The ISP angle is more treacherous than it was back when Schneier wrote this. Now if somebody uses your open network for piracy, many ISPs will provide you with a couple of warnings and then either throttle or shut off your Internet. (Incidentally, there does not appear to be a limit on how much time must pass between these warnings, so it is conceivable to receive more than one in a 24-hour period, I think. Risky business.)
It seems like the telecommunications industry is trying to scare people away from being charitable to strangers with their wifi, because it forces people to purchase expensive internet plans on their cell phones if they want to use the internet outside.
The ISP's have fought tooth and nail against every Government regulation to try and curb piracy or force the ISP's into compliance.
They have argued that the same laws which state the post office cannot be held responsible for malicious packages also applies to the telecommunications traffic they enable.
SkyBSB and Virgin Media lined up behind Talk Talk as prominent opposition to the Digital Economy Bill in the UK. They were simply beat down into regulatory compliance.
One thing that's changed since 2008: most routers used to be factory-preset to be wide open, or have silly default passwords (netgear etc), so networks were open by default. Now it's more the exception than the rule to default to lengthy random hex strings, and it takes work and skill to make them open.
That should also provide deniability "sorry it must have been the mean neighbors connecting to my free wifi".
Also that was in 2008, now I would guess it is possible to get reasonable security with WPA2, AES and a very long key? Anyone know the consensus on that?
I know to check router model (some have backdoors). Disable WPS (sometimes it is even impossible todo), as that was a for a few years the weakest spot.
Unfortunately, "just find another ISP" is no longer an option for plenty of people. I can appreciate the sentiment, but the risk of being kicked off of your local internet mono/duopoly is a lot higher for a lot of people than it was in 2008.
In areas where cable companies had much build out, there is usually at least 2 choices (the incumbent cable player + the incumbent telco). In lots of areas, there will be more than 2 big players (you can pretty much predict this based on how wealthy the area is).
More remote areas are probably gaining high speed wireless faster than they are gaining other infrastructure. It's expensive, slower and has more limitations, but it compares pretty favorably to dial up, which may be the existing option.
Given the various changes in policies in the UK of late, how many of these actually provide complete Internet access? (as opposed to "Some" Internet access)
I travel frequently to the UK, I use a torrent based sync solution to sync between laptop <> desktop (outside UK) <> VPS ("oh shit backup") - and I've found it absolutely astonishing how many ISPs throttle bittorrent and in some cases any traffic to a host known to run a tracker. I've tried to resolve this by putting my torrent sync within SSH (poor speed) and inside a full VPN (OpenVPN) and found several throttle VPNs too! I've subsequently moved my VPN to port 443 which seems to work, for now. Then there's ridiculously strick fair use policies despite terms like "Unlimited" and "High Speed" etc being bandied about. Seems bizarre to me, I expect that when I pay for 100mbit cable Internet, I get what I pay for, all the time, every day.
Don't get the down votes really. Just reacting to the parent with my experiences with UK ISPs, and pointing out that despite the competition, there seems to be a trend towards degraded service.
The downvotes were because the throttling en masse that you speak of is largely non-existent.
There are problems in the UK with achieving advertised speeds (you are correct it's misleading) but it is not because of ISP throttling traffic.
Normally it is that the UK infrastructure outside of London and the South West is plagued by huge distances to the exchange (> 6 kilometres) making the advertised speeds nothing but a dream.
Most ISPs in the UK are extremely tolerant of torrenting as a fact of life. It was only when a court order forced them to do so that they blocked access to kickasstorrents et al.
When the mirrors sprung up the ISPs refused to block access since the court order was very specific what they had to do to comply. You said kat.ph specifically Judge nothing to do with katph.eu...
The Talk Talk CEO actually blogged about the ridiculousness of the legislation and stated they absolutely would not send letters to users of the service accused of illegal piracy.
The throttling you think you are seeing is normally caused by legitimate issues. Although you are correct some ISPs have a fair use limit but that is becoming rare to non-existent (even across our mobile spectrum - most plans are all you can eat data).
> The downvotes were because the throttling en masse that you speak of is largely non-existent.
Really? Well, let me elaborate on what I've explicitly described as the situation I've encountered personally, as opposed to anecdotally. Though it should be obvious by the fact that I give ample indication that I'm absolutely certain what I encountered through the means I used to circumvent it. It has nothing to do with the blocking of websites (kickasstorrents or otherwise). My problem is the use of L7 packet filtering/deep packet inspection to identify and connections using torrents and penalize them for it. As I stated, I'm peeved about this because it inhibits my sync solution, so no .torrent files or public trackers are involved at all. In some cases the ISP doesn't just throttle the "offending" traffic, the throttle the entire connection.
You don't need to believe me, on this - here're a whole bunch citations, including from the horses mouth:
EE
Section 2: Traffic management to optimise network utilisation
(what happens during busy times and places in addition to traffic management as
described in section 1)
Virgin Media
Virgin Media also manages P2P traffic and in its Fair Use Policy explicitly points
the finger at proscribed sites like Limewire, Gnutella and BitTorrent. Access to
newsgroup services like Usenet are also restricted, with those accessing similar sites
subjected to slower connection speeds. On services where you get speeds of above
30Mbps, your connection speed will be halved for a 5 hour period if you exceed the
following limits:
Source: http://www.broadbandbuyer.co.uk/News/Article.asp?TextID=1554
Got bored of searching at this point, but DDGing or googling for virtually every ISP I could think of in conjunction with "site:co.uk" and combinations of "AUP" "Fair Use" "Throttle", "Peer to peer" "p2p" and "bit torrent" returns matches that at least from the summary text seem to indicate they do implement it in some form.
How about you, or some other helpful poster, instead of down voting me, point me in the direction of some ISPs that don't throttle, as I obviously haven't been able to find any? :)
I never downvoted you. I just gave an educated guess at why it was occurring. Trial by Google search results is never helpful because you only cherry pick the data that supports your hypothesis. For instance I searched for throttling ISP UK and found a comparative study by ISP Traffic Management that stated thus -
>>BT Broadband Services
P2P traffic on BT broadband connections are slowed between 4pm and 12pm on weekdays and 9am and 12pm on weekends.
While P2P traffic is slowed, no other services - like gaming, newsgroups or VoIP - are subject to any throttling or traffic management and nor are they prioritised.
Apart from P2P throttling on its entry-level packages, BT does not shape or alter traffic in any way.
-------------
>>Sky Broadband Services
Sky Broadband was for some time unique among the UK’s major ISPs in that it doesn’t apply any kind of traffic management at all, now others are following suit.
Nothing is prioritised or de-prioritised at any time of the day or any day of the week, including P2P services like BitTorrent.
So when we said at the start of this piece that every ISP has a traffic management policy we weren’t wrong. Sky does have a policy, one which basically says ‘do what thou will’.
That still hasn’t stopped it complying with the UK Court Order and blocking The Pirate Bay.
-------------
>>TalkTalk Broadband Services
TalkTalk has removed all traffic management from its Essentials and Plus broadband products at all times, including P2P services (although like all the large ISPs some P2P sites are blocked).
No type of traffic receives priority over any other, although TalkTalk Plus TV susbcribers will find around 4Mbps of their connection is set reserved for TV when their YouView box is streaming TV, in order to ensure a smooth, high quality picture
Laws in that direction existed already before. For example if you left your car unlocked and gets stolen you're partly responsible for damages caused by the thief with the car (e.g. if the thief ends up in an accident driving with your car).
Essentially it boils down to, if you're in charge of some resource that can cause legally relevant interference (acts of piracy, fraud, etc.) you're in responsibility to secure it.
The already existing laws just got a little adjusted.
Some insight into the German psyche of legislation would be useful for context.
For instance -
> In the event of snowfall you are legally bound to clear the snow from the vicinity of your residence prior to 0700. If you don't and a pedestrian slips on the sidewalk you are liable for the damages. You could always tell the Brits because they refused to do it or begrudgingly complied.
> If you choose to go above the recommended speed limit on the Autobahn, you are free to do so as long as you are not in a limited zone for sound pollution. However, the insurance company reserve the right to invalidate your claim for taking an unnecessary risk. It's big boys rules with big boys pants.
It was refreshing to live in a society that advocates personal freedom in return for personal responsibility whilst balancing a really tight sense of community.
The ISP legislation is a reflection of that - if you choose to have internet access it comes with certain responsibilities and if you allow your connection to be used for illegal file sharing you take the punishment that goes with it (normally a not unsubstantial fine).
> In the event of snowfall you are legally bound to clear the snow from the vicinity of your residence prior to 0700. If you don't and a pedestrian slips on the sidewalk you are liable for the damages. You could always tell the Brits because they refused to do it or begrudgingly complied.
From your residence (i.e., not store/business/etc)?
by 0700?
What if you're away on vacation, too frail to safely clear the snow, or you just never in your life want to be awake before 7am if humanly possible?
Allowances are made in certain situations (vacations etc). Normally more able-bodied neighbours help elderly and disabled residents.
Not wanting to be awake before 7am is not tolerated. I am serious. The legislation is so ingrained that German people pay for separate insurance to cover them in case an individual has an accident on their sidewalk during winter conditions.
What is really interesting the strong sense of community-inclusion. The idea of someone not wanting to pitch in and help the street function normally is just not understood.
As an aside (anecdotally I grant you and wildly tangential) the community has benefits. I could go to the pub and my drinks would be recorded on my beer mat which I left behind the bar clearing the bill when I had the means to do so. Local vets could go weeks or months before a resident would pay their bill because it was an inclusive community of trust.
I saw similar attitudes in the smaller rural communities of mid-west and southern USA. In Germany it is just more widespread.
So, if you are the guy who doesn't clear his sidewalk you are the guy that gets no favours or trust. And potentially a lawsuit.
In France most ISP routers also serve as hotspots for other people. So if you're travelling and you're close to someone who uses the same ISP as you, you'll have access to a (granted, limited-speed) hotspot.
You can turn this feature off if you want to, but in order to use it somewhere else, you need to have this feature turned on in your own router ;)
It's a way to share an Internet access while requiring proper authentification of your guests, so that you will not be responsible for their behaviour.
yup, UPC .nl user here, and I shared my router as a wifi spot, that said, I don't see to many oter public UPC wifi spots at least in the area where I am the most zaandam / de pijp amsterdam.
The two major Belgian providers offer the same: Telenet only offer their own network, while Belgacom is a member of the international Fon network. I think both providers only offer the service to people with more expensive subscriptions, but I could be wrong about that.
I also run an unprotected wireless network and I highly doubt it will ever cause me problems. Computer science people always seem to think it's essential to take every possible precaution. In my opinion they are protecting against very rare events and they are mostly too young to realize that something terrible will happen in their lives first and make their choice of a DSA vs RSA ssh key really not important.
And yes, if someone did commit a crime using my network the police might visit, but what better defense is there than the fact that I have an open wireless network?
From a famous name in security who is well aware of the issues, that could easily be read as obfuscation intended to mask nefarious activity.
Surely that shouldn't matter? As long as the subscriber can prove their network is open or multi-user (which is easily done). That would make it necessary to prove the specific individual committed whatever crime is alleged. To my mind, given the prevalence of malware, compromises to security - that should be the case anyway, after all if malware does something illegal on your PC, why should you be liable? Expecting John "But it said I was infected and should click the EXE to clean it!" Doe to be responsible for their computer's security in this day and age is .. laughable and unreasonable.
I've toyed with the idea of running completely open WiFi network that is firewalled off my LAN and doing WiFi<->LAN networking via VPN (eg IPsec). My own devices would get prioritized, high-security internet access via the VPN too. Biggest stumbling block probably would be that many devices might not support the VPN tech of choice.
In theory it should be safe. But sometimes something could force the encryption down to a lower standard and also capture the initial key exchange. Then it might be cracked.
Also normal websites without https will open you up to session hijacking.
When I recently moved, the house was not yet completely finished, and not in a state where we could call our ISP to install broadband (we had to run coaxial inside first).
Luckily, my neighbor ran an open wifi hotspot, so we just used that for a few weeks. Sure, it was a spotty connection, but it did let us keep up on email.
I'm paying it forward by running an unencrypted 'guest' SSID, isolated (VLAN) from my encrypted SSID. Many consumer-grade wifi routers support this setup, and I can't see any reasonable excuse not to do this as a courtesy to visitors and neighbors.
>Certainly this does concern ISPs. Running an open wireless network will often violate your terms of service. But despite the occasional cease-and-desist letter [...]
Can someone explain this to me? How does your ISP know that you're running an open wifi network? I doubt they drive around to every customers checking for them.
That said, I've been thinking about running an open hotspot. If it's on a different vlan, with only port 22/53/80/443 open and speed/number of connections throttled it shouldn't cause any problems for anyone, and it's just a nice thing to do.
If you own a coffee shop, they would want you to buy a business plan that costs more than a home plan. They would detect it by calling your business to ask if you want a business plan and when you said you were using the internet from your apartment they may send you a letter.
While I may feel a responsibility to be a good neighbor/host/ friend, I also have a responsibility to protect the data of those neighbors/guests/friends who are using my network.
While I may think I am capable of securing my host in all network scenarios, not all of my guests may be so equipped. For me, the most friendly thing I can do is then to encrypt my network with WPA2-PSK key and share that with those who may wish to use my network.
46 comments
[ 3.1 ms ] story [ 137 ms ] threadAs such, I am not giving access to strangers, as good as it might be.
The ISP's have fought tooth and nail against every Government regulation to try and curb piracy or force the ISP's into compliance.
They have argued that the same laws which state the post office cannot be held responsible for malicious packages also applies to the telecommunications traffic they enable.
SkyBSB and Virgin Media lined up behind Talk Talk as prominent opposition to the Digital Economy Bill in the UK. They were simply beat down into regulatory compliance.
Also that was in 2008, now I would guess it is possible to get reasonable security with WPA2, AES and a very long key? Anyone know the consensus on that?
I know to check router model (some have backdoors). Disable WPS (sometimes it is even impossible todo), as that was a for a few years the weakest spot.
In the UK we have 6 prominent providers with over 100+ niche providers who must (by law) be given rental agreements on the existing infrastructure.
In other countries, e.g. the US, there tends to be one Telco per region which both owns the infrastructure and provides service.
I have upvoted because the comment deserved it not because the US is getting telecommunicationsly-screwed.
More remote areas are probably gaining high speed wireless faster than they are gaining other infrastructure. It's expensive, slower and has more limitations, but it compares pretty favorably to dial up, which may be the existing option.
I travel frequently to the UK, I use a torrent based sync solution to sync between laptop <> desktop (outside UK) <> VPS ("oh shit backup") - and I've found it absolutely astonishing how many ISPs throttle bittorrent and in some cases any traffic to a host known to run a tracker. I've tried to resolve this by putting my torrent sync within SSH (poor speed) and inside a full VPN (OpenVPN) and found several throttle VPNs too! I've subsequently moved my VPN to port 443 which seems to work, for now. Then there's ridiculously strick fair use policies despite terms like "Unlimited" and "High Speed" etc being bandied about. Seems bizarre to me, I expect that when I pay for 100mbit cable Internet, I get what I pay for, all the time, every day.
Anyhoo nbd
There are problems in the UK with achieving advertised speeds (you are correct it's misleading) but it is not because of ISP throttling traffic.
Normally it is that the UK infrastructure outside of London and the South West is plagued by huge distances to the exchange (> 6 kilometres) making the advertised speeds nothing but a dream.
Most ISPs in the UK are extremely tolerant of torrenting as a fact of life. It was only when a court order forced them to do so that they blocked access to kickasstorrents et al.
When the mirrors sprung up the ISPs refused to block access since the court order was very specific what they had to do to comply. You said kat.ph specifically Judge nothing to do with katph.eu...
The Talk Talk CEO actually blogged about the ridiculousness of the legislation and stated they absolutely would not send letters to users of the service accused of illegal piracy.
The throttling you think you are seeing is normally caused by legitimate issues. Although you are correct some ISPs have a fair use limit but that is becoming rare to non-existent (even across our mobile spectrum - most plans are all you can eat data).
Really? Well, let me elaborate on what I've explicitly described as the situation I've encountered personally, as opposed to anecdotally. Though it should be obvious by the fact that I give ample indication that I'm absolutely certain what I encountered through the means I used to circumvent it. It has nothing to do with the blocking of websites (kickasstorrents or otherwise). My problem is the use of L7 packet filtering/deep packet inspection to identify and connections using torrents and penalize them for it. As I stated, I'm peeved about this because it inhibits my sync solution, so no .torrent files or public trackers are involved at all. In some cases the ISP doesn't just throttle the "offending" traffic, the throttle the entire connection.
You don't need to believe me, on this - here're a whole bunch citations, including from the horses mouth:
EE Section 2: Traffic management to optimise network utilisation (what happens during busy times and places in addition to traffic management as described in section 1)
Source: http://ee.co.uk/content/dam/ee-help/e-gain.s3.amazonaws.com/...Virgin Media Virgin Media also manages P2P traffic and in its Fair Use Policy explicitly points the finger at proscribed sites like Limewire, Gnutella and BitTorrent. Access to newsgroup services like Usenet are also restricted, with those accessing similar sites subjected to slower connection speeds. On services where you get speeds of above 30Mbps, your connection speed will be halved for a 5 hour period if you exceed the following limits: Source: http://www.broadbandbuyer.co.uk/News/Article.asp?TextID=1554
Also have a look at the UK section of: https://torrentfreak.com/new-data-exposes-bittorrent-throttl...
Or the broadbandbuyer link at the top or: http://www.v3.co.uk/v3-uk/news/2292840/ofcom-publishes-inter...
Got bored of searching at this point, but DDGing or googling for virtually every ISP I could think of in conjunction with "site:co.uk" and combinations of "AUP" "Fair Use" "Throttle", "Peer to peer" "p2p" and "bit torrent" returns matches that at least from the summary text seem to indicate they do implement it in some form.
How about you, or some other helpful poster, instead of down voting me, point me in the direction of some ISPs that don't throttle, as I obviously haven't been able to find any? :)
While P2P traffic is slowed, no other services - like gaming, newsgroups or VoIP - are subject to any throttling or traffic management and nor are they prioritised.
Apart from P2P throttling on its entry-level packages, BT does not shape or alter traffic in any way.
-------------
Sky Broadband was for some time unique among the UK’s major ISPs in that it doesn’t apply any kind of traffic management at all, now others are following suit.Nothing is prioritised or de-prioritised at any time of the day or any day of the week, including P2P services like BitTorrent.
So when we said at the start of this piece that every ISP has a traffic management policy we weren’t wrong. Sky does have a policy, one which basically says ‘do what thou will’.
That still hasn’t stopped it complying with the UK Court Order and blocking The Pirate Bay.
-------------
TalkTalk has removed all traffic management from its Essentials and Plus broadband products at all times, including P2P services (although like all the large ISPs some P2P sites are blocked).No type of traffic receives priority over any other, although TalkTalk Plus TV susbcribers will find around 4Mbps of their connection is set reserved for TV when their YouView box is streaming TV, in order to ensure a smooth, high quality picture
-------------
REF [http://recombu.com/digital/news/isp-traffic-management-bt-sk...]
Helpful enough? :-)
> https://de.wikipedia.org/wiki/Mitst%F6rerhaftung
Essentially it boils down to, if you're in charge of some resource that can cause legally relevant interference (acts of piracy, fraud, etc.) you're in responsibility to secure it.
The already existing laws just got a little adjusted.
For instance -
> In the event of snowfall you are legally bound to clear the snow from the vicinity of your residence prior to 0700. If you don't and a pedestrian slips on the sidewalk you are liable for the damages. You could always tell the Brits because they refused to do it or begrudgingly complied.
> If you choose to go above the recommended speed limit on the Autobahn, you are free to do so as long as you are not in a limited zone for sound pollution. However, the insurance company reserve the right to invalidate your claim for taking an unnecessary risk. It's big boys rules with big boys pants.
It was refreshing to live in a society that advocates personal freedom in return for personal responsibility whilst balancing a really tight sense of community.
The ISP legislation is a reflection of that - if you choose to have internet access it comes with certain responsibilities and if you allow your connection to be used for illegal file sharing you take the punishment that goes with it (normally a not unsubstantial fine).
From your residence (i.e., not store/business/etc)?
by 0700?
What if you're away on vacation, too frail to safely clear the snow, or you just never in your life want to be awake before 7am if humanly possible?
Not wanting to be awake before 7am is not tolerated. I am serious. The legislation is so ingrained that German people pay for separate insurance to cover them in case an individual has an accident on their sidewalk during winter conditions.
What is really interesting the strong sense of community-inclusion. The idea of someone not wanting to pitch in and help the street function normally is just not understood.
As an aside (anecdotally I grant you and wildly tangential) the community has benefits. I could go to the pub and my drinks would be recorded on my beer mat which I left behind the bar clearing the bill when I had the means to do so. Local vets could go weeks or months before a resident would pay their bill because it was an inclusive community of trust.
I saw similar attitudes in the smaller rural communities of mid-west and southern USA. In Germany it is just more widespread.
So, if you are the guy who doesn't clear his sidewalk you are the guy that gets no favours or trust. And potentially a lawsuit.
You can turn this feature off if you want to, but in order to use it somewhere else, you need to have this feature turned on in your own router ;)
http://www.lifehacker.com.au/2014/05/telstras-new-wi-fi-netw...
http://arstechnica.com/information-technology/2013/06/comcas...
https://corp.fon.com/en
From a famous name in security who is well aware of the issues, that could easily be read as obfuscation intended to mask nefarious activity.
Of course don't do your banking on that device.
Alternatively only your wifi router needs to vpn into your lan and that offer a secure wireless solution.
Using correctly configured HTTPS (banks do use https) over open network is easily attackable?
Also normal websites without https will open you up to session hijacking.
Luckily, my neighbor ran an open wifi hotspot, so we just used that for a few weeks. Sure, it was a spotty connection, but it did let us keep up on email.
I'm paying it forward by running an unencrypted 'guest' SSID, isolated (VLAN) from my encrypted SSID. Many consumer-grade wifi routers support this setup, and I can't see any reasonable excuse not to do this as a courtesy to visitors and neighbors.
Can someone explain this to me? How does your ISP know that you're running an open wifi network? I doubt they drive around to every customers checking for them.
That said, I've been thinking about running an open hotspot. If it's on a different vlan, with only port 22/53/80/443 open and speed/number of connections throttled it shouldn't cause any problems for anyone, and it's just a nice thing to do.
While I may think I am capable of securing my host in all network scenarios, not all of my guests may be so equipped. For me, the most friendly thing I can do is then to encrypt my network with WPA2-PSK key and share that with those who may wish to use my network.