Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Privacy Security IT

Cloudflare Launches a DNS-Based Parental Control Service (bleepingcomputer.com) 58

Cloudflare introduced today '1.1.1.1 for Families,' a privacy-focused DNS resolver designed to help parents in their efforts to safeguard their children's online security and privacyââââââ by automatically filtering out bad sites. From a report: This new tool makes it simple for parents to add protection from malware and adult content to the entire home network, allowing them to focus on working from home instead of worrying about their kids' online safety. "1.1.1.1 for Families leverages Cloudflare's global network to ensure that it is fast and secure around the world," Cloudflare's CEO Matthew Prince said in an announcement published today.
This discussion has been archived. No new comments can be posted.

Cloudflare Launches a DNS-Based Parental Control Service

Comments Filter:
  • by nyet ( 19118 ) on Wednesday April 01, 2020 @04:52PM (#59898530) Homepage

    The DoH endgame is this. No more distributed DNS

    • Except for now, DoH is how you get to bypass Cloudflare's filter. It's an ironic time to announce a DNS-based web filter.

      • by tlhIngan ( 30335 )

        Except for now, DoH is how you get to bypass Cloudflare's filter. It's an ironic time to announce a DNS-based web filter.

        Isn't the default DoH server Cloudflare?

    • by tlhIngan ( 30335 )

      The DoH endgame is this. No more distributed DNS

      DoH iand DNS as your OS uses them aren't distributed.

      Sure DNS itself is a distributed database, but the stub resolver your OS uses is too dumb to actually do that. Instead, the stub resolver talks to a recursive resolver that then queries through the DNS hierarchy for the address, the result is returned back to the stub resolver.

      All DoH does is replace the stub resolver your OS ships with and the recursive resolver it uses with another stub and recursive resol

    • DoH is a protocol to query DNS servers which support it.
      How distributed the DNS system is depends entirely on who is providing the DNS service and where they are getting their data from and is completely unaffected by how you chose to query your DNS system of choice.

      Of choice. You know choice? Like how 100% of DoH implementations to date offer you the ability to enable, disable, choose custom servers, or even set domains to bypass this functionality? Additionally DoH is configurable to use whatever server y

  • by mi ( 197448 ) <slashdot-2017q4@virtual-estates.net> on Wednesday April 01, 2020 @04:56PM (#59898546) Homepage Journal

    Amimojo's earlier submission of the same advertising for Cloudflare [slashdot.org] complained about "some LGBT sites" being blocked, while "Nazis" aren't...

    The particular set of examples is, of course, ridiculous. Still it shows, once again, how such things can be dangerous. All it takes is for government to mandate the use of such services in libraries or schools.

    • All the more reason to support commercial providers of filtering software, rather than let the government create one.

      At least if your library's filter is bad you can petition them to switch to a better one.

      • by mi ( 197448 )

        rather than let the government create one

        That's true, of course &mdash and applies to the likes of FDA, OSHA, and your town's building inspectors as well.

      • by ahodgson ( 74077 )

        If your library has a filter your librarian needs to be fired and replaced.

      • Are all filters created by clever algorithms nowadays? HTML5 doesn't allow the META tags for PICS-label content ratings... So I'm guessing nobody actually content-rates their websites anymore, they just let other companies' algorithms label them?

  • by Kitkoan ( 1719118 ) on Wednesday April 01, 2020 @05:00PM (#59898556)

    ÃÃÃÃÃÃ

    Pretty much sums it up.....

  • by magzteel ( 5013587 ) on Wednesday April 01, 2020 @05:14PM (#59898584)

    OpenDNS Home is free and works great.

    https://signup.opendns.com/hom... [opendns.com]

    • Isn't that the one that captures all domain typos instead of allowing for failure detection?

      • Isn't that the one that captures all domain typos instead of allowing for failure detection?

        You can disable it if you wish [labnol.org]. You can't really expect a free service to stick around if you prohibit them from making money in any way. They gotta pay their bills somehow. And at least they let you disable it if it really bothers you.

        • Nice, thanks. As to business, if they wanted a few bucks a month for the service instead of ads that would probably be fine, but when it started up it was basically browser hijacking and made me skeptical about their entire service... How much redirecting were they doing? Was it also on the roadmap to redirect existing ad networks to their own? Are they going to express their political opinion via censorship? etc, etc.

          Maybe I'm just too cynical ;)

  • This new tool makes it simple for parents to add protection from malware and adult content to the entire home network, allowing them to focus on working from home instead of worrying about their kids' online safety.

    This is the worst "think of the kids" excuse I have seen. We no longer need to worry about our kids' online safety. We can hand it all over to Cloudflare and get some real work done for a change.

    Fuck you Cloudflare. Fuck you.

    • Grow up. They're offering a service. If you like it, use it. If not, move along.

    • by AmiMoJo ( 196126 )

      It doesn't even work. Stormfront is not blocked, LGBT support sites are. Whatever blacklist they used was complete shit.

    • Fuck you Cloudflare. Fuck you.

      For providing a 100% optional service that parents can choose to use? WTF is wrong with you.

      And what is wrong with Slashdot moderators today? Were only the tinfoil hat psychoes given modpoints or something? Why is this drivel being modded up?

  • by Pyramid ( 57001 ) on Wednesday April 01, 2020 @05:25PM (#59898612)

    It's a good thing kids will never figure out how to bypass DNS based filtering.

    • yea - I mean having a setup like I do where all requests on port 53 are redirected to my preferred DNS regardless what a client sets who would have thunk it - its not bypassed
      • yea - I mean having a setup like I do where all requests on port 53 are redirected to my preferred DNS regardless what a client sets

        who would have thunk it - its not bypassed

        DNS over HTTPS uses port 443.

        You're welcome.

    • It's a good thing kids will never figure out how to bypass DNS based filtering.

      By the time they figure out how to bypass the filter, they are old enough to not need it.

      8-year-olds should be sheltered from the ugliness of the world. 15 year-olds can make their own decisions.

      If you are old enough to form a babby you are old enough to know how is babby formed.

      • If I had mod points you'd get it. I mean, the parent has to replace the resolver in their router and/or PC. Day to day it probably doesn't affect the parents much and they know their kids (well mostly sure) aren't going to visit weird russian porn sites. You have to have some technical knowhow to install this so the parents are putting in an effort...and when the kid is old enough, he knows how to change his resolver or use a VPN, win win!
    • It's a good thing kids will never figure out how to bypass DNS based filtering.

      Define kids. Kids has a big range. Are teenager as a kid? Yeah no chance. A gradeschooler, well the point of that isn't to prevent them from bypassing a filter, it's to isolate them from the world so they don't realise that they *need* to bypass a filter in the first place.

      Filtering definitely has its place. The fact that it doesn't work on 15 year olds is irrelevant.

  • So they're blocking *google* (and it's minions) too right?

    That's the biggest anti-privacy elephant in the room.

  • by Cyberax ( 705495 ) on Wednesday April 01, 2020 @06:25PM (#59898752)
    Look at the date!
  • 1. Who gets to decide what IS and IS NOT 'adult content'? Apparently Cloudflare! Oh, I'm sure they would never, ever apply their own personal agenda to what to block!
    2. 'Net Nanny' software never works. It either blocks things it shouldn't block (see above), allows things it shouldn't allow, or can be bypassed; what's to prevent your teenage son from using a numeric IP address instead of a URL?
    3. Parents, are you really going to let Cloudflare have a say in how your kids are raised? Do you trust your kids
    • (Crap, didn't close a bold properly. Sorry about that!)
    • Also, shouldn't you be the ones to decide what they should and shouldn't be doing on the internet?

      You are the one deciding, by deciding to use a simple DNS filter

      • You are the one deciding, by deciding to use a simple DNS filter

        ..no, you're ceding control of the situation to Cloudflare; you have no control over their choices of what is blocked and what is not.

        • By choosing to use a service, just like any service. I could build my own datacenter, but AWS works just fine. I could use my own SMTP server, but Exchange Online works just fine. I could go and setup my own whitelist or blacklist, but that's a fucking pain in the ass, so I use services for things that I don't want to manage myself. And if I don't like the outcome, I can easily change it at no cost to anyone.
          • That's nice. But it also doesn't address what I just said [slashdot.org]. You 'choose to use their service' but you have ZERO control over it.
            Here's a better idea for you: how about you raise your kids to respect you and your decisions regarding them, so you don't have to use force to keep them away from things on the internet you don't want them accessing? Then you won't need a 'service' of any kind. Bonus points: they grow up to be better adults.
    • by raymorris ( 2726007 ) on Wednesday April 01, 2020 @09:20PM (#59899246) Journal

      > what's to prevent your teenage son from using a numeric IP address instead of a URL?

      Teenagers aren't kids in this regard. I guarantee you my 5yo isn't going to be entering IP addresses when she intended to load her school website.

      > 3. Parents, are you really going to let Cloudflare have a say in how your kids are raised?

      It's MY decision that I don't want Peppapig.xxx loading on her machine. This service is one thing parents can do to help avoid the.

      > Do you trust your kids so little that you need to actively block them from so-called 'adult' content?

      Given the things I've seen accidentally come up on screen during business meetings, no I don't trust that my kid will always know what's okay to click and what isn't. Especially with sickos out there purposely trying to trick kids and parents with sites and videos featuring preschool characters along with sexually explicit material and blood and gore.

      You forgot the one I used to say. "Shouldn't the parent be staring at the screen and the kid all day? Parents don't have to poop, or shower, or work, right?"

    • No one gives a fuck. Let their agenda apply to block as much of the internet from kids as possible. No porn! Check, No politics, check, no other bullshit, check. Blocking things it shouldn't block for kids, oh woes me.

      2. 'Net Nanny' software never works.

      Net Nanny software works just fine for it's intended purpose. You just don't seem to have a clue what that intended purpose is and are catch-alling it with other requirements.

      3. Parents, are you really going to let Cloudflare have a say in how your kids are raised?

      You have no idea how the world works do you. Otherwise you wouldn't ask a question for which the answer is an obvious y

  • DNS was designed to allow anyone anywhere to query a hierarchy of server to convert domain names (like for example "www.slasdhot.org") to an IP or IPv6 address.

    This breaks all that... violates the DNS RFCs... and is an egregious censorship grab by a company known for denying DoS attacks. Now they'll be known for breaking DNS for anyone using them. Bad move, CloudFlare.

    Ehud Gavron
    Author of RFC-1535
    Tucson AZ

  • I'm the chairman of our school board and our school is closed due to the national lock down.
    The teachers have handed out the classroom laptops (google chromebooks) and iPads to the kids.
    Normally, within the school network, there would be a blanket filtering system in place.
    The school principal sent out an email last week suggesting parents look into safe online practices for their kids - ie supervised, no technical solution given.
    I don't like the idea of a filtered internet any more than any of the rest of

    • Except for those of us that care we've been doing it all along.

      Sure, some of us may be more geek level to do it but anywhere from "kids computing devices in the living room only" to " well, I run a Pi on my home network that acts as a DNS server and hijacks DNS for known malware and advertising and tracking domains as well as whatever i decide to add".

      Only change this work from home stuff has done is that I now throttle the "not my stuff" subnet of my LAN down to near dialup speeds while I'm "at work" since

  • It appears you (or your ISP) have to specifically "opt in" by choosing to use one of the two DNS options (1.1.1.2/1.0.0.2 or 1.1.1.3/1.0.0.3) so why is it a big deal? These kinds of services (most being far more effective than simple DNS blocking) have been around for decades at both the individual and ISP level. As long as it doesn't become the default I don't think it really changes anything. And at least for the foreseeable future there are plenty of DNS servers out there if Cloudflare starts misbehav

  • Neustar has been doing something like this for many years.

    156.154.70.3, 156.154.71.3 for parental controls. Not DNS over HTTP, though.

    https://www.home.neustar/dns-s... [www.home.neustar]

For God's sake, stop researching for a while and begin to think!

Working...