Comment by selcuka
1 day ago
I'm wondering how many automated tests this change broke.
Yes, I know it's not the example.com's fault, and it's a side effect of Hyrum's Law:
> This is not a service, avoid relying on it for testing and monitoring purposes.
Don't we all have a few fragile tests?
That's an excellent reason to change the page design occasionally, so that people learn not to rely on it (the hard way if necessary).
Go a step further and randomize it. Different page at every request.
But then people will rely on the randomness to pick their quicksort pivots or something like that.
2 replies →
If 1.1.1.1 ever stops responding to pings…
… then you'll be back in the world before CloudFlare set up its public DNS service, which is also the world where taking over 1.1.1.1 in the first place came at the price of having to measure how many people had ignorantly or lazily put four ones into somewhere that they had to fill in an IP address, and how much bogus and positively risky (to them) traffic there was being caused by people just thinking 'I will just use 1.1.1.1, which is not a real IP address.'.
Just before COVID, a random unidentifiable person reported that 1.1.1.1 saw 60Mb/s of ICMP echo traffic. When APNIC first experimented with making it a valid network almost a decade before that, it was being sent 50Mb/s of general IP traffic. Amusingly, a side-effect of what CloudFlare has done is that it has stopped all of that traffic leaving the edges of the Internet, and funnelling in to one big central place.
There are those who remember the risks of 'just use 1.1.1.1' and how the people who did that used be characterized as 'bad Internet citizens'. The ServerFault answer (q.v.) is from 2011.
* https://serverfault.com/a/339782
That was part of Cloudflare's pitch to take over the 1.1.1.1 address block - that Cloudflare had the relatively unique ability to handle all the junk traffic as anycast nearby to any source, not overloading the wider internet.
I don’t use this one, because I remember when long, long ago it was in some random IP address block belonging to someone, and this particular address didn’t reply to ping.
Likely for good reason, even back then there would have bound to be lots of misconfigured endpoints trying to access 1.1.1.1, so just blocking it at the earliest point possible kept at lot of the annoyance away. Nowadays, it’s an anycast address, so it’s slightly less bad.
But for me, old habits die hard.
I've already seen a couple of train hotspots respond locally to pings directed at 1.1.1.1 and 8.8.8.8, apparently in effort to convince devices that they are on a good network event if the internet itself is broken due to being in the tunnel.
If 1.1.1.1 fails, I will try 8.8.8.8
> 1.1.1.1
Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses "anycast" routing methodology.
https://en.wikipedia.org/wiki/Anycast
Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.
Fundamentally, the question is "what do you really want to test?" by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP's backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?
... the possibilities are endless. Your router can do anything. Ping zombo.com.
Why is pinging an anycast address an issue? Most people, myself included, ping addresses like 1.1.1.1 to check for internet connectivity. It's a perfectly valid check, you don't need a fine grained test all the time. If it fails, then I go looking in detail. Most of the time it will pass.
Pinging a domain name could fail for a variety of other reasons, particularly if it's not a reliable site. Cloudflare's business is being reliable; few sites would be a better choice.
6 replies →
I ping 1.1.1.1 to see if my internet is working or not after a couple of websites don’t load. I reboot the router. I keep the terminal where I’m pinging 1.1.1.1 open until I start seeing responses and then I know my internet is back. Then I continue my web browsing and other online activities.
7 replies →
Fun fact, ping is the standard windows way to wait a given number of seconds[0]. You're supposed to ping 127.0.0.1, but I saw a lot of scripts pinging 1.1.1.1 or 8.8.8.8
[0]: https://stackoverflow.com/questions/1672338/how-to-sleep-for...
2 replies →
Any IP address could one day change where it is being announced from, or become anycast, or change the number of hops between you and it.
I don't think people are using `ping 1.1.1.1` as a stable API, rather as a yes/no test of the network segment that they control.
>Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve
Look what happened because of what you did, what it led to! Two microservices are in critical condition and you're laughing. You're laughing.
Why would it matter?
2 replies →
[dead]
that's a really good point I'd not considered but if you just hash the response and the followups remain consistent (they do in this case)... you're gonna do just fine.