1.1.1.1: Cloudflare's New DNS Attracting 'Gigabits Per Second' of Rubbish (zdnet.com)
An anonymous reader quotes a report from ZDNet: Cloudflare's new speed and privacy enhancing domain name system (DNS) servers, launched on Sunday, are also part of an experiment being conducted in partnership with the Asia Pacific Network Information Center (APNIC). The experiment aims to understand how DNS can be improved in terms of performance, security, and privacy. "We are now critically reliant on the integrity of the DNS, yet the details of the way it operates still remains largely opaque," wrote APNIC's chief scientist Geoff Huston in a blog post. "We are aware that the DNS has been used to generate malicious denial of service attacks, and we are keen to understand if there are simple and widely deployable measures that can be taken to mitigate such attacks. The DNS relies on caching to operate efficiently and quickly, but we are still unsure as to how well caching actually performs. We are also unclear how much of the DNS is related to end user or application requirements for name resolution, and how much is related to the DNS chattering to itself."
The Cloudflare-APNIC experiment uses two IPv4 address ranges, 1.1.1/24 and 1.0.0/24, which have been reserved for research use. Cloudflare's new DNS uses two addresses within those ranges, 1.1.1.1 and 1.0.0.1. These address ranges were originally configured as "dark traffic addresses", and some years ago APNIC partnered with Google to analyze the unsolicited traffic directed at them. There was a lot of it. "Our initial work with it certainly showed it to be an unusually strong attractor for bad traffic. At the time we stopped doing it with Google, it was over 50 gigabits per second. Quite frankly, few folk can handle that much noise," Huston told ZDNet on Wednesday. By putting Cloudflare's DNS on these research addresses, APNIC gets to see the noise as well as the DNS traffic -- or at least "a certain factored amount" of it -- for research purposes.
The Cloudflare-APNIC experiment uses two IPv4 address ranges, 1.1.1/24 and 1.0.0/24, which have been reserved for research use. Cloudflare's new DNS uses two addresses within those ranges, 1.1.1.1 and 1.0.0.1. These address ranges were originally configured as "dark traffic addresses", and some years ago APNIC partnered with Google to analyze the unsolicited traffic directed at them. There was a lot of it. "Our initial work with it certainly showed it to be an unusually strong attractor for bad traffic. At the time we stopped doing it with Google, it was over 50 gigabits per second. Quite frankly, few folk can handle that much noise," Huston told ZDNet on Wednesday. By putting Cloudflare's DNS on these research addresses, APNIC gets to see the noise as well as the DNS traffic -- or at least "a certain factored amount" of it -- for research purposes.
You are P0wned!
Suckers gonna get fucked IN THE MOUTH, by definition.
Oh, this was their plan all along. Heh, well, I hope it doesn't turn out to be a mistake that to have hired people who don't understand DNS...
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
I would be very interested in following the research they are undertaking. Anyone know how/where this will be published?
The summary repeatedly calls this an 'experiment' - does that also indicate that at some point, these nameservers will be disabled / changed / removed in the guise of 'science'? Since TANSTAAFL, I find it difficult to believe that even Cloudflare (who makes buckets of money in other ways) is just going to give away this service forever. I know, THEY'RE GATHERING DATA - if you're that concerned about the crap you post on the internet, you either need to re-evaluate your exposure or just cut your ethernet cable entirely....
Implement RFC 2827 and disconnect all peers who refuse to implement it - or refuse to disconnect peers who refuse to implement it.
Yes, might be messy for a little while.
Traffic to these addresses should be dropped at the earliest router possible. The 1.1.1.1 in particular is going to attract all sorts of traffic generated by systems configured with dummy IP addresses. Those tens of gigabits are going to increase the load on internet backbones, only to be dropped in the end. Cloudflare just needs to use some better IP addresses for the DNS service.
"yet the details of the way it operates still remains largely opaque"
Opaque to whom? Not to net admins and other people who understand DNS. If they're hoping Joe Schmoe will understand or care then they've got a long wait.
BCP 38.
It needs to be mandated globally.
Meh. Implementing RFC 3514 is far more useful, you could automatically disconnect all evildoers, not just threaten to disconnect people who may be evil.
generating automatic blacklist from the trash traffic and publishing it online for public consumption?
Comment removed based on user account deletion
There are plenty of examples of people suggesting ping to 1.1.1.1 as a delay in batch scripting. The thought of batches all over the world now failing because people used a kludge method to pause was only slightly more amusing than the thought of all the junk traffic 1.1.1.1 would see as a result.
For our next amazing trick, we're going to make 555-xxxx a valid number range! Follow the action live at example.com!
[Sorry, this signature is unavailable in your country/region]
https://en.wikipedia.org/wiki/...
You can't be ahead of the curve, if you're stuck in a loop.
TRUMP: We beat Mexico before - like in the '30s - and we can beat them again! That is why I am sending the military to the Alamo, where we beat those Mexican rapists before, and will do it again!
I get that the traffic to these specific IP addresses (or ranges) are interesting - but which DNS names resolve to these addresses? Or are reverse lookups involved?
I think a web server running on a low end system is powerful enough to prevent from being Slashdotted today.
There haven't been enough people on slashdot for many years for the slashdot effect to be a thing. Plus as you point out the networks are a lot more robust these days.
Slashdot hasn't grown at the same rate computing has grown.
Indeed, slashdot has substantially shrunk to all appearances. This used to be a place where a lot of alpha geeks hung out but slashdot never evolved or got better. Just look at how the average number of comments per article has shrunk over the last decade.
Directing traffic at 1.1.1.1 is a little like calling 867-5309.
More like calling 555-1212 than Jenny, I'm afraid.
I recently was setting up a VPN after having set up many VPNs. I've often joked about using non-publicly-used military/government ranges do avoid collisions. I recently set up for a client for one and saw they were using 1.1.1.1 for some things. It does seem to be a choice for routers and dns. I think you'll get it on any easily types "valid" address because people will just think what's the chance of having to be able to access though IP addresses over WAN (IE if it's a few in a billion your break) and if it happens they can shift it to 1.1.1.2. Unfortunately a lot of people operate like that rather than according to the spec.
MODDOWN! ; creimer youtube spam post again!
CREIMER' SUBMISSIONS UPDATE: /. so make sure to go to:
Note also that creimer is trying to regain karma by getting his submissions published as articles on
https://slashdot.org/~__aaclcg...
https://slashdot.org/~IDrinkFa...
https://slashdot.org/~_sharp'r...
https://slashdot.org/~crreimer
https://slashdot.org/~cdreimer
https://slashdot.org/~criss69
https://slashdot.org/~Anonymou...
https://slashdot.org/~FatCashe...
https://slashdot.org/~ILoveFat...
https://slashdot.org/~IHateFat...
https://slashdot.org/~IAteFatC...
https://slashdot.org/~ITapeFat...
https://slashdot.org/~IApeFatC...
https://slashdot.org/~IPrayFat...
https://slashdot.org/~FatCashe...
and mod down his submissions as well. The great thing is that you don't even need mod points to mod down a submission, just click on the "minus" icon!
Yes, believe it or not, creimer owns all the above sock puppet accounts. It is a mystery why Slashdot management tolerates it!
creimer wrote:
I don't bother with mod points. I'm doing something much more sinister. It took ten story submissions ? I'll have to double check the number ? to move cdreimer's karma from neutral to excellent without ever being exposed to the capricious mods. Mmmmmwwwwahahahahahahaha!
https://slashdot.org/comments....
Danger, Will Robinson, Danger! Creimy is posting more than 2 posts a day. Hurry! mod down otherwise /. will go to hell again!
Note: you can mod down even if already at -1 to lower karma and to prevent lost /. users to accidentally mod up.
creimer wrote:
All you need to do is find a website with a permissive TOS, say, Slashdot, create a Python script to scrape your own comments, sprinkle Amazon affiliate links in various posts, and then re-post past links whenever possible. Won't be long before you start making "coffee money" each month.
https://slashdot.org/comments....
C.D. Reimer is a renowned Slashdot collaborator, as he puts it himself; "Because of the quality of my posts and my article submissions, I'm a highly rated commentator and moderator."
But does anybody ever wondered what "C.D." stands for? Well, it stands for Creimy Dumpty of course!
Creimy Dumpty sat on the wall,
Creimy Dumpty had a great fall.
All the king's horses
And all the king's men
Couldn't put Creimy Dumpty
Together again.
Creimy's siblings video and theme song, very realistic, especially the pants, just like Creimy's:
https://www.youtube.com/watch?...
With "Vice President Pence Vowing US Astronauts Will Return To the Moon", we are sure they will need miracle workers up there, here is what it would look like. Note that Creimy takes care of bringing a lot of food to the moon as depicted below:
https://www.youtube.com/watch?...
Creimy's real pictures:
Before the sex change:
just look at how the average number of comments per article has shrunk over the last decade.
Nothing worth commenting on.
(1) Crap articles
(2) Reposts of crap articles
The Cloudflare-APNIC experiment uses two IPv4 address ranges, 1.1.1/24 and 1.0.0/24, which have been reserved for research use.
I could be wrong, but I'm pretty sure that 1.1.1/24 is not a valid IPv4 address range. IPv4 addresses consist of quadruplets of values. The proper address ranges are 1.1.1.0/24 and 1.0.0.0/24.
Cloudflare started its life with seeding from NSA and CIA as a honeypot used for nefarious purposes. Trusting this business to be the solution to private and secure DNS is complete madness. The solution must be within DNSSEC, out of the hands of American agencies and companies.
(3) Creimertards who are upset that creimer left Slashdot for YouTube.
Just look at how the average number of comments per article has shrunk over the last decade.
Can you prove that? I'm betting that just the average number of AC's we have per thread now greatly exceeds the number named postings per thread ten or twenty years ago.
The new DNS isn't "attracting" anything. All the traffic to 1.1.1.1 was already there, that's why they put the DNS host on that address. They wanted to experiment with exposing it to tons of crap traffic.
This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
I'm really curious as well. Does slashdot have a proper api that would allow someone to do some analysis on this?
Also, where did everyone go? Reddit? What subs? Has the very specific nature of subreddits fractured what used to be a large single audience?
As usual, everything has to revolve around yourself; me, myself and I, you selfish disgusting pig!
There you are shit posting with yet another fake account, you revenue stream hogging disgusting fat sexist tube of lard, Christopher Dale Reimer!
You can be sure I will be watching this fake account too. I know this is you because you told me you were working on your freepass 11 file server and you are so dumb that you can't even masquerade yourself properly.
Now, I told you I was out of meds last week and you didn't even care to contact me you lazy fucker.
How many times do I have to express the emergency of the situation??????
The python click script you wrote for my pheromone revenue stream web site suddenly stopped to work!!!!!!
You fucking incompetent python script writer!!!
When it works, I get 4000+ clicks a day on my pheromone revenue stream web site but only 5 or 6 without it!!!!
Now, it seems like you dont care and that you have abandoned me you heartless fucking pig!
Bonus:
Here is a story that creimer told me when convincing me what a hard life he had:
The tree was him and the tree knot was his butt hole!
So, his uncle packed his fat ass with lard and with his cock! Not that it makes much of a difference but anyway, there it is!
Signed:
Ethell, The girl that used to love you and now hates you, burn in hell where you belong you sexist pig!
#1 crap articles
#2 dupes of crap articles
Slashdot doesn't even support fucking unicode, why would you think it has any kind of api?
Comment removed based on user account deletion
Comment removed based on user account deletion
invoke a better humor response.
Humor timed out. No route to host.
Have gnu, will travel.
I think he's talking about macroscopic behavior.* Better if they could extend this geographically to other roots to see what DNS does worldwide.
*DNS traditionally hasn't been instrumented. Just tailored as a service.
... I hope it doesn't turn out to be a mistake that to have hired people who don't understand DNS...
Yeah, that stood out to me, too. ... How can you hire a "Chief Scientist" who doesn't understand the basic mechanisms of the environment you're operating within?
I dunno, that sounds about right for the current political environment in the US. Ideology and Wishy Thinking FTW!
:-P
Cheers,
"What in the name of Fats Waller is that?"
"A four-foot prune."
There goes my Skynet's comms strategy :(
When shit hits the fan get some of these https://youtu.be/pY-GncsZ-UE
As you're no doubt aware, RFC 2827 Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing, is primarily designed to prevent TCP SYN flood attacks. It is less beneficial for ICMP and UDP flood attacks.
Ignoring zone transfers the majority of DNS traffic, especially the problematic DNS Amplification Attacks, use the UDP protocol not the TCP protocol.