Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

171–180 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#172

Earlier quoted context omitted.

Anyone work at AT&T who could give us the inside scoop on these firmware changes? Snapping a photo of the blocking code would be a valuable public service. Remember to scrub EXIF data!

More than likely: - If the action was malicious, the people involved in writing this code are likely okay with it and not likely to leak details of it. - If the issue is a bug, the people involved in writing this code are probably working to fix it, and not likely to leak details of it. - People not involved with making it would likely leave an internal access trail (independent of EXIF data) when they access that co…

1. Probably.

2. True.

3. Unlikely; it's likely in a big repo that's synched all at once.

Alternatively, we can just obtain the firmware from a device and diff it against the last-known-working version, to see how the routing is failing.

Re: AT&T updates firmware to block access to 1.1.1.1

#173
post #87

Earlier quoted context omitted.

Then the odds appear to not be in our favor. CF CEO tweets that 1.0.0.1 is also blocked. https://twitter.com/eastdakota/status/991718955021623296 Others have confirmed that the ipv6 address belonging to CF appears to be blocked.

Just curious - can cloudflare blackhole all of Att traffic?

Could they physically? Yes. But they'd be screwing over their own customers who rely on that traffic.

Re: AT&T updates firmware to block access to 1.1.1.1

#174
post #7

Does this just apply to setting the default DNS on the router, or are the blocking traffic to 1.1.1.1 from any device connected to it?

I'm on ATT right now and I can't go to https://1.1.1.1 right now. It works fine when I disable WiFi on my phone (Verizon).

I have AT&T internet and also can't get to http://1.1.1.1. but I can on my phone using AT&T's cellular service. Apparently not all of AT&T dislikes CloudFlare.

Re: AT&T updates firmware to block access to 1.1.1.1

#175
post #95

Earlier quoted context omitted.

1.1.1.1 was working for me on AT&T after Cloudflare released 1.1.1.1, then shortly after that it ceased working. Maybe the firmware update has a bug, but it's very suspiciously timed. Notice that the OP is dated April 2, while 1.1.1.1 was released April 1.

This is what happened to me as well. It worked for a day or so and then stopped. I have ATT U-verse internet service and use their Arris BGW210-700 gateway One interesting thing is that if I go to the gateway management page, and use their diagnostic tools, I'm able to ping / traceroute the address - but I can't from any devices connected to the gateway From gateway diag page: PING 1.1.1.1 (1.1.1.1): 56 data bytes 64…

Yes, 1.1.1.1 is in use on your Arris device, the same issue with the 5268AC since day one.

Re: AT&T updates firmware to block access to 1.1.1.1

#177

Earlier quoted context omitted.

I was using 1.1.1.1 with AT&T Fiber and it stopped working. I didn't really question it, I figured maybe something went down at Cloudflare so I just switched my Mac back to using the defaults again. It never even occurred to me that AT&T might be blocking it. Maybe stupid question, but why would AT&T block it?

They want you using their DNS for traffic snooping?

They can snoop on your DNS anyways.

Re: AT&T updates firmware to block access to 1.1.1.1

#179
post #95

Earlier quoted context omitted.

1.1.1.1 was working for me on AT&T after Cloudflare released 1.1.1.1, then shortly after that it ceased working. Maybe the firmware update has a bug, but it's very suspiciously timed. Notice that the OP is dated April 2, while 1.1.1.1 was released April 1.

A possible explanation is that the traffic from active use of 1.1.1.1 caused some backend service to get overloaded with traffic due to a faulty assumption that the address would never be used by customers. Anyone keep traceroutes while before the patch to see if there were errant stops or delays? They had the choice of "fix the whole backend" or "block 1.x on the user end". Guess we know which one was easier. If all…

1.1.1.1 is well known (based on the announcement from cloudflare anyway) to have tons of random traffic. That's part of the reason it wasn't implemented by others as a valid address for anything. Could the fact that they're simply allowing traffic at that address cause additional stress on AT&T's network?

I ask because I don't know. I figure any traffic headed that direction would go anyway it just wouldn't get routed very far with no valid destination.

Post reply on HN