Cloudflare is over the moon because its pro-privacy 1.1.1.1 DNS service got a clean bill of health from everyone's favorite auditor – KPMG
- Reference: 1585659613
- News link: https://www.theregister.co.uk/2020/03/31/cloudflare_dns/
- Source link:
The biz positioned itself as a [1]speedier , privacy-focused alternative to Google Public DNS, which operates using the IPv4 address address 8.8.8.8 and also [2]promises privacy despite Google's extensive online ad business. Other DNS providers plainly acknowledge they'll [3]sell network traffic data.
Internet service providers generally offer a DNS resolution service so that when people's browsers, apps, and other software need to connect to a server by its human-friendly domain name, such as theregister.co.uk, the DNS service will point towards the appropriate numeric network IP address for the server, such as 104.18.235.86.
Cloudflare contends that third-party services like its own can provide greater security and performance than an ISP-run offering, particularly if used in conjunction with a protocol such as [4]DNS-over-HTTPS .
But since talk is cheap, Cloudflare went the extra mile to have its privacy claims verified by a neutral, third-party auditor: global professional services firm [5]KPMG .
Now, after rather more time than Cloudflare expected, the results show that the biz has lived up to its commitment, apart from a minor router oversight. On Tuesday, Cloudflare plans to publish the results of its audit on its [6]compliance page .
"Cloudflare's business has never been about targeted advertising or selling user data," said CEO Matthew Prince in a phone interview with The Register . "The interesting thing for us is it turned out to be a lot harder to find an auditor who could do this than we expected."
Prince said he thought the entire process would take six months. Instead, it took nearly two years because the accounting firms approached didn't have a playbook for this sort of technically-focused review of policy and practice. The actual audit took over three months to complete.
"It has made us better as an organization," said Prince, "but I also hope it makes people realize that we're committed to doing what we said we were going to do, which is not using this data in a way that threatens the privacy of individuals."
The audit did reveal one unanticipated finding. The company's routers were randomly capturing 0.05 per cent of all network traffic, including the IP address queries of 1.1.1.1 resolver users.
As CTO John Graham-Cumming explained in a blog post provided in advance to The Register , Cloudflare does this separately from its 1.1.1.1 service, retaining this fraction of traffic for a limited period of time for network troubleshooting and defending against denial of service attacks.
"If a specific IP address is flowing through one of our data centers a large number of times, then it is often associated with malicious requests or a botnet," said Graham-Cumming. "We need to keep that information to mitigate attacks against our network and to prevent our network from being used as an attack vector itself."
Graham-Cumming said this data is not linked to DNS queries and does not affect user privacy. Cloudflare has updated its published privacy commitments to clarify this practice. The most salient of these is a promise not to sell or share public resolver users' personal data with third parties or use that for ad targeting.
Cloudflare previously disclosed that APNIC, the organization that provided the 1.1.1.1 address to Cloudflare, has access to some DNS query data (but not the log of IP addresses of those making such queries) for research related to DNS operations.
"We've tried to design all of our products from the beginning that data held by us is a toxic asset," said Prince. ®
Full disclosure: The Register is a Cloudflare customer.
[1] https://www.cloudflare.com/learning/dns/what-is-1.1.1.1/
[2] https://developers.google.com/speed/public-dns/privacy#what_we_log
[3] https://www.theregister.co.uk/2019/11/04/mozilla_doh_congress/
[4] https://www.theregister.co.uk/2019/09/09/mozilla_firefox_dns/
[5] https://search.theregister.co.uk/?q=kpmg
[6] https://www.cloudflare.com/compliance/
Re: Not yet, at least
Plus weren't KPMG the company involved in the HPE/Autonomy trial?
OK, it looks like it may be the case that they only answered very specific questions but I can't help but wonder if they're the best people to audit anything any more...
Re: Not yet, at least
Maybe that's why it took 2 years... they customer actually *WANTED* an audit done!
Re: Not yet, at least
Cant upvote this enough
Re: Not yet, at least
Good point, but I still commend Cloudflare for taking that (current) position.
I am beginning to wonder if, with that position, using their DoH service might actually be better than rolling my own? I am currently intending to run a DoH service on my own (internet-visible) server, backed by my own recursive resolver (not forwarded to another resolver).
However, that makes the fact that I (the server owned in my name, with a static IP, running DoH) am looking up that name visible to all the servers I touch during the resolution (and potentially visible to other players like the networks my server transits to get to those servers).
If I use Cloudflare's DoH service then, obviously, Cloudflare know that I (or actually, my end device, which is probably behind carrier-grade NAT somewhere) looked up that name. But nothing else knows: my communication with Cloudflare is encrypted and the nameservers involved only know Cloudflare's DoH server looked up the name.
Interesting that using their service might actually end up being more private than rolling my own.
Re: Not yet, at least
DoH to your own private server is only going to protect you from a potentially insecure local network as far along as your ISP. Of course, compared to standard DNS, it at least gives you that, but nothing more. Your server also has an ISP, and it can watch your standard DNS resolutions to figure out where you're going. If you didn't want to trust Cloudflare, the best way to maintain privacy is to make the server available to others, either a specific set of people to maintain a cap on resource usage or making the server public. Since this inevitably entails quite a bit of resource usage for others and since others don't know for sure that you can be trusted, that might not work as expected.
Poor old 8.8.4.4, overlooked again.
P.S. dig dns.google TXT +short
8.8.4.4
Yeah, but that's Google, which is definitely not pro-privacy.
Why?
Instead, it took nearly two years because the accounting firms approached didn't have a playbook for this sort of technically-focused review of policy and practice.
Then why not use an organisation that is specifically set up for IT security auditing? There are some good ones around and some have a long tradition in science and industrial auditing as well as IT, so they have a good reputation. TÜV springs to mind.
Re: Why?
IMTech?
My coat with a breached contract in the pocket...
Carillion's favourite auditor... 'nuff said
"We've tried to design all of our products from the beginning that data held by us is a toxic asset,"
That is a VERY good way of looking at data retention.
Been trying to get this into Marketing People's heads for the last few years. Data Is A Liability.
Just because you _can_ get that Excel spreadsheet with the email address, name, phone number, time and IP of everyone who opened your daft B2B email last week - doesn't mean you should. I don't care if "the Sales team" want it. In that case push that data through your CRM and restrict access to just those people.
Do not request an XLSX: which gets generated by an Agency Developer, gets emailed to an Agency Account Manager, then emailed to you, then distributed by you to an ever-growing mailing list. Thus creating dozens, even hundreds of copies - dutifully backed up forever, any one of which could easily be left in a train, bus, taxi, hotel room at any time.
Toxic Asset is a great way of describing it. Might start trying that one instead!
Not yet, at least
"Cloudflare's business has never been about targeted advertising or selling user data," said CEO Matthew Prince
That would fall in the category famous last words not yet . The problem is never with current management. It is always a problem with who will follow. Either an internal policy change or a big investor, who wants to squeeze the last cent out of it too. But then it is too late. Your infrastructure has been committed and changing it is hard and expensive.
The lesson, that we all should have learned by now, is that a promise is just a promise. It does not say anywhere, how long that promise may last or is applicable. So, yes, good promise but use caution. Do not make yourself (too) dependent.