Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Read the announcement: https://blog.cloudflare.com/announcing-1111/ "APNIC's research group held the IP addresses 1.1.1.1 and 1.0.0.1. While the addresses were valid, so many people had entered them into various random systems that they were continuously overwhelmed by a flood of garbage traffic. APNIC wanted to study this garbage traffic but any time they'd tried to announce the IPs, the flood would overwhelm any conventional network.

We talked to the APNIC team about how we wanted to create a privacy-first, extremely fast DNS system. They thought it was a laudable goal. We offered Cloudflare's network to receive and study the garbage traffic in exchange for being able to offer a DNS resolver on the memorable IPs. And, with that, 1.1.1.1 was born."



Have they discussed what this means in terms of the privacy promises? What "garbage traffic" does APNIC have access to in order to study?


HA failover pings that get routed rather than being sent to their peer, captive portal requests that no longer exist. Things of that nature.

There is a lot of documentation, Cisco being one of the primary at-fault companies, that uses 1.1.1.1 for all kinds of various internal configuration.

Given hundreds of thousands of devices configured with 1.1.1.1, even a simple misconfiguration on just 10% of those is a lot of garbage traffic.


I think that's part of the point of all this - to find out what all that garbage traffic is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: