Jump to content

Cloudflare DNS outage

piratemonkey

At about 2:15 PM (pacific time) Cloudflare experienced an outage for it's DNS services for about 25 minutes. Affected sites and services include Discord, Shopify, League of Legends, and many more. Google seems to have been affected (youtube and google search engine). Cloudflare's 1.1.1.1 seems to have gone down too

The problem seems to be fixed now

 

Quote

Many major websites and services were unreachable for a period Friday afternoon due to issues at Cloudflare’s 1.1.1.1 DNS service. The outage seems to have started at about 2:15 Pacific time and lasted for about 25 minutes before connections began to be restored. Google DNS may also have been affected.

Cloudflare at 2:46 says “the issue has been identified and a fix is being implemented.”

Discord, Feedly, Politico, Shopify and League of Legends were all affected, giving an idea of the breadth of the issue. Not only were websites down but also some status pages meant to provide warnings and track outages

 

I think this could've been a lot worse. With 1.1.1.1 being affected, people using it would not have been able to use the internet. Smh

Google seems to have been affected, this could be a bigger problem with internet companies (see twitter hack). 2020 is just a bad year

 

Sources

https://techcrunch.com/2020/07/17/cloudflare-dns-goes-down-taking-a-large-piece-of-the-internet-with-it/

People in comments (for 1.1.1.1 and google DNS)

Edited by piratemonkey
updated it for 1.1.1.1 and google being affected

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

was using 1.1.1.1, took me down with it

 

edit: I should mention that all my devices are back up after I changed my dns settings

CPU: Intel core i7-8086K Case: CORSAIR Crystal 570X RGB CPU Cooler: Corsair Hydro Series H150i PRO RGB Storage: Samsung 980 Pro - 2TB NVMe SSD PSU: EVGA 1000 GQ, 80+ GOLD 1000W, Semi Modular GPU: MSI Radeon RX 580 GAMING X 8G RAM: Corsair Dominator Platinum 64GB (4 x 16GB) DDR4 3200mhz Motherboard: Asus ROG STRIX Z370-E Gaming

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Jumballi said:

was using 1.1.1.1, took me down with it

 

There goes the neighbourhood

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

I'm pretty sure Googles DNS took a slight hit too, on down detecor status, google, amazon web based service, and cloud flare all had issues, resulting in just about everything messing up.

Link to comment
Share on other sites

Link to post
Share on other sites

google did take a hit. youtube didnt work, neather did a google search

I could use some help with this!

please, pm me if you would like to contribute to my gpu bios database (includes overclocking bios, stock bios, and upgrades to gpus via modding)

Bios database

My beautiful, but not that powerful, main PC:

prior build:

Spoiler

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, RAM555789 said:

I'm pretty sure Googles DNS took a slight hit too, on down detecor status, google, amazon web based service, and cloud flare all had issues, resulting in just about everything messing up.

 

Just now, TheTechWizardThatNeedsHelp said:

google did take a hit. youtube didnt work, neather did a google search

thank you. will update

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

When it came back uBlock in FireFox stopped working for me... I forgot how many ads are on the internet... I also couldn't get to the options of uBlock.

 

Not knowing I did a reinstall of FireFox.

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, SKHSVideo said:

When it came back uBlock in FireFox stopped working for me... I forgot how many ads are on the internet... I also couldn't get to the options of uBlock.

 

Not knowing I did a reinstall of FireFox.

That's interesting. I wasn't using FireFox during the outage, but I do use uBlock Origin on Chrome. I didn't notice anything out of the norm (though I don't aggressively block like FireFox, only for trackers)

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, lewdicrous said:

This sums up everyone's reaction.

*snip*

This isn't the first time something like this happens. We need a backup in case it happens again and is out for longer.

That's accurate

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

I thought I was actually pretty well isolated from occurrences like this.  I run my own DNS caching server, it does forward lookups through 1.1.1.2 normally, but also has backups through 4.4.4.4, 9.9.9.9, and a couple ISPs.  I still couldn't get anything to be looked up unless it was very recent in the cache, even though I could ping 1.1.1.2 and 9.9.9.9 just fine.  During that time, FB stopped loading for me too, even though I had all of their DNS info cached.

 

This feels more like a takedown of a part of the backbone, which happened to also take out DNS servers for some CDNs, rather than just DNS issues.  I look forward to hearing the full on security analysis of it all once that's done.

Link to comment
Share on other sites

Link to post
Share on other sites

OK, looks like the basic info is actually out already.

 

Quote

Update - This afternoon we saw an outage across some parts of our network. It was not as a result of an attack. It appears a router on our global backbone announced bad routes and caused some portions of the network to not be available. We believe we have addressed the root cause and are monitoring systems for stability now.

...

...

...

Data Centers impacted include: SJC, DFW, SEA, LAX, ORD, IAD, EWR, ATL, LHR, AMS, FRA, CDG

Quote

With regards to the recent outage that we experienced with our DNS resolver and network, our team has identified that this issue appears to be related to our routing backbone that caused bad routes to be announced which caused some portions of the network to be unavailable.

...

The time stamp for Incident is between 21:11 and 22:05 UTC;

 

So, yep...

 

Above taken from various Cloudflare responses on their community forums.  Official incident update here:

https://www.cloudflarestatus.com/incidents/b888fyhbygb8

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, justpoet said:

OK, looks like the basic info is actually out already.

From where? Cloudflare's support page?

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, piratemonkey said:

From where? Cloudflare's support page?

Yep.  They say it wasn't an attack, but that's a weird thing to have suddenly start happening.

Link to comment
Share on other sites

Link to post
Share on other sites

35 minutes ago, justpoet said:

Yep.  They say it wasn't an attack, but that's a weird thing to have suddenly start happening.

It likely didn't "suddenly start happening" for any reason other than maintenance.  Someone probably goofed up and pushed a maintenance when he/she shouldn't have.  Note:

 

We believe we have addressed the root cause

 

Which can be read as: "We found the the mistake the person made and un-did it."

Editing Rig: Mac Pro 7,1

System Specs: 3.2GHz 16-core Xeon | 96GB ECC DDR4 | AMD Radeon Pro W6800X Duo | Lots of SSD and NVMe storage |

Audio: Universal Audio Apollo Thunderbolt-3 Interface |

Displays: 3 x LG 32UL950-W displays |

 

Gaming Rig: PC

System Specs:  Asus ROG Crosshair X670E Extreme | AMD 7800X3D | 64GB G.Skill Trident Z5 NEO 6000MHz RAM | NVidia 4090 FE card (OC'd) | Corsair AX1500i power supply | CaseLabs Magnum THW10 case (RIP CaseLabs ) |

Audio:  Sound Blaster AE-9 card | Mackie DL32R Mixer | Sennheiser HDV820 amp | Sennheiser HD820 phones | Rode Broadcaster mic |

Display: Asus PG32UQX 4K/144Hz displayBenQ EW3280U display

Cooling:  2 x EK 140 Revo D5 Pump/Res | EK Quantum Magnitude CPU block | EK 4090FE waterblock | AlphaCool 480mm x 60mm rad | AlphaCool 560mm x 60mm rad | 13 x Noctua 120mm fans | 8 x Noctua 140mm fans | 2 x Aquaero 6XT fan controllers |

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Jumballi said:

was using 1.1.1.1, took me down with it

 

edit: I should mention that all my devices are back up after I changed my dns settings

That's why you have more than one DNS.

 

Personally I just leave the DNS set to the ISP, and 8.8.8.8 (google) is the secondary, not the primary.

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, huilun02 said:

I use OpenDNS...

 

NextDNS is nice but its going paid. Didn't use it because it wouldn't take a self made custom domain block list.

NextDNS is still free. Just not unconditionally like in BETA. It's fully free if you only use it for domain resolving. If you use blocklists, you get 150.000 queries/month for free. Once you get past that it'll operate as regular DNS without any blocklists till next month begins and then it starts over. It's like 20€/year if you go unlimited.

 

I get through month with the free plan just fine and really don't see a reason why I'd need a custom block list given how many they offer and you can also add your own blacklist entries. I've needed to block some stuff on top of list and I've done it through blacklist (now Denylist coz racism is a real thing in software LMAO XD).

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, huilun02 said:

my self made block list is almost 3,000 lines of entries that organisations really dont want people blocking

Like what?

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, huilun02 said:

Mostly telemetry, data collection and tracking servers of the big players like Google, Microsoft. And manufacturer of my equipment that are also using the DNS service (for example blocking Samsung, Oneplus, and Xiaomi's naughty stuff because I use those brands of devices) And some ads/tracking delivery networks that are missed out.

 

Entries all of which I could not find in the available selectable block lists so I had to compile them into my own.

Good job. I'm just using uBlock origin with several lists. I need to up my blocking game

Either @piratemonkey or quote me when responding to me. I won't see otherwise

Put a reaction on my post if I helped

My privacy guide | Why my name is piratemonkey PSU Tier List Motherboard VRM Tier List

What I say is from experience and the internet, and may not be 100% correct

Link to comment
Share on other sites

Link to post
Share on other sites

GRC's DNSBench is a good way to find the lowest latency DNS to use, based on your location in cyberspace. Try to pick 3-4 different "providers" for your list.

 

Here's mine, set on the firewall so everything uses them:
image.png.f211264cbaaa58f69eb0d1151a58f43f.png

 

DNSBench is here: https://www.grc.com/dns/benchmark.htm and this tool will also tell you if the provider redirects non-existent domains to adverts etc.

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, huilun02 said:

Mostly telemetry, data collection and tracking servers of the big players like Google, Microsoft. And manufacturer of my equipment that are also using the DNS service (for example blocking Samsung, Oneplus, and Xiaomi's naughty stuff because I use those brands of devices) And some ads/tracking delivery networks that are missed out.

 

Entries all of which I could not find in the available selectable block lists so I had to compile them into my own.

For which NextDNS provides OS level lists. There is also NoGoogle list that blocks everything Google. Also LightSwitch05 blocks telemetry from MS and bunch of others. If you need over 600.000 queries a month, then 20€ a year is not exactly expensive given you can then filter unlimited number of devices and queries...

Link to comment
Share on other sites

Link to post
Share on other sites

Internet is down, time to log off everyone... 

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

15 hours ago, jasonvp said:

Which can be read as: "We found the the mistake the person made and un-did it."

Looks like CloudFlare published an RCA of sorts which basically backs up what I suspected: someone goofed.

 

Quote

The outage occurred because, while working on an unrelated issue with a segment of the backbone from Newark to Chicago, our network engineering team updated the configuration on a router in Atlanta to alleviate congestion. This configuration contained an error that caused all traffic across our backbone to be sent to Atlanta. This quickly overwhelmed the Atlanta router and caused Cloudflare network locations connected to the backbone to fail.

 

 

Maintenance on a Friday afternoon.  Never, ever a good idea.  Heh.  What could possibly go wrong?!

 

Editing Rig: Mac Pro 7,1

System Specs: 3.2GHz 16-core Xeon | 96GB ECC DDR4 | AMD Radeon Pro W6800X Duo | Lots of SSD and NVMe storage |

Audio: Universal Audio Apollo Thunderbolt-3 Interface |

Displays: 3 x LG 32UL950-W displays |

 

Gaming Rig: PC

System Specs:  Asus ROG Crosshair X670E Extreme | AMD 7800X3D | 64GB G.Skill Trident Z5 NEO 6000MHz RAM | NVidia 4090 FE card (OC'd) | Corsair AX1500i power supply | CaseLabs Magnum THW10 case (RIP CaseLabs ) |

Audio:  Sound Blaster AE-9 card | Mackie DL32R Mixer | Sennheiser HDV820 amp | Sennheiser HD820 phones | Rode Broadcaster mic |

Display: Asus PG32UQX 4K/144Hz displayBenQ EW3280U display

Cooling:  2 x EK 140 Revo D5 Pump/Res | EK Quantum Magnitude CPU block | EK 4090FE waterblock | AlphaCool 480mm x 60mm rad | AlphaCool 560mm x 60mm rad | 13 x Noctua 120mm fans | 8 x Noctua 140mm fans | 2 x Aquaero 6XT fan controllers |

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×