← Back to context

Comment by ButlerianJihad

19 hours ago

> 1.1.1.1

Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses "anycast" routing methodology.

https://en.wikipedia.org/wiki/Anycast

Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.

Fundamentally, the question is "what do you really want to test?" by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP's backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?

... the possibilities are endless. Your router can do anything. Ping zombo.com.

Why is pinging an anycast address an issue? Most people, myself included, ping addresses like 1.1.1.1 to check for internet connectivity. It's a perfectly valid check, you don't need a fine grained test all the time. If it fails, then I go looking in detail. Most of the time it will pass.

Pinging a domain name could fail for a variety of other reasons, particularly if it's not a reliable site. Cloudflare's business is being reliable; few sites would be a better choice.

  • The problem is pinging 1.1.1.1 can end up hitting a really really close-by server. You could be having ISP issues and 1.1.1.1 could end up being closer to you than the issue is, so you get okay ping results but still unable to access resources on the other side of the issue

    • You're thinking far too hard. If I can ping 1.1.1.1, it means traffic is flowing from inside my network, to outside my network. I'm not going to diagnose my ISP's issues, that's their job, I just need to know that it's not my problem.

    • Most of my connection issues are between the street and my computer, I don't think Cloudflare got there. Yet.

    • You can have routing issues that alow some IP addresses to work and others not, anycast or not. It's not supposed to be a comprehensive connectivity report, just a sanity check that the intertubes are connected at all.

    • Of course. Ping 1.1.1.1 is not a test that everything is working great. DNS could be dead. IPv6 could be black holed.

      But it’s a good “is traffic making it past my router with some semblance of connectivity” sanity check, and easier than finding the provider-side next hop address.

  • The corollary is that when it fails, you've no idea what failed, or how it failed, or if the "fail" is even valid or relevant, because you're abusing a service that isn't designed for you and isn't fit for use. So if it succeeds, you really don't know, because perhaps your train's WiFi router is responding with a spoofed IPv4 address while it goes through the Chunnel. And if it fails, you really don't know, because you DGAF about learning formal troubleshooting methods and couldn't be arsed to find out your upstream router's address in order to simply isolate your PING to a singular link, rather than relying on complex routing rules, especially those introduced by "anycast". And perhaps you can manually dig in when your manual checks fail, but your AI agent or automated script DGAF about your nuanced knowledge that 1.1.1.1 isn't your upstream router; in fact it's not yours at all and has nothing to do with your network topology. But at least it looks elegant.

I ping 1.1.1.1 to see if my internet is working or not after a couple of websites don’t load. I reboot the router. I keep the terminal where I’m pinging 1.1.1.1 open until I start seeing responses and then I know my internet is back. Then I continue my web browsing and other online activities.

Any IP address could one day change where it is being announced from, or become anycast, or change the number of hops between you and it.

I don't think people are using `ping 1.1.1.1` as a stable API, rather as a yes/no test of the network segment that they control.

Fun fact, ping is the standard windows way to wait a given number of seconds[0]. You're supposed to ping 127.0.0.1, but I saw a lot of scripts pinging 1.1.1.1 or 8.8.8.8

[0]: https://stackoverflow.com/questions/1672338/how-to-sleep-for...

>Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve

Look what happened because of what you did, what it led to! Two microservices are in critical condition and you're laughing. You're laughing.