1.1.1.1 Cloudflare DNS Resolver Soon to Be Announced?
webcache.googleusercontent.com
webcache.googleusercontent.com
Also, Google has 8.8.8.8 which could be for the same thing and has similar problems (large scale data collection, singe point of failure).
I think it's simply that a lot more people have used Cloudflare because it has a free plan, whereas Akamai is expensive in comparison.
Dealing with salespeople is a massive PITA. They're not going to tell me anything that's not in the docs or support forums and I don't want to spend a week negotiating. I've seen many others make this point on HN over the years.
Maybe Akamai only focuses on large enterprise customers while CloudFlare also goes for the SMB market. IDK. The HN crowd seems to work at SMBs (startups included) or at companies big enough to operate their own CDN.
Fuck you. Sell me boxes and tell me how much they cost. But they won't.
Last project I could have spent that money to pay for 3-4 additional full time engineers for 3 years and built a better solution with open source because I still had to devote 2 plus myself to do integration. And then didn't have overpriced SMS for the next decade and licensing headaches and afford to keep at least 1 of the engineers indefinitely.
Is there room in this space for a new no-nonsense vendor? Someone who cuts out all the goddamn middlemen and just asks what hardware you want, how you want it configured, and quotes you a frickin price without all the bullshit?
We sell incredibly complicated systems that necessarily interact with many other complicated systems. We don't work natively with all of them, and sometimes we need to do custom work. Not to mention that we need hardware in many geographical areas, yet still need to work when the virtual space doesn't line up with the physical space.
It's not as easy as "am I buying the small, medium, or large solution". Before you invest tens of millions of dollars into this one product, you need someone from the vendor to analyze your infrastructure and tell you if our product will work, and then how many you need to buy and where you need to put them geographically, and then how many hours of custom programming it will take to get everything working with the other systems.
That's far outside any definition of "salesman" I've ever heard. These people are project architects and their speciality is solution design. It's not a three-tier SaaS solution.
We'd actually love to be able to give you an "add to cart" price, but the reality is that most of our systems are configured to your specific requirements (with the exception of the FreeNAS Mini, which you can just add to cart on Amazon) instead of just "off the shelf".
It's actually not about trying to figure out how much is in your wallet, I assure you. In fact, we have one of the most transparent pricing processes in the biz. For example, we tell you your end price on our storage systems before a Reseller/VAR is even involved. We also fought the concept of having "list prices" for years, since we all know they're completely fictitious. However, it's something our F500, Gov't, and University customers almost always require so that they can measure and compare their discount.
Nonetheless, we do try to make the design process as quick and painless as possible for you, and regardless of whether or not you give us another shot, the feedback is always appreciated.
Cheers!
The problem is if you only need one or two servers that's too small for most vendors to bother responding. If you're buying 10 or more it can work well.
Obviously they must extract some value for the business but the experience of haggling with some sales bro to get a decent price leaves me so annoyed with services that I usually skip signing up when it’s the only option.
> Let’s talk about solutions!
No thanks. I just want to insert dollars and get the service.
A salesperson could at least ask 'what is a better price we can shoot for?' or 'what features do you really need?' whereas a visitor to a pricing page just disappears.
Your platform may have 1000's of features, not all of which all your clients want or can pay for. Packaging into simple groups may not possible until you have the volumes to figure out what works
Many clients need specific features that you don't have yet, pricing calculation becomes very complex, and depends on customer to customer as well. We will charge more to some customers simply because we know they need a lot of hand holding and special assistance
Note that B2C is totally different and unless you're doing some very high priced / bespoke delivery then you have to go cookie cutter.
and they publish their pricing, no minimum purchase: https://azure.microsoft.com/en-us/pricing/details/cdn/
https://www.akamai.com/us/en/resources/brute-force-attacks.j...
I’m clearly missing something, but why doesn’t that solve the problem?
And I’m keeping the scope of my comment on the technical side, and ignoring the business/antitrust potential.
As opposed to hosting everything on AWS, so half the Internet goes down when they have a no-so-uncommon outage.
I don’t think Cloudflare is that much of a bottleneck in comparison. Not to mention 3 points of failure is the definition of “not a single point of failure”.
google-public-dns-a.google.com 8.8.8.8
IPv6 address 2001:4860:4860::8888
google-public-dns-b.google.com 8.8.4.4
IPv6 address 2001:4860:4860::8844Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.
4.2.2.1
4.2.2.2
For as often as I manually configure DNS (I use DHCP) it's not onerous to look up the IPs of whatever DNS is preferable for your purpose.edit: Depending on who you are this may redirect you to a search portal. Probably best to find an alternate DNS provider.
; <<>> DiG 9.9.7-P3 <<>> thisprobablydoesntexist.com @4.2.2.2
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12860
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; ANSWER SECTION:
thisprobablydoesntexist.com. 10 IN A 104.239.213.7
thisprobablydoesntexist.com. 10 IN A 198.105.254.11
Contrast that with 8.8.8.8: ; <<>> DiG 9.9.7-P3 <<>> thisprobablydoesntexist.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 7991
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
The NXDOMAIN response is proper - the level3 DNS servers are just a faster version of my ISPs goal to garner ad revenue at this point.There is this comment from a few years ago, https://news.ycombinator.com/item?id=7120248 , linking to a blog post which is now only accessible from the Internet Archive, where a VP at Level3 stated they were public.
I use 4.2.2.x and I do get NXDOMAIN from them, and I'm not a L3 customer. I wonder if they respond differently depending on who you are...
; <<>> DiG 9.9.7-P3 <<>> @4.2.2.1 thisprobablydoesntexist.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10665
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; ANSWER SECTION:
thisprobablydoesntexist.com. 10 IN A 104.239.213.7
thisprobablydoesntexist.com. 10 IN A 198.105.254.11
;; Query time: 29 msec
;; SERVER: 4.2.2.1#53(4.2.2.1)
;; WHEN: Fri Mar 30 09:27:39 PDT 2018
;; MSG SIZE rcvd: 77Looks like I ran into that issue and went back to Google.
I just changed DHCP config to 1.1.1.1 :)
; <<>> DiG 9.9.7-P3 <<>> @1.1.1.1 thisprobablydoesntexist.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 28530
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1536
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; AUTHORITY SECTION:
com. 900 IN SOA a.gtld-servers.net. nstld.verisign-grs.com. 1522427379 1800 900 604800 86400
;; Query time: 33 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Fri Mar 30 09:29:56 PDT 2018
;; MSG SIZE rcvd: 132 # dig +short this-should-be-a-nxdomain.com @4.2.2.2
198.105.254.11
104.239.213.7
They do it a little more cleanly than some other attempts I've seen, but there's still flaws in their approach. In particular, they will generate redirects for NXDOMAIN responses to certain records under domains that do exist: # dig +short why-does-this-resolve.example.com @4.2.2.2
198.105.254.11
104.239.213.7
Specifically, they'll generate a redirect for any record that starts with the letter "w". (No, I'm not kidding. Try it.) Other records generate a real NXDOMAIN. dig @9.9.9.9 icnerd-1e5f.kxcdn.com
icnerd-1e5f.kxcdn.com. 3600 IN CNAME s-us-ca00.kvcdn.com.
s-us-ca00.kvcdn.com. 55 IN CNAME p-ussj00.kxcdn.com.
p-ussj00.kxcdn.com. 55 IN A 209.58.129.70
dig @8.8.8.8 icnerd-1e5f.kxcdn.com
icnerd-1e5f.kxcdn.com. 21599 IN CNAME p-uklo00.kxcdn.com.
p-uklo00.kxcdn.com. 59 IN A 217.146.91.55From their FAQ:
Does Quad9 support DNS over TLS?
We do support DNS over TLS on port 853 (the standard) using an auth name of dns.quad9.net.At least I'm not paying Google to do the same, and I can trust that they'll send the proper results.
isn't that the recommended behavior? otherwise you can do a bunch nasty stuff like rebinding attacks.
https://www.ietf.org/proceedings/52/I-D/draft-ietf-dnsop-don...
Take your 1.1.1.1, 8.8.8.8, 9.9.9.9, maybe your ISP DNS, etc., check against them randomly to try and avoid giving any one of them all of your DNS request traffic, maybe look up the same address on two of them to confirm that you're getting the same destination from both?
That's a DNS service everyone would love to use, right?
I suspect that the whole reason why 8.8.8.8 is a Google DNS server is that they were originally only 4.4.4.4 until someone Chinese pointed out that 4 is an unlucky number. :)
https://www.quad9.net/faq/#Is_there_a_service_that_Quad9_off...
$ dig @9.9.9.10 +dnssec +short verisignlabs.com
72.13.58.64
A 8 2 3600 20180413202737 20180330202737 31485 verisignlabs.com. KrnT9i6qytaYWDZWThBmBwc6anOmawNxJTxmSlpaY3L7Yfupga9FS70l 8nMVp8ggbEtA+CnS9AbNwObkPaYvk3nFpDvo4C+2hg+PECsP1HVTgGxl G3eblfnYAMNfYzLYlfUnSBgM7kLSIXY4rLBxsl01KiPJYezNhmQ53KYf ygs=Use cases are different - Quad9 for "nasty" filtered and 8.8.8.8 for err probably not filtered.
Do it yourself otherwise.
Cloudflare gets a lot of press and is doing great things; I’m not concerned about them being a single point of failure on the internet.
The number of sites on Cloudflare is a pretty small fraction of the internet as a whole.
It's definitely possible Cloudflare may go the way of Google at some point in the future, but right now, I'd rather have the former than the latter involved in my Interneting. And in this case, it's a new/additional option, a second point.
In general, in distributed systems a number of inconveniences arise as a natural cost of the distributed nature of the system.
This creates a tendency for a critical mass to circle around a single central entity that uses its central position to provide convenience and further creating a "distributed in theory if you really want it but not really" environment (example: Github).
Not really super related to Cloudflare, just a general observation.
They offer/sell a service that is built using those technologies. People go to them for the convenience you mention. If there were other convenient ways to use those services people would use them as well.
... and there are! Github has competitors (Gitlab, bitbucket, ...) and GMail has competitors (Fastmail, hotmail, yahoo, and a bazillion others). Maybe it doesn't feel like they have enough competition, but if they actually turned git/email into "distributed only in theory" then there wouldn't actually be competition.
That's far from the perfect opposite of “distributed and open”, since these habits can be more fluidly shifted and alternate versions of the convenience processes can exist in theory, but it's also far from what I usually hear people implying when they expect things to be socially distributed as well as technically.
(I'm told that GMail similarly changes the nature of email by making it socially unsafe to operate email addresses in certain ways, but I believe this effect is weaker and I don't have real experience with it.)
Do people here actually think about the alternatives when they complain certain systems are too centralized?
If you stop using Github/Gitlab/Bitbucket today, you won't be able to collaborate because you no longer have a way to do the things Github lets you do. This isn't Github's fault.
Git is decentralized in that it has logic that allows multiple upstreams/downstreams. It's not magic. It's not "blockchain" or whatever.
Github is not decentralized, it's a SaaS product which offers git-compatible and svn-compatible repository storage, an excellent UI, comments, reviews, issue tracking and a bunch more. FOSS developers are asking you to create accounts to Github not so you can download their repository (you don't need to!), but so you can actually use the contributing tools on offer.
Sorry, I realize this isn't the tone you want to hear, but these comments about "centralized systems in decentralized worlds" are just so empty and meaningless. There's a few projects out there which actually try to solve the abstract issues you mentioned by, for example, adding comment/review metadata to git repositories. But you still have access control to take care of and at the end of the day, you need to trust some party; just like at the end of the day, with DNS, you have to put in a couple of IPs that you trust to provide you with good results.
Yes, you have to create a Github account to contribute to some projects. Has nothing to do with git, has everything to do with being able to use the services that Github provides. What is it that you're actually suggesting?
FTFY
Git works without a website just fine. Linus manages one of the largest Git repos purely via e-mail.
And you can do the same. Sure, Github/Gitlab/Bitbucket is more convenient, but you can just put up a Git repo with a static website that says "send patches to <mailinglist>" like it's 2003.
[1]https://addons.mozilla.org/en-GB/firefox/addon/decentraleyes...
They booted the daily stormer, knowing full well the ramifications:
https://blog.cloudflare.com/why-we-terminated-daily-stormer/
"Get out of the way so we can DDoS this site off the Internet."
Matthew Prince basically said "this is dangerous" and a month or two later that exact decision was being used against them in court to take down a copyright infringer.
Not saying one way or another about it being a good or bad decision, but they definitely knew they were setting a scary precedent when they did it.
Let me spell that: A W S
The difference is that when a company with a spotless record decides it's time to change their ways, it can be a pretty radical change (look at Reddit). But with cloudflare I know we're a long way from that.
It's kind of absurd how everyone expects spotless companies. I'd like to live in that world as well but the reality of this one is that such companies do not exist. Cloudflare gets criticism on both too much censorship and not enough. I don't envy them...
I don't believe we are going to suddenly flock to cloudflare to provide all dns ever. Between ISPs hardcoding or force-defaulting their own (awful) dns servers, and the amount of geeks and IT techs who have memorized 8.8.8.8, we're safe for a long time. And if I'm wrong on that, that wouldn't speak highly of the "decentralized" nature of DNS, would it?
As long as nobody knew what was happening, it went unpoliced. One of the ongoing HR-related lawsuits explicitly claims Google prohibits employees from revealing illegal conduct that the company engages in.
IPv6, other debate.
Even when they do change, knowing ping times plus IP address owner plus superficial usage patterns would easily be enough to narrow down to a single household. Many households will have a unique DNS footprint based on the exact makeup of internet connected devices in the household that are constantly phoning home.
How I monitor my house also lets me know when my public address changes, and its extremely rare.
I also note that Cloudflare doesn't make a performance comparison with Google DNS.
If Cloudflare did this, would they pass the audit?
Had the Daily Stormer folks kept their mouths shut, they probably would've been fine.
And then Cloudflare continues on to describe why they don't think companies should censor content, whereas Google has numerous blogs and entire technologies revolving around how to censor content even more than they do now.
> Section 18 - Because Cloudflare has no control over such sites and resources, you acknowledge and agree that Cloudflare is not responsible for the availability of such external sites or resources, and does not endorse and is not responsible or liable for any content, advertising, products, or other materials on or available from such sites or resources.
It's a clear ToS breach, a bit of thought would have avoided the whole thing. You got lawyers on hand? Talk to lawyers!
I may support my friend's right to free speech in general, but if they are at my house and start bad-mouthing myself and my family, I'll ask them to leave. They can still say what they want (if not libel/slander), but they don't need to do it in my house. They can go say it elsewhere.
> I wonder if this signals a more general change in attitude
CloudFlare CEO says his Daily Stormer takedown was “arbitrary” and “dangerous” https://news.ycombinator.com/item?id=15034304
> If this is true [Daily Stormer made the claim that CloudFlare were secretly supporters], then I agree with the takedown [...] But in this interview, the CEO says something totally different
The Terrifying Power of Internet Censors https://news.ycombinator.com/item?id=15238415 (September 2017)
> If you think that [...] government has a tendency to suppress dissent, then censoring [...] is just opening the door and setting a precedent
‘Daily Stormer’ Termination Haunts Cloudflare in Online Piracy Case https://news.ycombinator.com/item?id=15377292
> Cloudflare set up a limit to what they allow or not so now they will have to fight where that limit is
if someone tells me they have a 100% SLA I write them off as a liar, but tell me you have a 99.995% SLA and have only ever had this one exception and here's why, that builds much more trust with me.
It's plainly wrong.
https://en.wikipedia.org/wiki/Exception_that_proves_the_rule
If you expect that the SLA has very likely been violated at some point, hearing that it has at some point means that the statement confirms to what you already believe to be true given your existing knowledge. That doesn't mean the statement is true, but since it's not obviously conflicting with what you already believe to be true, it at least allows you to believe it is not immediately false.
Instead of thinking about it increasing the likelihood of being entirely true, think about it as decreasing the likelihood it's entirely false. Depending on your point of view that may not be much, but it's something.
>No, it's a matter of reality matching expectations.
What an agent tells me is what they choose to tell me. You're describing some sort of luck-based updating via that third party's choice.
I don't live in a tinseltown universe full of model trains and animatronic NPCs. None of us do. All reasoning about real-world agents is subject to incomplete information and uncertainty.
That much is trivial. More, it's mutually understood to be the case.
Also mutually understood: basic world knowledge stemming from the same. These are principles simple enough to be patronizing in written description, yet persistently ignored or misused at implementation-level. Like:
1. Actors are variably susceptible to errors in reasoning under uncertainty
2. Actors are variably skilled at exploiting 1 to modulate 3rd party behavior
3. Actors are variably motivated to make use of 1-2
It follows from the above that allowing an actor to subtly shift your expectations as if you ever held a platonic model of their behavior is simply a cognitive error. There's no way around it.
Take the "99.995% SLA" example.
In the absence of that figure, would you have assumed a God-Mode level of performance? Clearly not. You can cross all the factors like whether you care about the figure, whether it's above or below average, whether disclosure is standard in this context, … to just enumerate all the cases and see clearly that there's no time when this information is surprising.
I mean, just look at a top google hit for SLA⁽¹⁾. You really think a CIO reader is in any way surprised to hear that some metric they negotiated into a contract indeed holds? Or that it doesn't?
Continuing: A figure like 99.995% is well within reasonable bounds for any number of business processes, so it's not necessarily false precision here. What it almost definitely is, however, is precision in pursuit of persuasion.
There are plenty of industries for which exacting figures at the high end of some performance criterion — manufacturing quality, service availability, measurement accuracy, etc — are essential to informed consumer behavior. Those industries almost universally have norms or regulations setting out certain expectations about what will be found on a specsheet, how units will be tested, how this information will be reported. If not, the spiel is just spiel.
Facts and figures as token gestures of fallibility, however, are confidence tricks.
I already know you're fallible. You cannot sway this comprehension by reframing around some very likely sort of figure: charm pricing⁽²⁾ and related uses of odd figures are marketing weaselry targeting plebs. To point these things in the direction of clientele is to tell them how much you think of their ability to resist bullshit-fatigue.
My feels about whether I'd wanna have a beer with <The Guy>, modulated by his current demeanor toward me or whatever audience he imagines me to be a member of, do not determine his fitness for any high-stakes job.
The same is true here.
Cloudflare is in the MITM business. Absolutely trusted at no point in time, independent of whatever cost/benefit has gone into the decision to use a MITM. This isn't even defeated by being too big a client to lose: if you were big enough to be a lifeline for cloudflare, you'd have no need for cloudflare.
____________________
¹ https://www.cio.com/article/2438284/outsourcing/outsourcing-...
Cloudflare actually went out of their way to make it easy to whitelist Tor IPs that would generally get automatictly blacklisted for abuse.
EDIT: Maybe not anymore? See replies
What they went out of their way to do, was explicitly make it less painful for legitimate users to use Tor, despite the amount of malicious content they get from Tor. I'd argue for most companies, if 94% of the traffic from somewhere is malicious, the answer is "block it and be done with it", but clearly, Cloudflare actually values Tor and what it stands for enough to come up with a workaround.
nope, you're spreading un-sourced/unconfirmed FUD. Provide a source, or this is just FUD. Tor IPs are treated like any other IP by default, not "more questionable by default".
https://support.cloudflare.com/hc/en-us/articles/203306930-D...
The options for Tor are:
Whitelist (trust)
CAPTCHA (visible challenge which the visitor must interact with to pass)
JavaScript Challenge (visible challenge with less friction, testing the browser)
Block (blacklist -- available only to Cloudflare Enterprise customers)
I'm not sure you actually made a point other than to confirm that we allow website owners to fully whitelist Tor if they'd like to.
The website owner's settings defaults to secure, and they can intentionally take action to make the website less secure if they'd like to. That is their decision, of course we do not default to a less secure posture.
Starting November 1, 2015 [1], you could no longer obtain certificates for "Reserved IP Addresses" [2] and any still in existence on October 1, 2016 had to be revoked.
Section 3.2.2.5 of the BRs indicate how one can demonstrate control over the IP address.
--
1 - https://github.com/cabforum/documents/blob/master/docs/BR.md...
2 - https://www.iana.org/assignments/ipv4-address-space/ipv4-add...; http://www.iana.org/assignments/ipv6-address-space/ipv6-addr...
3 - https://github.com/cabforum/documents/blob/master/docs/BR.md...
(You might have been thinking about issuance for IP addresses in private/reserved IP space. That is indeed prohibited nowadays, just like "internal names", i.e. domains that don't end in a public suffix.)
There is a certificate extension - Certificate Subject Alternative Name that lists the following:
DNS Name: *.dns.cloudflare.com
DNS Name: dns.cloudflare.com
IP Address: 1.1.1.1
IP Address: 1.0.0.1
Most likely the extension was included as part of the certificate signing request.1 - Before Cloudflare I used to do this with OpenSSL and it requires half a dozen steps, but with cfssl you can do this quite easily: https://github.com/cloudflare/cfssl/wiki/Creating-a-new-CSR.
Guess I'll have to pick a new one.
There was a paper from a couple years ago when 1.1.1/24 (or bigger, don't remember) was still unassigned; at some AS they logged what kind of traffic was targeted at that subnet, by IP, port and protocol and 1.1.1.1 stood out. Can't find that paper just now unfortunately. :-(
Never had any issue and there's an extremely low, almost infinitely zero, chance of the domain dropping and being taken over by squatters (re: neverssl)
If that's the case that's really nice actually. Google DNS kinda silently launched DNS-over-HTTPS in 2016 but still no DNSCrypt; opendns are the only major ones supporting it.
Of course I stopped using dnscrypt at some point because it was a pain to maintain, and wasnt supported on most of my devices :/
https://dnscrypt.info/faq mentions some drawbacks of DNS over HTTPS;
- Requires a full TLS stack and a web server
- Interception/monitoring tools are readily available
- Key management can be surprisingly hard especially if public key pinning is used by clients
- Allows insecure algorithms and parameters
- Requires TCP
- RFC is in draft stage
So the question remains; does 1.1.1.1 support DNSCrypt or are there any plans for it to do so?
I also totally trust Cloudflare for the TLS security part, especially since they support TLS 1.3 already.
Quad9 said they will support DNSCrypt soon, and the software they use just got an update to do it nicely. So, this will be a decent alternative if you are looking for an anycast resolver.
Thanks for making this :) Also, thanks for using the ISC license, it is my favorite license.
PS: And additionally then, the text I was quoting from https://dnscrypt.info/faq was probably written by you. Good thing I was sufficiently convinced by what you said that I didn't argue against it, that'd been embarrassing. Embarrassing but also funny ofc ;)
Edit, another 40 minutes later: And you've authored libsodium, and you've done a bunch of other really cool things also. Holy crap! I'd buy you a beer if I ever met you but you are probably way busy anyway lol.
All the required parameters to connect to a server (protocol, certificate hashes, public keys, bootstrap IP address, URL...) are now represented as a string ("DNS Stamp").
See https://dnscrypt.info/stamps/
Cloudflare's DNS stamp is sdns://AgcAAAAAAAAABzEuMS4xLjEg63Ul-I8NlFj4GplQGb_TTLiczclX57DvMV8Q-JdjgRgSZG5zLmNsb3VkZmxhcmUuY29tCi9kbnMtcXVlcnk
Cloudflare's resolvers have been supported by dnscrypt-proxy for quite some time and are even present in the example configuration.
https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pd...
Are encrypted DNS requests used by default? Does 1.1.1.1 somehow advertise to your client (whether it's a browser, the OS or a router) that encryption is possible? Do I have to configure my endpoint, which may expect to be able to send normal plaintext DNS requests, for it?
I guess DNS over HTTPS will surely not be supported by normal routers, but I don't know what other protocol Cloudflare refers to as "encrypted DNS", so maybe that will work.
It also said it would support DNS over HTTPS.
Edit: Here's the snapshot from wayback machine, https://web.archive.org/web/20180328150501/https://dns.cloud...
https://1.1.1.1 and also every1dns.com seem to point there
APNIC-LABS is probably just a joint partner in that Cloudflare resolver project.
So China Telecom will never have been given 1.1.1.0/24
https://www.merit.edu/wp-content/uploads/2016/01/1.0.0.08.pd...
This is consistent with information on the page.
> 1.1.1.1 is a partnership between Cloudflare and APNIC.
"This is Google's cache of https://1.1.1.1/."
server_names = ['cloudflare']
And I wonder if all ISP should group together to start a single / few DNS.
>For IPv6: 2001:2001::, 2001:2001:2001::
Replace those addresses with the Cloudflare DNS addresses: For IPv4: 1.1.1.1 and/or 1.0.0.1 For IPv6: 2001:2001:: and/or 2001:2001:2001::
> Cloudflare had the network. APNIC had the IP address (1.1.1.1). Both of us were motivated by a mission to help build a better Internet. You can read more about each organization’s motivations on our respective posts: Cloudflare Blog / APNIC Blog.
The blog post links just links to the blog themselves, not actually to a post, so this submission seems premature.