Live data from Hacker News

AT&T updates firmware to block access to 1.1.1.1

dslreports.com

371–380 of 382 posts

Re: AT&T updates firmware to block access to 1.1.1.1

#371

Earlier quoted context omitted.

The digital economy act 2017 requires porn with "insufficient" age verification to be blocked. Required by law. So exactly what parent said, happened.

Nope. It's fascinating how many people believe this, but it isn't what that law says, and so sure enough such sites are accessible via my ISP. The ISP is required by law to provide some means by which consumers can choose not to be able to access "adult" content. It does this during sign up, if you pick "Yes, block adult content" it informs you that they choose not to do business with you and suggest you use a differ…

>Nope. It's fascinating how many people believe this, but it isn't what that law says

They do because it's true and that's exactly what the law says.

Digital Economy Act 2017 14 (1):

>A person contravenes this subsection if the person makes pornographic material available on the internet to persons in the United Kingdom on a commercial basis other than in a way that secures that, at any given time, the material is not normally accessible by persons under the age of 18.

Section 23: Regulator’s power to require internet service providers to block access to material

(1) Where the age-verification regulator considers that a person (“the non-complying person”) is—

(a)contravening section 14(1), or

Re: AT&T updates firmware to block access to 1.1.1.1

#372

Earlier quoted context omitted.

Nope. It's fascinating how many people believe this, but it isn't what that law says, and so sure enough such sites are accessible via my ISP. The ISP is required by law to provide some means by which consumers can choose not to be able to access "adult" content. It does this during sign up, if you pick "Yes, block adult content" it informs you that they choose not to do business with you and suggest you use a differ…

>Nope. It's fascinating how many people believe this, but it isn't what that law says They do because it's true and that's exactly what the law says. Digital Economy Act 2017 14 (1): >A person contravenes this subsection if the person makes pornographic material available on the internet to persons in the United Kingdom on a commercial basis other than in a way that secures that, at any given time, the material is no…

Like its predecessor, the Digital Economy Act 2017 has a huge amount of text that's basically predicated on the relevant Minister pushing the button. And of course this text is a huge mess (which is why it doesn't take effect immediately, the intent is you can come back and fix it before pushing the button) and so in reality nobody pushes the button. Section 23 is one of those parts. The hypothetical regulator doesn't exist, the infrastructure for all this doesn't exist. None of this is actually law.

Go read the "commencement" section - it's actually eye-opening to do this for other laws you've heard are supposed to have drastic effects.

Re: AT&T updates firmware to block access to 1.1.1.1

#373
post #360
post #343

Earlier quoted context omitted.

I'm using Bell in Ontario. It could be either my Router doesn't support it, the Apartment isn't wired up to support it (if that's required?), my ISP doesn't support it in my area, or my Bell internet plan doesn't cover IPv6... I'll ask them about it when they ring me up next time asking for more money.

Hmm... looked at this again and it looks like Rogers may have rolled out IPv6 last year. I recall on Teksavvy I had to pay extra for a "static IP" to get IPv6. Not sure if you're with Bell directly, though.

Everyone in Ontario on TekSavvy should have IPv6 now without having to pay for a static IP address but at least for me it's still wonky at best.

Re: AT&T updates firmware to block access to 1.1.1.1

#374

Earlier quoted context omitted.

Yeah. And there's also a lot of traffic going in Facebook's direction, for example. Hey, let's blackhole that too - and alleviate the stress on our network that comes from people using it . (In non-sarcastic tone: that doesn't make any sense.)

Based on what I understand, the amount of traffic headed to 1.1.1.1 is much more significant. I agree with you though, that wouldn’t be justification to block it. It looks like they’re also blocking 1.0.0.1 and the relevant ipv6 addresses which shouldn’t have the same traffic issue.

I doubt it's all that significant, it's a really small portion of traffic compared to a web page, javascript, css or images... and with caching even less of an impact.

Re: AT&T updates firmware to block access to 1.1.1.1

#375

Earlier quoted context omitted.

I was using 1.1.1.1 with AT&T Fiber and it stopped working. I didn't really question it, I figured maybe something went down at Cloudflare so I just switched my Mac back to using the defaults again. It never even occurred to me that AT&T might be blocking it. Maybe stupid question, but why would AT&T block it?

A few others have mentioned this already, but 1.1.1.1 has become a colloquial private address, used either as a blackhole or as a destination for internal traffic. Sort of like how 555-5555 technically isn't reserved (only 555-01xx is, according to Wikipedia), but practically, it's not really a workable number and phone companies don't hand it out. According to the announcement post, part of the reason that Cloudflar…

and the reports of 1.0.0.1?

Re: AT&T updates firmware to block access to 1.1.1.1

#376
post #333

Earlier quoted context omitted.

So it's not just malice but doubly so: they used an IP they didn't have the rights to and they're now blocking proper users of it.

Let's not act like using a "probably not in-use IPv4 but we can't really be sure" is a crime against humanity. If you're designing any kind of large scale system over the internet you end up hitting the problem sooner or later (like how some VPN solutions started using 5.x.y.z to be sure not to clash with LAN IPs for instance). The real solution of course would be to switch to IPv6 where any vendor can claim some pri…

It's not reasonable. We have RFCs for a reason, which define which subnets can be used for public use, and which can be used internally. This has been written down for a long time and anyone working at ATT that can make these kind of decisions should know better.

Re: AT&T updates firmware to block access to 1.1.1.1

#377
post #87
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

Then the odds appear to not be in our favor. CF CEO tweets that 1.0.0.1 is also blocked. https://twitter.com/eastdakota/status/991718955021623296 Others have confirmed that the ipv6 address belonging to CF appears to be blocked.

I have AT&T internet, and the BGW-210 gateway with the latest firmware. And my area was upgraded to native dual stack ipv6 about a year ago. So I tested it out and the ipv6 CloudFlare DNS (2606:4700:4700::1111 , 2606:4700:4700::1001) works perfectly fine. https://imgur.com/a/grUzeDD Its only the ipv4 1.1.1.1 that dose not. And AT&T made a statement why that is.

""With the recent launch of Cloudflare's 1.1.1.1 DNS service, we have discovered an unintentional gateway IP address conflict with 1 of their 4 usable IPs and are working to resolve the issue,"

https://arstechnica.com/information-technology/2018/05/att-i...

A few of you will be disappointed to know its not a evil attempt to block you from using it. Same way they have literally never blocked the ability to use any other DNS service before.It's simply a bug caused by the way the BGW-210, and Pace 5268AC operate and make use of 1.1.1.1 internally in some way and it will be fixed with a firmware update.

Re: AT&T updates firmware to block access to 1.1.1.1

#378
post #71

I'd say there is a 98% chance this is a bug in some firmware and a 2% chance AT&T is intentionally trying to block Cloudflare DNS. I get why people are paranoid about ISPs blocking content and net neutrality, but let's not cry wolf prematurely. The technical details here strongly suggest a bug rather than intentional blocking of 1.1.1.1 DNS traffic.

My router stopped working a few weeks after using 1.1.1.1. Weird things are happening with it.

Re: AT&T updates firmware to block access to 1.1.1.1

#379

How is the ISP performing this remote update? Is it TR-069/CWMP or an open SSH port or something? Many routers will allow the user to disable TR-069 even while it's running. Often a hardware reset will also disable it and then the user can put the manufactures update on it and prevent the ISP from managing it in the future. If it's an open SSH port then we all have bigger problems.

AT&T's internet service requires you to use one of THEIR "gateways". Which is a combination modem and wireless router. When AT&T wants a new gateway they go to a company (mainly Arris now) and have them build a gateway that will only be for AT&T to deploy . AT&T completely controls the software/firmware on the device. There is no site you can go to and download a "manufacturer" firmware. Even if you could it wouldn't accept it because it wouldn't be signed by AT&T. And yes AT&T uses CWMP to remotely manage the gateway. That's how they can send firmware updates, customer service can retrieve signal stats, remotely reboot the gateway etc etc. And no they certainly do not put in a option on the gateway to disable CWMP or any of the remote management stuff they use.

You can turn off the Wi-Fi on AT&T's gateway and run your own router behind the AT&T hardware. But since your router is behind the gateway everything still goes through it and AT&T still can do all the CWMP stuff to their gateway.

Re: AT&T updates firmware to block access to 1.1.1.1

#380
post #362

This isn't malice. AT&T has an internal IP they assigned to 1.1.1.1 because it was unused and they used it as an image caching proxy so it browsing the internet would feel faster on early phones. I've seen it when I was reverse engineering on Android a while back.

If not malice, it is incredibly bad engineering. Every IP address on a foreign, public network has to be considered as "in use".

This is actually the reason that 1.1.1.1 gets so much traffic. People just assume it's not in use and can be abused a bit. Once it's available on the internet then all that excess traffic that was going nowhere gets transferred there.

Still, it looks more like malice since there are other addresses besides 1.1.1.1 that are also blocked.

Post reply on HN