14 ms·
Threeuk is blocking Tutanota
- jonas-w 4y agoPrevious discussion: ThreeUK blocks access to encrypted provider Tutanota due to 'age restriction' - https://news.ycombinator.com/item?id=33981873 https://news.ycombinator.com/item?id=33981873
- schappim 4y agoThe same privacy preserving features of Tutanota enjoyed by privacy conscious individuals, make it ideal for fraudsters. We experience a large number of fraudulent ecommerce orders using Tutanota email domains. I'm not shocked to think that this could be an example of an algorithm gone awry based on the signals it received.
- Raed667 4y agoIt is not the job of an ISP to decide what is fraudulent and what is not. They should be a dumb pipe between services and people.
- masklinn 4y agoThat is not really true, ISPs are relied on by non-technical customers who have neither the personal chops nor a 24/7 technical assistant to help them. Whether ISPs succeed in any way is an entirely different ballgame, but this is absolutely the job of the ISP, especially in their role of email provider. Its ability to properly discriminate and aggressively block or plonk messages isvery much one of the reasons people like gmail.
- throwaway0x7E6 4y agoyes comrade, lets confine everyone to a handful of party-approved websites, for their own good.
- robertlagrant 4y ago> Whether ISPs succeed in any way is an entirely different ballgame, but this is absolutely the job of the ISP, especially in their role of email provider. They aren't providing email in this example, as far as I can tell. They're providing internet access to an email service. Or they should be.
- psychphysic 4y agoThat's not how the UK works. We invented the nanny state.
- EdwardDiego 4y agoAnd the nanny fetish, although that seems to be rather particular to a certain class of people in the UK. That said, full credit on the nanny dog, Staffordshire bull terriers are amazing with children.
- geraldwhen 4y agoThey’re certainly good at silencing children permanently.
- kitd 4y agoNot Staffs. You may be thinking of pitbulls.
- EdwardDiego 4y agoBe sure to distinguish the English staffies from the American staffies. Very different dogs.
- callahad 4y agoIt shouldn't be the role of the ISP, but in the UK content blocking is legally mandated. E.g., "The Digital Economy Act 2017 placed the requirement for ISP filtering into law and introduced a requirement for ISPs to block pornographic sites with inadequate age verification." https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kingdom https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin...
- Eleison23 4y ago
- that_guy_iain 4y agoPorn and fraud are two very different things.
- IshKebab 4y agoYeah I'm not sure how much ISPs still bother with that. Up until a year or so ago my ISP was pretty good at blocking torrent sites but now I can visit e.g. 1337x.to with no problems. I think this is talking about 3's adult content filter which is different and has existed for ages and has always been shit (I assume most people disable it).
- lost_tourist 4y agoYeah but email is a service completely unrelated to porn.
- roenxi 4y agoHow can an ISP be sure an end-to-end encrypted communication channel isn't being used for porn? It is encrypted. By design they have no idea what it is being used for. It would be very easy to set up a ring of pornography distributors using email (at least in the UK, in civilised countries they'd probably be put out of business by the open internet).
- Nextgrid 4y ago
- hrrsn 4y agoFraudulent ecommerce orders are the only time I've seen tutanota addresses in the wild.
- nonrandomstring 4y agoI have two colleagues who regularly send me emails from that domain. For the first , I assumed it was her own domain. When I saw messages from a second person I assumed they might both work for the same company. Now I figured it's an ISP. I checked it out and it looks like a good, legit service for people who don't want creeps and advertisers grubbing through their messages. Three UK have no place blocking traffic from legitimate users and must identify problematic use on a per case basis. Modern legal systems usually limit criminal liability to individuals [1]. Companies engaging in acts of collective punishment (That goes for you too Cloudflare) should at least try to raise their ethical standards to those expected by International Law. https://en.wikipedia.org/wiki/Collective_punishment https://en.wikipedia.org/wiki/Collective_punishment
- masklinn 4y ago> Now I figured it's an ISP. It's not an ISP, it's an email provider. > Modern legal systems usually limit criminal liability to individuals [1]. Companies engaging in acts of collective punishment (That goes for you too Cloudflare) should at least try to raise their ethical standards to those expected by International Law. There is no "criminal liability", and blocking malfeasants on the internet has always been a heuristic fight. If a service originates an extremely high rate of fraud versus legitimate uses, it's a good heuristic for fraud. It's a shame for legitimate users, but it's also how it's always worked. And more generally minor (or self-hosted) MTA have always had that issue, it's not news that they get delivered less reliably than big "trusted" mail hosts, and that they can get blacklisted real fast.
- schappim 4y agoTotally, especially that CloudFlare wall of harrassment... It is a form of harassment, and it needs to be recognised as such!
- agumonkey 4y agoIt's strange how cryptography, in mail or 'coins' is always leading to the same dilemma.
- nicce 4y agoEcommerce service itself should be using Tutanota if fraudsters want the most privacy benefits. If not, Tutanota is like any other email provider, possibly with better privacy policy.
- infinitedata 4y agoI’m sure there are the same or more number of fraudulent cases coming from gmail accounts but they don’t block that one
- jamespo 4y agoAs a proportion of total email volume for each service?
- masklinn 4y agoThe question is one of ratio, and false positives versus false negatives. If 90% of tutanota-orginated emails are fraudulent, tutanota is an excellent fraud indicator, even though it will block legitimate emails. If 10% of gmail-originated emails are fraudulent, gmail is a terrible fraud indicator, even though it will let fraudulent emails pass through, possibly more than the count of fraudulent emails coming from tutanota.
- newaccount74 4y agoBut if you block Tutanota the fraudsters will just switch to Gmail, and all you accomplished is that you inconvenienced legit Tutanota users. I wonder why so many companies drag their feet when implementing actually useful anti-fraud measures (like supporting Verified-by-Visa) and instead block random email providers.
- schappim 4y ago> drag their feet when implementing actually useful anti-fraud measures (like supporting Verified-by-Visa) Most ecommerce merchants are non-technical, and utilise 3rd party platforms (Shopify, Bigcommerce etc) that in combination with their Payment Gateway don't support these systems. I can safely say that every order my business has received with a Tutanota address has turned out to be fraud. It is a really strong indicator for a fraudulent transaction. There are many other signals, but for some reason this is a really strong one. We see a similar trend with Aleeas, and Simplelogin. We still get fraud from Gmail and Outlook addresses, but it is picked up using other indicators, IP, IP owner, Shipping Address, phone number reachability, carrier, Payment Methods, name, useragent, "for lease" or "for sale" status of the delivery address etc etc...
- schipplock 4y agoYou can register an account for free. You don't need to provide anything when registering an account, just choose an E-Mail and a password. Is that what you mean with "privacy preserving"?
- deleted 4y ago[deleted]
- jonatron 4y agoThree also have a transparent HTTP proxy, which breaks apt updates, so you have to manually replace http with https in your apt sources.list.
- andreareina 4y agoHow are they breaking apt? Aren’t signatures checked only on the package itself?
- jonatron 4y agoYou randomly get 4xx or 5xx response codes (can't remember which one)
- deleted 4y ago[deleted]
- jonas-w 4y agoWhy was it only http in the first place?
- iforgotpassword 4y agoSo it could be cached by transparent proxies.... Ones that work properly that is.
- mwagstaff 4y agoSlightly off topic, but I was with Three UK for a while. Reception was universally terrible, and trying to use mobile data was a joke. This was in a small urban centre... called London. Would never, ever touch them again. Back on topic, it seems that they are not using Bluecoat/Symantec Site review (which I suspect other providers do), which has the domain categorised correctly: https://sitereview.bluecoat.com/#/lookup-result/https%253A%252F%252Ftutanota.com%252F https://sitereview.bluecoat.com/#/lookup-result/https%253A%2...
- acqbu 4y agoHad a similar experience and everyone I know has nothing but bad things to say about Three UK. It doesn't surprise me that it's the least popular network out of the 4 main mobile operators. https://www.statista.com/statistics/375986/market-share-held-by-mobile-phone-operators-united-kingdom-uk/ https://www.statista.com/statistics/375986/market-share-held...
- aix1 4y agoThree UK made me jump through quite a few hoops when I decided to leave them, and then kept billing me after I'd cancelled the contract (at the end of the tie-in period) and had returned all hardware. I ended up having to escalate things to the ombudsman in order to have them resolved. Would never go anywhere near Three ever again.
- psychphysic 4y agoYes similar, truly awful. Often had to manually switch to 3G for any utility. Also made the mistake of switching to Smarty their budget brand. Even worse (of course)
- azalemeth 4y agoThree are owned by CK Hutchinson Holdings [1], a Hong-Kong and Cayman islands registered multinational conglomerate that owns a number of telephone/ISP companies, ports, and some gas pipelines, as well as the main HV electricity maintainer in the east and south east of England, UK Power Networks. Rather than privatisation giving democratic power over essential infrastructure to good-old capitalist citizens, I would politely argue that we appear to have sold it to the Chinese government instead. [1] https://en.wikipedia.org/wiki/CK_Hutchison_Holdings https://en.wikipedia.org/wiki/CK_Hutchison_Holdings
- pzmarzly 4y agoInterestingly, ThreeIE doesn't block them. And I'm fairly happy with them (>1Gbit/s on 5G still blows my mind), except for when I'm travelling to London and have to roam on 3 UK (I agree it sucks)
- hunta2097 4y agoSimilar experience in my town. I got a strong 5-bar signal but their backhaul must be running on 56k modems.
- wheybags 4y agoOut of curiosity, do the UK content blocks apply to people roaming with a foreign sim? I'm also on three ie, just haven't been to the UK in ages.
- g_p 4y agoNormally not, as historically traffic from roaming users has been "home routed". That is, it was sent over a tunnel (think IPsec or similar) back to the user's home network, where it left through their usual infrastructure. Especially in late 4G and 5G, with ideas of low latency services (that would break if you did this), there are options to route traffic into the visiting network instead. Not sure if anyone's using this though.
- pzmarzly 4y agoGood question, I don't remember. I think it wasn't filtered? The only thing I remember for sure is that when I was recently in the Netherlands, the 3IE content blockers weren't in effect. So I think it's the same when visiting the UK, falling open by default. (Yes, I don't want to send my passport photo to 3IE, that's why I'm dealing with these blockers. And I heard that even if you do verify yourself, they still mess with the DNS records.)
- Nextgrid 4y agoGenerally no. Roaming data sessions are tunnelled back to the host provider.
- deleted 4y ago[deleted]
- Throwaway3user 4y agoWhen I am roaming, I notice lots of google results that are HTTP go through a couple of redirects to end up being "age-restricted".
- cloutchaser 4y agoWelcome to the Uk nanny state, where safety rules above all else.
- Throwaway3user 4y agoBut this seems more like a bug? Correcting to use https has no issues...
- RockRobotRock 4y agoBecause they can't intercept HTTPS.
- fmajid 4y agoThey don’t need to. DNS is still mostly in the clear, and SNI is still unencrypted so they may not know exactly what you are reading, but they definitely know what sites you are on.
- BoxOfRain 4y agoI remember reading one poll during the pandemic where a quarter of Britons wanted nightclubs to shut permanently even after the threat of the virus had subsided. For the Vernon Dursley archetype it's not enough for themselves to be allowed to live a very beige and conventional life but everyone else must be made to as well.
- kellyharsh 4y ago[flagged]
- throwaway378037 4y agoOnce again I will say that ThreeUK is the worst UK network. I switched to EE and it’s been a breeze. Giffgaff was also good when I used it.
- _joel 4y agoGiffgaff is rubbish where I am. They throttle down massively during the day, 3Mbit if lucky, even forcing LTE. Found Voxi (Vodafone) to be miles better, at least for my location (which is close to the mast)
- callahad 4y agoI can access Tutanota on Three UK, even with the filter enabled. When this blew up last Friday[0], Three's response was, paraphrased, "you contacted the wrong department, here's how to contact the correct department. Their turnaround time is three business days." Here we are three business days later, and it works for me. This seems a bit overwrought? (Content filters are an issue, but they're mandated by the UK government for large ISPs. All major mobile providers in the UK block by default. In an environment like that, false positives are going to happen; I'm not sure how this could have worked better in practice, so long as ISP-level blocking exists at all.) [0]: https://news.ycombinator.com/item?id=33981873 https://news.ycombinator.com/item?id=33981873
- miohtama 4y agoIt is a good case study about abuse of unchecked power - even if accidentally. Tutanota is a false positive and obviously should not be flagged in the first place. Do they have any business or legal remedies? Likely not.
- ndsipa_pomu 4y agoThree business days seems way excessive to just flip a bit. Three minutes would be more appropriate.
- odiroot 4y agoThree is quite a bad network in general. I can barely get any signal in my estate. Ironically, when walking around city centre, I have full bars but rarely ever an actual Internet connection. Their links seem to be universally overloaded.
- dncornholio 4y agoWhy is nobody giving slack to the horrible UK laws but instead go on how bad ThreeUK is. This is a prime example why traffic filtering breaks the internet and causes unfair advantage.
- verisimi 4y agoYes - why create laws that mandate you giving your details to access the site? Porn or whatever is just a justification. This is just another attack on privacy. You can call it it a nanny state if you like - but what this is really about, is the loss of anonymity online. How long will it be that you are forced to id yourself to get online. I see this as a small step to that end.
- lost_tourist 4y agobecause it isn't happening on other providers evidently.
- dncornholio 4y agoThat doesn't mean anything. This same shit can happen on any provider in the UK.
- eptcyka 4y agoIn my personal experience, I bought a Three SIM card for some testing, and in about a month after not using the SIM for anything besides calling one of my own numbers I started receiving marketing calls. The marketer was upfront about how Three will give out your number to advertisers. The only redeeming quality they have is their US data plan.
- senko 4y agoThey should reach out to other networks, get a referral deal (20% for three months or whatever) and reply to their users with "your ISP is blocking us, and many more sites, and is horrible in general; here, switch to one of the normal ones".
- fmajid 4y agoThe UK is almost as bad an enemy of the Internet as Australia and the nanny-state filters are beyond obnoxious. Back when I was with “Vodafone Full Fibre broadband” (in reality shitty VDSL because the truth-in-advertising authority gave ISPs license to lie), they had accidentally blocked StackOverflow for 3 days because it was actually the test site for implementation of the filters and they had been turned on by accident. A VPN is essential to defend yourself from the jackbooted UK government. I run my own, based on my https://GitHub.com/fazalmajid/edgewalker/ https://GitHub.com/fazalmajid/edgewalker/ As for Three, their 4G is abysmal but they have the best 5G coverage.
- tomxor 4y ago> A VPN is essential to defend yourself from the jackbooted UK government. I tend to agree. Unfortunately even VPN doesn't entirely solve it though. On the one hand wiregaurd makes this feel far more transparent and comfortable technically compared to how it used to with old fashioned crappy TCP over TCP style VPN... instead we now get low overhead, low latency, native, simple configuration etc. The only problem is the end point: Running your own makes you very uniquely identifiable; using shared gets you on tons of blocklists or excessive captcha-walls of various popular and common services and underlying services like cloudflare or auth services such as google. Even when running your own server you tend to get blocked due to having an IP from a VPS provider rather than a consumer ISP. It's basically impossible to get normal neutral internet these days... I find myself jumping between different servers, and turning it on and off, there is no single all access method... it's like wtf leave it alone guys, we are not in north Korea.
- vladvasiliu 4y ago> The only problem is the end point: Running your own makes you very uniquely identifiable I think it depends on where you are. In France, my fiber connections have had a fixed IPv4 since I first got one, 10 years ago. Some ISPs have recently switched to CG-NAT, though. But they also started offering fixed ipv6. My point is that trying to hide behind a non-fixed IP is a losing game. Plus, you can probably be indentified quite reliably but the pattern of websites you visit.
- 4y ago
- keraf 4y agoThe great British firewall, starts here, ends where? As I understand, the lists are maintained per carrier but implemented based on UK regulation. I still find it baffling that despite giving extensive personal information (ID/Passport, bill as proof of address, credit score) to get a mobile contract for an adult, this is opt-out with no questions asked (for example "do you wish to enable/disable this feature?" when the contract is signed). This leaves a lot of room for abuse, as it's demonstrated here. Personal anecdote, I had to phone Three to disable the filter a few years back when I wanted to browse 9GAG on my commute to work...
- InCityDreams 4y agoProviding they allowed your request, you should have called the next day "Right, thanks. Now who do i need to ask to browse 9GAG on my way home?"
- jackweirdy 4y agoIf your company and your customers are suffering due to another company’s dubious policy, don’t contact customer service, contact legal@
- pfoof 4y agoInterestingly enough iOS picks up the site as filtered as well, maybe due to some keywords
- mmkos 4y agoI moved away from Three. I recently took out a phone contract, initially with Three. Took me two days to realise that they started charging a daily roaming fee while in another country in Europe - £2 a day. I immediately cancelled the contract and took out a new one with O2. Not ideal either, but at least O2 don't have this ridiculous policy. Do not go with Three. I should've ditched them long ago.
- borissk 4y agoJust advice your users to switch away from Three - of the three and a half mobile operators in UK (O2 and Vodafone share cell towers) Three is the worst anyway. A VPN may be a solution currently, but recently a Labour Party MP - Sarah Champion proposed the government needs to do something about the VPN providers (obviously the plebs can't have too much freedom).
- irusensei 4y agoQuestion to UK people based on the responses I’m reading here. If I, a privacy loving person were ever to migrate to the UK is it possible to have a as private and unrestricted anonymous internet as much of the rest of the sane world? Both this and previous thread mentioned some really ridiculous things like lifting restrictions through credit card or drivers license.
- concordDance 4y agoYes. Tor.
- AndrewDucker 4y agoSure, use a VPN.
- kosikond 4y agoLondoner here. On daily basis I don't _feel_ restricted on broadband, besides some thepiratebay and some other good old thorns in copyright industrial complex... But I know GCHQ is watching. So nextdns.io is my trusty friend, VPN is no problemo. On phone I have EE MVNO and without VPN I get blocked pr0n, but not much else. Yes they wanted proof of ID despite having my Direct Debit details. Personal note: But if you were to migrate to UK, probably not a good time this decade, the cost of living is hitting here hard, post-Brexit shambles are annoying and the compensation is not worth it anymore IMHO. Just the music scene is unbeatable, hence staying.
- sealeck 4y ago> But I know GCHQ is watching But we also know that they're watching everyone else (i.e. not in the UK) as well.
- callahad 4y agoI moved from the US to the UK. I don't feel like my access is any different, aside from the many North American sites that block all European IPs for fear of the GDPR. Notably, smaller ISPs tend to be exempted from the surveillance and censorship requirements. And you actually have a choice of ISPs, because infrastructure and service providers are kept separate, unlike the monopolies in the States. So, for example, Andrews and Arnold ("AA ISP") tends to take a pretty strong stance as outlined at https://www.aa.net.uk/broadband/real-internet/ https://www.aa.net.uk/broadband/real-internet/. Very old-school, clueful hacker vibe. Hell, they even GPG sign their invoices. They're also happy to proactively inform their customers about legislative corner cases, like how the overbroad legal definition of a "communications provider" allows customers to legitimately self-identify in such a way that compels A&A to discard copyright infringement notices (https://www.aa.net.uk/legal/legal-status-customers/ https://www.aa.net.uk/legal/legal-status-customers/). There are legislative threats in the UK, like the recent Draft Communications Data Bill ("Snooper's Charter"), or government-funded campaigns against encrypted communications (https://news.ycombinator.com/item?id=29955893 https://news.ycombinator.com/item?id=29955893). Those scare me. But thus far they've generally been beaten back, much the same as SOPA/PIPA were Stateside.
- Matsta 4y agoUnrelated to 3, but we had an issue where our brand new site was blocked by Vodafone UK. Turned out they had some automatic firewall service that marked our site as suspicious and blocked it. They seemed a bit better than 3 as there was a process for applying for it to be reviewed and removed. I'm assuming something similar happened to 3 where it was probably automatically picked up and blocked.
- teekert 4y ago"Thanks for reporting this to us. Don't worry, we're always here to help our customers with best possible resolution. I understand your clients are facing issue with accessing this website. All you need to do is just ask them to get in touch with us and we will validate your accounts and help them to get the restrictions lifted." One would almost be tempted to code a button that sends that email, or even ask permission to every user to send it for them automatically.
- LatteLazy 4y agoI realise that Three are shit and this is shitty service. But I cannot bring myself to blame them. They're forced by law to push this non-sense because multiple (re-elected) governments have decided that the internet needs to be child safe but are not prepared to actually do it. So they have dumped it on Three (and other ISPs) who are not qualified, resourced or skilled enough to do what is ultimately a pointless and impossible task. The problem here is not that Three are useless. It's that they are useless AND required to interfere. Behind that is a very social root cause: we pander to morons who think they should get to decide what other people can read/see/watch. The solution is that we, as a country, grow up and either supervise our own kids or actually pay someone else to. But no boomer will buy that, they just keep crying until someone promises them a free lunch...
- sneakymichael 4y agoThe support chat transcript is so uncomfortable to read– the person on the other end 'at Three' (aka a contact centre on the other side of the world, contracted out at the lowest possible cost) might as well be a bot, but the chat reads as if the person at Tutanota genuinely thought that they were chatting to a logical coherent human. Having used Three UK on and off for two decades, this support chat lines up exactly with how I remember– 'robot humans' that say any ol' tosh to finish the contact session. Avoid Three. FWIW: all UK consumer telecoms services seem to have horrendous contact experiences (Though Three, of the prominent handful of providers, tops the charts in my opinion), but I've used EE for the last few years, and it has been consistently solid and fast, and thus I thankfully haven't /needed/ to contact anybody there. I cannot say the same for Three.
- deleted 4y ago[deleted]
- Nextgrid 4y agoIn consumer-grade telecoms, support is outsourced to idiots - it's not a UK-specific thing. Absent regulation against it, it will happen in any country.
- Jamie9912 4y agoArticle doesn't explain how they've blocked Tutanota.. Firewalled the IP address? DNS blackholed? SNI snooping?
- kybernetyk 4y ago>With its strict data protection laws and the GDPR, Germany has some of the best laws in the world to protect your secure emails. That's a lie. German law enforcement can get access any time to the emails - the court orders are trivially to get. Which is a known problem in Germany as for a judge to sign off a search warrant all he needs to do is to sign the dotted line. If he wants to deny the search warrant he has to write up a justification for his denial. Judges being completely swamped in work tend to go the easy route here. Also prosecutors not being independent but having to follow orders from the ministry of the inner (which is a reason why Germany isn't allowed to use the EU arrest warrant system btw) make political overreach very possible and plausible in such a case. I wish this "Germany is a safe haven for data" meme would die.
- deleted 4y ago[deleted]
- dotBen 4y agoFrom their website: "Regardless of what is causing the issue, this shows why net neutrality is so important for internet users and online services alike." For the UK that ship already sailed given its enshrined in law that ISPs have to block adult sites unless you register with the government.