Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

261–270 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#261
post #253
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

Blocking 1.1.1.1 -> 98% chance it is a bug Blocking 1.1.1.1 and 1.0.0.1 -> what are the odds here?

Only one may be coincidental. Two is enemy action.

Re: AT&T updates firmware to block access to 1.1.1.1

#262
post #235
post #228

Earlier quoted context omitted.

I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy. But hey, if you have advanced needs, no problem, let me refer you too our Gaming Provider and Streaming Provider subsidiaries. Oh you need actual technical access to the internet because you write your own software? Tricky, but I'm sure our Business Technology Services Provider…

> I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy. They'd also become unreliable and untrustworthy. "Mom, I'm going over to Timmy's house tonight. They have _good_ Internet"

"Mom, we need to move downtown, where there are two competing shady ISPs and not just the one we've got here, so we can buy different packages from both to get 95% of the Internet we need."

Re: AT&T updates firmware to block access to 1.1.1.1

#263
post #14

Earlier quoted context omitted.

The argument I've made is that if they're blocking certain parts of the internet, then they shouldn't be allowed to call themselves an Internet Service Provider.

Great point. Like at some point Hershey was on the verge to lose ability to call it's chocolate 'milk chocolate' because it's contents didn't have enough of it and cocoa. I really love your idea.

You know what happens then . . .

"Last year, a number of industry groups lobbied for a change to the FDA’s definition of chocolate — a change that would have allowed cocoa butter to be replaced with vegetable oil. At the time, Hershey’s spokesman Kirk Saville told the Harrisburg Patriot-News that “there are high-quality oils available which are equal to or better than cocoa butter in taste, nutrition, texture and function, and are preferred by consumers.”"

https://www.today.com/food/chocoholics-sour-new-hersheys-for...

Re: AT&T updates firmware to block access to 1.1.1.1

#264
post #212
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

This is almost funny. We have the exact opposite problem in Sweden, it was just in the news today. One ISP has been convicted for allowing access to facebook even though the user has reached it's data limit for the month. This is unfair competition since the local swedish newspapers are still blocked when you reach your limit.

This is so-called zero rating. EU net neutrality regs are usually interpreted as banning it, at least on fixed line connections (mobile is more sketchy). Enforcement by country varies wildly, though, as is often the problem with EU regs.

Re: AT&T updates firmware to block access to 1.1.1.1

#265
post #250
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

>in order to promote their own business model. What's the theory exactly? What would be the benefit for AT&T to block a new 3rd party DNS? Did they do similar things in the past for other 3rd party DNSs such as OpenDNS, Quad9 or Google's? Seems odd to target this one service in particular.

I would think that being able to see what people are looking up would be quite valuable to an ISP; would help with customer profiling and selling ads.

The ship may have sailed on blocking 8.8.8.8 at this point; some things _hard-code_ it.

Re: AT&T updates firmware to block access to 1.1.1.1

#266

Earlier quoted context omitted.

I would guess it has something to do with cisco asking them to help alleviate issues with their 1.1.1.1 squatting on a bunch of devices. I tested it when it came out, and if I set my DNS to 1.1.1.1, then logged into a hotel wireless network (that I knew was running those devices), as soon as a request was made, I was logged out of the captive portal. I would have expected 1.1.1.1 to already be blocked if anyone filte…

1/8 hasn't been "bogus" since 1/2010. ( http://www.iana.org/assignments/ipv4-address-space/ipv4-addr... ) Using unallocated IPs for "internal" or bogus purposes is sketchy, continuing to use them after they are allocated is something else. Especially so nearly a decade on.

The wheels of technological change in the Telecom space turn very, VERY slowly.

Not upgrading equipment and configs for 10 years is nothing in the ISP world.

Re: AT&T updates firmware to block access to 1.1.1.1

#267

Earlier quoted context omitted.

Net neutrality started disappearing long before it was even called "net neutrality" --- a lot of residential ISPs won't even let others send packets to the full 64K port range of TCP/UDP to the IP it gives you, blocking some of them for "security reasons", throttling/cutting off certain protocols like BitTorrent, censoring "malicious" sites, etc. If we want true Internet connections we're going to have to fight a lot…

I would guess it has something to do with cisco asking them to help alleviate issues with their 1.1.1.1 squatting on a bunch of devices. I tested it when it came out, and if I set my DNS to 1.1.1.1, then logged into a hotel wireless network (that I knew was running those devices), as soon as a request was made, I was logged out of the captive portal. I would have expected 1.1.1.1 to already be blocked if anyone filte…

For anyone else wondering:

> A bogon prefix is a route that should never appear in the Internet routing table. A packet routed over the public Internet (not including over VPNs or other tunnels) should never have a source address in a bogon range. These are commonly found as the source addresses of DDoS attacks.

Re: AT&T updates firmware to block access to 1.1.1.1

#268

It shocks me that there are no AT&T network/sysadmins at the right level and department on this forum that don't cringe in shame and sort this out.

I'm certain there are, but AT&T is a 250,000-person organization with a bureaucracy to match. Things take weeks to sort out, assuming the right person is pushing for it.

Re: AT&T updates firmware to block access to 1.1.1.1

#269
post #228
post #14

Earlier quoted context omitted.

The argument I've made is that if they're blocking certain parts of the internet, then they shouldn't be allowed to call themselves an Internet Service Provider.

I think ISPs would be welcoming to that change. They'd market as "WWW-Providers" or "Social media providers" and most people would be happy. But hey, if you have advanced needs, no problem, let me refer you too our Gaming Provider and Streaming Provider subsidiaries. Oh you need actual technical access to the internet because you write your own software? Tricky, but I'm sure our Business Technology Services Provider…

No doubt. That is absolutely how it would work out.

Re: AT&T updates firmware to block access to 1.1.1.1

#270
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

It's either malicious or a major fuck up. Either way it's worth shouting about.
Post reply on HN