12 ms·
ISP Spying
- mmrezaie 9y agoIs there a portal like-place to share our findings of ISPs generally in the world so that others can work together with better transparency? I do data analytics and data engineering and a couple of months ago indirectly I have been contacted by an ISP in Spain and they literally were collecting every bit of data that their customers were seeing on internet (websites, timestamps, how much data were transferred and etcetera with the user's id and basically in another table name and address). I was shocked how easy they were talking about it. I didn't accept but for sure someone has done it! I never heard the name of the ISP, I wish I didn't bark at them so fast and I could collect more information about them.
- rishabhd 9y agowell, who isn't? Even at the most basic level, my local ISP is injecting ads into browsers.
- mysterypie 9y agoThe original title before the admins changed it was "Your ISP is Probably Spying On You", and you wrote: > well, who isn't? I can understand that we all get weary from the constant news of yet another privacy intrusion, surveillance method being discovered, or new government law eroding privacy. But why be dismissive? When Snowden revealed what he knew, it confirmed what I had already suspected. But I didn't go and say, "well of course, we all knew that we were being illegally spied on us". I thought that getting the specific information was very important.
- icc97 9y agoAs far as I can tell we should just be safety first. This does indeed mean getting as much information about how to browse privately. If we all use tor, it will help the tor project because then it's harder to spot individuals using it. Tor is slightly slower, but it's pretty much a perfect browser replacement. The only reason I don't use it all the time is that I like my browser history. Plus I've got a self built VPN which is about as good as I can hope for.
- rishabhd 9y agoMy apologies, I did read the article and then commented. The author is obviously privacy focused and is writing for a similar audience. Unfortunately, here in India, things are quite different as there are very few legal measures to protect privacy and there is a general lack of awareness regarding why digital privacy actually matters. Things are so bad at some places that even local ISPs (even with no BGP AS) are able to collect data, and sell it to markets in gaffar for as low as 2 USD (for instance a list of 25K users with their browsing habits). A small, cottage industry of data mining and selling operates with zero implications and even the cops can't do anything about it as they are brutally unaware about the privacy laws and shrug it off. I have my own VPN setup (openVPN to tinc mesh over scaleway/hetzner) for my general surfing and have configured it for my whole family through a raspberry pi as well. But again, the when the smallest of enterprises can operate with zero ramifications for mining, there is little you can do en masse without the backings of an informed government.
- breakingcups 9y agoThat is so fucked up. That isn't the case at all over here. Why do people accept it, a monopoly in their area?
- rishabhd 9y agoUnfortunately people are simply unaware about their rights in general regarding privacy and the locals laws are not stringent. They are not even aware that their data is being collected, and even if they knew, they can do little about it. Privacy focused users create their own infrastructure or get VPN, rest all contribute to a small cottage industry of data collection, analysis and selling unknowingly.
- mirimir 9y agoI always assume that they might be. So I always use my own perimeter router/firewall running pfSense. Plus I use VPN services. And so my ISps don't end up seeing anything except encrypted streams. And have no visibility into my vLANs.
- moviuro 9y agoYou're just paying some extra third-party that handles all your traffic now. What's to prevent them from doing the same? You're moving trust to another actor.
- jstanley 9y agoIt's easy to move your VPN to an arbitrary VPS anywhere in the world, but there's only a handful of residential ISPs available in any given area, and they are almost univerally scummy.
- thinkMOAR 9y agoscummy often by law, if it was up to many ISPs, like in the early days of the internet, they only cared if you paid your monthly bill.
- Aaargh20318 9y ago> there's only a handful of residential ISPs available in any given area Depends on where you live, I haven't exactly counted them but I have at least 20 options. Worst-case you can start your own ISP.
- Tijdreiziger 9y ago> and they are almost univerally scummy Source? I do not think most of the ISPs in my area are particularly scummy. They provide reliable plain internet service with no data caps (and also TV/phone service if you so desire) for a reasonable monthly fee, and in my experience, most of them hire enough customer service workers on their support phone. All of them also resisted internet filtering until the legal system forced them to do so. What more is there to ask of an ISP?
- deleted 9y ago[deleted]
- Buge 9y agoThat router looks like its control panel is hosted on an external server. Router control panels usually show what devices are connected. So for router control panel functionality, they need to have the router report all connected devices to the server. Obviously they should be doing this encrypted, not unecrypted. But ignoring encryption, this is the price you pay for cloud management: the could knows your data.
- philjohn 9y agoRemember, the TR-069 traffic starts at your device, and terminates at their end, it's not making it out onto the public internet, it's entirely within the ISP network. That's not to say it still shouldn't be encrypted, but with a FTTH connection using a PON network there's already physical layer encryption going on typically, otherwise a custom configured ONT could snoop on other peoples traffic on the same segment.
- Teever 9y ago> it's not making it out onto the public internet, it's entirely within the ISP network. What if technical support is outsourced to a call-center in India?
- tinus_hn 9y ago> otherwise a custom configured ONT could snoop on other peoples traffic on the same segment. Why would an ISP care about that?
- Buge 9y agoIf there's already encryption, how did the author snoop on the content?
- jstanley 9y agoIn the UK, they're legally required to spy on you (but not through your router). https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016 https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016
- tzahola 9y agoI don't know if it's true, but I've heard that some ISPs route your entire traffic through their machines. They even have access to your IP packets. Very shady!
- rocqua 9y agoISP's intercepting HTTP traffic to modify it is far from unheard of. In the best case, this is to notify customers of required changes. This is actually used by comcast [1]. In the worst case, this is a service sold to advertisers, or a service that includes arbitrary java-script injection. For something close to the worst case, see [2] (previously discussed on HN [3]). [1] https://tools.ietf.org/html/rfc6108 https://tools.ietf.org/html/rfc6108 [2] https://defplex.wordpress.com/2017/08/15/how-a-south-african-isp-hacks-it-subscribers-each-month/ https://defplex.wordpress.com/2017/08/15/how-a-south-african... [3] https://news.ycombinator.com/item?id=15423393 https://news.ycombinator.com/item?id=15423393
- tzahola 9y agoWhy on Earth would you visit plain HTTP sites with JavaScript enabled?
- drchickensalad 9y agoBecause you have to be in the know-how and do work to achieve that?
- gcb0 9y agoyou're so late to the party. verizon even adds tracking cookies to your outgoing http requests
- philjohn 9y agoThis isn't an issue if you're not using the ISP equipment, or put the ISP equipment into a bridge modem mode. For instance, BT in the UK do the same reporting over TR-069 if you use their home hub - however - if you connect a different VDSL modem/router you can disable TR-069, and if you use a dedicated VDSL modem in bridged mode and a wireless router behind that there's no TR-069 to worry about in the first place.
- mseebach 9y agoOr if you just use the provided router, either in bridge mode or in regular mode, the only device it will ever see and report on is your own router, which is hardly a critical leak.
- LeoPanthera 9y agoI've been forwarding all outgoing connections on port 80 (and a selection of other commonly-unencrypted ports) through a VPN (in the router) for a while now - but leaving all other ports (including most importantly 443) connecting directly. It feels like a good compromise between privacy and speed. (I realise this is not the subject of the article exactly but I figured it's a related issue.)
- brigade 9y agoWhy do you feel that way? VPNs are vastly more likely to actually read your traffic than any ISP.
- pasta 9y agoDepends on where the VPN connects to.
- deltaprotocol 9y agoCan you provide more background on your blanket statement? There are good and bad VPNs but ISPs are much larger corporations with direct ties to governments. I fail to see how a good VPN is worse than ISP + Governments.
- oger 9y agoNot an issue when you run your own VPN with a cheap VPS - meaning the data is exiting in a datacenter in a location of your choice. While they or their upstream providers will certainly have some 'lawful interception' capability they are usually not interested in analyzing / selling the data on their wires as the consumer-facing ISPs.
- LeoPanthera 9y agoI control the other end of the VPN, I'm not using a public VPN service. All I care about is routing around my ISP. (Which is Comcast - whom I do not trust.)
- MaxBarraclough 9y agoInteresting approach. It has the happy property that the performance penalty will trend toward zero over time, as fewer and fewer holdout websites stick with unencrypted HTTP. Even Netflix streaming uses HTTPS these days. By the end of the year I figure we'll have virtually no such holdouts. https://www.theregister.co.uk/2018/02/08/google_chrome_http_shame/ https://www.theregister.co.uk/2018/02/08/google_chrome_http_...
- icc97 9y agoWho didn't think they were being spied on? This is why you used https to hide the full URL, VPN to push the problem to a 3rd party who might care a bit more about privacy and then Tor on top of it all. Here's the good old EFF explanation [0] [0]: https://www.eff.org/pages/tor-and-https https://www.eff.org/pages/tor-and-https
- danieldk 9y agoThis is why you used https to hide the full URL, VPN to push the problem to a 3rd party who might care a bit more about privacy and then Tor on top of it all. Did you read the article? The ISP-provided modem/router automatically sends an overview of devices actively connected to the router (with their MAC address, name, and whether they are currently connected) to the ISP. This is a different issue than private browsing and using a VPN/HTTPS/Tor is not going to solve this particular problem. The solution to this problem is replacing the router or putting another router between the ISP router and your internal network to hide your internal network from the ISP-provided router.
- icc97 9y agoGood point, my bad, I'd skimmed it and not read the bit after the XML text. The title was somewhat misleading, and the HN admins have changed it now. I'd still be more concerned about my unencrypted HTTP traffic though.
- 45h34jh53k4j 9y agoNo, dont run Tor over VPN. Its VPN over Tor. Tor provides anonymity, VPN provides privacy. You want anonymity between you and the VPN, and privacy between you and internet hosts. From the OpSec for xyz series: https://grugq.github.io/presentations/Keynote_The_Grugq_-_OPSEC_for_Russians.pdf https://grugq.github.io/presentations/Keynote_The_Grugq_-_OP... • TOR connection to a VPN => OK • VPN connection to TOR => GOTO JAIL
- deleted 9y ago[deleted]
- wowamit 9y agoEvery now and then, we are reminded that our router remains the prominent data collector for our online presence. And ISP, the prominent data aggregator. And neither are really too keen to protect our data online.
- slhck 9y agoI recently learned about this when I reported Internet speed issues to my home ISP (upload was basically impossible, while download was at 100 MBit/s). They said they'd look into it, but they couldn't process my claim unless they could prove something was connected via Ethernet to their router. (They apparently never trust customer WiFi speed test results, probably because WiFi on their crappy routers can be notoriously unreliable.) I ultimately had to connect something to the router's Ethernet port, so I grabbed another WiFi router, configured it as an access point, plugged it in, and voilà, they could verify that a device was connected and processed my complaint. Obviously customer service reps can easily get access to a list of what is connected to the router.
- book_mentioned 9y agoOne time the next-tier tech shut off my WiFi while I was troubleshooting with the entry-level phone support; I hadn't been warned this was an option or would happen so it really rubbed me the wrong way.
- javajosh 9y agoIs it just me or does this look like a huge opportunity? Last I checked we still have control over our devices, and if they are stupid enough to trust the data they collect, then we should feel free to poison the well. I'm talking about opening random connections to endpoints (either random or those we want to protect), to inject noise into the system. I call the idea "data flak". It could be something as simple as a daemon running in the background, or a browser plugin. You want to spy on my traffic? Fine, good luck picking out my real behavior from the gigabytes of utter crap I'm shoving into your sensors. This works not just at the ISP level, but at every intermediate host, too. The only counter is for an adversary to own your box, which is far more expensive.
- gruez 9y ago>The only counter is for an adversary to own your box, which is far more expensive. or require your clients to run your software, like in AOL days
- javajosh 9y agoWell, in general, you'd want to draw a casual link between real physical measurement and network traffic; so yeah, if you own the client (and can accurately determine whether or not it's running in a VM, and/or manipulated by a robot, which is tricky) you can filter out the data flak. If I worked for a data-collection org I'd probably ignore (or blacklist, if I could get away with it) a known source of noise.
- jwilk 9y agoPlease use the original title.
- thecatspaw 9y agoThe Original posters did use the title of the blogpost. @Admins, why did you change it? I feel like the original title "Your ISP is Probably Spying On You" better describes what this post is about. Not using the original router can be due to all kinds of reasons, not just privacy
- dang 9y agoThe HN guidelines ask: "Please use the original title, unless it is misleading or linkbait." This one was linkbait—it used the linkbait "you" twice. We took that out. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- jwilk 9y agoI could figure out that "you" doesn't refer to me personally, and so can the rest of HN. There's nothing "linkbait" about it. You can express your opinion about the original title in a comment. There's no need it impose this (twisted, IMO) view on everyone.
- dang 9y agoAs the people who read the most headlines here, probably by an order of magnitude, I'm afraid we have to pull rank on that. Gratuitous "you" in titles is one of the biggest linkbait tropes. Presumably we're all wired to direct our attention to someone saying "hey you!"; headline writers figured this out and have been milking it ever since.
- alxndr13 9y agoIn Germany you are able to use any router you want, regardless of which ISP you use. https://www.cr-online.de/bgbl116s0106.pdf https://www.cr-online.de/bgbl116s0106.pdf
- gruez 9y agoDo ISPs actually prevent you from doing that? At the very leas you can hook your router to the ISP's router and set up DMZ?
- oger 9y agoNo. DSL-providers are legally obliged to let the customers use their own equipment (which includes the account details / passwords to establish the connection). Most of them even provide the details for the SIP connection that is included most of the times. If I remember correctly cable providers were fighting this - not sure about the final outcome...
- Cieplak 9y agoAnother cool thing about WiFi routers is that you can use them as radars to monitor people in a home. The 2.4ghz frequency is perfect for reflecting off water bodies while having great penetration through walls.
- ourmandave 9y agoI wonder what kind of resolution you can achieve. Would it be ghostly figures or more like black and white photos?
- Fnoord 9y agoThe URLs [1] [2] describe the content. I thought [1] was interesting but not answering your question. [2] Answers your question, and shows black and white and thermal pictures. [1] https://www.medgadget.com/2014/06/mits-wifi-system-detects-peoples-breathing-heart-rate-even-through-walls.html https://www.medgadget.com/2014/06/mits-wifi-system-detects-p... (June 2014) [2] https://hackaday.io/project/5452-wifi-thermal-camera https://hackaday.io/project/5452-wifi-thermal-camera (2015) [EDIT] I stand corrected, [2] is unrelated. My bad! Here's some good sources as alternative. "MIT turns Wi-Fi Into Indoor GPS New tech from CSAIL lab lets one Wi-Fi device locate another to within centimeters" [3] "RF-Capture: Capturing the Human Figure Through a Wall It can know who the person behind a wall is. It can trace a person's handwriting in air from behind a wall. It can determine how a person behind a wall is moving." [4] They also contain further resources. [3] https://spectrum.ieee.org/tech-talk/telecom/wireless/mit-turns-wifi-into-indoor-gps https://spectrum.ieee.org/tech-talk/telecom/wireless/mit-tur... [4] http://rfcapture.csail.mit.edu/ http://rfcapture.csail.mit.edu/
- zydeco 9y ago[2] is a thermal camera with WiFi connectivity, it's completely unrelated.
- deleted 9y ago[deleted]
- nmeofthestate 9y agoISP Spy: Hey boss, looks this guy in Oslo has a friend called Dave who owns an Android device. ISP CEO: This is it! We're gonna be rich boys! Arrange a meeting with GlobalAdvertCorp immediately.
- floatboth 9y agoMy ISP never gave me a router. Just an Ethernet cable coming into my apartment :)
- kalleboo 9y agoI got a fiber cable coming in through a hole in the doorframe to the balcony, and an ONU box to convert the fiber media to Ethernet. Everything else is my own responsibility.
- wepple 9y agoI’ve pulled apart router firmware plenty of times, and am never surprised to see nbtscan, nmap, and all sorts of other tools on there. A lot of ISPs will perform remote diagnosis by connecting into your router and scanning your internal hosts to see if there are any problems. Between that capability and general appalling security of routers, you’re basically on Starbucks WiFi from a security perspective even at home. important note: buying an off the shelf netgear/tplink/linksys/whatever might stop your ISP remoting in, but is still wildly full of vulnerabilities.
- markwaldron 9y agoThis is very informative! What router would you suggest purchasing?
- tortasaur 9y agoPlenty of routers can be flashed with open source third-party firmware like OpenWRT.
- jrcii 9y agoOpenBSD with CLI pf (not pfSense)
- alyandon 9y agoUsually, anything you can install a third party firmware on like openwrt, dd-wrt or tomato (shibby's version of tomato is the one I used the most). However, I gave up on consumer hardware and went with Ubiquiti for wifi AP and Mikrotik as my router. It was a bit of a pain to set up all my NAT rules in the Mikrotik router because unfortunately consumer devices do a lot of extra work behind that scenes (like setting up NAT reflection) to facilitate having NAT work painlessly. I'm perfectly content with the end result now though.
- a012 9y agoOpposite on me, I'm having a Mikrotik hAp ac and considering to use it as AP only then buy a Ubiquiti ER-X in front of it.
- 534b44a 9y agoMy ISP provides an online user interface where I can remotely change my Wi-Fi password even if I haven't explicitly enabled port forwarding. If they have access to that, I don't see why they can't easily see my network shares and its contents (I don't password protect the directories for convenience reasons). I've long ago lost the PPPoE password and this same router gets it automatically somehow. When I install another router, it won't do that.
- laveur 9y agoWhen I bought my fist house a few years ago here in the Bay. Comcast tried to give me one of their new routers wifi and everything built in. I let them but I wasn't happy. I hooked up my own router and ended up double natting it. After a few hours of frustration I went out bought my own cable modem. Installed that and returned the one comcast had provided. When asked why I sighted security and privacy concerns. Working for a fortune 500 means they could easily do some sneaking and see a lot of stuff that I worked on. Either way I use Ubiquity hardware throughout my house. Its a bit expensive but god is it good.
- notyourday 9y agoI had one of those icky things from a cable company. It is not possible to get rid of it. So the thing is sitting inside a home made Faraday cage with a Linux box acting as a router/firewall.
- EADGBE 9y agoDoes not using their own routers make ISP traffic sniffing that much harder? I'd assume if you're using their pipes, they can see what goes through it, regardless. Genuinely intrigued in this.
- dsr_ 9y agoUsing their CPE routers implies (but does not guarantee) that you are using them for NAT and firewalling, and thus the ISP has a device inside your security perimeter.
- etskinner 9y agoEnd-to-end encryption like SSL (https) is meant to limit the middle man's ability to 'see everything'. Instead of seeing the details of your Google search, all they see is that you accessed Google at [x] time, and exchanged [y] amount of data. This is why there is such a push for end to end encryption on web traffic, chat apps, etc.
- Scottn1 9y ago
- liotier 9y agoI plugged French Orange's GPON FTTH ONT into my Debian router's RJ-45 port, added a VLAN interface, added a couple of lines to my DHCP client configuration to pretend my router is some Sagem device and pass authentication to the server... And that's all - sweet 500/200 Mb/s throughput, no ISP CPE in sight (well, technically the ONT...) and Orange even waived the 3€/month CPE rental fee ! Former provider offered FTTB and I used the coaxial cable CPE as a bridge - and even when I do not have that option, I insist on having a router of my own as my network's demarcation: it is basic hygiene. Other option for GPON would have been to plug a GPON SFP module into one of my switches - the friendly guy who laid the fiber to my apartment even left me one in case I changed my mind... But going through the switch to the router and back to the switch on a different VLAN is unnecessarily complicated in my case. Anyone wants a free GPON SFP module ?
- wil421 9y agoI thought about bridging an Ubiquit EdgeRouter and putting in front of the AT&T gateway. You must pass authentication back to the gateway. Users were also reporting around 100megs max speed which wasn’t acceptable for me since I pay for gigabit. There is a new line of EdgeRouters out and maybe it has some acceleration for bridging. I would like this setup.
- aus_ 9y agoYou might try this: https://github.com/jaysoffian/eap_proxy https://github.com/jaysoffian/eap_proxy You have to enable `set system offload ipv4 vlan enable` else your routing performance will suffer.
- RoadieRoller 9y agoSomewhere someone could be selling your data for money. I can imagine the below happening. After all, all corporates are hand-in-glove with each other when it comes to public's privacy. This is probably what your ISP is doing. Take your MAC Addresses, try to find the phones in your house which is connected to the wifi, take those MAC addresses to all the telecoms, get the SIM card number and the phone number associated with those MAC numberss, send those phone numbers to the banks to find matching bank accounts and the associated credit card number, along with your registered email address, get the purchase history from the bank on the credit card number, compare it with your browsing history and sell all of this to another company and make money.
- madez 9y agoThat is very soon illegal in the EU thanks to the GDPR, and it is already in some countries like Germany.
- gcb0 9y agoabsolutely not. gdpr is a nightmare for websites, because of the consent rule. but guess what is the first thing you with a ISP. You sign a contract. done. it's all legal with gdpr or not.
- madez 9y agoIn Recital 43, the GDPR adds a presumption that consent is not freely given if there is “a clear imbalance between the data subject and the controller, in particular where the controller is a public authority.” Importantly, a controller may not make a service conditional upon consent, unless the processing is necessary for the service. Also, data subjects have the right to withdraw given consent.
- gcb0 9y agothey had similar wording to the cookie things. you had to say for what feature the cookie would be used, at the time the user was actually starting use of the feature. advertising? logging in? ....in the end everyone just says "to use this website" and use for whatever (but mostly ads)
- aus_ 9y agoThere is varying levels of difficulty when you want to BYO router. The situation for AT&T U-Verse isn't too fun. If you want to use your own hardware, you only have a few options: 1. They offer "IP Passthrough" which is fake Bridge Mode. They still do routing and you'll still hit NAT table limits of 4096. Connection falls apart for anything over 3000. 2. You can dump and reverse the router-gateway firmware and 802.1X/EAP authentication. Oh goodie. 3. There's a history of exploits for the NVG510, NVG589 and NVG599. Try your luck. [1] [2] 4. Create some "magic" to split the 802.1X and untag VLAN0. Works in Linux at least. [3] 5. But good luck if you want to do this in pfSense or FreeBSD. There's an open BTC bounty if you've got any netgraph / networking chops. [4] [1]: http://earlz.net/view/2012/06/07/0026/rooting-the-nvg510-from-the-webui http://earlz.net/view/2012/06/07/0026/rooting-the-nvg510-fro... [2]: https://www.nomotion.net/blog/sharknatto/ https://www.nomotion.net/blog/sharknatto/ [3]: http://blog.0xpebbles.org/Bypassing-At-t-U-verse-hardware-NAT-table-limits http://blog.0xpebbles.org/Bypassing-At-t-U-verse-hardware-NA... [4]: https://forum.pfsense.org/index.php?topic=111043.0 https://forum.pfsense.org/index.php?topic=111043.0
- dbolgheroni 9y agoTwo huge cases from previous years: https://nakedsecurity.sophos.com/2012/10/01/hacked-routers-brazil-vb2012/ https://nakedsecurity.sophos.com/2012/10/01/hacked-routers-b... https://www.welivesecurity.com/2016/10/21/cybercriminals-target-brazilian-routers-default-credentials/ https://www.welivesecurity.com/2016/10/21/cybercriminals-tar... Your router is critical, and choosing them wisely is one of the most important things if you care about some security.
- jacksmith21006 9y agoProblem is in the US ISP they can sell your data without telling you. So I prefer to keep my data away from them. I trust Google more to not sell my data and fine with them renting it out. Others might not. So use them for DNS for example so it does not go to my ISP. https://www.usatoday.com/story/tech/news/2017/04/04/isps-can-now-collect-and-sell-your-data-what-know-internet-privacy/100015356/ https://www.usatoday.com/story/tech/news/2017/04/04/isps-can... ISPs can now collect and sell your data: What to know about Internet ...