11 ms·
CenturyLink is blocking customer internet, saying Utah legislators told them to
- walrus01 8y agoSenior network engineer for an mid sized ISP here: These people should be ashamed of themselves. I honestly don't care even the tiniest bit about whatever sort of excuses or justification they put up. It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile, and develop workarounds like VPN tunneling their traffic, such as I would do if I found myself using an ISP in Turkey for a month. This bullshit of injecting content into pages has been tried before, a long time ago by Comcast. I really don't see the point to it in an era of LetsEncrypt and nearly everything worthwhile moving to TLS1.2 or better end-to-end. https://arstechnica.com/tech-policy/2009/08/comcasts-dns-redirect-service-goes-nationwide/ https://arstechnica.com/tech-policy/2009/08/comcasts-dns-red... Also you absolutely should not mess with DNS returns from your client-facing recursive resolvers. Various ISPs have tried things like redirecting nonexist results to pages laden with "suggestions" and "advertising".
- api 8y agoUnfortunately enough ISPs have abused their position that treating them as hostile is where we're going. VPNs are a stopgap. The future is end-to-end encrypted protocols like QUIC that obscure even connection state information and prevent anything from being modified in transit at all, DNS over HTTPS, etc. Everything has to be encrypted and authenticated end-to-end.
- walrus01 8y agoYes, I agree. If the global internet community is developing software to deal with threat models that deal with a worst case scenario (the government of Uzbekistan ordering ISPs to randomly block things), the Chinese great firewall, and so forth, we absolutely need technology like encrypted SNI in TLS1.3 and similar. If we develop software with end-to-end crypto to deal with repressive-regime threat models, its crypto should also be inherently sufficient to deal with more normal traffic interception and modification attempts. A lot of non democratic regimes in places outside of North America take a very blunt approach, of having government agencies order all of their domestic ISPs to simply null route huge chunks of the Internet (like, entire ipv6 /16s belonging to Azure and AWS) in order to ban politically objectionable sites. Or to order all ISPs to be singlehomed to, and downstream of the government state run telecom. There is one ASN in Iran which is allowed to have international IP transit connectivity to other non-Iranian ASes, for instance. https://bgp.he.net/AS12880 https://bgp.he.net/AS12880
- jillesvangurp 8y agoYes, men in the middle cannot be trusted. Especially ISPs. Most mean well but are incompetent. Some don't mean well and are incompetent. ISPs that mean well and actually know what they are doing are relatively rare. If you have a device with wifi, most of the time you are on untrusted networks. So, it makes no sense whatsoever to default to some random isp's DNS just because the wifi you are on is suggesting that you use it.
- behringer 8y agoThey're only rare because their CEOs go to jail: https://en.wikipedia.org/wiki/Joseph_Nacchio https://en.wikipedia.org/wiki/Joseph_Nacchio https://www.bizjournals.com/denver/news/2015/04/29/joe-nacchio-speaks-out-on-prison-broken-justice.html https://www.bizjournals.com/denver/news/2015/04/29/joe-nacch...
- gnode 8y ago> Everything has to be encrypted and authenticated end-to-end. This isn't really enough. Even with QUIC / TLS your ISP can still know what endpoint you're connecting to, which may in itself be too bad. This is the problem VPNs are solving (or at least moving the trust). There's also the touted alternative of conglomerate everything onto Cloudflare and have encrypted SNI.
- walrus01 8y agoIf your ISP is doing netflow analysis and DPI on your connection (like the Chinese GFW), with malicious intent specifically aimed at you, you're pretty much screwed anyhow. If they decide to start blocking traffic to VPN endpoints and such. This can be seen if you try running a non-obfuscated openvpn link into and out of China.
- gnode 8y agoExcluding steganography, an eavesdropper will know if they're unable to understand your communications. What's important is that what they can glean isn't enough for them to be specifically motivated or able to harm you. Being seen to be using a VPN only labels you as a VPN user. In China, the authorities dislike individual VPN use, and attempt to curb it with technical measures, but for the most part, they don't go around imprisoning people only for VPN use, because there isn't much expected gain to be had from the average VPN user.
- walrus01 8y agoThe new thing with the GFW in the last 3-4 years is to identify VPN-resembling traffic from DPI, using a fully automated/scripted system, and then over a period of several hours/days, the GFW causes incredibly high packet loss for all traffic to/from the non-china endpoint, eventually culminating in a nullroute of all traffic.
- dylz 8y agoWithout malicious intent, ISPs are already doing this, both to sell aggregated traffic data and to shit all over their network. On Sprint and ATT Mobility I cannot maintain many TCP connections for long durations - websockets will be killed after a while and require reconnection, long-connected TCP games will drop after a few minutes, quite a handful of HTTPS/TLS sites do not load and immediately hardfail with a TLS protocol error or connection reset, traffic appears modified and periodically injected, DNS is hijacked, images' hash values do not match the server side on plaintext connections, NXDOMAIN DNS values are hijacked, traffic crossing any port will be tampered with as long as it looks like HTTP/1.x, etc.
- WorldMaker 8y agoUnfortunately even QUIC and DNS over HTTPS can't save us from the ISPs (and Enterprise ITs) that think TLS/SSL proxies are a good idea, and especially sadly things like QUIC and DNS over HTTPS may push more ISPs towards that line of thinking.
- jimktrains2 8y agoThat would still require a custom cert installed on the end user device, which may not be feasible in the case of some iot devices and generally a pain for most users in general, especially as more websites pin their certificates.
- WorldMaker 8y agoPain for the users has never stopped enterprises from doing it, sadly.
- jimktrains2 8y agoThat is often handled by group policy. I'm not entirely aure how pinni is handled, maybe it's disabled in ie or chrome via group policy too?
- WorldMaker 8y agoJust because it is handled automatically by "group policy" doesn't mean that users don't feel day-to-day pains from it. It just means it is more likely that don't understand where their pain is coming from. ("If I pull up google.com in Chrome or IE it works, but why can't I use Firefox?" "Because we don't support it here." [Because group policy deploying CA certificates to it is harder and it has stricter CA requirements, such as no self-signed certs.]) Enterprise IT can sweep some of that under the rug by controlling which software is allowable to be installed at all, but there's always going to be edge cases in a TLS Interception environment to cause users papercuts, at the very least. To answer your direct question: So far pinning in browsers is still just TOFU [Trust on First Use], I think? So pinning alone still works with TLS Interception so long as it is intercepted on Day One. The Chrome security team has been threatening for a couple versions now that certain pinned lists, including (but not limited to) Google's own sites, would be baked into the browser in such a way that no one should be able to disable them. I wish they have the gumption to pull that off. With Chrome being the current darling browser of a lot of the same IT groups using TLS Interception, that might actually send a clear message that TLS Interception is a bad idea. Unfortunately, it might just be received as "Here's Google's list of sites that have to be whitelisted or outright blocked from our Interception Proxies so as not to confuse our users", but that would still be a step in the right direction in so far as end-to-end internet security.
- liveoneggs 8y agoI attempted to organize resistance within the dns/network group when my former job had us implement this but did not get any support. Oh well.
- WorldMaker 8y agoMy ISP (Time Warner/Charter/Spectrum) DNS hijacked bing.com [0] and non-existent domains for their own "search page" [1]. Since then I've been sure to always configure my own DNS in my router. (Used Google's 8s for a while, now on Cloudflare's 1s.) It's unfortunate that I have to treat my ISP as hostile, but they are the only high speed provider to my address. I sadly can't even assume that there is anyone in management there that feels ashamed at their hostile practices. It's just "good business" to squeeze free ad dollars from your users as you take advantage of your monopoly position to keep prices as high as the market will bear while doing so. [0] Even if I didn't prefer Bing, hijacking any of the major search engines just because it might be an "accidental default" and "no one would notice" is just wrong on so many levels. [1] Scare quotes because it was 90% terrible ads and 10% barely legible search results from who knows what API.
- markovbot 8y agoThat's horrible, did you call them up and ask why their DNS servers are fraudulently lying about IP addresses of certain high traffic domains?
- WorldMaker 8y agoI hate how the conversation goes when I ask them why they are adding fees to my bills that don't make any sense. (I intentionally own all my own equipment, why would I ever have an "equipment return fee" show up other than them trying to screw me over and see if I notice?) I complained to some friends that are very low on the totem pole and they agreed with me that DNS hijacking is extremely wrong but had zero power to do anything. We need strong Regulatory Commissions to hold these sorts of Monopolists accountable, and right now the political climate in states like mine remains that "Regulations are Bad" and "Profit/Greed are Good".
- jrnichols 8y agoI have the feeling they wouldn't get much past the overly scripted front line service, unfortunately.
- 8y ago
- haasted 8y agoLet’s not forget to include Belkin among the companies that have attempted variations of this. In this case, it was their wireless router which would grab a random out-going request and serve up advertisements instead. Imagine being in the middle of buying plane tickets and suddenly finding yourself at a random advertisement. https://www.geek.com/news/belkin-routers-misdirect-users-to-advertising-sites-553765/ https://www.geek.com/news/belkin-routers-misdirect-users-to-...
- walrus01 8y agocheap router manufacturers have been doing dumb things for a long time: http://pages.cs.wisc.edu/~plonka/netgear-sntp/ http://pages.cs.wisc.edu/~plonka/netgear-sntp/
- JohnFen 8y ago"It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile" It should not be, I agree, but the sad fact is that if the ISP is one of the heavy-hitters, then you absolutely have to treat them as a hostile force to be defended against and worked around. Because they are.
- skuhn 8y agoComcast is still doing content injection, for a similar reason. If you go over your monthly quota, they inject a pop-window into HTTP sites to inform you. Every other business manages to inform customers by e-mail or text message or phone call, but ISPs have these additional options by virtue of the product they provide and they just can't seem to help themselves (at least for the large shitty ones, which they all become eventually).
- anticensor 8y agoWhich mid-sized Turkish ISP do you work at? Netspeed or TÜRK.net?
- pwg 8y agoAnd here we see the disconnect between what politicians say, and what they write into law. The bill's sponsor's response to the blog authors query: SB134 did not require that ...They were only required to notify customers of options via email or with an invoice. And here is the text of the statute that was written: (ii) A service provider may provide the notice described in Subsection (2)(b)(i): (A) by electronic communication; (B) with a consumer's bill; or (C) in another conspicuous manner. Note the difference in language breadth. Bill sponsor: "via email" - text of statute: "by electronic communication". And note clause (C): "in another conspicuous manner". Century link is notifing by: "electronic communications" (DNS hijacking to force viewing of the page is "electronic communications") and/or by "another conspicuous manner" (it is definitely "another" and it is clearly "conspicuous" (one will not miss it)). So, the fault here lies with the politician. He wrote a law that allowed Century link too much leeway to "do whatever they wanted to do to notify". If they were really only required to "notify ... via email or with an invoice", then clause (A) should have said "via email" and clause (C) should not have been present.
- deleted 8y ago[deleted]
- pureagave 8y agoI agree that the fault lies with the politician, but I would argue that the real issue is that they forced all ISPs to send notice to customers. If a politician wants something communicated, they can fund a public awareness program, not force it on ISPs. That fault doesn't exonerate CentryLink's action. edited to add CentryLink responsibility
- fpgaminer 8y agoHmmm, so if I were on CenturyLink and in the "SOL" category the following could have happened. Attempting to email my state senators to express a political opinion? Freedom of speech: Blocked. Buying from a company online, located in another state? Interstate commerce: Blocked. Trying to run an online business? Blocked. Trying to contact my kids? Blocked. My elderly grandmother is dying and family was trying to Skype me in since I couldn't make it? Blocked. The number of constitutional laws, federal laws, and moral laws broken here is mindbogglingly astronomical. Good luck, CenturyLink.
- kingbirdy 8y agoYour constitutional protections are protections from the government, not businesses.
- blattimwind 8y agoThis isn't necessarily true. E.g. the fourth amendment applies, according to precedent, to communications service providers in at least some capacity.
- wahern 8y agoIn their capacity as agents of the government.
- craftyguy 8y agoIs the line a bit fuzzy though because most ISPs in the US are government-sanctioned monopolies?
- erikpukinskis 8y agoAre you sure?
- craftyguy 8y agoNo, that's why I'm asking... Not every question on the internet is a thinly veiled attempt to make a statement!
- sonatas 8y agoThe blind leading the blind....
- zapdrive 8y agoSo what happens if a CenturyLink customer is not using their DNS, and using for example Google's DNS. They will suddenly have their internet disabled and will never see this page, where they have to click "OK" to reconnect their internet.
- sleepydog 8y agoYou could argue that they are failing to notify customers who do not use their DNS, and aren't complying with the law. Email or a notice on their invoice would not have had that problem.
- jeroenhd 8y agoThey will probably forward all DNS traffic to their own resolvers by just changing the destination IP of any UDP traffic to port 53. This won't work with DNSSEC or encrypted DNS though.
- aflag 8y agoThe tldr section of the article says that's not the case.
- snapwich 8y agoIt wasn't the case for me, however I'm not exactly sure how they've implemented this DNS hijacking and if I was just an exception or the rule. Other people using custom DNS seemed to have a similar experience from what I read on reddit though.
- tptacek 8y agoIt'll work just fine with DNSSEC for the overwhelming majority of sites on the Internet, since virtually none of them are signed and DNSSEC doesn't actually encrypt traffic. Encrypted DNS, though, like DoH or DNS-over-TLS or DNSCrypt, stops this cold.
- jrnichols 8y agoOf all the way to inform customers of something, Centurylink picked the most obnoxious and intrusive way they could think of. wow.
- waffle_ss 8y agoThe original article title is more accurate. Replacing "CenturyLink" with "Utah ISP" as if they're some podunk lil' no-name ISP is misleading. CenturyLink is a Tier 1 ISP, and 5th largest in the country by customer count. Maybe city folk haven't heard of CenturyLink but they have monopolies over vast swathes of rural copper networks.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- riffic 8y agoThis is a company with an interestingly convoluted corporate history: https://en.wikipedia.org/wiki/CenturyLink https://en.wikipedia.org/wiki/CenturyLink
- snapwich 8y agoYeah that's my bad. I thought saying Utah ISP might highlight that this is currently only a Utah issue and CenturyLink isn't blocking everyone's traffic... I think.
- gtdawg 8y agoIf the title said just Centurylink instead of Utah, people would be complaining of click bait, so I think Utah was the better choice. Using "Centurylink (only in Utah)" or something similar would have been the most ideal from an accuracy POV.
- abrowne 8y agoUnfortunately they are the only option for fiber in the part of Minneapolis where I live. It's slightly better than Comcast.
- gtdawg 8y agoThey purchased Level(3) who already previously owned Global Crossing, Savvis Video and Genuity, among other acquisitions. The Level(3) name was much more memorable in the carrier/enterprise/ISP field and it feels like they are starting from scratch on brand recognition, because as you said, lots of people haven't heard of Centurylink before. Edit: And as noted by the thread "CenturyLink is totally shady.", Centurylink's retail consumer reputation is quite tarnished (as are most large consumer ISP companies) and mixing that reputation with Level(3) was a bad decision, IMO.
- hartz 8y agoMore widespread use of DNS-over-TLS/HTTPS/QUIC can't come soon enough
- dcbadacd 8y agoESNI also can't come soon enough.
- crispyporkbites 8y agoWhy is this so surprising? You pay for your internet from this service provider and this is the trust you're putting in this private company. All your communication that goes down this channel is subject to their rules, and unless you encyrpt it they can do what they like. I think these kind of crappy implementations just surface a bigger problem underneath. If you don't choose your own DNS servers, if you don't have proper DNS security, https by default everywhere etc. etc. you don't have a secure connection.
- deleted 8y ago[deleted]
- westbywest 8y agoYour reasoning would be fine, were it not for the fact that an ISP's mere existence in an area, no matter how crappy, generally satisfies FCC's mandate to promote/fund broadband penetration. So, Crappy-ISP, LLC existing and being able to pencil-whip FCC filings about minimum speed expectations across its coverage area means the FCC will make no effort to provide funds for Less-Crappy-ISP, LLC or Moderately-Crappy-ISP, LLC to come in and fill gaps.
- wl 8y agoIt's sad that even ISPs seem to think that WWW = the internet these days. If I were traveling and I couldn't VPN into my home network because of this, I'd be really pissed.
- arnonejoe 8y ago5G will put century link out of business.
- inetknght 8y agoI'll believe that when I see it. Until then, I believe that any wireless communication is inherently inferior to wired communication.
- Someone1234 8y agoIf it can achieve 1 Gbit/s as advertised and scale to enough customers? It just might. But I'm going to be interested to hear the first real customer's experiences. For example what is the latency they're seeing? Weather outages? How well does it handle peak hours? Don't misunderstand, the current ISP competition in much of the US is super toxic, and I don't support it. But 5G promises a whole lot, and I cannot ignore the technical side of why it may fall short.
- markovbot 8y agoSo we'll have a different shitty ISP? My shitty carrier (T-Mobile) does DNS hijacking of all NXDOMAINs, and pretends like it's perfectly reasonable.
- mholt 8y agoGoogle Fiber just sent a nice email with some links to resources for families. And it was totally sufficient to satisfy the law. (Source: am in Utah) So there are two problems at play here: - Laws are technically ambiguous - CenturyLink and most other large ISPs are awful, incompetent companies
- kstrauser 8y agoI loathed CenturyLink when I had to deal with them. Quick reminder: they never specify which century they're linking you to.
- timerol 8y agoGiven that they were founded in 1930, I think the century is pretty clear, though not favorable.
- diebir 8y agoWell, is the ultra conservative (LDS) Utah for you. LDS church has issues with porn, they pushed an idiotic law, the consequences did not have to wait long.
- xahrepap 8y agoCenturyLink is totally shady. My wife just yesterday spent a significant amount of time fixing our phone bill. She decided a couple months ago to upgrade to a "fixed" bill plan (apparently they've been raising our prices $10/mo every year for the last few years). This plan price won't change until we change the plan. It's bundled with their internet though, but my wife told them to not send the modem because we weren't going to be using it and didn't want to be charged for it. Fast forward to yesterday and we had a modem in the mail a $200+ bill for our landline that should be <$60. She called and the guy on the other end was very helpful (surprisingly). He went through the bill line-by-line and almost every time said something to the extent of, "Why is that here?" "I'm going to have to talk to {previous sales lady who 'upgraded' us}". Some of the items he didn't even know what they were and couldn't remove them, so he instead gave us a permanent $10/mo discount or whatever it was billing. About the modem, he said, "You can keep it or mail it back. I can make a note on our software that you didn't want it and it shouldn't bill you for it. However, I recommend you mail it back because sometimes that note will disappear from our software and start charging you again". Wait... what!? Did he just acknowledge what some of us has suspected all along? That their software has intentional "bugs" that don't remember to stop billing someone for something? The whole thing feels like a scam to me. I don't trust them at all. This isn't the first time and won't be the last either. The reason we haven't canceled? No other traditional landline offerings in our area. Everything is VOIP or Cell. My wife wants something independent for emergencies. She's starting to question the value of it all though.
- illumin8 8y agoThe quickest way to resolve all of these billing shenanigans: file a consumer complaint with the FCC. Magically, you'll almost immediately get a phone call from someone fairly high up in the company (typically executive relations or similar) that has the power to fix things and will make it right. The sad truth is that these telcos will systematically screw millions of customers with shady fees and fraudulent billing practices, but when the FCC gets involved, they are facing potential fines of tens of thousands for each infraction, so they'll bend over backwards to get you to drop the complaint. Try it sometime, it sucks that it's necessary, but you'd be amazed at the results.
- ryanolsonx 8y agoThis happened to my brother-in-law. They told me that their internet went down and that they need help. Since I'm good with computers, I came over to "fix"
- ryanolsonx 8y agoThis happened to my brother-in-law. He asked for help when his router wasn't "working". Since I'm pretty computer savvy, I agreed to come and "fix" it. Little did I know that it was this BS. I got to that notice and then finally the internet started working again. This is a small reason why NET neutrality is important. Total BS. I'll never use CenturyLink. I've thought about it in the past, but after this, H no.
- dreamcompiler 8y agoThis is an example of why the FCC needs to regulate ISPs and enforce net neutrality. CenturyLink needs to be fined $$$ per incident for stunts like this. Their shareholders need to feel the pain.
- twhb 8y ago“It’s because the law gave them too much leeway” doesn’t make sense. If you have leeway, you choose the easiest and cheapest method, not the one that involves building a whole new communication system. “They thought it was the only way to satisfy the law” also doesn’t make sense. There’s no reasonable way to get that from the law, they didn’t confirm it was necessary, and they didn’t publicly fuss about being forced into a large expenditure. Today is, by the way, the one year anniversary of the repeal of net neutrality. ISPs, including CenturyLink, were viciously fighting to end rules preventing the sale of selective internet access, and won. In order to sell selective internet access, you need exactly the system that just showed up. This system would take a while to build—maybe a year. And once it’s built, you would want to test it. The test would put your capitalization on the lack of net neutrality in the spotlight—unless you just serve a legal notice, and pretend you thought you had to. For that to work, you need to make sure people know the “legally required” part; for a legitimately legally-required notice, companies typically don’t say as much. CenturyLink literally highlights it.
- nacs 8y ago1) Most ISPs have something like this router/software -- one that is capable of injecting/redirecting web requests to whatever they want. I remember seeing this kind of thing when I was a Comcast customer -- they implemented a bandwidth limit and to warn you that you were about to exceed it, they used this type of web request injection. 2) There's likely a profit motive here as the software that is being advertised via this injected message costs money. They're likely getting a commission/affiliate fee from every customer that installs said software via this notice.
- B-Con 8y ago> “It’s because the law gave them too much leeway” doesn’t make sense. If you have leeway, you choose the easiest and cheapest method, not the one that involves building a whole new communication system. No, you choose the most self-interested option. That type of criticism is usually levied against laws that provide an incentive to enforce it in a self-serving way. In this case what CenturyLink did should itself be illegal. CenturyLink knows fully well this was a self-serving move and they likely only did it because they're betting they can avoid lawsuits by blaming the law. Interfering with traffic on a paying customer's active account should be illegal so there is no option to do this for any reason.
- otakucode 8y ago"that the consumer may request material harmful to minors be blocked under Subsection (1)(a)" absolutely unequivocally does NOT translate to "inform the customer that they can pay for filtering themselves". The law really clearly puts the burden on the ISP to perform the filtering, and requires the ISP to inform the customer that they can request the filtering be turned on - not that the customer can purchase some product that does filtering.
- logfromblammo 8y agoI saw something similar with a hotel wi-fi setup. In order to reach the Internet, you have to agree to the hotel's terms of service. The page to accept the terms of service is presented by redirecting any HTTP request from an unauthorized device. But (!) the redirect page was resolved by DNS, and DNS traffic to the Internet is also blocked. Only the local DNS resolver is accessible. The instant any machine that specifies a specific DNS resolver tries to connect, the attempted redirect fails silently. In order to get things working, you have to clear your DNS settings to use the DHCP-specified DNS resolver, click the "accept" button on the redirect page, and then re-enter your previous DNS settings. I wasn't so much angry that this was happening, than angry that they did such a ham-handed, botched job of it. If you're going to block outside DNS, you have to redirect to an IP address rather than a DNS-resolved address.
- zzo38computer 8y agoThe customer might not even see it without compatible software, or if using a different port number or protocol, or if not using DNS to access something, or using a different DNS. Or if you are using a web browser but with customized settings that make it incompatible. Same with many hotels. If you are not even using HTTP(S), or DNS, then it won't work, and even if you are using HTTP but not with a web browser program, it won't work (there is a HTTP response code (511) defined for this purpose at least), using nonstandard port numbers, etc. For terms of service requirements, one possibility to avoid these problem is to make the printed terms of service document with the wi-fi password mentioned in that document.
- cronix 8y agoI don't know if they do this (I no longer have them), but Comcast used to do this for DMCA notices. They'd inject an iframe with the message into the websites you were viewing.
- LeoPanthera 8y agoI use Xfinity. (It’s my only option for internet.) They would routinely inject crap into unencrypted HTTP webpages, bill notifications, adverts for antivirus, stuff like that. In the end I configured my (pfSense) router to forward all data on port 80 (and a small selection of other commonly unencrypted ports) through a VPN to a local VPS. Port 443 HTTPS is still allowed to connect directly. Makes me feel a lot better. Comcast should be a dumb pipe, not fucking with my data.
- RKearney 8y agoThere's an RFC[0] for that [0] https://tools.ietf.org/html/rfc6108 https://tools.ietf.org/html/rfc6108
- joshu 8y agoThat Comcast wrote.
- beatgammit 8y agoI have a municipal fiber connection, but the bandwidth is atrocious and Comcast seems to be much better priced for faster speeds. What router do you have? Is it just something running OpenWRT, or something fancier? Also, how much do you pay beyond the listed service price (fees, taxes, etc), and can you waive the installation fee?
- LeoPanthera 8y agoMy router is a PC Engines APU2 running pfSense. When I signed up there was no installtion fee, and no problem doing a self-install. But this was years so, so I have no idea if things have changed or not.
- beatgammit 8y agoThanks! That machine looks pretty awesome, and it even supports ECC and core boot. I might have to pick one up and see if I can get more SATA through the mini PCIe and have to be a storage server that also routes traffic. I've been hoping for an ARM chip, but with ECC, this might just win out.
- aplummer 8y agoThe comments here interesting but nuts for foreigners. I’m so used to a slight mention of an ombudsman being a 15 second turnaround to almost anything I ask for happening with ISPs / telcos. I worry about buying anything in the USA with such scant consumer protection.
- nimbius 8y agoFor anyone in Utah currently trying to deal with this issue, you might be able to workaround with pihole: https://pi-hole.net/ https://pi-hole.net/ or perhaps a local resolver?
- bogomipz 8y agoWow this is a new low. Can someone say is CenturyLink a monopoly is most of the state? Can these customers vote with their wallet and go elsewhere for Internet? I really hope.
- nhumrich 8y agoReally depends on the city and area. In some places, there is a plethora of options. But I currently cant vote with my wallet. They are the only provider in my neighborhood.
- ezoe 8y ago> I would switch ISPs but I have no other options where I live. Hopefully making this issue more public will help CenturyLink make better decisions, Seriously? I won't trust such ISP to send/receive even one bit of information if I were him. Even if they changed their mind because of this, Don't trust them until all the boards resigned, all the employees implemented this be fired, lost the massive lawsuit from all the customers, and then, after acquired by other sane ISP.
- sbrother 8y agoFor any other Utah residents in areas that aren't served by cable, check out Utah Broadband. They've been fantastic for us, serving up 60Mbps over line-of-sight fixed wireless. Also their customer service rocks.
- mproud 8y agoYou can choose to opt out of their DNS ads with a phone call. That’s what I did a long time ago.
- ngngngng 8y agoCentury link is my only option for internet here in rural Utah at a max speed of 3Mbs per second. Luckily our municipal network is going up soon with max speeds of 10GBs per second. I'm very excited.
- hathawsh 8y agoI'm not going to defend CenturyLink, but in the interest of attributing this mistake to incompetence rather than malice, I'd like to suggest how this might have happened. CenturyLink is a multi-state ISP and their generic system has limited ability to support state-specific policies. They have a well-developed system for creating state-specific packet processing rules, but they don't have a well-developed way to notify all customers in a state. Therefore, when Utah surprised CenturyLink with a new law, they didn't have a way to comply with the law quickly except by changing their packet processing rules. This was the ugly result. CenturyLink should obviously have some way to add state-specific notifications to customers' bills. I hope they learn that lesson from this ridiculous event.
- techsupporter 8y agoWould it be too difficult to select all service addresses where state is equal to "UT" and then send a bulk rate piece of paper to each of them with these same words? On my CenturyLink bill in Washington State, I get state- and city-specific notices every month, but even if that's not easily changed, a piece of paper in the mail would have sufficed quite nicely with no packet blocking required at all.
- al2o3cr 8y ago> CenturyLink should obviously have some way to add state-specific notifications to customers' bills. If only there was some relevant piece of data, already required to ensure the bill reaches it's destination, that could help them determine which customers are in which states. They know billing addresses, and service addresses. They just didn't care.
- beatgammit 8y agoI think it was that this was cheaper and easier to implement, so they didn't bother doing the better option.
- enzanki_ars 8y agoI don’t think CenturyLink thought through the implications of what they just pulled. I know that there are a significant number of people that use VoIP services like Vonage. Imagine waking up in the middle of the night with a need to call 911, but your ISP purposely broke your internet just to sell you a “security offering.”
- bradenb 8y agoWell this sucks. I have CenturyLink for residential gigabit fiber. Honestly, they've been a fantastic ISP for me. I also haven't received the notice and I'm one of those "SOL" customers that uses non-CenturyLink DNS. We'll see what happens. I'd be surprised if they didn't stop this immediately as soon as it blew up. I have been noticing comments from people in my area on social media over the last month with the recurring theme "Is anyone else's CenturyLink down?" This must have been it.
- emilfihlman 8y agoThe bill is the issue.
- jiveturkey 8y ago1. The actions in the article don't seem possible. Google search is forcibly https, using HSTS. In Chrome and Clank (android), maybe others, google is additionally cert-pinned. It is not possible, through DNS or any other trick, to get forcibly navigated away from the google search page or to have content injected. He says he "turned to a google search on his phone" but he must have done something else before actually searching google, to get the injected notice. I feel this is an important point. 2. This doesn't meet the requirements of the law. The person using the internet, especially at some arbitrary moment, is not likely the subscriber. The law is that the consumer must be notified, with consumer explicitly defined as the subscriber. Email to the address on record, or an insert in a mailed invoice, or a special mailing, seem the only reasonable ways to meet the requirements of the law.
- auslander 8y agoAlways on VPN on all your devices is pretty much a must today. Added benefit when using commercial VPNs is hiding your IP address, a key feature for tracking you by Adtech industry. Finding good VPN provider is tricky though. Definitely avoid free ones. Look for ones providing configuration for native VPN clients, like profile.mobileconfig file for the native iOS / MacOS IKEv2 client. Using native (OS supplied) clients lets you avoid installing third party VPN apps.
- gmac 8y agoDepending on what you're trying to achieve, running your own can be a good and simple option: https://github.com/jawj/IKEv2-setup https://github.com/jawj/IKEv2-setup https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- auslander 8y ago> running your own can be a good and simple option + trusted vpn - unique IP that only you use, bad for tracking. Your searches and browsing history is linked easily to you.
- time-domain0 8y agoFucking Mormons and their censorship bollocks coupled with corporate BS equals steaming crap piled higher and deeper.
- stefek99 8y agoClickbait. "displaying popup and clicking OK to dismiss" is not as harmful as blocking the internet. They control all the traffic anyway...