Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

121–130 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#121
post #95
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

1.1.1.1 was working for me on AT&T after Cloudflare released 1.1.1.1, then shortly after that it ceased working. Maybe the firmware update has a bug, but it's very suspiciously timed. Notice that the OP is dated April 2, while 1.1.1.1 was released April 1.

I was using 1.1.1.1 with AT&T Fiber and it stopped working. I didn't really question it, I figured maybe something went down at Cloudflare so I just switched my Mac back to using the defaults again. It never even occurred to me that AT&T might be blocking it.

Maybe stupid question, but why would AT&T block it?

Re: AT&T updates firmware to block access to 1.1.1.1

#122
post #84

Earlier quoted context omitted.

You're absolutely right about this. This is almost certainly just there to block people who mistakenly paste in an example configuration somewhere. Back in 2010 there were problems that came up when IANA started allocating out of 1.0.0.0/8 (e.g. [1]). Things that were once assumed to be unused started being used, leading to strange issues. Also, why on earth would AT&T block 1.1.1.1 and not Google DNS and OpenDNS? [1…

According to the thread the timing on this looks pretty bad since those DNS IPs were previously working on the earlier firmware.

How would it make sense to block it only on a small fraction of their entire network? It wouldn't accomplish anything.

Re: AT&T updates firmware to block access to 1.1.1.1

#123
post #95

Earlier quoted context omitted.

1.1.1.1 was working for me on AT&T after Cloudflare released 1.1.1.1, then shortly after that it ceased working. Maybe the firmware update has a bug, but it's very suspiciously timed. Notice that the OP is dated April 2, while 1.1.1.1 was released April 1.

I was using 1.1.1.1 with AT&T Fiber and it stopped working. I didn't really question it, I figured maybe something went down at Cloudflare so I just switched my Mac back to using the defaults again. It never even occurred to me that AT&T might be blocking it. Maybe stupid question, but why would AT&T block it?

They want you using their DNS for traffic snooping?

Re: AT&T updates firmware to block access to 1.1.1.1

#124
post #84
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

You're absolutely right about this. This is almost certainly just there to block people who mistakenly paste in an example configuration somewhere. Back in 2010 there were problems that came up when IANA started allocating out of 1.0.0.0/8 (e.g. [1]). Things that were once assumed to be unused started being used, leading to strange issues. Also, why on earth would AT&T block 1.1.1.1 and not Google DNS and OpenDNS? [1…

when 1.1.1.1 was first announced a few weeks ago, many people pointed out at the time that it was already blocked because so many people had effectively polluted it by over-using it for demo examples and testing traffic. CF announced they knew this and intended to do a project analyzing the data. Perhaps this done, whether conveniently or not, with the same intention. We'll see if they reverse it.

Re: AT&T updates firmware to block access to 1.1.1.1

#126
post #118
post #97

Earlier quoted context omitted.

Do you have a reference for the ipv6 address being blocked? That would be a much bigger smoking gun

https://blog.cloudflare.com/dns-resolver-1-1-1-1/ > For IPv6, we have chosen 2606:4700:4700::1111 and 2606:4700:4700::1001 for our service. It’s not as easy to get cool IPv6 addresses; however, we’ve picked an address that only uses digits. For me up in Canada, ping 1.1.1.1 works. But ping6 2606:4700:4700::1111 ping6 2606:4700:4700::1001 shows "connect: Network is unreachable". Am I using ping6 wrong? We also need to…

You're using the IPV6 address correctly, does https://test-ipv6.com report everything's dandy for you? If it does maybe they're blocking traffic or there's something else going on.

Re: AT&T updates firmware to block access to 1.1.1.1

#127
post #118
post #97

Earlier quoted context omitted.

Do you have a reference for the ipv6 address being blocked? That would be a much bigger smoking gun

https://blog.cloudflare.com/dns-resolver-1-1-1-1/ > For IPv6, we have chosen 2606:4700:4700::1111 and 2606:4700:4700::1001 for our service. It’s not as easy to get cool IPv6 addresses; however, we’ve picked an address that only uses digits. For me up in Canada, ping 1.1.1.1 works. But ping6 2606:4700:4700::1111 ping6 2606:4700:4700::1001 shows "connect: Network is unreachable". Am I using ping6 wrong? We also need to…

most modern linux distros regular `ping` will work for ipv6.

(US based) frontier, vz, and spectrum all can ping that ipv6 address (though all have way over 10ms latency)

Re: AT&T updates firmware to block access to 1.1.1.1

#128
post #36
post #17

Earlier quoted context omitted.

That’s what I want to know. I’ll save the soapbox speech and just leave it at isn’t this why monopoly laws exist?

The issue is that the cable companies have monopolies set in law already. There are numerous regulations designed to stop any new last-mile telecom companies from starting up, which literally guarantees a monopoly for the few companies that already exist in the vast majority of the US. As good as Net Neutrality sounds in theory, all we really need to do is drop the regulations and allow new players to enter the game…

[deleted]

Re: AT&T updates firmware to block access to 1.1.1.1

#129
post #118
post #97

Earlier quoted context omitted.

Do you have a reference for the ipv6 address being blocked? That would be a much bigger smoking gun

https://blog.cloudflare.com/dns-resolver-1-1-1-1/ > For IPv6, we have chosen 2606:4700:4700::1111 and 2606:4700:4700::1001 for our service. It’s not as easy to get cool IPv6 addresses; however, we’ve picked an address that only uses digits. For me up in Canada, ping 1.1.1.1 works. But ping6 2606:4700:4700::1111 ping6 2606:4700:4700::1001 shows "connect: Network is unreachable". Am I using ping6 wrong? We also need to…

I tested out both addresses via my phone's web browser just now.

Connecting to WiFi (Time Warner), I got a 403 from cloudflare (presumably there just isn't a web server set up on that address).

Using mobile data (AT&T), I got ERR_ADDRESS_UNREACHABLE. However, 1.1.1.1 actually works on AT&T cellular, so I'm not sure what to think.

Re: AT&T updates firmware to block access to 1.1.1.1

#130
post #52
post #14

Earlier quoted context omitted.

The argument I've made is that if they're blocking certain parts of the internet, then they shouldn't be allowed to call themselves an Internet Service Provider.

I've made this argument before (and it does make some sense), but I also doubt that enough people will understand this nuance for it to really matter.

> but I also doubt that enough people will understand this nuance for it to really matter.

Certainly that's the first step.

There's options for the second step. But advertising seems like it would be the most powerful.

"Why use us over AT&T? Because you're not getting the Internet. You're getting what AT&T decides you should look at."

"We don't block Netflix or Hulu or a whole host of other streaming services, unlike AT&T"

Post reply on HN