Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Cloudflare Launches Free Secure DNS Service

Cloudflare Launches Globally Available Secure Free DNS Resolver

Cloudflare Launches Globally Available Secure Free DNS Resolver

Cloudflare launched a new free service, designed to improve both the speed and the security of the internet, on April Fool’s Day (4/1/2018). But this is no joke. The idea is that 4/1 is geekery four ones, or 1.1.1.1 — the name and heart of the new service.

1.1.1.1 (and 1.0.0.1) is the address of Cloudflare’s new, globally available, free DNS resolver service. It is similar to — but according to Cloudflare — faster and more secure than, Google’s 8.8.8.8 service. Both address speed and security issues in the standard internet DNS look-up process. The biggest problem is security because DNS lookups are primarily controlled by ISPs; and ISPs are commercial organizations seeking to monetize data; and are often heavily controlled or influenced by governments.

In the U.S., ISPs are allowed to sell customer data — including website visits — to marketing firms. In the UK, ISPs are required by law to record and hand over such customer data to law enforcement, intelligence and other government agencies. In Turkey, in 2014, the Turkish government censored Twitter by getting ISPs to block DNS requests for twitter.com — and activists took to the streets to spray paint Google’s 8.8.8.8 DNS service as a workaround. Turkey has a history of using the DNS system for censorship, including a block on Wikipedia in April 2017.

Google’s service is good and fast, and bypasses ISP instigated blocks, but user data is still available to Google. Cloudflare wants to provide an even faster service, but one where no commercial entity can easily monetize the user data, nor government gain access without a court order. Since the firm is committed to never writing that data to disk, and to wiping all log records within 24 hours (to be independently audited by KPMG with a published public report) there will be little historical data available anyway.

“Cloudflare’s business has never been built around tracking users or selling advertising,” blogged Matthew Prince, co-founder and CEO of Cloudflare, on Sunday. “We don’t see personal data as an asset; we see it as a toxic asset.” Cloudflare retains the log data for a maximum of 24 hours for abuse prevention and debugging issues. 

“We think it’s creepy that user data is sold to advertisers and used to target consumers without their knowledge or consent,” said Prince. “Frankly, we don’t want to know what people do on the Internet — it’s none of our business — and we’ve designed 1.1.1.1 to ensure that we, along with ISPs around the world, can’t.”

The insecurity of the DNS infrastructure struck the team at Cloudflare, he says, as a bug at the core of the Internet, “so we set out to do something about it.” The firm decided to combine a DNS Resolver with its existing Authoritative DNS service across its worldwide network, but still needed some memorable IP addresses. 

Advertisement. Scroll to continue reading.

Little could be more memorable than 1.1.1.1. This address was held by the APNIC research group, which agreed to provide it to the new service. “We began testing and found that a resolver, running across our global network, outperformed any of the other consumer DNS services available (including Google’s 8.8.8.8),” says Prince.

1.1.1.1 is primarily a consumer service (the IPv6 numbers are 2602:4700:4700::1111 and 2602:4700:4700::1001). Technical details are provided in a separate blog written by director of engineering, Olafur Gudmundsson. The service uses DNS Query Name Minimization defined in RFC7816 to minimize the data sent, and supports privacy-enabled TLS queries on port 853 (DNS over TLS), “so,” he writes, “we can keep queries hidden from snooping networks.”

Furthermore, he adds, “by offering the experimental DoH (DNS over HTTPS) protocol, we improve both privacy and a number of future speedups for end users, as browsers and other applications can now mix DNS and HTTPS traffic into one single connection.”

Cloudflare is working with major browsers, operating systems, app manufacturers, cloud platforms, and router manufacturers to enable DNS over HTTPS. Mozilla is already working to integrate the standard into its Firefox browser:

“Like Cloudflare, Mozilla cares about making the Internet faster and more privacy-conscious so people have a better experience on the web,” says Selena Deckelmann, senior director of engineering, Firefox Runtime at Mozilla. “We are always looking for new technologies like DNS over HTTPS to ensure Firefox is at the cutting edge of speed, privacy and improving life online.”

The resolver is built on the fairly new open source Knot Resolver from CZ NIC — whose original main developer has been working with Cloudflare for more than two years.

The service uses Cloudflare’s 149 data centers distributed around the world. “In March alone, we enabled thirty-one new data centers globally,” as far apart as Pittsburgh and Houston, Reykjavik and Tallinn, and Edinburgh and Bogota, notes Gudmundsson; “and just like every other city in our network, new sites run DNS Resolver, 1.1.1.1 on day-one!”

San Francisco, CA-based Cloudflare was founded in 2009. It has raised a total funding amount of $182,050,000 — the most recent being $110 million Series D funding led by Fidelity Investments in September 2015. It routes traffic through its own global network, blocking DoS attacks, reducing spam and improving performance.

Related: Internet Provider Redirects Users in Turkey to Spyware: Report 

Related: Group Launches Secure DNS Service Powered by IBM Threat Intelligence 

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

CISO Conversations

SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...

Network Security

Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on areas...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...