internet world you can't really advertise subnets smaller than a /24, so 1.1.1.1/32 isn't a route, it's via 1.1.1.0/24 You can see they are separate routes, say looking at Telia's routing IP https://lg.telia.net/?type=bgp&router=fre-peer1.se&address=1.0.0.1 https://lg.telia.net/?type=bgp&router=fre-peer1.se&address=1... https://lg.telia.net/?type=bgp&router=fre-peer1.se&address=1.1.1.1 https://lg.telia.net/?type=bgp&router=fre-peer1.se&address=1... In this case they both are advertised from the same peer above, I suspect they usually are - they certainly come from the same AS, but they don't need to. You could have two peers with cloudflare with different weights for each /24
- kalmar 1y agoI don't know of it's the reason, but inet_aton[0] and other parsing libraries that match its behaviour will parse 1.1 as 1.0.0.1. I use `ping 1.1` as a quick connectivity test. [0] https://man7.org/linux/man-pages/man3/inet_aton.3.html#DESCRIPTION https://man7.org/linux/man-pages/man3/inet_aton.3.html#DESCR...
- tom1337 1y agoWasn’t it also because a lot of hotel / public routers used 1.1.1.1 for captive portals and therefore you couldn’t use 1.1.1.1?
- immibis 1y agoBecause operating systems have two boxes for DNS server IP addresses, and Cloudflare wants to be in both positions.
- codingminds 1y agoWasn't that the case since ever?
- globular-toast 1y agoIn general there's no such thing as "DNS backup". Most clients just arbitrarily pick one from the list, they don't fall back to the other one in case of failure or anything. So if one went down you'd still find many requests timing out.
- JdeBP 1y agoThe reality is that it's rather complicated to say what "most clients" do, as there is some behavioural variation amongst the DNS client libraries when they are configured with multiple IP addresses to contact. So whilst it's true to say that fallback and redundancy does not always operate as one might suppose at the DNS client level, it is untrue to go to the opposite extreme and say that there's no such thing at all.
- 0xbadcafebee 1y agoIn general, the idea of DNS's design is to use the DNS resolver closest to you, rather than the one run by the largest company. That said, it's a good idea to specifically pick multiple resolvers in different regions, on different backbones, using different providers, and not use an Anycast address, because Anycast can get a little weird. However, this can lead to hard-to-troubleshoot issues, because DNS doesn't always behave the way you expect.
- ben0x539 1y agoIsn't the largest company most likely to have the DNS resolver closest to me?
- fragmede 1y agoYour ISP should have a DNS revolver closer to you. "Should" doesn't necessarily mean faster, however.
- lxgr 1y agoI’ve had ISPs with a DNS server (configured via DHCP) farther away than 1.1.1.1 and 8.8.8.8.
- encom 1y agoIn case of Denmark, ISP DNS also means censored. Of course it started with CP, as it always does, then expanded to copyrights, pharmaceuticals, gambling and "terrorism". Except for the occasional Linux ISO, I don't partake in any of these topics, but I'm opposed to any kind of censorship on principle. And naturally, this doesn't stop anyone, but politicians get to stand in front of television cameras and say they're protecting children and stopping terrorists. </soapbox>
- nullify88 1y agoNot just that. ISPs are often subject to certain data retention laws. For Denmark (And other EU countries) that maybe 6 months to 2 years. And considering close ties with "9 eyes" means America potentially has access to my information anyway. Judging by Cloudflare's privacy policy, they hold less personally identifiable information than my ISP while offering EDNS and low latencies? Win, win, win.
- bigiain 1y agoI mean, aren't we already? My Pi-holes both use OpenDNS, Quad9, and CloudFlare for upstream. Most of my devices use both of my Pi-holes.
- johnklos 1y agoIf you're already running Pi-hole, wny not just run your own recursive, caching resolver?