I know several people working as software engineers at Cloudflare. According to one of them, this incident (blog.cloudflare.com/the-mistake-th) was hardly a mistake. Cloudflare is including block lists sourced from far right evangelical groups as part of their 'family friendly' DNS service.
Conversation
We've had a bad experience with their malware blocking. It blocked several of the domains and we had to get them to fix it. The variant they offer without malware blocking also doesn't enforce DNSSEC and no mainstream OS has local support for enforcing DNSSEC yet.
1
1
6
It was due to faulty data from one of the threat intelligence feeds they use to implement the blocking. They made exceptions for the domains that were wrongly blocked and continued using the faulty feed. I don't think there's enough transparency about how they're doing filtering.
None. Buy a Raspberry Pi. Run PiHole and Unbound on it. Make your own DNS resolver.
/j (unless you want to)
1
1
Show replies



