1.1.1.1 for Families
blog.cloudflare.com
blog.cloudflare.com
Edit: I missed this text:
> In the coming months, we will provide the ability to define additional configuration settings for 1.1.1.1 for Families. This will include options to create specific whitelists and blacklists of certain sites. You will be able to set the times of the day when categories, such as social media, are blocked and get reports on your household's Internet usage.
Regardless, I am still opposed to this service, and opposed to all forms of internet censorship and spyware. CloudFlare is already really bad for the internet, and this isn't helping their case.
FWIW, it seems like 1.1.1.3 doesn't block sites like Twitter where a lot of the kink community moved after Tumblr shut down.
It just seems obvious that making porn slightly harder to get to than disney.com is a smart move if you're a parent. Make it so that a typo in a URL doesn't splash hardcore porn in one click.
And sure there are lots of ways to accomplish this. Cloudflare is just providing one more and I personally like that. Even as a techie, I really hate doing network stuff at home and will be taking a close look at this at least after the configuration options become available.
I currently use AdGuard's DNS offering that blocks many surveillance IPs plus adult content. Will have to compare offerings.
I totally understand the critique of this from the political war zone they're diving into, but not from a "it's not perfect so it's stupid" perspective.
That's why you set up your router/pihole to do DNS hijacking. Any DNS request gets rerouted to the DNS server of your choosing.
Source: my dad did this on the home router.
> In the coming months, we will provide the ability to define additional configuration settings for 1.1.1.1 for Families. This will include options to create specific whitelists and blacklists of certain sites. You will be able to set the times of the day when categories, such as social media, are blocked and get reports on your household's Internet usage.
Also, re: “how they evaluate websites”—most websites explicitly opt into being considered “adult content” by these filters, either by submitting themselves to the filter, or by adding meta tags to their pages to declare either specific content warnings, or a category of some age-rating taxonomy (usually a country-specific one repurposed from that country’s film/TV rating system, but crawlers make do.) Unlike malware, “adult content” is not adversarial to the ecosystem it’s a part of.
I have my browser crash at least once a month when viewing such content.
What are police in your metaphor? Someone who has any conversation on policy?
And what’s with the “I don’t want to hear you complain, just go away if you don’t like it” attitude?
UK policing is built on community consent. Law enforcement is part of their duty, but so is having a discussion about what the community want’s enforced and how.
It’s not unusual for UK police to kindly ask you to not do something and go home, and only escalate to handcuffs if you continue to ignore them.
Since UK police can be so nice, is there a difference between UK police telling you to stop doing something, and a HN person doing the same online?
You can absolutely tell a police officer to piss off, and if you’re not doing anything illegal there’s nothing they can or will do.
Police officers don’t just get involved in crimes. They also have a huge role in discouraging asocial (but completely legal) behaviour. The idea that policing can only be done with enforcement and a stick is completely false.
With regards to your point regarding a HN person on the internet. They’re on the internet, not in front of me, that’s a much bigger factor than if they’re a police officer or not.
The web context is our context though.
And there is a question about what policing is without enforcement. The reason why police can scare people with mere conversation is because they're not sure about the law in any situation. I presume that an attitude of "I know the law" is a dangerous play anywhere in the world with the police.
It's also possible to get people to do things because they respect the authority of the officer. "If this cop says I am being an asshat and should stop, maybe I am being an asshat and should stop." This is what people mean when they talk about soft power.
Blindly following what the authority says is a gateway behaviour to fascism.
Regardless, this does not seem like a soft power and it is going to happen in the police of any counrty. If you do not follow what they said you are going to be in trouble after all. And no matter the country they DO rely on the threat of violence, this is the whole point of the police, their words are backed with a legal (or illegal) threat of violence.
Compare it to some random citizen telling you not to talk loudly because their child is sleeping. They do not have a state-backed ability to cause violence, and if they did try to attack you, you could go to the authorities.
If you want to get into semantics, consider that Congress or Parliament (or whatever) are supposed to be that bilateral conversation that formulates policies for police to enforce. So in that respect, you could say they too are "policing" like OP is here.
There is no "enforcement" component to what cloudflare is doing. You can either use it or don't.
Now, you might say children are oppressed when their parents enforce these restrictions on them, but I'd say back that my children live under an oppressive government (me). They don't have the requisite life experience to participate in a high-stakes decision making democracy yet.
I was just talking about you, and what I see as "No, _you_ are the moral policeman." ddevault is going to morally police you? With HN comments? Like having a conversation with the UK police, or Congress making laws?
It might not discriminate against gay people but it discriminates against child people (including people who have not moved out of their homes yet due to various reasons and are stuck in an ultra-conservative household)
> I find it absurd that some of the comments on this thread are implying that the act of blocking say a 2 year old from stumbling upon pornographic content is abuse.
I am pretty sure that they do not care about 2 year olds. More like they care about 13 or 16 year olds having censored internet access.
I'm genuinely confused as to where your complaint is coming from. Isn't this Cloudflare DNS server "opt in" for families? Why would voluntary filters be censorship? Censorship is more "top down" (e.g. government) that you can't opt out of.
Likewise, I just "opted into" into NextDNS a few days ago to block ads so I didn't have to set up a Raspberry Pi-hole. Is NextDNS "censoring" ads? Well yes, because that's what I want.
It is entirely commonplace for a family to impose restrictions on its children — anything less is neglect.
It also seems very strange to deem not restricting information as neglect. Why not just have a conversation about them as to why they shouldn't do whatever you want them not to do? Advice doesn't breed distrust, but censorship and other regulations do.
She's 2.5. Lots of things in her life aren't voluntary. It's my responsibility and choice to keep her safe. You can let your kids watch all the lemon parties they want but I'll just keep that stuff blocked.
If your 2.5 year old is mature enough to manage that, then yeah, maybe they ought to be able to have unfettered internet access, too.
Think of it like a child safety lock: you only need them until they can figure them out. By the time they know how they work, you can have a conversation with them about being safe around the house.
On the matter of ethics, while I don't feel inclined to filter the world away from older kids, I'm firmly believe you're wrong. There's nothing unethical about making choices for your kids until they're old enough to make informed choices. The amount of garbage online (revenge porn, sexual degradation of women, red pills) makes easy for kids to find bad information at an age where they can't process is correctly. Parents determine what age that is because that's their role and it's entirely situational.
Found your issue, go and use an adblocker (or dns-based adblock filtering)
> revenge porn
Indistinguishable from normal porn
> sexual degradation of women
Just because you are not into extreme bdsm it does not mean that it is garbage.
> red pills
Your 2.5 year olds won't be able to read it. If they somehow find a way then you simply have to explain to them why you think that it is wrong.
The only "bad information" are straight up lies.
I don't think that kids watching explicit content is something they should be doing, but treating them like property rather than someone you can genuinely influence the views of in a positive way is incredibly destructive.
Why not install an ad-blocker on the tablet and be done with it? If she's 2.5 and for some reason going to explicit sites with intention, you should be fast-tracking her to private schooling, not installing filters on information.
> not installing filters on information.
you're literally advocating opposing viewpoints in the same phrase
What's more important is protecting children (think <10) from coming across pornography accidentally while browsing the internet and looking at kid stuff. It's not only fairly well-accepted by society but in many jurisdictions, allowing children to see pornography is considered neglect.
I think you need to speak to more parents.
For a DNS service that could become a kind of LetsEncrypt of DNS, its use case will be a little bit of everything. Cloudflare already has to make moral and social policing decisions, but then again, the bigger your company, the more morally interesting decisions it has to consider. This is especially the case when you're the kind of infrastructure company that serves the world.
Moral filters are going to be about the enforcement of moral norms. Are sites about condom usage, abortion, STD's, premarital sex, and homosexuality an adult topic? Are race relations an adult topic? Are shootings an adult topic? Is this going to be the kind of filter you lift at precisely the age of 12?
There's naturally going to be a lot of questions about how a filter is going to interact with situations, because it's going to be Cloudflare's vision of the web. In my view, DNS settings are often things other people set up for you and you don't really think about it.
I think you're partially right but kids don't need to understand the underlying reasoning, they just need to be told what to do. When I was in school, everyone used PHP-based proxy sites to access restricted material on the school network. Nobody had a clue what a "proxy" was or how it worked, they just knew that's what they had to Google to get at whatever they wanted to get at.
Kids these days are the same. They don't need to know what "DNS" is or how a VPN works, they just need to know that a friend told them to look for a VPN app on the app store.
> Are sites about condom usage, abortion, STD's, premarital sex, and homosexuality an adult topic? Are race relations an adult topic?
The question isn't so much "are these adult topics" as "are these topics parents will want small children to encounter on the internet" and I'd say that's a definite "no".
That isn't to say small children shouldn't learn about them, they'll definitely need to be taught, however I don't think that many parents would be comfortable with their children being taught by whatever resources their child happens to stumble upon.
And to be clear, I'm not saying that homosexuality or interracial relations are morally any different to regular relationships, I'm saying that internet material isn't likely to be suitable for educating small children. It'll be very easy for them to stumble across material that's overly sexual in nature, racist or homophobic.
FWIW I come from a country where sex education is covered fairly well by both primary and secondary school curricula, which may colour my response here.
> Are shootings an adult topic?
That one's difficult and depends on the specific cultural norms you live under I think.
> Is this going to be the kind of filter you lift at precisely the age of 12?
That's a decision for the parents.
1. Protecting my child sufficiently that they will grow up to be a relatively non-traumatized adult.
2. Teaching them about life
3. Protecting others from my child
Obviously #1 and #3 are in tension with #2, as harm is part of life, and natural consequences are great teachers.
In public school where I live, the internet is required for at least some of their work starting around 2nd or 3rd grade. No reasonable filter is going to let me give them otherwise unfettered access to the internet at that age. I find having the computer in an area where I can see the screen is good. It's possible that 1.1.1.3 might be helpful in making it a bit harder for them to stumble something while my back is turned for 2 minutes cooking dinner or helping out a sibling.
Obviously there are limits to what I can do. I have one kid with PTSD that we closely monitored internet usage for at home, told the school she ought not be on any internet connected evice in class, but still managed to cyberbully a classmate to the point where the victim withdrew from school by editing a shared google-document during classtime.
Another kid was shown some fairly extreme pornography in 2nd grade by an older student who had a cell-phone.
This is a fantastic idea - I can't believe I never thought of this ...
I'm sorry to hijack, but about the nextDNS product ... how do they determine who is a paying customer ? Do you have to log your IP-space with them ?
I also have no idea, in the context of modern web browsing, how large or small 300,000 DNS queries per month is[1]. It seems quite large to me - as if even my entire household would never possibly produce 300k DNS queries each month ... but perhaps I underestimate how many queries modern web pages produce ?
Can I run my own very simple local resolver and use NextDNS as my upstream such that only one of my systems (my DNS server) is talking to NextDNS ? This would allow me to use NextDNS globally without them tracking me all over the world ...
They determine which configuration to use for you by the endpoint you've configured, whether it's the app or using their specific endpoint.
FWIW, here at home, my DNS servers are reporting a combined total of ~138k (from 21 unique clients) over the last (rolling) 24 hour period.
(Of course, mine probably isn't indicative of a "typical" American household when it comes to browsing habits and such.)
I just looked at my NextDNS stats dashboard for the previous 6 hours and it says 5900 queries. I was surprised by that high number. The intuition is to count in terms of manual clicks on urls but the part I underestimated is how "chatty" many web pages are with Javascript (e.g. analytics, ads, etc). In my case, I see about 1000 hits in 6 hours to just 2 urls: msh.amazon.com, content.googleapis.com.
Based on being awake 16 hours a day over 30 days, I extrapolate ~540,000 queries per month. This is for 2 people with no kids at home at the moment.
If my modest internet usage is ~540k queries per month, I'm guessing NextDNS definitely did the spreadsheet modeling to come up with 300k threshold so most people easily pass it after mid-month and therefore enticed to pay for the service to continue the ad blocking. When I get to that point, I'll re-evaluate the idea of setting up a Raspberry Pi-Hole. I really don't want to mess with hardware.
Maybe if I'm more aggressive with a local "hosts" file to locally block more sites to 127.0.0.1, I can drastically cut down the number of DNS queries hitting NextDNS.
I have it running in a vm on a machine that is on 24/7 anyways.
I installed dietpi as the OS and selected pihole in its install options. 10 min later it's up and running. No issues!
Which may start to show why this is such a bad idea.
Regardless of how you see it, it's literally doing that.
Sure, it may not be the most grievous occurence of it, but that doesn't change the fact that it is, in fact, policing.
https://en.wikipedia.org/wiki/List_of_fallacies#Red_herring_...
Fallacy of relative privation (also known as "appeal
to worse problems" or "not as bad as") – dismissing an
argument or complaint due to what are perceived to be
more important problems. First World problems are a
subset of this fallacy.[95][96]
Only if you hate language and you purposely warp definition of commonly understood words and concepts to support your conclusion or ideology.I'm fairly certain this is what you're attempting presently.
Raising children by imparting morals, and providing structure and constraints is NOT authoritarian policing. Those are two different things.
I (and they) said policing. You can call it authoritarian or you can choose to refrain from that. It's still policing.
And though children certainly are humans (who actually claims otherwise?), they are not endowed with the same societal rights and responsibilities that adults are.
Humans can dissent, and have certain natural rights. If you agree that children are humans, then coercing them into something without consent is policing. While you can say that you've got the right to partake in policing, there doesn't seem to be a case for the idea that it isn't policing.
Most people understand this distinction instinctively. You, on the other hand, have some trouble there.
Plenty of people understand things instinctively. This is why stoning women to death still happens in certain parts of the world, and was also the argument for owning slaves. Just because something is "instinctive" for certain people doesn't mean that it's correct.
Changelog on this comment: removed a bit of personal information because I figure making myself easier to identify isn't worth it for a message board argument.
I personally wouldn't use any of the filtered ones, but lots of companies provide free resolvers with blocklists like these. I don't really see how anyone could be fine with the existing 1.1.1.1 resolver but have a problem with this announcement. (If they were also against the original 1.1.1.1 resolver, then I can at least understand their being opposed to all of them.)
$ host www.sex.com
www.sex.com is an alias for dmz01.cdn.live.
dmz01.cdn.live has address 15.222.131.21
$ host www.sex.com 1.1.1.3
Host www.sex.com not found: 5(REFUSED)
$ host www.nothing 1.1.1.3
Host www.nothing not found: 3(NXDOMAIN)
I hadn't noticed a DNS REFUSED response before. That seems reasonable, although a web browser's error message doesn't differ between REFUSED and NXDOMAIN.NXDOMAIN is a valid response that won't pass a signature verification.
REFUSED just means that DNS Server can't or won't provide a response at this time.
I'm looking forward to when the customization options are available as an alternative/addition to OpenDNS. The morality police argument doesn't seem to hold much water if they are going to let you whitelist or blacklist anything you want or turn categories on or off.
Do you have problems with connecting to public wifi when running the app? I've noticed setting the DNS locally on a computer throws off the local library wifi that has the captive page that makes you agree to terms before proceeding.
Yesterday it was http://www.futureus.com/
battle.net comes to mind... that always connected, even if my providers DNS failed.
Regardless, it is an interesting service. I would imagine that corporations, who have the tech support and need, will find this more useful than non-technical families.
Examples:
https://www.vpn-accounts.com/blog/how-to-open-blocked-sites-...
https://www.jakarta100bars.com/2019/10/porn-websites-blocked...
Porn really is the driver of many technical innovations. Home movies and online financial transactions, for example, wouldn't be where they are today if people weren't so dedicated to watching other people smush.
If you care about privacy, I recommend running your own resolver with Unbound, and block ads/tracking/malware/adult content etc. using Pi-Hole.
* Just porn * Erotic content (eg lingerie shops) * Any sexual content (eg Wikipedia article on anal sex) * Or also e.g. medically relevant (sex ed, abortion provider sites, ...) * Gore, violence, videos of people dying ... * Information on or shops for drugs * Content on terrorism, weapons, manuals to build bombs * Content on Al Qaeda, Scientology and other extreme/dangerous religious stuff * ...
?
But blocking your kid from having access to sexual education does not sit right with me, and I can imagine how they might not have proper sex ed at school or not be comfortable discussing it with their parents.
The average American seems happy with plenty of violence, but any nudity at all is strictly off-limits.
I can't write "average European" for this, but most would prefer less violence and accept more nudity. There's still plenty of difference within Europe.
There are also websites that are for teenagers, which some parents would be uncomfortable with -- LGBT support and advice sites for example, or even general sex education.
You can't write "average American" for this, either.
Europe doesn't, and so a film can receive different ratings in each country.
The first film I found searching for a good example of this, Eight Grade, is rated suitable for children in Luxembourg, Spain, Sweden etc, and 15 year olds in the UK and Ireland -- with the UK possibly more concerned with the language than the sex.
The US rates the film R, so 17.
https://www.imdb.com/title/tt7014006/parentalguide?ref_=tt_s...
Here's the BBFC (British Board of Film Classification) listing for it: https://bbfc.co.uk/releases/eighth-grade-2018
The ratings info says this:
> Language
> There is strong language ('fk'), as well as milder terms (for example, 'dick', 'shit', 'goddamn', 'God', 'Jesus Christ').
> Sex
> There is a scene in which a web search shows a woman explaining a sexual technique, accompanied by strong sex references.
> There is also a scene in which a young teenage girl suffers a panic attack, as well as one in which an older teenage boy tries to pressurise a younger teenage girl into having sex; however, she does not agree to this.
I don't know enough about BBFC to say which of these they place more importance upon.
(Eighth Grade is a very good film btw, and A24 are currently my favourite film production / distribution company).
It's DNS level filtering so you can't handle specific content on sites at this level of the network stack.
From my quick poking of the service, it appears to filter things like sex shops, but not sites that do host mixed content. (i.e. Reddit, Imgur, etc)
To your question regarding health issues, plannedparenthood isn't blocked etc.
I sadly don't know a ton of terrorist URL's so I can't check them.
jihadology.net isn't blocked
https://thewire.in/uncategorised/nia-jihadology-jihadi-websi...
"The National Investigation Agency (NIA) believes that a US-based blog that collects and analyses communications from terror organisations and is used extensively for academic research was one of several “jihadi sites” that was used to radicalise a young person from West Bengal and encourage him to become an ISIS member"
Most terrorist recruitment happens on sites like instagram, facebook, tiktok, etc anyway.
https://www.irishcentral.com/news/real-ira-other-dissidents-...
"The Police Service of Northern Ireland has said that it is investigating reports that social networking sites are being used to recruit children - some as young as 13 - into dissident Republican groups.
The news comes as Northern Ireland faces an upsurge in activity by dissident Republicans. Last month, for the first time in over a decade, a British soldier was killed in Northern Ireland."
Acknowledging the existence of GLBTQ+ people is apparently "inappropriate" to them.
* Fixed.
dig +short glaad.org @1.1.1.3
23.185.0.11. How the block list was initially populated
2. What clear and objective rules govern which sites should and shouldn't be included
3. Who determines those rules, and what is the process for changing the rules
4. How often are those rules proactively reviewed or changed
5. How is the block list verified as following those rules
6. What the process is when a false positive or false negative is found, reported either internally or externally
Maybe I missed it but I didn't see any of this information posted on the site.
$ dig @1.1.1.3 reddit.com
reddit.com. 298 IN A 151.101.65.140
And the largest advertising and tracking site. $ dig @1.1.1.3 pagead2.googlesyndication.com
pagead2.googlesyndication.com. 262 IN CNAME pagead46.l.doubleclick.net.
pagead46.l.doubleclick.net. 262 IN A 172.217.7.2Edit: Someone below added more info on this for anyone curious: https://cleanbrowsing.org/articles/block-youtube-comments-re...
It's really shameful; they need to stop the hypocrisy and either become a content-neutral host and own the consequences, or censor arbitrarily, and own the consequences. They're trying to have their cake and eat it too, and it's entirely unfair, much in the same way shadowbanning is.
It's a realistic approach to navigating the real world where there are bills to pay, Reddit Gold isn't going to cut it, and advertisers don't want their brand associated with random NSFW/NSFL content.
I don't get this obsession with browbeating every content provider not living up to these Stallmanistic extremes.
Reddit should not have to give up any sort of protection for allowing advertisers to not have their ads show up on certain subreddits, or censoring Nazis.
If Reddit of all sites is what we're calling shameful, there is no hope.
They have tons of porn. They just don't have tons of political variation.
In fact, iirc every single subreddit is “Not Safe For Brand” by default. How does that jibe with trying to avoid “political variation”
Subs get whitelisted for advertising with it. That’s it.
Signaling to advertisers something is a safe choice for ads or not is not censorship, and it’s not unreasonable.
The kind of content that's quarantined (because nsfb is an advertising thing) isn't "political variation." They're absolute cesspools hate, doxxing, threats of violence. Were these communities gathered in a physical room I would genuinely feel unsafe.
Reddit actually has a good amount of political variation and opinion. A staggering amount of Redditors are authoritarian conservatives by their opinions given how often people say Reddit is full of bleeding-heart liberals, but they would never associate themselves with the Republican party or "conservatives".
people here aren't demanding that reddit (and other sites) let people post whatever they want. they are asking for sites of a certain size to actually be neutral as a condition of safe harbor protections. to me this seems pretty fair. if you have millions of users and exercise editorial control over the content, you should be on the hook for what's left.
I think you are confusing NSFB (brand_safe) with quarantining.
Quarantining is used for subs which are borderline being banned. Subs with frequent racism, subs with very fringe ideas (like 9/11 conspiracy theory). You need to login to view them, so they don't turn up in Google search etc. Example: https://www.reddit.com/r/911truth (try that link in a private browsing window if you are logged in to Reddit)
I don't think the brand_safe field is exposed in the public API any more (I presume it probably still exists behind the scenes). But my understanding of what it means, it is supposed to mark subs which are not advertiser-friendly. For example, subs that discuss controversial topics such as politics or religion. Anonymous users can view these subs fine and they turn up in Google. But, Reddit will display their own ads instead of third-party advertiser ads. Most companies don't want their advertising to pop up in the middle of a debate about whose religion is more correct, or what the Bible/Quran/etc has to say about sexual morality, it is bound to create a bad association in someone's mind.
But, the growing availability/awareness/popularity of such DNS-driven solutions should incrementally increase the likelihood that firms like Reddit choose to segregate/label their sections by IP address.
Gotta get the ball rolling somehow!
$ host www.stormfront.org 1.1.1.3
www.stormfront.org has address 104.22.6.143Reddit isn't a porn site in the sense that if you go to "reddit.com", you're automatically shown porn. It's a diverse site that has adult content areas.
Reddit has profile settings like:
[ ] NSFW content hide images for NSFW/18+ content (Don't show thumbnails or media previews for anything labeled NSFW)
[ ] I am over eighteen years old and willing to view adult content (required to view some subreddits)
Needless to say, these are implicitly off or a visitor to the site who does not have an account.
Still, Reddit will not prevent visitors from seeing "adult content" in a more general sense:being exposed to adult discussions that can touch on any sort of topic from any angle.
If we're talking about protecting kids, I think a whitelist of allowed sites will be better than a blacklist, which is intractable.
and
>DNS isn't appropriate for filtering porn or ads
So, if you're trying to filter porn out, dns doesn't work because of sites like reddit.
For kids, a whitelist of approved domains should work. If you don't think Reddit should be on it, you don't add Reddit. No brainer.
The problem with DNS is mobile devices; your custom DNS runs only in your own intranet, not whatever devices connect to.
Undoubtedly there are hacks for that, but they are mucky compared to the pure DNS solution, which can be perpetrated entirely externally to devices.
Do you do all of the your movement with a car? No, it doesn't work well for very short or very long distances. That doesn't mean it doesn't work.
Hostname based blocking can never be accurate.
Fine-grained filtering of content within Google domains doesn't seem tractable in any way shape or form.
Btw I see some resemblance with google here. Initially they were all “do no harm”. Only after they captured the whole market we realized we shouldn’t have succumbed to free shit. These guys are following the same model. Give free shit and get traffic, even though they lose money. They themselves claim they only charge businesses not consumers.
Where do you set up the filtering or accountability? With so many connected devices in houses I've found DNS is common denominator. It's perhaps the easiest to circumvent, but it covers all the mobile devices, gaming consoles, etc. that are connected to my home network.
My kids are too young to circumvent things, but if they start doing that I'll be equal parts proud and preparing for a loving talk.
It prevents accidental access while making it easy for anyone who is sufficiently inclined to circumvent it.
> YouTube Restrict works by re-mapping YouTube IP addresses to the CNAME restrict.youtube.com (or restrictmoderate.youtube.com). It means that instead of visiting YouTube at their normal IP addresses, you will re-route the traffic to a special load balancer provided by Google that will block access to non children friendly videos.
I did not know about that
https://cleanbrowsing.org/articles/block-youtube-comments-re...
Also the canary domain only works if Firefox is not explicitly set to use DoH. If using DoH has explicitly been set by the user than the canary domain has no effect.
Edit: Some testing seems to show that Mozilla has lumped these in with a select few others and will not bypass them when DoH is the default instead of explicitly selected even though they don't report the canary domain as an error. It will bypass them when DoH is explicitly enabled.
At least with a word like Apple, the capital "A" designates it as a proper noun and can easily be recognized as a brand or company name in most cases.
Our company's captive portal still takes you to 1.1.1.1
The project is from IBM and few other companies, and includes threat data from major players in the security space
Https://quad9.net
However, it does not seem 1dot1dot1dot3.cloudflare-dns.com works yet.
Also, how are they going to make this configurable like they write? Tie the configuration to the IP address? What if someone has a shared or dynamic IP address?
Likely the same way as opendns, nextdns, and a ton of other dns providers who do the same. It's for home use - if it doesn't fit your home use case, then use another filter.
As a kid I would have figured out a way to get around this, and that would have been part of the fun, but, this option adds more choice to the market and that is a good thing.
Block advertising this way, and one hits the further problem that one often wants to operate based upon more than just the domain part of the URL. Or one wants to do things like make temporary redirects to static placeholder images. Fiddling with DNS service cannot achieve these.
In the past we used OpenDNS for DNS filtering and it worked pretty well. Then they were purchased by Cisco and the prices went up and functionality went down. If CloudFlare can offer some management capabilities (ie. whitelist / blacklist) we would switch in a minute. I can't wait to see how this product matures.
I don't see any IPv6 endpoints published for the 1.1.1.2 and 1.1.1.3 equivalents, do they exist?
For malware:
* 2606:4700:4700::1112
* 2606:4700:4700::1002
For malware and adult:
* 2606:4700:4700::1113
* 2606:4700:4700::1003
Do you filter Wikipedia as "adult content"? Certainly one of these[1] images qualifies under most standards?
1: NSFW https://en.wikipedia.org/wiki/MediaWiki:Bad_image_list
Now all that being said, this is a decent enough way to at least block the obvious stuff like Pornhub. For some, that might be good enough.
No pages on the English Wikipedia use this file (pages on other projects are not listed).
... so why do these images persist in the wikipedia ?
But I can't answer your question.
Stormfront is not.
So. That's pretty gross.
I would imagine they automatically crawl and do some basic keyword matching, so false positives are expected. Curious about stormfront though.
Running an extra internal dns server just to do 'last chance' filtering is extra maintenance i don't want to have to do. I'd much rather let cloudflare do that.
The cloudfare site calls googletagmanager.com, marketo.com, linkedin.com, and bizible.com. Do any of these sell user data or support targeted advertising?
Sure you can change your country at an individual level but why create a problem in the first place.
As we can see in this thread, there's already been a mistaken block - expect many, many more of these to come.
They will be chasing their tail between their legs for years to come, and they'll only get bad PR from this.
It'll be dead and buried in a year after a shit storm hits reddit
They don't understand the political world they just entered.
Or the amount of work this will take.
They have to take a stance so many political issues from here.
From a company that prided itself on non-censorship (Minus two cases). This is easy, twice they have broken and been hated for it.
Now, the twitter campaigns that will smash them on everything, in a sustained way.....
Whats changed? did Matthew prince suddenly give up on free speech? or is it just another way to identify a target demographic.
Edit: Ok, I guess not. But how?
On the other hand, it might lead to the next generation of children who kick their technical careers off by figuring out how to circumvent censorship and that despise the companies enforcing it.
Maybe not, though.
https://twitter.com/SarahJamieLewis/status/12453743777570406...
$ host www.glaad.org 1.1.1.3
Using domain server:
Name: 1.1.1.3
Address: 1.1.1.3#53
Aliases:
Host www.glaad.org not found: 5(REFUSED)
Looks like some things don't change. This is the kind of shit Peacefire was exposing back in the 1990s: Completely innocuous GLBTQ+ content being labeled as "inappropriate" by content censors. And Cloudflare doesn't even have the figleaf excuse of having a financial incentive to dance to the tune of the kinds of people who think GLAAD is somehow inherently bad.Also:
$ host www.peacefire.org 1.1.1.3
Using domain server:
Name: 1.1.1.3
Address: 1.1.1.3#53
Aliases:
www.peacefire.org is an alias for peacefire.org.
peacefire.org has address 65.181.125.58
peacefire.org mail is handled by 10 mail.peacefire.org.
This verges on the comedic. Host www.thetrevorproject.org not found: 5(REFUSED)
That's a site for teenagers with "trained counselors are here to support you 24/7. If you are a young person in crisis, feeling suicidal, or in need of a safe and judgment-free place to talk, call …"It's also exactly the type of site that's first on the list of examples of what not to block, by any privacy / anti-censorship group. It should have been an easy test before launching.
There's a site run by the Open Rights Group in the UK, recording incorrect blocks made by ISP-provided "parental control" filters.
They already check against OpenDNS, so I assume they'll add 1.1.1.3.
There are lists of overblocked domains: https://www.blocked.org.uk/stats
$ host stormfront.org 1.1.1.3
Using domain server:
Name: 1.1.1.3
Address: 1.1.1.3#53
Aliases:
stormfront.org has address 104.22.7.143
stormfront.org has address 104.22.6.143
stormfront.org has IPv6 address 2606:4700:10::6816:68f
stormfront.org has IPv6 address 2606:4700:10::6816:78f
stormfront.org mail is handled by 10 dc-c5d58999adca.stormfront.org.
There seems to be a distinct political stand being made here.They must be using a blocklist they never vetted properly.
Also, I'm not the only one to notice this:
https://web.archive.org/web/20200401164820/https://news.ycom...
% host www.glaad.org 1.1.1.3
Using domain server:
Name: 1.1.1.3
Address: 1.1.1.3#53
Aliases:
www.glaad.org is an alias for live-glaad.pantheonsite.io.
live-glaad.pantheonsite.io is an alias for
fe1.edge.pantheon.io.
fe1.edge.pantheon.io has address 23.185.0.1
fe1.edge.pantheon.io has IPv6 address 2620:12a:8000::1
fe1.edge.pantheon.io has IPv6 address 2620:12a:8001::1