logoalt Hacker News

aetherspawntoday at 1:20 PM5 repliesview on HN

Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout.

ISP: 1ms to Cloudflare

Cloudflare: 10ms to Cloudflare

Thank you for your attention to this matter.

Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA


Replies

layer8today at 1:56 PM

That’s no good if you want uncensored DNS.

show 1 reply
marginalia_nutoday at 2:17 PM

Changing your DNS does basically bupkis for privacy, since they can still read your DNS queries and SNIs.

show 5 replies
richardlblairtoday at 3:36 PM

> Thank you for your attention to this matter.

Had me in stiches

vimdatoday at 4:53 PM

Cloudflare famously does anycast so the DNS answer you get is the same no matter where you're coming from. Your numbers there can't be attributable to DNS. On the contrary, Cloudflare can short circuit the recursive lookup for any of their properties, providing potential speedups at the resolution stage, and can use eDNS client subnet to route based on where you are if necessary

show 1 reply