Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

231–240 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#231

Earlier quoted context omitted.

It's very unfortunate that people are simply fatigued of fighting this fight. Also see the UK as well for an example of how previously unregulated speech has become regulated because the authorities have pushed over and over again, backing off every time there's a loud enough protest, but trying again after a short time.

All the stuff in the UK is voluntary (except the traffic analysis snooping stuff, but that's centralised and the Americans were doing that to their own citizens when it was theoretically illegal, so, meh). All the big famous ISPs you see advertising on TV have decided to volunteer to censor, but it's not a law. Smaller specialist ISPs just say "No". Mine even had a thing saying look at this great endorsement and it w…

The digital economy act 2017 requires porn with "insufficient" age verification to be blocked. Required by law.

So exactly what parent said, happened.

Re: AT&T updates firmware to block access to 1.1.1.1

#232

Earlier quoted context omitted.

I was using 1.1.1.1 with AT&T Fiber and it stopped working. I didn't really question it, I figured maybe something went down at Cloudflare so I just switched my Mac back to using the defaults again. It never even occurred to me that AT&T might be blocking it. Maybe stupid question, but why would AT&T block it?

A few others have mentioned this already, but 1.1.1.1 has become a colloquial private address, used either as a blackhole or as a destination for internal traffic. Sort of like how 555-5555 technically isn't reserved (only 555-01xx is, according to Wikipedia), but practically, it's not really a workable number and phone companies don't hand it out. According to the announcement post, part of the reason that Cloudflar…

Not an acceptable thing to do silently though, in any term.

Re: AT&T updates firmware to block access to 1.1.1.1

#233
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

I really hope that's the case, was 1.1.1.1 allocated before CF acquired it? Was 1.0.0.1 also blocked?

1.1.1.0/24 was reserved by APNIC for research use.

Lots of cisco example config use 1.1.1.1 for router internal identifier / DHCP server / OSPF dummy network .

Not suprised if it break anything.

Re: AT&T updates firmware to block access to 1.1.1.1

#234
post #59

Earlier quoted context omitted.

They were blocking 1.1.1.1 on some firmwares long before cloudflare's dns service started. From what I've read, the routers use it on some internal interface. It's likely incompetence, not malice. If they didn't want people using other DNS, and were willing to fuck with ip addresses they don't own to accomplish that, they'd be blackholing google's and opendns's public caching nameservers too. It might even have been…

I like to use 33.0.0.0/8 for that stuff since I don't believe any of those IPs are available on the open internet.

Which is the exact problem that we're seeing, here. "Oh, I know, I'll just use a segment allocated to somebody else; it's not like they use it!" Aaand...whoops, they do.

Re: AT&T updates firmware to block access to 1.1.1.1

#235
post #228
post #14

Earlier quoted context omitted.

The argument I've made is that if they're blocking certain parts of the internet, then they shouldn't be allowed to call themselves an Internet Service Provider.

I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy. But hey, if you have advanced needs, no problem, let me refer you too our Gaming Provider and Streaming Provider subsidiaries. Oh you need actual technical access to the internet because you write your own software? Tricky, but I'm sure our Business Technology Services Provider…

> I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy.

They'd also become unreliable and untrustworthy.

"Mom, I'm going over to Timmy's house tonight. They have _good_ Internet"

Re: AT&T updates firmware to block access to 1.1.1.1

#236
post #11

Earlier quoted context omitted.

I think they'll block 8.8.8.8 if the anger for blocking 1.1.1.1 isn't too loud. I think they're blocking 1.1.1.1 because customers are now using DNS that isn't them, which deprives them of valuable data on which domain names their customers go to, which they can sell to advertisers. Yes, there's other ways to get that information but the DNS server is an easy one.

> I think they'll block 8.8.8.8 if the anger for blocking 1.1.1.1 isn't too loud. On what basis? Google started Google Public DNS in 2009 and, as far as I know, it was never intentionally blocked by any ISPs. The issue with 1.1.1.1 is a lot of hardware treats it as though it was reserved for private networks. For instance, I can't access 1.1.1.1 right now since I'm connected to a Cisco router. So this could very well…

> As far as I know, it was never intentionally blocked by any ISPs.

My Spanish ISP (Vodafone ES) doesn't block external DNS at the ISP level. However, the router they give you:

1) Blocks outgoing DNS requests from the internal network by default. This can be disabled.

2) Doesn't let you specify any other than Vodafone's DNS servers on the DHCP Server configuration. This cannot be changed.

I'll let you decide whether this is blocking or not...

Re: AT&T updates firmware to block access to 1.1.1.1

#237
post #66

That's so crazy, I actually experienced this today. I've been using 1.1.1.1, and today went to the library for a quick work break. I pulled out my laptop and tried to connect to the wifi, and it wasn't working. After a few minutes of troubleshooting, I tried deleting my custom DNS entry in my network settings and that did the trick. I guess the library uses AT&T routers.

No, they use that for captive portals or broadcasts.

Exactly. This is why 1.1.1.1 won't work on Airplane WiFi either.

Re: AT&T updates firmware to block access to 1.1.1.1

#238
From https://en.wikipedia.org/wiki/1.1.1.1#Criticism_and_problems :

Technological websites noted that by using 1.1.1.1 as the IP address for their service, Cloudflare created problems with existing setups. While 1.1.1.1 was not a reserved IP address, it was and is used by many existing routers (mostly those sold by Cisco Systems) and companies for hosting login pages to private networks, exit pages or other purposes, rendering the use of 1.1.1.1 as a manually configured DNS server impossible on those systems. Additionally, 1.1.1.1 is blocked on many networks and by multiple ISPs because the simplicity of the address means that it was previously often used for testing purposes and not legitimate use. These previous uses has lead to a huge influx of "garbage" data to Cloudflare's servers.

Re: AT&T updates firmware to block access to 1.1.1.1

#239

My parent company uses 1.1.1.1 as a captive portal address on the guest network. Easy to remember, but cloudflare probably needs to stand up some more conventional DNS ips.

No your parent company needs to stop abusing that IP.

Cloudflare is using a conventional IP, you are the one that isn't.

Re: AT&T updates firmware to block access to 1.1.1.1

#240

My parent company uses 1.1.1.1 as a captive portal address on the guest network. Easy to remember, but cloudflare probably needs to stand up some more conventional DNS ips.

No your parent company needs to stop abusing that IP. Cloudflare is using a conventional IP, you are the one that isn't.

I wasn't disagreeing...? They're using an IP that wasn't assigned by IANA.
Post reply on HN