Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

271–280 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#271
post #238

From https://en.wikipedia.org/wiki/1.1.1.1#Criticism_and_problems : Technological websites noted that by using 1.1.1.1 as the IP address for their service, Cloudflare created problems with existing setups. While 1.1.1.1 was not a reserved IP address, it was and is used by many existing routers (mostly those sold by Cisco Systems) and companies for hosting login pages to private networks, exit pages or other purposes,…

What kind of demented person uses 1.1.1.1, a routable public address since 2010, for internal addresses. What's wrong with 10.0.0.0/8 or 192.168/16?

Re: AT&T updates firmware to block access to 1.1.1.1

#272
This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

Re: AT&T updates firmware to block access to 1.1.1.1

#273
post #86

Earlier quoted context omitted.

I can't see anything about the 33.0.0.0/8 range being reserved https://en.wikipedia.org/wiki/Reserved_IP_addresses

https://www.iana.org/assignments/ipv4-address-space/ipv4-add... It's allocated to "DLA Systems Automation Center," a branch of the US military. The addresses are probably used on NIPRNet/SIPRNet, but not publically routed. (Much like 22.0.0.0/8.)

The OP better not have anything juicy on his network. The Russian and Chinese are gonna be on you like a wife in a Finnish wife-carrying competition.

Don't use Kaspersky!

Re: AT&T updates firmware to block access to 1.1.1.1

#274
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

It's either malicious or a major fuck up. Either way it's worth shouting about.

It's the latter. Here is the CEO of Cloudflare tweeting about it: https://twitter.com/eastdakota/status/991718955021623296

D

Re: AT&T updates firmware to block access to 1.1.1.1

#275
post #221

Earlier quoted context omitted.

The problem with the "let the market decide" is that there is no free market for Internet access in the US! In most areas there is effectively a government imposed monopoly on who can provide you access. So there is no "market" to normalise things. You simply cannot vote with your feet. In Europe, where the regulatory framework is different, people would just switch ISPs if one started acting in bad faith.

>In most areas there is effectively a government imposed monopoly on who can provide you access. And that government is elected by the people, right? Which means they could make this an election issue and vote candidates that don't support monopolies, right? I don't understand what part of my statement you're arguing with.

That would be less of a problem if most US elections weren't duopolies as well.

Re: AT&T updates firmware to block access to 1.1.1.1

#276

This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

Re: AT&T updates firmware to block access to 1.1.1.1

#277

This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

"Never attribute to malice that which is adequately explained by stupidity"

Re: AT&T updates firmware to block access to 1.1.1.1

#278
post #59

Earlier quoted context omitted.

They were blocking 1.1.1.1 on some firmwares long before cloudflare's dns service started. From what I've read, the routers use it on some internal interface. It's likely incompetence, not malice. If they didn't want people using other DNS, and were willing to fuck with ip addresses they don't own to accomplish that, they'd be blackholing google's and opendns's public caching nameservers too. It might even have been…

I like to use 33.0.0.0/8 for that stuff since I don't believe any of those IPs are available on the open internet.

Until they are and then everything breaks, which is basically what happened for 1.1.1.1.

Re: AT&T updates firmware to block access to 1.1.1.1

#279
post #182

Earlier quoted context omitted.

The arguments for anti-net-neutrality has basically come down to "let the free market sort it out." I don't agree with that, but if we can't have net neutrality, at least define to the customers what the "internet" means. And in that case, the town just lost it's internet. What makes you think the residents won't remember this come election day?

Except they haven't, really. They can still turn on their phone and login onto Facebook and watch stuff on YouTube. Someone telling them they no longer have Internet will just sound silly.

Oh god I really hate that that sounds so accurate in so many cases.

How do we provide a kiddie day care service level for people who won't or don't want to care, and a full service level for the rest of us?

Or do I owe the Internet an apology?

Re: AT&T updates firmware to block access to 1.1.1.1

#280

This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

and theres nothing we can do about it.
Post reply on HN