zlacker

[return to "Does Cloudflare's 1.1.1.1 DNS Block Archive.is? (2019)"]
1. koboll+S9[view] [source] 2021-09-11 20:48:04
>>jahnu+(OP)
Out of curiosity - not defending the behavior - what kind of problems could omitting EDNS cause? What is the steelman case for Archive.is here?

The author says Archive.is's claim that it causes problems is "questionable", but he doesn't mention what those purported problems are or address why they're illegitimate, so it's hard to evaluate whether that's accurate.

◧◩
2. judge2+Bj[view] [source] 2021-09-11 21:53:08
>>koboll+S9
To add, apparently another reason is that he believes using Cloudflare as your recursive resolver could lead to phishing[0]:

> the same entity which answers your DNS queries is able to issue SSL certs for any domain, so using CloudFlare DNS you never know whether you access the original website or a fishing one

Generally this is protected via certificate transparency+CAA records. If CF's CA were to issue a bad certificate, it'd be blocked by the browser and, should it get out, jeopardize the entire company, likely DigiCert as well given they cross-signed Cloudflare's issuing CA.

0: https://blog.archive.today/post/634795612966125568/when-will...

[go to top]