6 ms·
While I fully support this instance, I wonder what else Cloudflare has set to "Censored", apart for the obvious CSAM
by breppp 7mo ago
While I fully support this instance, I wonder what else Cloudflare has set to "Censored", apart for the obvious CSAM
- Kwpolska 7mo ago1.1.1.2 is their malware-blocking DNS, and 1.1.1.3 is their parental-controls DNS. If you want an unfiltered DNS, use 1.1.1.1 - which resolves archive.today just fine, although archive.today itself refuses to work on Cloudlfare DNS.
- sgbeal 7mo ago> 1.1.1.2 is their malware-blocking DNS, and 1.1.1.3 is their parental-controls DNS. ... TIL, thank you. Time to go tweak my pi-hole server...
- arvid-lind 7mo agoI'm just curious, given all the other options that respect your privacy and don't put data collection at the center of their business model, why do you use Cloudflare on your pi-hole?
- daymanstep 7mo agoWhich options respect your privacy?
- travoc 7mo agoAdGuard DNS servers are excellent.
- nom 7mo agoquad9
- diarrhea 7mo agoI use unbound (recursive resolver), and AdGuard Home as well (just forwards to unbound). Unbound could do ad-blocking itself as well, but it's more cumbersome than in AGH. So I use two tools for the time being. The upside is there's no single entity receiving all your queries. The downside is there's no encryption (IIRC root servers do not support it), so your ISP sees your queries (but they don't receive them).
- dannyfritz07 7mo agoI'll throw https://nextdns.io https://nextdns.io into the mix. Been very happy with it. Supports DOH, block lists, among a plethora of other features.
- ranger_danger 7mo agoThe ones where you don't send a single company all of your queries
- sgbeal 7mo ago> why do you use Cloudflare on your pi-hole? Because "if it ain't broke, don't fix it." i'm not one of those users who want to endlessly tweak their ad blocker. i want to set it up, clicking as few checkboxes as necessary to get it going, and then leave it. However, (now) knowing that Cloudflare filters different only each of their servers, i'm incentivized to go tweak a number in the config (as opposed to researching the pros and cons of every possible provider, a detail i truly have no interest in pursuing).
- OJFord 7mo agoIf you mean you had 1.1.1.2 as a secondary, and don't want it to have a different configuration, you can use 1.0.0.1 along with 1.1.1.1 instead.
- sgbeal 7mo ago> If you mean you had 1.1.1.2 as a secondary, and don't want it to have a different configuration, you can use 1.0.0.1 along with 1.1.1.1 instead. i had no clue which one was active. It was, for me, just a checkbox at the time. This thread prompted me to go check and tweak appropriately.
- TZubiri 7mo agowhat is the vector here? dns traffic is practically anonymous, there would have to be some very specific and purposeful trickery going on to link dns traffic to an identity. It sounds like something more hypothetical than a tangible threat model
- hirako2000 7mo agoIt isn't anonymous. DNS server resolve, IP addresses by hostnames. It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit. Since ISP know your identity, and all it takes is to (request and get) the DNS logs and ISP servitude for all sort of questionable information, you as an identity are giving away all sites domains you visit.
- sgbeal 7mo ago> It cannot then inspect further traffic but it certainly can log your IP address and all URL's a given IP ever hit. Correction: they can log host names/IPs, not URLs. The path of any given URL is part of the HTTP header, invisible to onlookers (assuming HTTP and assuming HTTPS is uncracked).
- hirako2000 7mo agoI can't edit. That is correct. URLs can't be known to a DNS server. Just the hostname and IP.
- UqWBcuFx6NV4r 7mo ago[flagged]
- hirako2000 7mo agoI didn't mean to offense. It did seem OP didn't get the IP can be logged, either that or how an IP can reveal identity.
- TZubiri 7mo ago
- UqWBcuFx6NV4r 7mo ago[flagged]
- arvid-lind 7mo agothat's an observation, I guess... OP set up a pi-hole so it's not a stretch they would do a quick search for "free privacy dns". you make it sound like it takes some kind of reprioritization, why?
- philipallstar 7mo agoStrong counter-evidence: they ask why.
- TZubiri 7mo agoToday we are one of the lucky 10k
- Hamuko 7mo agoThe "censored" part of archive.today seems unrelated to the filtering itself. 1.1.1.3 flags Pornhub.com as "EDE(17): Filtered" but archive.today is "EDE(16): Censored". Supposedly it should be an external party that's requiring Cloudflare not to publish the DNS record. https://www.rfc-editor.org/rfc/rfc8914.html#name-extended-dns-error-code-16- https://www.rfc-editor.org/rfc/rfc8914.html#name-extended-dn...
- surgical_fire 7mo agoI have no idea why anyone would use Cloudflare DNS, much less trust their more filtered versions.
- saaaaaam 7mo agoI use cloudflare DNS because it’s faster. But should I worry, having read your comment? What is the downside to using it? What would you recommend instead?
- surgical_fire 7mo agoQuad9. Many years ago I used Cloudflare, and more than once I had issues with them blocking websites I wanted to access. I absolutely despise that. I want my DNS to resolve domain names, nothing else. For blocking things I have Pi-Hole, which is under my control for that reason. I can blacklist or whitelist addresses to my needs, not to the whims of a corporation that wants to play gatekeeper to what I can browse.
- akerl_ 7mo agoSo… why not use 1.1.1.1, cloudflare’s resolver that does not block resolution? 1.1.1.2 and .3 are explicitly offered with filtered responses.
- surgical_fire 7mo agoI used to use 1.1.1.1. I still had issues. Quad9 behaves exactly as I expect a DNS to work, in the sense that I only remember I use it when the topic of DNS pops up.
- akerl_ 7mo agoYour claim was that 1.1.1.1 was blocking sites. Are you saying now you just had issues with the quality of service? Or do you want to provide more details to substantiate the claim that they were blocking sites?