Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

331–340 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#331

Earlier quoted context omitted.

1.1.1.1 is a normal IP.

> The Cloudflare-APNIC experiment uses two IPv4 address ranges, 1.1.1/24 and 1.0.0/24, which have been reserved for research use. Cloudflare's new DNS uses two addresses within those ranges, 1.1.1.1 and 1.0.0.1. They had acknowledged to themselves going into it that the IPs weren't "normal". They could have easily chosen a safer range if that was a priority.

1.1.1.1 is a normal IP as it was reserved for internet use. There are already IP ranges that are supposed to be used for internal use, and 1.1.1.1 is not one of them

Re: AT&T updates firmware to block access to 1.1.1.1

#332

Anyone else facing such issues with their ISP for 1.1.1.1 ? Cloudflare DNS seems to be down for couple of major ISP's in India as well according to CF forums - [ACT] https://community.cloudflare.com/t/cloudfare-dns-blocked-wit... [Airtel] https://community.cloudflare.com/t/cloudflare-dns-not-workin...

I'm on comcast and can't seem to ping em.

Re: AT&T updates firmware to block access to 1.1.1.1

#333

This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

Let's not act like using a "probably not in-use IPv4 but we can't really be sure" is a crime against humanity. If you're designing any kind of large scale system over the internet you end up hitting the problem sooner or later (like how some VPN solutions started using 5.x.y.z to be sure not to clash with LAN IPs for instance). The real solution of course would be to switch to IPv6 where any vendor can claim some private address anywhere without any realistic risk of collision but we all know that we're not ready for that yet.

By their own admission CF receives a ridiculous amount of garbage traffic at this IP, it was not absurd for AT&T engineers in the past to thing "well, we need an IP that we can be reasonably sure nobody is going to use and is never going to conflict with anything on any network, 1.1.1.1 seems reasonable". Seeing everybody in this thread jumping into conspiracy theories instead of the much more likely configuration issue is a bit disappointing for a community that's supposed to understand technology.

Re: AT&T updates firmware to block access to 1.1.1.1

#334

Good. If cloud fare is allowed to block sites from their hosting service based on opinions, then att should be allowed to do the same. Also fuck cloud fare for choosing 1.1.1.1 when any network engineer worth his salt would have told them it's going to cause problems. There are things like conventions and traditions, you break them at your own peril.

>APNIC's research group held the IP addresses 1.1.1.1 and 1.0.0.1. While the addresses were valid, so many people had entered them into various random systems that they were continuously overwhelmed by a flood of garbage traffic. APNIC wanted to study this garbage traffic but any time they'd tried to announce the IPs, the flood would overwhelm any conventional network. >We talked to the APNIC team about how we wanted…

> It's not a reserved address

I know. That's why I wrote "tradition" instead of the RFC numbers. Way to miss my point though.

Re: AT&T updates firmware to block access to 1.1.1.1

#336

Earlier quoted context omitted.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

They used an IP that was originally reserved for what reserved IP's are used for. Now that Cloudflare convinced 1.1.1.1 to be released, I'm sure AT&T wants service continuity and had to make this decision, which is well within their rights as an ISP. I dislike AT&T so if this was entirely opinion-based, I would be against them here. But this is a knee-jerk reaction to a well justified decision.

I'd be more inclined to agree with you if AT&T were to come out and say what the problem is along with assurances that they are working on rectifying the situation and expect to have 1.1.1.1 available in X days.

Re: AT&T updates firmware to block access to 1.1.1.1

#337
post #315

Late to the party, but here's some traceroutes run from AT&T Gigapower with their router entirely bypassed via an 802.1x MitM: # traceroute 1.0.0.1 traceroute to 1.0.0.1 (1.0.0.1), 30 hops max, 60 byte packets 1 45-18-124-1.lightspeed.austtx.sbcglobal.net (45.18.124.1) 59.462 ms 61.348 ms 63.373 ms 2 71.149.77.208 (71.149.77.208) 1.304 ms 1.695 ms 1.957 ms 3 75.8.128.136 (75.8.128.136) 1.329 ms 1.682 ms 1.393 ms 4 12…

I have AT&T Gigapower as well (I'm also in Austin). Can you give a description of the 802.1x bypass? What's the advantage?

Re: AT&T updates firmware to block access to 1.1.1.1

#338

Earlier quoted context omitted.

Just curious - can cloudflare blackhole all of Att traffic?

Could they physically? Yes. But they'd be screwing over their own customers who rely on that traffic.

Isn’t AT&T screwing their own customers by blocking 1.1.1.1 as well ?

Re: AT&T updates firmware to block access to 1.1.1.1

#339
post #333

Earlier quoted context omitted.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

Let's not act like using a "probably not in-use IPv4 but we can't really be sure" is a crime against humanity. If you're designing any kind of large scale system over the internet you end up hitting the problem sooner or later (like how some VPN solutions started using 5.x.y.z to be sure not to clash with LAN IPs for instance). The real solution of course would be to switch to IPv6 where any vendor can claim some pri…

> it was not absurd for AT&T engineers in the past to thing

That is an utterly unreasonable conclusion.

The same logic resulted in Y2K, which was generally a huge waste of time, money, and resources.

The same logic has resulted in the anemic adoption of IPv6, which is NOT a correct solution, because it doesn't work properly for large swaths of the public.

The correct answer always was, and will continue to be, to use internal routes for internal routing, and external routes for external. Clashes with your LAN? Too fucking bad.

This sort of pushing out of externalizes onto the customer results in the same exact outcome anyway: customer gets screwed.

The customer always gets screwed. Don't rationalize the incompetence of engineers who should know better, and corporate execs who don't give a fuck.

Re: AT&T updates firmware to block access to 1.1.1.1

#340
post #289

Earlier quoted context omitted.

It's stupidity, then malice as a cover-up.

No, that's not what malice means. Unless you're actually trying to say that AT&T has a grudge against Cloudflare and are only doing this to harm their company. This is something more like negligence or gross negligence.

> only doing this to harm their company

That's not wholly unthinkable as far as AT&T is concerned. They're historically a bad player.

Post reply on HN