Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

11–20 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#11
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

Are they blocking 8.8.8.8? Why do you think they're blocking 1.1.1.1?

I think they'll block 8.8.8.8 if the anger for blocking 1.1.1.1 isn't too loud.

I think they're blocking 1.1.1.1 because customers are now using DNS that isn't them, which deprives them of valuable data on which domain names their customers go to, which they can sell to advertisers. Yes, there's other ways to get that information but the DNS server is an easy one.

Re: AT&T updates firmware to block access to 1.1.1.1

#13
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

Are they blocking 8.8.8.8? Why do you think they're blocking 1.1.1.1?

Because users were able to connect and after the firmware update they are not? And also because they didn't even let you change this setting to begin with.

There is not enough data to attribute this to malice yet, but it does not look good (see CloudFlare's tweet).

Re: AT&T updates firmware to block access to 1.1.1.1

#14
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

The argument I've made is that if they're blocking certain parts of the internet, then they shouldn't be allowed to call themselves an Internet Service Provider.

Re: AT&T updates firmware to block access to 1.1.1.1

#15
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

Maybe something about being neutral on the internet.

Re: AT&T updates firmware to block access to 1.1.1.1

#16
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

Are they blocking 8.8.8.8? Why do you think they're blocking 1.1.1.1?

Curious to know if they block Google’s DNS servers as well. That 1.x space was a RIPE research segment, so it’s possible that some internal AT&T group was using it with the assumption it would not be publicly routable and got bit. I was enjoying the shorthand ping of 1.1 for my router at home until Cloudflare took it over. Needless to say, if that was the case for AT&T, their ‘fix’ is not at all acceptable.

Re: AT&T updates firmware to block access to 1.1.1.1

#17
post #2

Cloudflare's CEO confirms: https://twitter.com/eastdakota/status/991718955021623296

How is this not illegal?

That’s what I want to know. I’ll save the soapbox speech and just leave it at isn’t this why monopoly laws exist?

Re: AT&T updates firmware to block access to 1.1.1.1

#18
post #5
post #4

How are they going to spy on your DNS traffic and sell it to advertisers after you secure it?

For most people who aren't configuring DNSec or TLS can't the ISP still see all of the plain-text domain names in port 53 traffic?

Yes, they can; regardless of your resolver they can collect that if you're not using DNSec.

Same goes for https handshakes leaking your target domain(otherwise SNI wouldn't work), so DNSSec alone is fairly pointless for regular web traffic obfuscation; and of course the IP is in each TCP frame regardless.

It becomes more a matter of are they doing it yet(re:DNS monitoring in this manner); with enough people using third party resolvers(I'd argue google's public DNS already has enough usage to warrant it) they will be.

Optimally you'd VPN at all times to a provider you trust or one you've setup yourself.

What it all really boils down to though is that the populace simply can't be trusted(nor should they need to be) to make themselves acceptably secure from third party monitoring. We need to have much more discussion around data privacy and retention for ISP's.

It's not a matter of if the data will be misused, it's truly a matter of when and it's not fair to the general public.

Re: AT&T updates firmware to block access to 1.1.1.1

#19
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

You mean like net neutrality?
Post reply on HN