Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

241–250 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#241
post #118
post #97

Earlier quoted context omitted.

Do you have a reference for the ipv6 address being blocked? That would be a much bigger smoking gun

https://blog.cloudflare.com/dns-resolver-1-1-1-1/ > For IPv6, we have chosen 2606:4700:4700::1111 and 2606:4700:4700::1001 for our service. It’s not as easy to get cool IPv6 addresses; however, we’ve picked an address that only uses digits. For me up in Canada, ping 1.1.1.1 works. But ping6 2606:4700:4700::1111 ping6 2606:4700:4700::1001 shows "connect: Network is unreachable". Am I using ping6 wrong? We also need to…

fwiw, I am an AT&T customer in Atlanta on their fiber service.

the nslookup reddit.com 1.1.1.1 does not return for me, if I connect to work via VPN it does. 1.0.0.1 and 8.8.8.8 do work without VPN. while the AT&T modem shows IPV6 I did not test.

System Information Type Value Manufacturer Pace Plc Model 5268AC

Re: AT&T updates firmware to block access to 1.1.1.1

#242

Earlier quoted context omitted.

Maybe something about being neutral on the internet.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

I had one provider interfering with war thunder traffic somehow. packet loss always in the 20%+, which disappeared immediately if tunneled trough a vpn. switched provider and while war thunder now works, I can't play anymore dwarf fortress remote on my ipad.

even diagnosing the issue and finding someone on the other side that understand the topic is hard. I'm no network engineer and definitely neither are the support guys.

it's just a roulette. you have to change until you find one that works. and it sucks.

Re: AT&T updates firmware to block access to 1.1.1.1

#243
post #221

Earlier quoted context omitted.

The problem with the "let the market decide" is that there is no free market for Internet access in the US! In most areas there is effectively a government imposed monopoly on who can provide you access. So there is no "market" to normalise things. You simply cannot vote with your feet. In Europe, where the regulatory framework is different, people would just switch ISPs if one started acting in bad faith.

>In most areas there is effectively a government imposed monopoly on who can provide you access. And that government is elected by the people, right? Which means they could make this an election issue and vote candidates that don't support monopolies, right? I don't understand what part of my statement you're arguing with.

This doesnt work well in practice though.

Most people don't have the grasp on the technicalities to even be able to make the decision to vote for a specific candidates because their internet access is sub-par

Not to mention if you vote for someone you also get all the other things that candidate aligns with, not just better internet.

(not super sure how voting on city/state level works in the us, but it should be accurate enough)

Re: AT&T updates firmware to block access to 1.1.1.1

#244

Earlier quoted context omitted.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

I would guess it has something to do with cisco asking them to help alleviate issues with their 1.1.1.1 squatting on a bunch of devices. I tested it when it came out, and if I set my DNS to 1.1.1.1, then logged into a hotel wireless network (that I knew was running those devices), as soon as a request was made, I was logged out of the captive portal. I would have expected 1.1.1.1 to already be blocked if anyone filte…

1/8 hasn't been "bogus" since 1/2010. ( http://www.iana.org/assignments/ipv4-address-space/ipv4-addr... )

Using unallocated IPs for "internal" or bogus purposes is sketchy, continuing to use them after they are allocated is something else. Especially so nearly a decade on.

Re: AT&T updates firmware to block access to 1.1.1.1

#245
post #202

Earlier quoted context omitted.

Maybe not-really-ISPs should be made ineligible for certain privileges / rights given to real ISPs. Like not-really-doctors can't do everything that real doctors can (grasping for a better analogy).

Other entities could punish them by revoking peering agreements. Or if CloudFlare wanted to play hardball, they could deny access to their CDN from AT&T IP ranges. That would be punishing AT&T customers further, but it would get their attention quickly and they'd complain to their ISP.

It would also be punishing CloudFlare customers quite a lot.

Taking a moral stand is honorable, but using your customers to do it isn't.

Re: AT&T updates firmware to block access to 1.1.1.1

#246
post #235
post #228

Earlier quoted context omitted.

I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy. But hey, if you have advanced needs, no problem, let me refer you too our Gaming Provider and Streaming Provider subsidiaries. Oh you need actual technical access to the internet because you write your own software? Tricky, but I'm sure our Business Technology Services Provider…

> I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy. They'd also become unreliable and untrustworthy. "Mom, I'm going over to Timmy's house tonight. They have _good_ Internet"

"Mom, I'm going over to Timmy's house tonight. They have more internet, not just Facebook!"

Re: AT&T updates firmware to block access to 1.1.1.1

#248

Earlier quoted context omitted.

Maybe something about being neutral on the internet.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

You can't be too mad about the full port range. Residential ISPs blocking port 25 outbound (spam malware) and inbound (people installing mailer services as an open relay by default) contributed to tonnes of unwanted traffic.

I know there was an amount of collateral damage, but if you think about it, it's been many years since malware would get in user desktops and just send spam, largely due to this.

Re: AT&T updates firmware to block access to 1.1.1.1

#249
post #14

Earlier quoted context omitted.

The argument I've made is that if they're blocking certain parts of the internet, then they shouldn't be allowed to call themselves an Internet Service Provider.

Great point. Like at some point Hershey was on the verge to lose ability to call it's chocolate 'milk chocolate' because it's contents didn't have enough of it and cocoa. I really love your idea.

"Internet-like product"

Re: AT&T updates firmware to block access to 1.1.1.1

#250
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

>in order to promote their own business model.

What's the theory exactly? What would be the benefit for AT&T to block a new 3rd party DNS? Did they do similar things in the past for other 3rd party DNSs such as OpenDNS, Quad9 or Google's? Seems odd to target this one service in particular.

Post reply on HN