Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

31–40 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#31
post #16

Earlier quoted context omitted.

Are they blocking 8.8.8.8? Why do you think they're blocking 1.1.1.1?

Curious to know if they block Google’s DNS servers as well. That 1.x space was a RIPE research segment, so it’s possible that some internal AT&T group was using it with the assumption it would not be publicly routable and got bit. I was enjoying the shorthand ping of 1.1 for my router at home until Cloudflare took it over. Needless to say, if that was the case for AT&T, their ‘fix’ is not at all acceptable.

[deleted]

Re: AT&T updates firmware to block access to 1.1.1.1

#32

What is the likelihood of obtaining net neutrality through the courts? I.E. Cloudflare sues -> judicial process -> decision that establishes a "right to access"?

Likely 0% chance. The court cannot just go off and make up its own laws because it wants to, all it can do is decide how existing laws should be applied.

Re: AT&T updates firmware to block access to 1.1.1.1

#33
post #21

Earlier quoted context omitted.

How is this not illegal?

Because as it stands right now, AT&T sells you access to their network. What happens on their network is for AT&T to decide. With the FCC striking down net neutrality [1], AT&T is probably testing out the waters. [1] According to google, it's defined as: "the principle that Internet service providers should enable access to all content and applications regardless of the source, and without favoring or blocking partic…

They've done this before, during, and after net neutrality. AT&T regularly blocks entire ranges at the IP level because they are "suspected of cyberattacks." I've frequently had issues with web hosts who are blocked only on AT&T, and this was the case in October-November (before the FCC vote) while I was launching a new site.

Re: AT&T updates firmware to block access to 1.1.1.1

#34
post #5
post #4

How are they going to spy on your DNS traffic and sell it to advertisers after you secure it?

For most people who aren't configuring DNSec or TLS can't the ISP still see all of the plain-text domain names in port 53 traffic?

DNSSEC doesn’t encrypt DNS traffic; it only signs it.

Re: AT&T updates firmware to block access to 1.1.1.1

#35

Earlier quoted context omitted.

> I think they'll block 8.8.8.8 if the anger for blocking 1.1.1.1 isn't too loud. On what basis? Google started Google Public DNS in 2009 and, as far as I know, it was never intentionally blocked by any ISPs. The issue with 1.1.1.1 is a lot of hardware treats it as though it was reserved for private networks. For instance, I can't access 1.1.1.1 right now since I'm connected to a Cisco router. So this could very well…

> I can't access 1.1.1.1 right now since I'm connected to a Cisco router. I've never seen or heard of a Cisco router doing anything that would interfere with access to 1.1.1.1. Their wireless LAN controllers on the other hand, use 1.1.1.1 as the default (but entirely configurable) Virtual IP to use as an anchor for the captive portal. If you can't access 1.1.1.1 behind a Cisco router it's likely because someone set i…

> I've never seen or heard of a Cisco router doing anything that would interfere with access to 1.1.1.1.

Well, now you have.

> If you can't access 1.1.1.1 behind a Cisco router it's likely because someone set it up incorrectly.

That’s kinda the point.

Re: AT&T updates firmware to block access to 1.1.1.1

#36
post #17

Earlier quoted context omitted.

How is this not illegal?

That’s what I want to know. I’ll save the soapbox speech and just leave it at isn’t this why monopoly laws exist?

The issue is that the cable companies have monopolies set in law already. There are numerous regulations designed to stop any new last-mile telecom companies from starting up, which literally guarantees a monopoly for the few companies that already exist in the vast majority of the US. As good as Net Neutrality sounds in theory, all we really need to do is drop the regulations and allow new players to enter the game and the market will fix it for itself.

Re: AT&T updates firmware to block access to 1.1.1.1

#37
post #8

I wonder if anyone has considered some sort of legislation whereby internet service providers are not allowed to block or disrupt service to certain parts of the internet in order to promote their own business model.

You mean like net neutrality?

Thatsthejoke.jpeg

Re: AT&T updates firmware to block access to 1.1.1.1

#38
post #7

Does this just apply to setting the default DNS on the router, or are the blocking traffic to 1.1.1.1 from any device connected to it?

I just tried setting DNS to CloudFlare (primary and secondary + ipv6) on my downstream router behind AT&T fiber and I can't resolve any hosts. They are explicitly blocking CF DNS.

Re: AT&T updates firmware to block access to 1.1.1.1

#39

Earlier quoted context omitted.

Are they blocking 8.8.8.8? Why do you think they're blocking 1.1.1.1?

They were blocking 1.1.1.1 on some firmwares long before cloudflare's dns service started. From what I've read, the routers use it on some internal interface. It's likely incompetence, not malice. If they didn't want people using other DNS, and were willing to fuck with ip addresses they don't own to accomplish that, they'd be blackholing google's and opendns's public caching nameservers too. It might even have been…

Of course they don't want to use their own address space or commit to anything.
Post reply on HN