6 ms·
Never mind telnetd. Tier 1 transit providers doing port filtering is EXTREMELY alarming. They have partitioned the Internet, and in a way that automatic routing
by virgulino 8mo ago
Never mind telnetd. Tier 1 transit providers doing port filtering is EXTREMELY alarming. They have partitioned the Internet, and in a way that automatic routing (BGP) can't get around.
- acters 8mo agoSo basically the same as censorship because that is the exact same thing blocking ports does.
- fragmede 8mo agonot to mention, filtering on udp vs tcp, which makes using anything else impossible. Not that I have one, but it's just a bit in a field, why filter on it?
- oaiey 8mo agoI do not know what is more critical: the risk of censorship or stand by while hospitals, banking, nuclear power plants and other systems become compromised and go down with people dying because of it. These decision makers not only have powers but also have a responsibility
- gspr 8mo agoThis feels more akin to discovering an alarming weakness in the concrete used to build those hospitals, banks and nuclear power plants – and society responding by grounding all flights to make sure people can't get to, and thus overstress, the floors of those hospitals, banks and nuclear power plants.
- forty 8mo agoYou feel it's similar because having access to port 23 is similarly life critical as having access to an hospital? Or is it because like with ports, when people can't flight to an hospital, they have 65000 other alternative options?
- gspr 8mo agoAll I'm saying is that the only right place to fix this is at the hospital. Not at the roads leading to it.
- da_chicken 8mo agoThat's my question. Why is there infrastructure that has open access to port 23 on the Internet. That shouldn't be a problem that the service provider has to solve, but it should absolutely be illegal for whomever is in charge of managing the service or providing equipment to the people managing the service. That is like selling a car without seatbelts. We are beyond the point where not putting infrastructure equipment behind a firewall should result in a fine. It's beyond the point that this is negligence.
- forty 8mo agoThere again, I think the comparison fails. Fixing the hospital: single place to work on, easier Blocking all the roads/flights: everywhere, harder Vs Fixing all the telnet: everywhere, harder/impossible Blocking port 23 on an infra provider: single place, easier It makes sense to me to favor the realistic solution that actually works vs the unrealistic one which is guaranteed not fix the issue, especially when it's much easier to implement
- zh3 8mo agoIn the UK we have in fact discovered an alarming weakness in the concrete used to build schools, hospitals and other public building (in one case, the roof of a primary school collapsed without warning). The response was basically "Everybody out now". https://en.wikipedia.org/wiki/2023_United_Kingdom_reinforced_autoclaved_aerated_concrete_crisis https://en.wikipedia.org/wiki/2023_United_Kingdom_reinforced... https://www.theconstructionindex.co.uk/news/view/raac-crisis-escalates-as-more-than-100-schools-told-to-get-out-now https://www.theconstructionindex.co.uk/news/view/raac-crisis... https://www.theguardian.com/education/2023/aug/31/what-is-raac-reinforced-autoclaved-aerated-concrete-schools-buildings-england-close https://www.theguardian.com/education/2023/aug/31/what-is-ra...
- PunchyHamster 8mo agonah, that's like seeing an open gate to nuclear tank - a thing easily fixed within few minutes - and responding to it by removing every road in existence that can bear cars
- 7bit 8mo agoCensorship is one of these words that get slapped on anything. Filtering one port is not censorship. Not even close.
- trashb 8mo ago> censorship, the suppression or removal of writing, artistic work, etc. that are considered obscene, politically unacceptable, or a threat to security It is not the responsibility of the Tier 1 or the ISP to configure your server securely, it is their responsibility to deliver the message. Therefore it is an overreach to block it because you might be insecure. What is next. They block the traffic to your website because you run PHP? Similar to how the mailman is obligated to deliver your letter at address 13 even though he personally might be very superstitious and believe by delivering the mail to that address bad things will happen.
- 7bit 8mo agoI don't agree with your argument, but I don't want to debate that. But let's say I agree: That still is not censorship.
- citrin_ru 8mo agoHave you ever seen a hospital, a bank, a power plan to expose telnetd to the public internet in the last 20 years? It should be extremely rare and should be addressed by company’s IT not by ISPs.
- nedt 8mo agoIf that really affects them it's better to take them offline.
- NitpickLawyer 8mo ago> Tier 1 transit providers doing port filtering is EXTREMELY alarming. I was admining a small ISP when blaster and its variants hit. Port filtering 139 and the rest was the easiest way to deal with it, and almost over night most of the ISPs blocked it, and we were better for it. There was a time when if you'd put a fresh XP install on the Internet you'd get 5-10 minutes until it would get restarted. I guess if you're really an admin that needs telnet, you can move it to another port and go around it? Surely you'd tunnel that "old box that needs to stay alive" if that's the usecase? Is there anyone seriously running default telnet on 23 and is really affected by this filtering?
- RulerOf 8mo agoThe GP's concern isn't a practical one, it's ultimately about net neutrality. It's not the ISP's job to discriminate against traffic—it's their job to deliver it. This may seem like a good idea, and frankly is likely a net-positive thing, but it is literally the definition of "ISP decides what apps its customers can and cannot use." I share the concern and don't really like it either.
- tosti 8mo agoIt's not a net-neutrality issue because they're not banking on any alternative. Net-neutrality law doesn't work like that. Service providers still get to filter stuff. What's illegal for an ISP is e.g. to give VoIP services other than their own a lower priority. That would tie in customers to use their own service and they could even charge more for it. Net neutrality means a level playing field for services on the Internet. If you ask your ISP to do filtering, that's perfectly legal. If they filter specific traffic for the purpose of maintaining service, that's okay too. Now if there was no alternative and they'd try to sell their product by blocking telnet, they could be sued.
- ncruces 8mo agoThis is not an ISP. It's a Tier 1 transit provider.
- pjc50 8mo agoPort 23 has been filtered by most providers for decades. This is why everything converges on using TLS over 443 or a high port number. I don't see this as a huge deal, and especially not one deserving all caps rants about censorship. Save those for things like FOSTA/SESTA.
- gzread 8mo agoNot by tier 1 transit providers. You pay those to deliver your packets, no matter what.
- worksformeintx 8mo agoI can connect with the GNU telnet client via the Spectrum ISP to servers in both Seattle and the Netherlands.
- RupertSalt 8mo agoIt doesn’t matter what client you use. Is it on port 23/tcp, and what are the ASNs? The report specifically says that cloud networks like VPS, AWS seemed exempt.
- worksformeintx 8mo agoYes, port 23/tcp From ASN AS11427 (Charter Communications Inc) to ASN AS12859 (BIT BV) and to ASN AS14361 (HopOne Internet Corporation) (edit: formatting)
- ericpauley 8mo agoThis simply isn't happening, and we have the data to prove it: https://www.terracenetworks.com/blog/2026-02-11-telnet-routing https://www.terracenetworks.com/blog/2026-02-11-telnet-routi...
- virgulino 8mo ago> The sky is not falling. Great analysis, thank you! New thread: Reports of Telnet's Death Have Been Greatly Exaggerated https://news.ycombinator.com/item?id=46980355 https://news.ycombinator.com/item?id=46980355