Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

141–150 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#141

Here is the original Cloudflare post on what 1.1.1.1 is [1]. For those who don't know, 1.1.1.1 is Cloudflare's privacy focused DNS service. That means that when you type in www.google.com, that URL can be sent to 1.1.1.1, and then 1.1.1.1 resolves that URL an IP address and send the IP back to the user. All user requests are then sent to the IP address, not the URL. Supposedly this is better than using the DNS server…

One point: the whole URL doesn't get sent to the DNS server, just the domain name.

Regarding privacy, Cloudflare are at least saying they aren't spying on you. Your ISP may not even be saying this. Also, Cloudflare don't necessarily have access to your name and address, whereas your ISP does. Also, many different sites can be hosted on the same IP address, so merely tracking the IP addresses a client is connected to won't necessarily tell you what sites they're visiting.

Re: AT&T updates firmware to block access to 1.1.1.1

#142
post #98

Earlier quoted context omitted.

You could swap out those two odds and you would be just as right...

They could swap those odds with anything but 100% to 0% and they would still be just as "right" once the answer comes out.

exactly... why pull out random numbers out of your ass?

Re: AT&T updates firmware to block access to 1.1.1.1

#143
post #75

This is likely due to incompetence, not malice. FWIW, it’s possible to bypass AT&T’s router: https://github.com/jaysoffian/eap_proxy That said, I tried 1.1.1.1 and found I had to switch back to Google DNS since Cloudflare intentionally doesn’t support EDNS Client Subnet which was causing my AppleTV’s to have trouble loading content.

I don't know much about networking, but I do have that router. Can you please explain what this does/why someone would want this?

Re: AT&T updates firmware to block access to 1.1.1.1

#144

Earlier quoted context omitted.

I was using 1.1.1.1 with AT&T Fiber and it stopped working. I didn't really question it, I figured maybe something went down at Cloudflare so I just switched my Mac back to using the defaults again. It never even occurred to me that AT&T might be blocking it. Maybe stupid question, but why would AT&T block it?

They want you using their DNS for traffic snooping?

Pretty sure they don't block 8.8.8.8 though.

Re: AT&T updates firmware to block access to 1.1.1.1

#145
post #118

Earlier quoted context omitted.

https://blog.cloudflare.com/dns-resolver-1-1-1-1/ > For IPv6, we have chosen 2606:4700:4700::1111 and 2606:4700:4700::1001 for our service. It’s not as easy to get cool IPv6 addresses; however, we’ve picked an address that only uses digits. For me up in Canada, ping 1.1.1.1 works. But ping6 2606:4700:4700::1111 ping6 2606:4700:4700::1001 shows "connect: Network is unreachable". Am I using ping6 wrong? We also need to…

You're using the IPV6 address correctly, does https://test-ipv6.com report everything's dandy for you? If it does maybe they're blocking traffic or there's something else going on.

> No IPv6 address detected. Connections to IPv6-only sites are timing out. Any web site that is IPv6 only, will appear to be down to you.

Okay, guess my PC/LAN/ISP doesn't support IPv6 yet.

Re: AT&T updates firmware to block access to 1.1.1.1

#146

Earlier quoted context omitted.

Having it seem like a bug would be an effective way to block it intentionally. The timing of such an unusual regression is suspicious. The fact that 1.0.0.1 is also blocked is also suspicious.

A conspiratorial Hanlon's corollary: The most effective malice is that which can be ascribed to incompetence.

Have you seen the Underhanded C Contest? http://www.underhanded-c.org/_page_id_5.html

"Bugs are worth more points if, once discovered, they are plausibly deniable as an innocent programming error."

Re: AT&T updates firmware to block access to 1.1.1.1

#147
post #87
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

Then the odds appear to not be in our favor. CF CEO tweets that 1.0.0.1 is also blocked. https://twitter.com/eastdakota/status/991718955021623296 Others have confirmed that the ipv6 address belonging to CF appears to be blocked.

Just curious - can cloudflare blackhole all of Att traffic?

Re: AT&T updates firmware to block access to 1.1.1.1

#148
Shanghai. One of the largest Chinese data-centers with direct peering to all major national networks. I'm inside, testing a new colocation unit we just put there. Pinging 1.1.1.1 in 4.2ms, wow! Putting it in resolv.conf. Nothing works. WTF? Turns out they route 1.1.1.1 across the whole DC to one of their internal services "for engineers' convenience". Not gonna change. TIC.

Re: AT&T updates firmware to block access to 1.1.1.1

#149
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

A university I went to used 1.1.1.1 for its WiFi loginpage

I thiught thats what early cisco (after they bought air-something) used c. 2005 or so

Re: AT&T updates firmware to block access to 1.1.1.1

#150
post #95
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

1.1.1.1 was working for me on AT&T after Cloudflare released 1.1.1.1, then shortly after that it ceased working. Maybe the firmware update has a bug, but it's very suspiciously timed. Notice that the OP is dated April 2, while 1.1.1.1 was released April 1.

If they were so determined to block it, why would they do it in firmware and not upstream? I think people are reading too much into this.
Post reply on HN