TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

ISP Spying

251 pointsby earlyover 7 years ago

25 comments

weppleover 7 years ago
I’ve pulled apart router firmware plenty of times, and am never surprised to see nbtscan, nmap, and all sorts of other tools on there.<p>A lot of ISPs will perform remote diagnosis by connecting into your router and scanning your internal hosts to see if there are any problems.<p>Between that capability and general appalling security of routers, you’re basically on Starbucks WiFi from a security perspective even at home.<p>important note: buying an off the shelf netgear&#x2F;tplink&#x2F;linksys&#x2F;whatever might stop your ISP remoting in, but is still wildly full of vulnerabilities.
评论 #16392310 未加载
aus_over 7 years ago
There is varying levels of difficulty when you want to BYO router. The situation for AT&amp;T U-Verse isn&#x27;t too fun. If you want to use your own hardware, you only have a few options:<p>1. They offer &quot;IP Passthrough&quot; which is fake Bridge Mode. They still do routing and you&#x27;ll still hit NAT table limits of 4096. Connection falls apart for anything over 3000.<p>2. You can dump and reverse the router-gateway firmware and 802.1X&#x2F;EAP authentication. Oh goodie.<p>3. There&#x27;s a history of exploits for the NVG510, NVG589 and NVG599. Try your luck. [1] [2]<p>4. Create some &quot;magic&quot; to split the 802.1X and untag VLAN0. Works in Linux at least. [3]<p>5. But good luck if you want to do this in pfSense or FreeBSD. There&#x27;s an open BTC bounty if you&#x27;ve got any netgraph &#x2F; networking chops. [4]<p>[1]: <a href="http:&#x2F;&#x2F;earlz.net&#x2F;view&#x2F;2012&#x2F;06&#x2F;07&#x2F;0026&#x2F;rooting-the-nvg510-from-the-webui" rel="nofollow">http:&#x2F;&#x2F;earlz.net&#x2F;view&#x2F;2012&#x2F;06&#x2F;07&#x2F;0026&#x2F;rooting-the-nvg510-fro...</a><p>[2]: <a href="https:&#x2F;&#x2F;www.nomotion.net&#x2F;blog&#x2F;sharknatto&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.nomotion.net&#x2F;blog&#x2F;sharknatto&#x2F;</a><p>[3]: <a href="http:&#x2F;&#x2F;blog.0xpebbles.org&#x2F;Bypassing-At-t-U-verse-hardware-NAT-table-limits" rel="nofollow">http:&#x2F;&#x2F;blog.0xpebbles.org&#x2F;Bypassing-At-t-U-verse-hardware-NA...</a><p>[4]: <a href="https:&#x2F;&#x2F;forum.pfsense.org&#x2F;index.php?topic=111043.0" rel="nofollow">https:&#x2F;&#x2F;forum.pfsense.org&#x2F;index.php?topic=111043.0</a>
jstanleyover 7 years ago
In the UK, they&#x27;re legally required to spy on you (but not through your router).<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Investigatory_Powers_Act_2016" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Investigatory_Powers_Act_2016</a>
评论 #16391860 未加载
liotierover 7 years ago
I plugged French Orange&#x27;s GPON FTTH ONT into my Debian router&#x27;s RJ-45 port, added a VLAN interface, added a couple of lines to my DHCP client configuration to pretend my router is some Sagem device and pass authentication to the server... And that&#x27;s all - sweet 500&#x2F;200 Mb&#x2F;s throughput, no ISP CPE in sight (well, technically the ONT...) and Orange even waived the 3€&#x2F;month CPE rental fee !<p>Former provider offered FTTB and I used the coaxial cable CPE as a bridge - and even when I do not have that option, I insist on having a router of my own as my network&#x27;s demarcation: it is basic hygiene.<p>Other option for GPON would have been to plug a GPON SFP module into one of my switches - the friendly guy who laid the fiber to my apartment even left me one in case I changed my mind... But going through the switch to the router and back to the switch on a different VLAN is unnecessarily complicated in my case. Anyone wants a free GPON SFP module ?
评论 #16392739 未加载
mmrezaieover 7 years ago
Is there a portal like-place to share our findings of ISPs generally in the world so that others can work together with better transparency?<p>I do data analytics and data engineering and a couple of months ago indirectly I have been contacted by an ISP in Spain and they literally were collecting every bit of data that their customers were seeing on internet (websites, timestamps, how much data were transferred and etcetera with the user&#x27;s id and basically in another table name and address). I was shocked how easy they were talking about it. I didn&#x27;t accept but for sure someone has done it! I never heard the name of the ISP, I wish I didn&#x27;t bark at them so fast and I could collect more information about them.
laveurover 7 years ago
When I bought my fist house a few years ago here in the Bay. Comcast tried to give me one of their new routers wifi and everything built in. I let them but I wasn&#x27;t happy. I hooked up my own router and ended up double natting it. After a few hours of frustration I went out bought my own cable modem. Installed that and returned the one comcast had provided. When asked why I sighted security and privacy concerns. Working for a fortune 500 means they could easily do some sneaking and see a lot of stuff that I worked on. Either way I use Ubiquity hardware throughout my house. Its a bit expensive but god is it good.
评论 #16392634 未加载
评论 #16392809 未加载
LeoPantheraover 7 years ago
I&#x27;ve been forwarding all outgoing connections on port 80 (and a selection of other commonly-unencrypted ports) through a VPN (in the router) for a while now - but leaving all other ports (including most importantly 443) connecting directly.<p>It feels like a good compromise between privacy and speed.<p>(I realise this is not the subject of the article exactly but I figured it&#x27;s a related issue.)
评论 #16394690 未加载
评论 #16392134 未加载
Cieplakover 7 years ago
Another cool thing about WiFi routers is that you can use them as radars to monitor people in a home. The 2.4ghz frequency is perfect for reflecting off water bodies while having great penetration through walls.
评论 #16392024 未加载
评论 #16392033 未加载
评论 #16391688 未加载
评论 #16391752 未加载
Bugeover 7 years ago
That router looks like its control panel is hosted on an external server. Router control panels usually show what devices are connected. So for router control panel functionality, they need to have the router report all connected devices to the server. Obviously they should be doing this encrypted, not unecrypted.<p>But ignoring encryption, this is the price you pay for cloud management: the could knows your data.
评论 #16391243 未加载
javajoshover 7 years ago
Is it just me or does this look like a huge opportunity? Last I checked we still have control over our devices, and if they are stupid enough to trust the data they collect, then we should feel free to poison the well. I&#x27;m talking about opening random connections to endpoints (either random or those we want to protect), to inject noise into the system. I call the idea &quot;data flak&quot;. It could be something as simple as a daemon running in the background, or a browser plugin. You want to spy on my traffic? Fine, good luck picking out my real behavior from the gigabytes of utter crap I&#x27;m shoving into your sensors. This works not just at the ISP level, but at every intermediate host, too.<p>The only counter is for an adversary to own your box, which is far more expensive.
评论 #16392343 未加载
alxndr13over 7 years ago
In Germany you are able to use any router you want, regardless of which ISP you use.<p><a href="https:&#x2F;&#x2F;www.cr-online.de&#x2F;bgbl116s0106.pdf" rel="nofollow">https:&#x2F;&#x2F;www.cr-online.de&#x2F;bgbl116s0106.pdf</a>
评论 #16392205 未加载
mirimirover 7 years ago
I always assume that they might be. So I always use my own perimeter router&#x2F;firewall running pfSense. Plus I use VPN services. And so my ISps don&#x27;t end up seeing anything except encrypted streams. And have no visibility into my vLANs.
评论 #16391172 未加载
评论 #16391779 未加载
评论 #16391275 未加载
RoadieRollerover 7 years ago
Somewhere someone could be selling your data for money. I can imagine the below happening. After all, all corporates are hand-in-glove with each other when it comes to public&#x27;s privacy.<p>This is probably what your ISP is doing. Take your MAC Addresses, try to find the phones in your house which is connected to the wifi, take those MAC addresses to all the telecoms, get the SIM card number and the phone number associated with those MAC numberss, send those phone numbers to the banks to find matching bank accounts and the associated credit card number, along with your registered email address, get the purchase history from the bank on the credit card number, compare it with your browsing history and sell all of this to another company and make money.
评论 #16392968 未加载
评论 #16392650 未加载
philjohnover 7 years ago
This isn&#x27;t an issue if you&#x27;re not using the ISP equipment, or put the ISP equipment into a bridge modem mode.<p>For instance, BT in the UK do the same reporting over TR-069 if you use their home hub - however - if you connect a different VDSL modem&#x2F;router you can disable TR-069, and if you use a dedicated VDSL modem in bridged mode and a wireless router behind that there&#x27;s no TR-069 to worry about in the first place.
评论 #16392224 未加载
slhckover 7 years ago
I recently learned about this when I reported Internet speed issues to my home ISP (upload was basically impossible, while download was at 100 MBit&#x2F;s).<p>They said they&#x27;d look into it, but they couldn&#x27;t process my claim unless they could prove something was connected via Ethernet to their router. (They apparently never trust customer WiFi speed test results, probably because WiFi on their crappy routers can be notoriously unreliable.)<p>I ultimately had to connect something to the router&#x27;s Ethernet port, so I grabbed another WiFi router, configured it as an access point, plugged it in, and voilà, they could verify that a device was connected and processed my complaint.<p>Obviously customer service reps can easily get access to a list of what is connected to the router.
评论 #16391969 未加载
dbolgheroniover 7 years ago
Two huge cases from previous years:<p><a href="https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2012&#x2F;10&#x2F;01&#x2F;hacked-routers-brazil-vb2012&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nakedsecurity.sophos.com&#x2F;2012&#x2F;10&#x2F;01&#x2F;hacked-routers-b...</a><p><a href="https:&#x2F;&#x2F;www.welivesecurity.com&#x2F;2016&#x2F;10&#x2F;21&#x2F;cybercriminals-target-brazilian-routers-default-credentials&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.welivesecurity.com&#x2F;2016&#x2F;10&#x2F;21&#x2F;cybercriminals-tar...</a><p>Your router is critical, and choosing them wisely is one of the most important things if you care about some security.
wowamitover 7 years ago
Every now and then, we are reminded that our router remains the prominent data collector for our online presence. And ISP, the prominent data aggregator. And neither are really too keen to protect our data online.
rishabhdover 7 years ago
well, who isn&#x27;t? Even at the most basic level, my local ISP is injecting ads into browsers.
评论 #16391287 未加载
评论 #16391459 未加载
534b44aover 7 years ago
My ISP provides an online user interface where I can remotely change my Wi-Fi password even if I haven&#x27;t explicitly enabled port forwarding. If they have access to that, I don&#x27;t see why they can&#x27;t easily see my network shares and its contents (I don&#x27;t password protect the directories for convenience reasons).<p>I&#x27;ve long ago lost the PPPoE password and this same router gets it automatically somehow. When I install another router, it won&#x27;t do that.
floatbothover 7 years ago
My ISP never gave me a router. Just an Ethernet cable coming into my apartment :)
评论 #16392031 未加载
icc97over 7 years ago
Who didn&#x27;t think they were being spied on?<p>This is why you used https to hide the full URL, VPN to push the problem to a 3rd party who might care a bit more about privacy and then Tor on top of it all.<p>Here&#x27;s the good old EFF explanation [0]<p>[0]: <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;pages&#x2F;tor-and-https" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;pages&#x2F;tor-and-https</a>
评论 #16391383 未加载
评论 #16391991 未加载
tzaholaover 7 years ago
I don&#x27;t know if it&#x27;s true, but I&#x27;ve heard that some ISPs route your entire traffic through their machines. They even have access to your IP packets. Very shady!
评论 #16391704 未加载
评论 #16392849 未加载
jacksmith21006over 7 years ago
Problem is in the US ISP they can sell your data without telling you. So I prefer to keep my data away from them. I trust Google more to not sell my data and fine with them renting it out. Others might not. So use them for DNS for example so it does not go to my ISP.<p><a href="https:&#x2F;&#x2F;www.usatoday.com&#x2F;story&#x2F;tech&#x2F;news&#x2F;2017&#x2F;04&#x2F;04&#x2F;isps-can-now-collect-and-sell-your-data-what-know-internet-privacy&#x2F;100015356&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.usatoday.com&#x2F;story&#x2F;tech&#x2F;news&#x2F;2017&#x2F;04&#x2F;04&#x2F;isps-can...</a> ISPs can now collect and sell your data: What to know about Internet ...
jwilkover 7 years ago
Please use the original title.
评论 #16391494 未加载
评论 #16394306 未加载
nmeofthestateover 7 years ago
ISP Spy: Hey boss, looks this guy in Oslo has a friend called Dave who owns an Android device. ISP CEO: This is it! We&#x27;re gonna be rich boys! Arrange a meeting with GlobalAdvertCorp immediately.