Cloudflare is over the moon because its pro-privacy DNS service got a clean bill of health from everyone's favorite auditor – KPMG

Proved for all sites, proved for all sites, there is nothing else we can do

Two years ago, network infrastructure biz Cloudflare launched the Public DNS Resolver, with the promise that internet users could use the service to surf the internet without being tracked - by Cloudflare at least.

The biz positioned itself as a speedier, privacy-focused alternative to Google Public DNS, which operates using the IPv4 address address and also promises privacy despite Google's extensive online ad business. Other DNS providers plainly acknowledge they'll sell network traffic data.

Internet service providers generally offer a DNS resolution service so that when people's browsers, apps, and other software need to connect to a server by its human-friendly domain name, such as, the DNS service will point towards the appropriate numeric network IP address for the server, such as

Cloudflare contends that third-party services like its own can provide greater security and performance than an ISP-run offering, particularly if used in conjunction with a protocol such as DNS-over-HTTPS.

But since talk is cheap, Cloudflare went the extra mile to have its privacy claims verified by a neutral, third-party auditor: global professional services firm KPMG.

Now, after rather more time than Cloudflare expected, the results show that the biz has lived up to its commitment, apart from a minor router oversight. On Tuesday, Cloudflare plans to publish the results of its audit on its compliance page.

"Cloudflare's business has never been about targeted advertising or selling user data," said CEO Matthew Prince in a phone interview with The Register. "The interesting thing for us is it turned out to be a lot harder to find an auditor who could do this than we expected."

Prince said he thought the entire process would take six months. Instead, it took nearly two years because the accounting firms approached didn't have a playbook for this sort of technically-focused review of policy and practice. The actual audit took over three months to complete.

"It has made us better as an organization," said Prince, "but I also hope it makes people realize that we're committed to doing what we said we were going to do, which is not using this data in a way that threatens the privacy of individuals."

The audit did reveal one unanticipated finding. The company's routers were randomly capturing 0.05 per cent of all network traffic, including the IP address queries of resolver users.

As CTO John Graham-Cumming explained in a blog post provided in advance to The Register, Cloudflare does this separately from its service, retaining this fraction of traffic for a limited period of time for network troubleshooting and defending against denial of service attacks.

"If a specific IP address is flowing through one of our data centers a large number of times, then it is often associated with malicious requests or a botnet," said Graham-Cumming. "We need to keep that information to mitigate attacks against our network and to prevent our network from being used as an attack vector itself."

Graham-Cumming said this data is not linked to DNS queries and does not affect user privacy. Cloudflare has updated its published privacy commitments to clarify this practice. The most salient of these is a promise not to sell or share public resolver users' personal data with third parties or use that for ad targeting.

Cloudflare previously disclosed that APNIC, the organization that provided the address to Cloudflare, has access to some DNS query data (but not the log of IP addresses of those making such queries) for research related to DNS operations.

"We've tried to design all of our products from the beginning that data held by us is a toxic asset," said Prince. ®

Full disclosure: The Register is a Cloudflare customer.

Other stories you might like

  • DigitalOcean tries to take sting out of price hike with $4 VM
    Cloud biz says it is reacting to customer mix largely shifting from lone devs to SMEs

    DigitalOcean attempted to lessen the sting of higher prices this week by announcing a cut-rate instance aimed at developers and hobbyists.

    The $4-a-month droplet — what the infrastructure-as-a-service outfit calls its virtual machines — pairs a single virtual CPU with 512 MB of memory, 10 GB of SSD storage, and 500 GB a month in network bandwidth.

    The launch comes as DigitalOcean plans a sweeping price hike across much of its product portfolio, effective July 1. On the low-end, most instances will see pricing increase between $1 and $16 a month, but on the high-end, some products will see increases of as much as $120 in the case of DigitalOceans’ top-tier storage-optimized virtual machines.

    Continue reading
  • GPL legal battle: Vizio told by judge it will have to answer breach-of-contract claims
    Fine-print crucially deemed contractual agreement as well as copyright license in smartTV source-code case

    The Software Freedom Conservancy (SFC) has won a significant legal victory in its ongoing effort to force Vizio to publish the source code of its SmartCast TV software, which is said to contain GPLv2 and LGPLv2.1 copyleft-licensed components.

    SFC sued Vizio, claiming it was in breach of contract by failing to obey the terms of the GPLv2 and LGPLv2.1 licenses that require source code to be made public when certain conditions are met, and sought declaratory relief on behalf of Vizio TV owners. SFC wanted its breach-of-contract arguments to be heard by the Orange County Superior Court in California, though Vizio kicked the matter up to the district court level in central California where it hoped to avoid the contract issue and defend its corner using just federal copyright law.

    On Friday, Federal District Judge Josephine Staton sided with SFC and granted its motion to send its lawsuit back to superior court. To do so, Judge Staton had to decide whether or not the federal Copyright Act preempted the SFC's breach-of-contract allegations; in the end, she decided it didn't.

    Continue reading
  • US brings first-of-its-kind criminal charges of Bitcoin-based sanctions-busting
    Citizen allegedly moved $10m-plus in BTC into banned nation

    US prosecutors have accused an American citizen of illegally funneling more than $10 million in Bitcoin into an economically sanctioned country.

    It's said the resulting criminal charges of sanctions busting through the use of cryptocurrency are the first of their kind to be brought in the US.

    Under the United States' International Emergency Economic Powers Act (IEEA), it is illegal for a citizen or institution within the US to transfer funds, directly or indirectly, to a sanctioned country, such as Iran, Cuba, North Korea, or Russia. If there is evidence the IEEA was willfully violated, a criminal case should follow. If an individual or financial exchange was unwittingly involved in evading sanctions, they may be subject to civil action. 

    Continue reading

Biting the hand that feeds IT © 1998–2022