Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

251–260 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#251

Earlier quoted context omitted.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

I would guess it has something to do with cisco asking them to help alleviate issues with their 1.1.1.1 squatting on a bunch of devices. I tested it when it came out, and if I set my DNS to 1.1.1.1, then logged into a hotel wireless network (that I knew was running those devices), as soon as a request was made, I was logged out of the captive portal. I would have expected 1.1.1.1 to already be blocked if anyone filte…

The most referred to bogon list is Team Cymru:

https://www.team-cymru.com/bogon-reference.html

This team provide a great side service - you can setup BGP with them using an internal AS. It's one of the few ways you can get practical experience setting up BGP in the home with a third party. I'm running it right now.

Re: AT&T updates firmware to block access to 1.1.1.1

#252
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

Isn't that what net neutrality is all about?

Re: AT&T updates firmware to block access to 1.1.1.1

#253
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

Blocking 1.1.1.1 -> 98% chance it is a bug

Blocking 1.1.1.1 and 1.0.0.1 -> what are the odds here?

Re: AT&T updates firmware to block access to 1.1.1.1

#255

Earlier quoted context omitted.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

You can't be too mad about the full port range. Residential ISPs blocking port 25 outbound (spam malware) and inbound (people installing mailer services as an open relay by default) contributed to tonnes of unwanted traffic. I know there was an amount of collateral damage, but if you think about it, it's been many years since malware would get in user desktops and just send spam, largely due to this.

It's the internet, blocking ports without explicit reason is totally unacceptable. It's also in most cases since people will just tunnel their traffic over ports used by other applications, such as 80.

The right response is to contact the owners of the servers/services they're running and tell them to configure them correctly - if they continue to abuse them or don't show the technical skills, then that's another matter.

Re: AT&T updates firmware to block access to 1.1.1.1

#256
post #238

From https://en.wikipedia.org/wiki/1.1.1.1#Criticism_and_problems : Technological websites noted that by using 1.1.1.1 as the IP address for their service, Cloudflare created problems with existing setups. While 1.1.1.1 was not a reserved IP address, it was and is used by many existing routers (mostly those sold by Cisco Systems) and companies for hosting login pages to private networks, exit pages or other purposes,…

That’s intentional, from what I remember. All non-DNS traffic is analyzed for research purposes (not by Cloudflare though).

A wake-up call for all those (ab)users of public address space is also desperately needed. All IPv4 addresses will soon be allocated. Failure to use only private address spaces will cause problems, very soon.

Re: AT&T updates firmware to block access to 1.1.1.1

#257

Earlier quoted context omitted.

No your parent company needs to stop abusing that IP. Cloudflare is using a conventional IP, you are the one that isn't.

I wasn't disagreeing...? They're using an IP that wasn't assigned by IANA.

What exactly do you mean by “wasn’t assigned”? According to this article [1], 1/8 was reserved in 1981. Only from 2008 to 2010 was 1.1.1.0/24 ever truly unallocated.

If, after 8 years, most providers still haven’t moved to either private networks or officially assigned networks, honestly – they suck.

[1]: https://labs.ripe.net/Members/franz/content-pollution-18

Re: AT&T updates firmware to block access to 1.1.1.1

#258

Earlier quoted context omitted.

Maybe something about being neutral on the internet.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

But at the same time doung nothing to prevent IP spoofing.
Post reply on HN