5 ms·
So recently TPG used their CWMP powers to disable the OpenVPN server on all of their customer's routers, including the VR1600V [1]. Without any notice too - an
by gwillz 6y ago
So recently TPG used their CWMP powers to disable the OpenVPN server on all of their customer's routers, including the VR1600V [1].
Without any notice too - and I know a few businesses that were pretty upset with this. Particularly because many of their employees were working from home and 'in this climate'.
A commenter has also pointed out [2]:
> The Archer VR1600V software is licensed under the GPL. This can be used to compel TPG to release the source behind their modifications, if anyone wants to use the legal system to chase TPG for information.
Edit: I know that the version of OpenVPN on the router was using TLS 1.0, which is deprecated in all clients now. That's besides the matter. I don't believe it's an ISPs role to be fiddling with the application level services of someone's internet.
[1]: https://community.tpg.com.au/t5/Broadband-Internet/Missing-VPN-Setup-on-Archer-VR1600v-v2/m-p/80095#M31146 https://community.tpg.com.au/t5/Broadband-Internet/Missing-V...
[2]: https://www.marcelvarallo.com/some-more-fiddling-with-the-archer-vr1600v/#comment-33884 https://www.marcelvarallo.com/some-more-fiddling-with-the-ar...
- milankragujevic 6y ago> I don't believe it's an ISPs role to be fiddling with the application level services of someone's internet. It is not but it doesn't mean they won't do it. I am lucky enough to be unlucky enough to be using VDSL2, so I use my own CPE where possible, and often just disable the TR069 interface and CWMP functionality so the ISP can't break into my modem. The reason for this is they often factory reset the modem if their automated auditing scripts notice something "forbidden", i.e. DMZ to my router, which causes me great inconvenience to have to log into the modem again and setup a DMZ. Same would happen if I was using (soft-disabled) Bridge mode. So I just deny them access. On some modems I also download the config, change SSH and Telnet password (as well as "admin" and "telecomadmin" passwords for web UI), remove CWMP entries completely, and then restore the config so the modem won't connect. Best part is, if I have a problem that I have to report to the ISP, I first factory reset the modem, it pulls the config via TFTP on TR069 interface, resets again and configures itself according to their wishes - then I try to reproduce the problem, and if it is present, I call them to open a support ticket. If it is not present, I roll back to my config and try to debug the issue on my side. No harm to the modem, no time wasted for me. Sadly this is not at all possible for DOCSIS cable modems nor GPON ONTs for fiber to the home service. There you're SOL if your ISP is being mean and displaying anti-user behavior.
- wil421 6y agoWhat’s worse having VDSL or DOCSIS/GPON and not being able monkey with your config?
- milankragujevic 6y agoHaving DOCSIS is the worst. The connection is unpredictably unstable and I personally reject any belief of a "tuned cable system" existing. It's all a mess. And by design since DOCSIS auth is done on the CPE (modem), the device is not trusted and you cannot use your own unless the ISP [is forced to] allows it and whitelists it. So DOCSIS is hell. GPON is ... depends. The technology is great, but some ISPs can and will ruin it because they're greedy and shortsighted. Someplaces you can get a bridge CPE (ONT) that does have remote access but doesn't allow configuration, someplaces the ONT itself is fine (i.e. HG8245 series for which too you can disable TR069 interface and CWMP and change the passwords - which I did), but someplaces you just get the "DOCSIS over fiber" experience, with hostile ONT in your home network the ISP uses to make your existence miserable. Personally, DSL is fine for me. I am so used to low speeds (~20/2 Mbps) when I am in the village (since march due to COVID, working from home), I have started bonding [0] DSL and LTE for around 95/45 Mbps and that is fine for me. So, I'd rather stay on tried-and-true, stable, low ping DSL, than muck around with DOCSIS and fear any rain or wind. For GPON it depends on the ISP, but the technology does not dictate any remote management requirements except OMCI which is not concerned with "higher layer" configuration such as WiFi or router features. [0] https://milankragujevic.com/openmptcprouter-true-bonding-of-2-wan-connections-for-cheap https://milankragujevic.com/openmptcprouter-true-bonding-of-...
- pabs3 6y agoI wish AON was more common than GPON, since with AON you can have your own CPE, while with GPON your CPE will get data from multiple customers, so you controlling it is a privacy risk.
- milankragujevic 6y agoYes, me too. But it's more expensive. And ISPs are so used to milking old infrastructure it's a miracle we're getting any fiber now that DOCSIS can do gigabit. edit: funnily enough, DSL is similar to AON in that it's dedicated last mile
- Namidairo 6y ago> The Archer VR1600V software is licensed under the GPL. This can be used to compel TPG to release the source behind their modifications, if anyone wants to use the legal system to chase TPG for information. I doubt many of the modifications done for them fall outside of flicking random config switches on/off and making sure the factory config will provision properly. Most of the source drops I see from embedded hardware manufacturers aren't usable out of the box for one reason or the other anyway. Open source devs won't touch a lot of Broadcom hardware just because the driver situation is an unabated nightmare. Despite this, many/most of the TPG (2nd/3rd largest Australian ISP) customers will have to keep their VR1600V's connected in some form anyway, as they provision the sip credentials to them, and refuse to allow you to use your own voip hardware...