14 votes

Cloudflare announces free 1.1.1.2 and 1.1.1.3 DNS resolvers that block malware and/or adult content

12 comments

  1. [11]
    skybrian
    Link
    Update: The Mistake that Caused 1.1.1.3 to Block LGBTQIA+ Sites Today
    15 votes
    1. [10]
      drannex
      Link Parent
      Absolutely absysmal on theit side even if they licensed the material from another that they didn't even check if it was going to block this type of information, or had anyone of an LGBT status on...

      Absolutely absysmal on theit side even if they licensed the material from another that they didn't even check if it was going to block this type of information, or had anyone of an LGBT status on the team thats part of the community. They blocked a ton of sex-positive information and LGBTQ+ news sites and information resources.

      Every 'sex' privacy measure in the last decade has had this issue (twitter tried, tumblr tried, facebook tried, youtube has tried a dozen times, google, reddit, and more) and every time it leads to the same thing until a big PR incident happens. Its deafening that they can't learn from mistakes, especially as Cloudflare has positioned themselves as the harbor of freedom and a crusader against censorship.

      5 votes
      1. [2]
        skybrian
        Link Parent
        Since it was corrected quickly, I think the damage from this particular bug is minimal. I doubt many people have even had time to notice that this new DNS service was available and try it out....

        Since it was corrected quickly, I think the damage from this particular bug is minimal. I doubt many people have even had time to notice that this new DNS service was available and try it out.

        Also, they clearly can and do learn from mistakes, and are admirably transparent about them. We would be fortunate if more institutions were as on-the-ball as Cloudflare.

        13 votes
        1. drannex
          Link Parent
          They have marginally fixed the issue. Many popular LGBT news sites and resources are still blocked. They have been preparing this feature for months (longer?) and they didn't do a complete systems...

          They have marginally fixed the issue. Many popular LGBT news sites and resources are still blocked.

          They have been preparing this feature for months (longer?) and they didn't do a complete systems check nor analyze the data they rented from their service provider before use. They should have done better.

          They 'fixed' this quickly, but it shouldn't have been a problem to begin with. This is a fault on the company no matter how quickly they attempt to rectify (and the only reason they responded so quickly was because of the fall out that had already started). They didn't even have a way to report misidentified information on their site before the damage started, another careless mistake.

          2 votes
      2. [4]
        teaearlgraycold
        Link Parent
        Did you read the article? It looks like they did check and were going to use a separate filter list but then they used another list in production by mistake.

        Did you read the article? It looks like they did check and were going to use a separate filter list but then they used another list in production by mistake.

        One of the providers has multiple "Adult Content" categories. One “Adult Content” category includes content that mirrors the Google SafeSearch/CIPA definition. Another “Adult Content” content category includes a broader set of topics, including LGBTQIA+ sites.

        While we had specifically reviewed the Adult Content category to ensure that it was narrowly tailored to mirror the Google SafeSearch/CIPA definition, when we released the production version this morning we included the wrong “Adult Content” category from the provider in the build.

        5 votes
        1. [3]
          drannex
          (edited )
          Link Parent
          I do not believe that statement as the initial heat had responses from their leads explaining the issue on twitter, and that they were purposely using multiple sources as an aggregate and the one...

          I do not believe that statement as the initial heat had responses from their leads explaining the issue on twitter, and that they were purposely using multiple sources as an aggregate and the one that was used, was implemented on purpose, until this issue was brought up.

          If they were doing proper quality checks, they would have done that before publicly releasing a product as big as this.

          I hope I am wrong, but I doubt it.

          1. [2]
            teaearlgraycold
            Link Parent
            Anyone who's not an idiot would have expected the internet wouldn't have been happy with Cloudflare blocking this content. If a few hours of backlash was enough for them to rapidly deploy the fix...

            Anyone who's not an idiot would have expected the internet wouldn't have been happy with Cloudflare blocking this content. If a few hours of backlash was enough for them to rapidly deploy the fix it was obviously a mistake.

            3 votes
            1. drannex
              Link Parent
              I'm not saying it wasn't a mistake (it was!), but that they obviously didn't have proper QA testing beforehand and learned from issues that every other 'block' method has encountered on every...

              I'm not saying it wasn't a mistake (it was!), but that they obviously didn't have proper QA testing beforehand and learned from issues that every other 'block' method has encountered on every other attempt.

              It's a careless mistake that should have been a moot point before a public release as big as this one. I applaud their speed, but it shouldn't have been needed.

      3. [3]
        MikeBos
        Link Parent
        So why is this a abysmal issue? I'm not a big fan of filtering of anything other than malware and or spyware, but if anyone chooses too block porn, do you really think they care? Even then when...

        So why is this a abysmal issue? I'm not a big fan of filtering of anything other than malware and or spyware, but if anyone chooses too block porn, do you really think they care? Even then when we're talking about lgtbq it's a very small (if extremely vocal) percent of the population. On top of that it got fixed quite quick.
        So seriously abysmal?
        I think it's abysmal what's happening with corona. I think it's abysmal that there are people with not enough resources to feed their childeren. The cloudflare issue? Not abysmal, annoying it may be for some but for most just a shrug.

        1 vote
        1. [2]
          drannex
          (edited )
          Link Parent
          A 'very small' amount that some believe includes roughly 4-10% of the population around you. That isn't a small number by any means. Another note, which takes your statement to the extreme is that...

          Even then when we're talking about lgtbq it's a very small (if extremely vocal) percent of the population.

          A 'very small' amount that some believe includes roughly 4-10% of the population around you. That isn't a small number by any means. Another note, which takes your statement to the extreme is that this is the same rhetoric used to justify genocides "its just a small portion of the population".

          For America - A 2017 Gallup poll concluded that 4.5% of adult Americans identified as LGBT with 5.1% of women identifying as LGBT, compared with 3.9% of men. This is just for those who are out or able to come to terms, so the poll will trend downwards from reality.

          Yes, abysmal - because this is an issue that has cropped up over and over on every platform for the past decade , and for a product that was aimed to be a big release, they should have the necessary means to anticipate and Q&A check before release. That's the issue at hand, but I am not going to argue linguistic semantics.

          3 votes
          1. MikeBos
            Link Parent
            Seriously a godwin? Let's agree to disagree, I still think it's a non issue as it's corrected, happened for a small time, affected a very small subset of people. And by that I mean people who...

            Seriously a godwin?
            Let's agree to disagree, I still think it's a non issue as it's corrected, happened for a small time, affected a very small subset of people. And by that I mean people who actually used the service for the hours that it was live and were affected by it.

            3 votes
  2. teaearlgraycold
    Link
    For anyone curious about how the filters respond: $ dig @1.1.1.3 -t A pornhub.com ; <<>> DiG 9.10.6 <<>> @1.1.1.3 -t A pornhub.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;;...

    For anyone curious about how the filters respond:

    $ dig @1.1.1.3 -t A pornhub.com
    
    ; <<>> DiG 9.10.6 <<>> @1.1.1.3 -t A pornhub.com
    ; (1 server found)
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 20415
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
    
    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1452
    ;; QUESTION SECTION:
    ;pornhub.com.			IN	A
    
    ;; ANSWER SECTION:
    pornhub.com.		60	IN	A	0.0.0.0
    
    ;; Query time: 44 msec
    ;; SERVER: 1.1.1.3#53(1.1.1.3)
    ;; WHEN: Wed Apr 01 21:55:18 PDT 2020
    ;; MSG SIZE  rcvd: 67
    
    7 votes