zlacker

[parent] [thread] 6 comments
1. nobody+(OP)[view] [source] 2019-10-04 06:30:15
A very silly one at that given their reasons for not resolving archive.is are quite rational and on the contrary makes me want to swap google's DNS servers for theirs.
replies(2): >>cnst+w5 >>tambre+d6
2. cnst+w5[view] [source] 2019-10-04 07:50:04
>>nobody+(OP)
What exactly do you use DNS for? If it's to subsequently make a HTTP and/or HTTPS request, then your full IP address (and not just a /24 subnet) will be leaked to the very same parties anyways.

Even if they eventually make DNS encrypted, even if encrypting TLSv1.3 SNI work properly (and both of these are pretty big ifs, BTW), the IP addresses will still leak, always, and with a much higher precision anyways. So, this we-don't-do-ECS-because-privacy is hardly a rational statement on Cloudflare's part in the end — it merely breaks the performance of their competitor CDNs without any real privacy angle.

replies(1): >>zamada+3r
3. tambre+d6[view] [source] 2019-10-04 07:58:04
>>nobody+(OP)
> their reasons for not resolving archive.is

They do solve archive.is. But archive.is's DNS servers have been configured to return bogus answers to queries from Cloudflare's servers.

replies(1): >>nobody+nm
◧◩
4. nobody+nm[view] [source] [discussion] 2019-10-04 11:59:55
>>tambre+d6
Not cloudflare servers in particular. They demand EDNS(optional by design) which cloudflare does not support due to privacy risks.
replies(1): >>jlokie+lp
◧◩◪
5. jlokie+lp[view] [source] [discussion] 2019-10-04 12:23:52
>>nobody+nm
From https://news.ycombinator.com/item?id=21155852

> Archive.is does not block all requests lacking EDNS. They specifically block requests coming from Cloudflare's datacenters.

replies(1): >>nobody+1w
◧◩
6. zamada+3r[view] [source] [discussion] 2019-10-04 12:36:26
>>cnst+w5
DNS isn't always run by the place the site is hosted and until the other 2 are implemented everyone along the lookup path can also see where you are going. Increasingly a destination IP is becoming less of a hint of what you are browsing to.

Whether you think that's enough to care about or not it's very different than the picture you painted.

◧◩◪◨
7. nobody+1w[view] [source] [discussion] 2019-10-04 13:15:50
>>jlokie+lp
Wow, what a bunch of not-so-smart people.
[go to top]