Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can they enforce DNS companies (ISP, cloudflare etc) to block these domains globally if they want to?


Cloudflare's DNS actually hasn't worked with archive.today for >5 years, due to the site returning bad results in response to Cloudflare not sending EDNS subnet info. HN comment from someone at Cloudflare: https://news.ycombinator.com/item?id=19828702

> Archive.is’s authoritative DNS servers return bad results to 1.1.1.1 when we query them. I’ve proposed we just fix it on our end but our team, quite rightly, said that too would violate the integrity of DNS and the privacy and security promises we made to our users when we launched the service.

> The archive.is owner has explained that he returns bad results to us because we don’t pass along the EDNS subnet information. This information leaks information about a requester’s IP and, in turn, sacrifices the privacy of users. This is especially problematic as we work to encrypt more DNS traffic since the request from Resolver to Authoritative DNS is typically unencrypted. We’re aware of real world examples where nationstate actors have monitored EDNS subnet information to track individuals, which was part of the motivation for the privacy and security policies of 1.1.1.1.


This was fixed/changed at some point. I use Cloudflare's DNS and it works fine for me.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: