8 ms·
ESR: Cisco provides a lesson
- quesera 14y agoI agree with Eric, but the problem is that even if you own your router (many residential users have provider-provided hardware), and run Tomato or DD-WRT, etc ... You have only one next hop, and zero control over that router. So yes, don't invite Cisco into your living room, obviously. (Nor Cisco/Scientific Atlanta, but that's another discussion..!) But you're still powerless and privacyless, sorry. Get a VPN box and tunnel everything (I do), but that's just kicking the can a few years down the road (less if you pick a cheap host). Also, the bigger message from this fiasco is that Cisco is feeling revenue pressure even in their protective low margin consumer networking business. Cisco has never been a good consumer company, but they've just never cared enough to get "creative" before. That's a bad bad sign for Cisco. Chambers, like Ballmer, has presided over ten-plus years of sideways, and this move seems desperate. Run for the exits.
- ableal 14y ago> many residential users have provider-provided hardware Yep. Even if I bothered to find a replacement for my combination cable modem/router, I don't know if the ISP / cable company would "talk" to the new hardware. Probably not contractually required to do so. I'm reminded of the liberation of phone handsets from the phone company - up until the 1980s, most everywhere, it used to be that one could only connect to the network a phone leased from the carrier. The issue of who controls (has root) on all the computers we supposedly own, starting with internet access routers and going on to printers, smart-phones, e-book readers, game consoles, disc players and TVs, is a vexing one.
- derleth 14y ago> I don't know if the ISP / cable company would "talk" to the new hardware I honestly, no-ulterior-motive wonder how often this happens. I mean, isn't ADSL governed by real-world written-down standards? Isn't DOCSIS an actual standard? If so, and given the absolute standardization of things like ARP, RARP, DHCP, and so on, where could the problem possibly come in? Do they scan routers and refuse to talk to ones that don't respond with the right software version numbers?
- rictic 14y agoA piece of anecdata: I've got comcast, and I recently bought my own cable modem because the provider given one was dropping packets. To get it to connect at all, I needed to call them up and tell them the model number and the the MAC address (or something that seemed analogous) of the router. I had two models to choose from (fewer than usual because I needed DOCSIS 3 I think), and they made it very clear that these were the only models they would allow you to use. (it almost goes without saying, despite using their business support, it took three or four days, most of which I was without usable internet)
- lesterbuck 14y agoI started Comcast service about a year ago. They have a page of approved hardware on the web, and I bought a new modem off of that page. It seemed there was plenty of choice even then. I happened to pick a Motorola SB6150. What surprised me was that there was not a shred of technical information or any management screen. After the cable was installed in my house, my brand new modem was attached to the cable infrastructure and then downloaded Comcast firmware for about twenty minutes. After my modem had completely joined the Borg, only then was it allowed to offer me internet service. Sigh...
- mmmooo 14y agosadly, that is DOCSIS. You get to see very little (some modems provide signal levels, some debug info, etc) if anything at all. Everything else comes from/is controlled by the CMTS. Even in the enterprise grade modems like cisco hwic's, the docsis portion is almost entirely hidden from you.
- earl 14y agoI had the same experience. I have comcast and I bought a Motorola SB6121 on amazon because it was $85 and comcast charges you $7/mo to rent a cablemodem so you save money after only one year. Anyway, I plugged the modem in, it downloaded some config, rebooted, and started talking to comcast. It was pretty painless. And I just picked the cheapest docsis 3 modem off a list of probably 25 approved models.
- nodata 14y ago> Even if I bothered to find a replacement for my combination cable modem/router, I don't know if the ISP / cable company would "talk" to the new hardware. Probably not contractually required to do so. You plug the vendor provided hardware into your hardware.
- dredmorbius 14y agoIf you own the first hop, you can run Tor or a similar proxy from it. There are also local "mesh" networks which are available, though I haven't played with them. They have some level of applicability in oppressive regimes, and if I understand properly are not quite as poorly performing as Tor can be / is.
- azernik 14y agoIf you're going to be running Tor, you don't even really need that first hop - you just need to control the software on your computer.
- dredmorbius 14y agoPoint, but Tor on router means automatic default privacy for the network. And no tattling to Cisco.
- Silhouette 14y agoThey might be technically capable of doing this, but I would enjoy reporting them to the police for possibly having committed criminal offences under the Computer Misuse Act, Regulation of Investigatory Powers Act and others if they ever tried it on me. I wonder if the much-hyped US-UK extradition treaty cuts both ways in such a flagrant case of unauthorised access...
- gwillen 14y agoThis reminded me that I owned some CSCO, and I need to sell some stock anyway. Sell sell sell! (I laughed when I saw how _much_ CSCO I own -- I bought it in high school, also total it's worth about $250, and that is apparently about the same as it was worth when I bought it.)
- robomartin 14y agoI really don't think that this has anything whatsoever to do with closed vs. open source. This is definitely a case of Cisco over-reaching. The genesis of the problem isn't really connected to closed source. There are plenty of closed source systems that don't even approach these kinds of issues. Would open-source prevent this kind of thing? Probably. In this case, someone has to make the hardware, supply and maintain the infrastructure, so the problem is probably a little more complex than the simple contrast between closed and open source. There really aren't a lot of large open-source-everything projects out there (hardware + software + mechanical + whatever else) to know how this would play out. Hardware, as a business, is really capital intensive. Software isn't. A college student in a dorm can sit down and write software that gets distributed to millions and reaches every corner of the world. And the cost of doing so is virtually nothing. To replicate this in hardware is almost impossible (yet). There's a lot more to it than just designing and building it. There's support, warranties, regulatory requirements, etc. Here's a dumb example: Who wants to be responsible for the lawsuit when an ill-designed piece of hardware kills someone because it does not deal with high-voltages in a safe manner? Or another one: Who wants to be responsible for a recall of thousands or even millions of devices if they are found to be defective in some way? Again, regardless of the contrast between hardware and software I don't think that this issue can be used to champion the FOSS flag.
- 1337p337 14y ago> I really don't think that this has anything whatsoever to do with closed vs. open source. [...] > Would open-source prevent this kind of thing? Probably. I don't think I could have made the argument better than you have. The point isn't that all closed source software does this, or even that most does it. The point is that when you cannot control the software, the abuse can happen. Anyone who has power can abuse it, which means that if you cede control over software in your router to Cisco, you have to trust Cisco not to abuse it. If you don't, then you don't have to worry.
- Getahobby 14y agoEven if Cisco was running open source code they could still put ALL of this language into this agreement. The difference would be you could see the actual mechanism in work if they had open source code. The egregious part is the language, not the implementation.
- munin 14y agohow would open source software prevent this? I have an open source Buffalo router that shipped with DD-WRT. it has a service onboard where I can run an alternate SSID as a free wifi hotspot, and software on the router will inject a frame into clients web browsers to serve ads. evil? yep. on by default? no. implemented entirely with open source software? yes. what would happen if this feature shipped in an open-source router on-by-default and without the software button to click to change it? are you seriously advocating to consumers that they download the source code to their router, change some #defines to remove the code that injects ads, recompile it, and reload it onto their router?
- wpietri 14y agoWhy would most consumers need to do that? It only takes one HNish person to get the code, fix it, and release something that consumers can easily use.
- munin 14y agoreflashing router firmware is still something out of reach to most consumers. it would probably not even occur to most consumers that the ads in their web browser would be something they could change.
- derleth 14y ago> reflashing router firmware is still something out of reach to most consumers I don't know. I'm always amazed at what a few good blog posts can do if enough people see them.
- jiggy2011 14y agoYou could ask/pay/sleep with a person of your choosing and have them do it for you. To the second point, if you had a world with mostly open source software then people would start to assume that things like that could be done. It's like arguing that you should design cars to be only serviceable by the manufacturer simply because not everyone is a mechanic.
- 14y ago
- ShabbyDoo 14y agoThe phrase 'better for consumers' doesn't seem to have any testable meaning. What hypothetical experiment, if performed, would determine whether a proposed rule change would be "better for consumers"? Let's pretend that we can clone the universe and run an A/B test. Universe A receives the new rule treatment and Universe B does not. In both universes, we inject happiness meters into every living person's head. These meters also inject clones of themselves into fetuses for the next 100 years. So, we can compute the average happiness levels of all people on earth over the next century. Is a net positive change in happiness levels the definition of "better for consumers"? Must we also consider changes in the distribution of happiness among individuals? Is happiness even the right metric to consider? When the word 'consumers' is used, does it imply that everyone's happiness should be considered? So, back to some reality. It's certainly possible that an Apple-like walled-garden approach might, for some particular technology/situation/problem/whatever set-off a chain of economic events which has a positive net effect on overall human happiness. However, I have no idea if I'm making a meaningful argument to those using the "better for consumers" phrase as no one seems too interested in attaching a strong definition to the term. W.r.t. anti-trust litigation, the phrase is oft thrown about. What has bothered me is that the "obvious" answer is provided by a static, short-term analysis of current economic conditions. In the short-term, it's better for consumers to regulate the price of electricity. After all, it costs "too much", you know. However, the disincentive to build new power generation facilities likely leads to an outcome very negative for consumers -- shortages, rationing, etc. tl;dr; Stop using the phrase 'better for consumers' unless you bother to attach to it a testable definition.
- corford 14y agoWithout wanting to start too much of a holy war, this is exactly why I prefer the GPL over BSD variants. The GPL takes ESR's argument in this blog post to its natural conclusion. The only way you (the user) can be completely free is if the code is forced to stay open. There's no other way around it. Even if Cisco's firmware blob consisted entirely of compiled open source code, if it was all BSD licensed you'd still be no better off.
- jiggy2011 14y agoThis really depends on how difficult it is to replace the firmware. On a consumer linksys router for example, this is a very simple process.
- lukeschlather 14y agoThe GPL is the reason it's easy to replace the firmware on a consumer router. If the GNU userspace tools were BSD licensed then DDWRT, OpenWRT and Tomato would not exist. It's actually one of the best examples of the GPL's power to allow people to do use their devices to their fullest potential.
- mxey 14y agoI don't see the connection. The Linux kernel being under GPL means manufacturers had to release source code for their devices. Where does the userspace come in? Do OpenWRT and the like even use GNU userspace tools? I would assume they use Busybox.
- saurik 14y agoWell, BusyBox also happens to be GPL. ;P (Also, it should be noted that GPLv3 requires the user not only to have the source code for the software on the device, but the ability to change the software running on the actual shipped device.)
- lukeschlather 14y agoThey use the GNU C Library. After a bit of Googling I'm not entirely sure what forced Linksys to open source the code, but it was definitely more than just Linux.
- cjbprime 14y agoThe same person announcing in this blog post that Cisco is "doing evil" and that it's not true that "Open systems and networks aren't always better for consumers" is the person who wrote this blog post last month: http://esr.ibiblio.org/?p=4386 http://esr.ibiblio.org/?p=4386 wherein he described how he's not at all like RMS, because RMS frames his advocacy "as a moral crusade" and because "his rhetoric and his thinking became dominated by terms like 'evil'" and RMS doesn't use "pragmatic argument about engineering practices and outcomes". I think ESR is really telling us that he wishes we'd all start listening to him tell us about how we should stop doing evil things instead of listening to RMS do the same.
- praptak 14y agoWhat I see in this case is evidence that RMS is not as deluded as his opponents paint him to be. This case shows that "evil", "good", "moral" aren't some vague abstract concepts that only matter to graybeard philosophers. You might think they are somehow detached from "practices and outcomes". Until Cisco bricks your router and holds it hostage until you sign off your privacy rights. Seriously, if I heard RMS rant about "what if Cisco bricks your router to force you to bend over" I'd wave him off as being unrealistic and exaggerating beyond common sense. Not anymore.
- emmelaich 14y agohttp://www.tonidoplug.com/ http://www.tonidoplug.com/ anyone?
- tux1968 14y agoEric has about the worst personality you could ask for in a representative of a movement; but i can't fault this post. Likely he doesn't realize that he's parroting RMS's key message more or less verbatim. But there's no reason to make a fuss about that when it's an important message for people to hear, regardless of the source.
- monochromatic 14y agoSo he disagrees withe the statement that "Open systems and networks aren’t always better for consumers." Ok, fine. But he asserts that open is absolutely never better, and he backs up that assertion with... a single example. That's not much of a syllogism.
- bconway 14y agolast a few days Cisco pushed a firmware update to several of its most popular routers that bricked the device unless you signed up for Cisco’s “cloud” service. It did no such thing, even for very liberal uses of the term "brick."