I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them.
What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from?
For DNS users of 1.1.1.1, we never provide APNIC any identifying information. We don’t upload any data to them. While they can query for questions like: “How many queries came from India in the last 24 hours?” they can’t query anything on a specific user.
If you have concerns, ask them here. I’ll answer.
As personal information count full IP addresses, the content of requests, or any set of data that can be used to recover these.
That is what "we respect your privacy" means.
We can query things like:
1. How much query traffic is from Africa? 2. What’s the peak time of query traffic? 3. What are the most popular DNS authoritative servers?
If you have specific concerns, please raise them here.
Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it.
Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often because employees believe in our mission. 1.1.1.1 helps with that.
I've been working a lot with open data and I have huge problem with Cloudflare ruining open internet with bot protection and such. The issue I have is that public data is public, be it bot or human.
I'm having real issue with you guys saying that your mission is to better the internet when you break shitton of floss apps that are essentially harmless and people who want to do harm, crawl at huge rates for commercial purposes break your systems like it's made of twigs. I'm saying this as a person who works on both sides and can't help but call you out.
So sorry unless you turn to non-profit I'm really not buying your "helping the internet" song.
As long as Cloudflare blocks that, it's hostile.
Maybe a way to register as spider with Cloudflare, and get a token that one passes in the header, with strict rate limits would be much better than the current solution of just showing captchas.
Are the gigabytes of junk billions of tiny requests or are there large requests as well?
Are you finding it more difficult than expected to manage the data?
I'm a 1.1.1.1 customer since you launched, thanks a lot for it.
Have seen edge traffic charts for major porn hosting companies and the out:in traffic ratio is like 97:3
What exactly do you mean by "user"? Can they query DNS traffic by IP address / subnet? Exactly what are all of the restrictions there?
EDIT: Is there a whitelist of things they can query by or do you simply trust them to be good citizens, have a binding legal agreement, all of the above?
Ding ding ding, we have a winner. If more people would realize this, we would have less data breaches. To get there, a data breach must become more costly for the companies.
"Specifically, APNIC will be permitted to access query names, query types, resolver location and other metadata via a Cloudflare API, that will allow APNIC to study topics like the volume of DDoS attacks launched on the Internet and adoption of IPv6."
I interpret "query names" as some values obtained from DNS queries hitting 1.1.1.1, e.g. "foo.example.com".
Is your answer to "What data do you provide to APNIC?" complete in the statement above?
Thanks for clarifying.
https://developers.google.com/speed/public-dns/docs/ecs
https://developers.google.com/speed/public-dns/faq#locations (when EDNS0/ECS isn't supported)
The tin foil hat brigade might suggest that this is deliberate to ensure that only what's served by cloudflare gets to be fast...
Conspiracy theory isn't a dirty word.
Speculation keeps people informed and alive.
It doesn't take much guessing to know who sent an anonymous DNS request for example.com to one of your countless PoPs if your CDN logs a HTTP GET request to www.example.com at the same location a few milliseconds later.
Our business is not about tracking people; it's about selling our service to businesses to make their web sites/APIs/applications faster and more secure.
Is there a guarantee that this will always be the case? Might there, in theory, be a point in the future where users' IPs are collected and stored?
Loving 1.1.1.1, btw.
To protect against that, could you commit not to log to disk any queries that come from fewer than N ips in 24 hours, and not to expose rare queries to APNIC or internally? (Not a demand, just brainstorming mitigation.)
It might also be fun to give an internal team access to the data you consider safe, and challenge them to dig up personal data from it.