Earlier quoted context omitted.
I’d argue that a reasonable network limitation with a minimal blast ratio is responsible. For example, I use SIP over 5060 on Spectrum without issue. Not having their network used by bots to inflict untold financial damage is being responsible. Would you argue that implementation of BCP38 to cut down on bots used in DDoS attacks is “not the ISP’s responsibility”? Plus, they get the abuse reports from the victims and…
Nah, just like port 25 outbound being blocked is shitty. How can we have a decentralized net when consumer ISPs make people call in or beg to have full network access? Yes, do some flood detection, but the problem is that the SIP provider should be, as another commenter put, block international calls or otherwise detect/reject calls to toll systems. Who the heck uses toll numbers anymore anyway?
Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
81–90 of 95 posts
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#82Earlier quoted context omitted.
Glad this is at the top. The linked Reddit thread demonstrates a common but fundamental misunderstanding of SIP. Port 5060 is used for call control and is very low traffic. At most you may have timed OPTIONS messages but a “standard” SIP deployment is at most a handful of (small) packets per second per call setup and tear down with occasional REGISTER messages on an interval measured in seconds. Very low traffic and…
Not the ISP's responsibility.
Of course, not all ISPs do this, which is why DDoS attacks are still a thing, but the point remains, that responsible ISPs will take steps to prevent malicious traffic on the Internet from exiting their systems.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#83Earlier quoted context omitted.
Not the ISP's responsibility.
I’d argue that a reasonable network limitation with a minimal blast ratio is responsible. For example, I use SIP over 5060 on Spectrum without issue. Not having their network used by bots to inflict untold financial damage is being responsible. Would you argue that implementation of BCP38 to cut down on bots used in DDoS attacks is “not the ISP’s responsibility”? Plus, they get the abuse reports from the victims and…
I'm the OP and I agree. Across 3 Twilio phone numbers and I maybe make 4 voice calls and 10 texts a week. I've been doing this for 4 years or more.
>> For example, I use SIP over 5060 on Spectrum without issue.
As did I, until a week or so ago. Until I was cut off, without notice. I've been a Spectrum residential customer since the 1990s.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#84Can you use port 5061?
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#85Earlier quoted context omitted.
Not the ISP's responsibility.
no, the ISP's responsibility is to ensure that the majority of their customers can access websites over http/s. and if their IP blocks are getting added to "likely scammer" lists because of SIP scams originating on their network, then it's in their best interest to do something do discourage those scams. the people working to defeat scammers aren't necessarily making distinctions between port numbers.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#86They are probably trying to reduce SIP abuse. It's a big problem.
Yeah, running SIP on a standard port without some serious firewall based rate limiting for unknown traffic is almost impossible. I tried running a PBX on UDP 5060 and got >4GiB of logged register attempts in a few hours after opening the port, while asterisk was running at 100% CPU just rejecting the registration attempts the whole time. It's insane compared to any other public service I run.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#87Earlier quoted context omitted.
You can do something similar in the US - many condos have it setup where they technically are an ISP and pay for transit. Usually it's not worth it because you end up doing end-user support for every neighbor and people are dumb as rocks. But you'd be surprised how cheap a "very fast" transit internet connection can be.
I agree with what you're saying about support. I get nauseous just thinking about the number of people who call their ISP just because their laptop has a flaky Wifi module, and the thought of having to deal with that.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#88They are probably trying to reduce SIP abuse. It's a big problem.
Glad this is at the top. The linked Reddit thread demonstrates a common but fundamental misunderstanding of SIP. Port 5060 is used for call control and is very low traffic. At most you may have timed OPTIONS messages but a “standard” SIP deployment is at most a handful of (small) packets per second per call setup and tear down with occasional REGISTER messages on an interval measured in seconds. Very low traffic and…
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#89My ISP breaks traceroute outside of the network. Their transit is cut out of my traceroutes. Full technical story at https://blog.habets.se/2022/05/Another-way-MPLS-breaks-trace...
Huh, I remember back in the day seeing weird latency cliffs like that when trying to troubleshoot latency issues when playing World of Warcraft. There always seemed to be one between basically any ISP I was connected to and the AT&T network blizzard was running their servers on.
Hops marked with "* * *" do not count as "missing" here.
Re: Tell HN: Spectrum is blocking TCP/UDP 5060 at my home
#90My ISP breaks traceroute outside of the network. Their transit is cut out of my traceroutes. Full technical story at https://blog.habets.se/2022/05/Another-way-MPLS-breaks-trace...
It looks like someone technical from your ISP also replied in the comments of your post and offered to set up a call to explain it to you. That is far better than you can expect from almost any other provider.
I hope they'll fix it soon, but not if it delays IPv6.
If I had a choice of FTTP providers then IPv6 support would weigh really high on my choice, but only one has dug up the street.