>Huston emphasised that APNIC intends to protect users' privacy. "DNS is remarkably informative about what users do, if you inspect it closely, and none of us are interested in doing that," he said.
Maybe it is reasonable to take them at their word as they seem trustworthy, but we should at least consider the fact that at least some of this DNS traffic is indeed being analyzed.
Users of the DNS service get the privacy guarantee.
Non-users do not. If you floodping 1.1.1.1 you are not a user of the DNS service and the privacy terms don't apply to you. Rather you're a member of the Misconfiguration Club, and the site you're pinging has the usual right to analyse your pings.
I get the general idea, but having "user-privacy oriented" and "we collect everything and make it available to many researchers" services under the same IP may lead to some issues.
https://developers.cloudflare.com/1.1.1.1/commitment-to-priv...
that's just the public stuff!
Another regional example, they have 20Gbps to the VANIX.
What is opaque is the size and scale of their PNI peering, which parties generally don't share. For example in a mid sized city where Comcast is the cable monopoly they almost certainly use a 100GbE interface direct to Comcast for just that isp.
Yes the scale is terabits globally. But it is highly decentralized.
Isn’t that the entire point of a CDN, to have decentralized POPs scattered globally?
Yes, they may max out at 100gb per public IX in most cases, but they still have lots of 100gb peers all over the globe.
Your post implied a total of 200-400gb, the real number is 10x that (otherwise known as “order of magnitude”). I’m not disputing your knowledge or experience, but the post as written has issues.
If you want privacy, you never do DNS queries from an ISP-assigned IP address. Tor exits do DNS queries on behalf of clients. Decent VPN services also handle DNS queries for clients.
Or are you arguing that even Cloudflare couldn't get raw DNS traffic?
I don't mean to question CloudFlare's integrity.
It's just that, for claims about privacy, I'd rather depend on more than trusting any one party.
Because these sorts of comments read to me as "yeah, you're the best right now, but are you perfect? No.". Nobody claimed perfection, and there's value in being the best.
But I never depend on any one of them. I use nested chains. That's my no means perfect, because routes are relatively static, unlike Tor with its frequently changing circuits. But the basic idea is the same. Compromise would depend on collusion, perhaps forced, of multiple parties. Or some serious traffic analysis.
Here, there's CloudFlare, its auditors, and perhaps Google. So maybe there is distributed trust in that. But still, I'm happier to put more independent parties between me and them. Tor, or at least a nested VPN chain.
This is relevant as the CEO has previously woken up one morning after a troublesome sleep and it has been argued, gone against his word (for good and anti nazi reasons). Many argue that he was entirely within his right to do so, and he was! So in this case, would he be entirely within his right to start monitoring all that data. As he asks, paraphrasing: "what more can I do to ensure my word is good."
I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them.
What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from?
For DNS users of 1.1.1.1, we never provide APNIC any identifying information. We don’t upload any data to them. While they can query for questions like: “How many queries came from India in the last 24 hours?” they can’t query anything on a specific user.
If you have concerns, ask them here. I’ll answer.
https://developers.google.com/speed/public-dns/docs/ecs
https://developers.google.com/speed/public-dns/faq#locations (when EDNS0/ECS isn't supported)
The tin foil hat brigade might suggest that this is deliberate to ensure that only what's served by cloudflare gets to be fast...
Conspiracy theory isn't a dirty word.
Speculation keeps people informed and alive.
It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www.example.com at the same location a few milliseconds later.
Our business is not about tracking people; it's about selling our service to businesses to make their web sites/APIs/applications faster and more secure.
"Specifically, APNIC will be permitted to access query names, query types, resolver location and other metadata via a Cloudflare API, that will allow APNIC to study topics like the volume of DDoS attacks launched on the Internet and adoption of IPv6."
I interpret "query names" as some values obtained from DNS queries hitting 1.1.1.1, e.g. "foo.example.com".
Is your answer to "What data do you provide to APNIC?" complete in the statement above?
Thanks for clarifying.
Are the gigabytes of junk billions of tiny requests or are there large requests as well?
Are you finding it more difficult than expected to manage the data?
I'm a 1.1.1.1 customer since you launched, thanks a lot for it.
Have seen edge traffic charts for major porn hosting companies and the out:in traffic ratio is like 97:3
What exactly do you mean by "user"? Can they query DNS traffic by IP address / subnet? Exactly what are all of the restrictions there?
EDIT: Is there a whitelist of things they can query by or do you simply trust them to be good citizens, have a binding legal agreement, all of the above?
Ding ding ding, we have a winner. If more people would realize this, we would have less data breaches. To get there, a data breach must become more costly for the companies.
To protect against that, could you commit not to log to disk any queries that come from fewer than N ips in 24 hours, and not to expose rare queries to APNIC or internally? (Not a demand, just brainstorming mitigation.)
It might also be fun to give an internal team access to the data you consider safe, and challenge them to dig up personal data from it.
Is there a guarantee that this will always be the case? Might there, in theory, be a point in the future where users' IPs are collected and stored?
Loving 1.1.1.1, btw.
As personal information count full IP addresses, the content of requests, or any set of data that can be used to recover these.
That is what "we respect your privacy" means.
We can query things like:
1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers?
If you have specific concerns, please raise them here.
Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it.
Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often because employees believe in our mission. 1.1.1.1 helps with that.
I've been working a lot with open data and I have huge problem with Cloudflare ruining open internet with bot protection and such. The issue I have is that public data is public, be it bot or human.
I'm having real issue with you guys saying that your mission is to better the internet when you break shitton of floss apps that are essentially harmless and people who want to do harm, crawl at huge rates for commercial purposes break your systems like it's made of twigs. I'm saying this as a person who works on both sides and can't help but call you out.
So sorry unless you turn to non-profit I'm really not buying your "helping the internet" song.
As long as Cloudflare blocks that, it's hostile.
Maybe a way to register as spider with Cloudflare, and get a token that one passes in the header, with strict rate limits would be much better than the current solution of just showing captchas.