upvote
… then you'll be back in the world before CloudFlare set up its public DNS service, which is also the world where taking over 1.1.1.1 in the first place came at the price of having to measure how many people had ignorantly or lazily put four ones into somewhere that they had to fill in an IP address, and how much bogus and positively risky (to them) traffic there was being caused by people just thinking 'I will just use 1.1.1.1, which is not a real IP address.'.

Just before COVID, a random unidentifiable person reported that 1.1.1.1 saw 60Mb/s of ICMP echo traffic. When APNIC first experimented with making it a valid network almost a decade before that, it was being sent 50Mb/s of general IP traffic. Amusingly, a side-effect of what CloudFlare has done is that it has stopped all of that traffic leaving the edges of the Internet, and funnelling in to one big central place.

There are those who remember the risks of 'just use 1.1.1.1' and how the people who did that used be characterized as 'bad Internet citizens'. The ServerFault answer (q.v.) is from 2011.

* https://labs.ripe.net/author/franz/pollution-in-18/

* https://news.ycombinator.com/item?id=19335833

* https://serverfault.com/a/339782

reply
That was part of Cloudflare's pitch to take over the 1.1.1.1 address block - that Cloudflare had the relatively unique ability to handle all the junk traffic as anycast nearby to any source, not overloading the wider internet.
reply
I don’t use this one, because I remember when long, long ago it was in some random IP address block belonging to someone, and this particular address didn’t reply to ping.

Likely for good reason, even back then there would have bound to be lots of misconfigured endpoints trying to access 1.1.1.1, so just blocking it at the earliest point possible kept at lot of the annoyance away. Nowadays, it’s an anycast address, so it’s slightly less bad.

But for me, old habits die hard.

reply
I've already seen a couple of train hotspots respond locally to pings directed at 1.1.1.1 and 8.8.8.8, apparently in effort to convince devices that they are on a good network event if the internet itself is broken due to being in the tunnel.
reply
If 1.1.1.1 fails, I will try 8.8.8.8
reply
> 1.1.1.1

Pinging such an address is inherently a troublesome practice. This address, like many public DNS servers (resolvers as well as root and authoritative ones), uses "anycast" routing methodology.

https://en.wikipedia.org/wiki/Anycast

Pinging an anycast address will yield a cornucopia of different results. Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve, especially when they enshrine it into software, unit tests, or the LLM coughs up such tokens on their behalf.

Fundamentally, the question is "what do you really want to test?" by pinging a particular IPv4? Do you want to test Layer 3 connectivity? Test your ISP's backbone and connectivity? Test only your upstream router? Test the existence of ICMP in your stack and theirs?

... the possibilities are endless. Your router can do anything. Ping zombo.com.

reply
Why is pinging an anycast address an issue? Most people, myself included, ping addresses like 1.1.1.1 to check for internet connectivity. It's a perfectly valid check, you don't need a fine grained test all the time. If it fails, then I go looking in detail. Most of the time it will pass.

Pinging a domain name could fail for a variety of other reasons, particularly if it's not a reliable site. Cloudflare's business is being reliable; few sites would be a better choice.

reply
The problem is pinging 1.1.1.1 can end up hitting a really really close-by server. You could be having ISP issues and 1.1.1.1 could end up being closer to you than the issue is, so you get okay ping results but still unable to access resources on the other side of the issue
reply
You're thinking far too hard. If I can ping 1.1.1.1, it means traffic is flowing from inside my network, to outside my network. I'm not going to diagnose my ISP's issues, that's their job, I just need to know that it's not my problem.
reply
Most of my connection issues are between the street and my computer, I don't think Cloudflare got there. Yet.
reply
You can have routing issues that alow some IP addresses to work and others not, anycast or not. It's not supposed to be a comprehensive connectivity report, just a sanity check that the intertubes are connected at all.
reply
Of course. Ping 1.1.1.1 is not a test that everything is working great. DNS could be dead. IPv6 could be black holed.

But it’s a good “is traffic making it past my router with some semblance of connectivity” sanity check, and easier than finding the provider-side next hop address.

reply
The corollary is that when it fails, you've no idea what failed, or how it failed, or if the "fail" is even valid or relevant, because you're abusing a service that isn't designed for you and isn't fit for use. So if it succeeds, you really don't know, because perhaps your train's WiFi router is responding with a spoofed IPv4 address while it goes through the Chunnel. And if it fails, you really don't know, because you DGAF about learning formal troubleshooting methods and couldn't be arsed to find out your upstream router's address in order to simply isolate your PING to a singular link, rather than relying on complex routing rules, especially those introduced by "anycast". And perhaps you can manually dig in when your manual checks fail, but your AI agent or automated script DGAF about your nuanced knowledge that 1.1.1.1 isn't your upstream router; in fact it's not yours at all and has nothing to do with your network topology. But at least it looks elegant.
reply
I ping 1.1.1.1 to see if my internet is working or not after a couple of websites don’t load. I reboot the router. I keep the terminal where I’m pinging 1.1.1.1 open until I start seeing responses and then I know my internet is back. Then I continue my web browsing and other online activities.
reply
I’m so lazy I just type `ping 1.1` and it still works (apparently 1.0.0.1 is also always up).
reply
It's much faster just pinging 127.0.0.1 for such purposes. Try it!
reply
In the spirit of M4v3R's post, that should be 127.1 . (-:
reply
ping 0 would save you 3 bytes!
reply
deleted
reply
deleted
reply
Any IP address could one day change where it is being announced from, or become anycast, or change the number of hops between you and it.

I don't think people are using `ping 1.1.1.1` as a stable API, rather as a yes/no test of the network segment that they control.

reply
Fun fact, ping is the standard windows way to wait a given number of seconds[0]. You're supposed to ping 127.0.0.1, but I saw a lot of scripts pinging 1.1.1.1 or 8.8.8.8

[0]: https://stackoverflow.com/questions/1672338/how-to-sleep-for...

reply
> standard windows way

The thread you linked to suggests 'timeout'[0]

[0] https://learn.microsoft.com/en-us/windows-server/administrat...

reply
Scroll down. Ping is preferred because timeout is buggy
reply
>Of course, people who naïvely "ping" a recognizable or easy-to-type IPv4 address get what they deserve

Look what happened because of what you did, what it led to! Two microservices are in critical condition and you're laughing. You're laughing.

reply
Why would it matter?
reply
reply
Don't see why this is relevant, ping is not traceroute or http. If you just want to test if packets can leave your network then its a good enough test and anycast doesn't affect that.
reply
[dead]
reply