Unconfigured Ad Widget

Collapse

Cloudflare DNS

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • #16
    remusrm
    Member
    • Jan 2013
    • 358

    I have been using it and it does seem faster then openDNS

    Comment

    • #17
      DRM6000
      CGN Contributor
      • Jan 2006
      • 5847

      How can I check to see if this is working?

      Comment

      • #18
        AreWeFree
        Veteran Member
        • Jan 2013
        • 4558

        Originally posted by DRM6000
        How can I check to see if this is working?
        nslookup

        Comment

        • #19
          SkyHawk
          I need a LIFE!!
          • Sep 2012
          • 23518

          Who cares if the time to resolve is 'fastest' when the resolved IP in the answer sends you to Ireland instead of San Jose for the actual content, if the site is on a CDN. The net-net is a huge performance penalty. If you care about true performance, do not use this crap. Some Apple App store downloads will go from minutes to hours, just for example. Cloudflare is not supporting EDNS0/ECS:

          Find answers to common questions about Cloudflare's 1.1.1.1 DNS resolver, including setup, privacy features, IPv6 support, and troubleshooting tips.

          EDNS Client Subnet
          1.1.1.1 is a privacy centric resolver so it does not send any client IP information and does not send the EDNS Client Subnet Header to authoritative servers
          And in my personal opinion - Matthew Prince is a hack, a pinko-commie type who cannot be trusted. He is pro hacker/pro anarchy, in my opinion. Only until very recently, he was giving up the contact info of security researchers who reported malware - to the hackers who hosted it.

          And in order to get the prestige IP 1.1.1.1 from APNIC, he had to agree to their 'research' deal and is giving up query data to them. That's China and North Korea if you aren't aware. He has the IP for 5 years, and if the commies don't like what he gives them, they take back the IPs. He says he wont give up your query logs, I don't believe him. I'd sooner believe Zuckerberg than this guy.

          The lack of ECS support is a non-starter, regardless of what you think about the other stuff. I personally like fast internet, not slow internet.



          Cisco Umbrella is cloud-delivered enterprise network security which provides users with a first line of defense against cybersecurity threats.


          The Catchpoint blog offers insights into Internet Performance Monitoring, market news, and the business itself. Don't miss out - sign up for updates today!


          Last edited by SkyHawk; 04-03-2018, 10:09 PM.
          Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

          Comment

          • #20
            Robotron2k84
            Senior Member
            • Sep 2017
            • 2013

            Once T-DNS (EDNS+TLS) gets going Extended DNS will be default anyway. No lightweight way to encrypt UDP traffic without a tunnel management server on each end.

            Comment

            • #21
              SkyHawk
              I need a LIFE!!
              • Sep 2012
              • 23518

              Originally posted by Robotron2k84
              Once T-DNS (EDNS+TLS) gets going Extended DNS will be default anyway. No lightweight way to encrypt UDP traffic without a tunnel management server on each end.

              https://ant.isi.edu/tdns/index.html
              Well do let us know 'once it gets going'.
              Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

              Comment

              • #22
                DRM6000
                CGN Contributor
                • Jan 2006
                • 5847

                Originally posted by AreWeFree
                nslookup
                Thanks.

                Comment

                • #23
                  Robotron2k84
                  Senior Member
                  • Sep 2017
                  • 2013

                  Originally posted by SkyHawk
                  Well do let us know 'once it gets going'.
                  Code is already there, patches for Unbound plus proxies and server code.

                  It's still sitting in RFC, maybe it will go, maybe it won't, but it's much more elegant and efficient than DNSCrypt or any of the other tunnel hacks and its end to end.

                  Got any better solutions?

                  Comment

                  • #24
                    SkyHawk
                    I need a LIFE!!
                    • Sep 2012
                    • 23518

                    Originally posted by Robotron2k84
                    Code is already there, patches for Unbound plus proxies and server code.

                    It's still sitting in RFC, maybe it will go, maybe it won't, but it's much more elegant and efficient than DNSCrypt or any of the other tunnel hacks and its end to end.

                    Got any better solutions?
                    I stick with what works, I don't reinvent the wheel - that is for younger folks. I have seen stuff sit in RFC for 20 years and never see the light of day in the real world, so I'm not holding my breath on some wonderboy come lately idea. If it flies, it flies. If it doesn't, it has plenty of company on the shelf where RFC ideas go to die.

                    In the mean time, as in right now today - no way no how do I use some anycast DNS resolver that doesn't support ECS, no matter who offers it.
                    Last edited by SkyHawk; 04-04-2018, 10:58 PM.
                    Click here for my iTrader Feedback thread: https://www.calguns.net/forum/market...r-feedback-100

                    Comment

                    • #25
                      Robotron2k84
                      Senior Member
                      • Sep 2017
                      • 2013

                      QUANTUMDNS and MORECOWBELL have proven unencrypted DNS is a liability. In that regard it is already broken and no-longer works.

                      Tunnels only get you privacy to the next hop, everything else is your *** hanging out in the open for all to profile.

                      Comment

                      Working...
                      UA-8071174-1