Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

351–360 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#353

Earlier quoted context omitted.

Any sane gateway would block any access to anything from RFC1918, and using a private IP address for a public service is a bad idea in general.

Fair enough, if it was traversing public (non-ATT) networks without a tunnel.

It would be reasonable for AT&T equipment to block any private IP traffic outside a customer's private network by default. That's ignoring that AT&T's network is public, and it wouldn't make sense to use a private IP for a service they provide.

Reversing that would likely require AT&T to make a firewall change to literally every piece of equipment they operate, and that's assuming that they don't use the blocks internally. That, and I can guarantee that some customer, somewhere, would be using whatever IP they chose.

Re: AT&T updates firmware to block access to 1.1.1.1

#354

This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

Was this on AT&T's wireless network or wireline DSL/fiber? This problem is about the wireline network/CPE.

Wireless

Re: AT&T updates firmware to block access to 1.1.1.1

#355
post #79

Earlier quoted context omitted.

They started blocking 1.0.0.1 and CF ipv6 DNS too. This has to be intentional.

Hmmm that's a fair point. But then why not also block 8.8.8.8?

At least google doesn't block rarbg or thepiratebay. Good riddance to CF.

Re: AT&T updates firmware to block access to 1.1.1.1

#356
post #75

This is likely due to incompetence, not malice. FWIW, it’s possible to bypass AT&T’s router: https://github.com/jaysoffian/eap_proxy That said, I tried 1.1.1.1 and found I had to switch back to Google DNS since Cloudflare intentionally doesn’t support EDNS Client Subnet which was causing my AppleTV’s to have trouble loading content.

I don't know much about networking, but I do have that router. Can you please explain what this does/why someone would want this?

The other person answered the what, the why is because you have a cool router and/or you don't like limited NAT tables.

Re: AT&T updates firmware to block access to 1.1.1.1

#357
post #331

Earlier quoted context omitted.

> The Cloudflare-APNIC experiment uses two IPv4 address ranges, 1.1.1/24 and 1.0.0/24, which have been reserved for research use. Cloudflare's new DNS uses two addresses within those ranges, 1.1.1.1 and 1.0.0.1. They had acknowledged to themselves going into it that the IPs weren't "normal". They could have easily chosen a safer range if that was a priority.

1.1.1.1 is a normal IP as it was reserved for internet use. There are already IP ranges that are supposed to be used for internal use, and 1.1.1.1 is not one of them

This whole thing is like the .dev TLD debacle.

Re: AT&T updates firmware to block access to 1.1.1.1

#358

Earlier quoted context omitted.

>APNIC's research group held the IP addresses 1.1.1.1 and 1.0.0.1. While the addresses were valid, so many people had entered them into various random systems that they were continuously overwhelmed by a flood of garbage traffic. APNIC wanted to study this garbage traffic but any time they'd tried to announce the IPs, the flood would overwhelm any conventional network. >We talked to the APNIC team about how we wanted…

> It's not a reserved address I know. That's why I wrote "tradition" instead of the RFC numbers. Way to miss my point though.

You seem to miss my point, in that Cloudflare specifically chose that IP in order to share research data with APNIC regarding people erroneously using 1.1.1.1 in the wild.

Just because something is a tradition doesn't make it a right course of action.

Re: AT&T updates firmware to block access to 1.1.1.1

#359
post #253
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

Blocking 1.1.1.1 -> 98% chance it is a bug Blocking 1.1.1.1 and 1.0.0.1 -> what are the odds here?

everything from 1.0.0.0/8 to 1.0.0.0/15 would encompass those IPs so who knows what but my guess would be some routing or other strange internal usage of some of those subnets

Re: AT&T updates firmware to block access to 1.1.1.1

#360
post #343
post #192

Earlier quoted context omitted.

If you're in Ontario, Rogers doesn't support IPv6 yet. If you want IPv6, then your only option is Bell (or a reseller, like Teksavvy).

I'm using Bell in Ontario. It could be either my Router doesn't support it, the Apartment isn't wired up to support it (if that's required?), my ISP doesn't support it in my area, or my Bell internet plan doesn't cover IPv6... I'll ask them about it when they ring me up next time asking for more money.

Hmm... looked at this again and it looks like Rogers may have rolled out IPv6 last year.

I recall on Teksavvy I had to pay extra for a "static IP" to get IPv6. Not sure if you're with Bell directly, though.

Post reply on HN