← Back to context

Comment by JdeBP

10 hours ago

… then you'll be back in the world before CloudFlare set up its public DNS service, which is also the world where taking over 1.1.1.1 in the first place came at the price of having to measure how many people had ignorantly or lazily put four ones into somewhere that they had to fill in an IP address, and how much bogus and positively risky (to them) traffic there was being caused by people just thinking 'I will just use 1.1.1.1, which is not a real IP address.'.

Just before COVID, a random unidentifiable person reported that 1.1.1.1 saw 60Mb/s of ICMP echo traffic. When APNIC first experimented with making it a valid network almost a decade before that, it was being sent 50Mb/s of general IP traffic. Amusingly, a side-effect of what CloudFlare has done is that it has stopped all of that traffic leaving the edges of the Internet, and funnelling in to one big central place.

There are those who remember the risks of 'just use 1.1.1.1' and how the people who did that used be characterized as 'bad Internet citizens'. The ServerFault answer (q.v.) is from 2011.

* https://serverfault.com/a/339782

That was part of Cloudflare's pitch to take over the 1.1.1.1 address block - that Cloudflare had the relatively unique ability to handle all the junk traffic as anycast nearby to any source, not overloading the wider internet.