Live data from Hacker News

Why I quit this battle

badmodems.com

91–100 of 126 posts

Re: Why I quit this battle

#91

Earlier quoted context omitted.

I thought "dark fiber" meant unused fiber. How can it be dark if you've got services running over it? Is there some other meaning in this context?

Usually, dark fiber means that you got that cable (with one or more hairs) completely for yourself, as a customer. It is not leased line, you are not sharing it, it is your fibre to communicate with. It is more expensive, for sure, since Carrier could make lot of $$ out of it (many many Internet Customers for example), but at the end of the day it is cost efficient actually since you have no other interference on you…

I think you got your definitions mixed up.

Even the name means: "it's dark, no light, as in no data, because that's what light is in this case"

Re: Why I quit this battle

#92
post #63

His experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations. I ended up maki…

> if they did a bug bounty program, they'd go bankrupt.

I believe it. When I worked for them a few years ago, their internal security was pretty bad, and they had tons of random teams with no security guidance, governance, etc. I think the only reason they could operate at all is nobody is trying to hack them. It might be a little bit better now, but knowing the scale and state of things, there's no way they've magically knitted everyone up into properly managed AWS Organizations, to say nothing of actually supporting individual teams' security needs.

The "good news" about your discovery is that it probably was limited to just one tiny system, because everyone maintained completely independent systems and didn't have access to anything else - not because they weren't allowed, but because you didn't even know what other systems there were, much less know how to request access, and virtually nothing internally used SSO. The only way to learn about what other systems there were was to walk around the floors of the Comcast Building and ask random people what they do.

Re: Why I quit this battle

#93
post #57

Earlier quoted context omitted.

Oh I’m sure that Comcast the company knew about a serious issue plaguing a huge percent of their modems. It’s likely they just decided to play dumb so that they didn’t have to do anything about it. A calculation was done and fixing or even acknowledging the issue would have been more expensive. So don’t even tell the front line support people about it.

Comcast will never have to play at dumb.

I'm not sure it was "playing"... they often are actually just dumb. But most likely is that they heard the complaint, created a backlog ticket, and went on with regular feature work.

Re: Why I quit this battle

#94
post #66

As a default, you should not consider your gateway network device in your trusted zone. This is one of many reasons why you should VPN (including personal, commercial, Tor, whatever your cup of tea) all traffic elsewhere. You might think "that only moves the attack surface" , you are both right and wrong. Technically it is moved but you eliminate LAN based, wireless (think wpa) and untrusted network devices from the…

I forgot, VPNs are unpopular on HN because? Someone popular said so? Lol. This includes wireguard to your vps too if that helps. Anything but nude networking as I call it.

Re: Why I quit this battle

#95

Earlier quoted context omitted.

FTTx systems make copper almost non-existent. All copper in my city is replaced by fiber, and only copper is from the FTTx box in front of my apartment to my flat. Eeerything (landline, internet, IPTV, etc.) runs from a single, dark fiber. With cabling already in place and VDSL can reliably provide 5 units of bandwidth (where 4 units is used for download and 1 unit is used for upload, e.g. 32/8 mbps), with a theoreti…

I thought "dark fiber" meant unused fiber. How can it be dark if you've got services running over it? Is there some other meaning in this context?

I used the term "dark" as in unshared, and as a result, you use it the way you like it.

Also, the term looks like it has both meanings.

Having a "dark fiber infrastructure" means having a web of unconnected fiber cables point to point, but since you connect your own devices to it, you don't have to share it with others.

As a result, its presence and its state is only known to you (i.e. it's in the dark).

I understand that my usage is not completely true, but in that context, it's not a flat-out blatant mistake either.

Re: Why I quit this battle

#96
post #29

I don't know the new context, but I will always be thankful to badmodems.com for highlighting the original Puma 6 issue. I was given a modem by my ISP that had a Puma 6 chipset and it was a nightmare - it would completely cut out multiple times per day, latency was all over the place, and it was a truly terrible experience. Doing a bit of digging I was able to short-circuit a lot of troubleshooting and replace the mo…

As an ISP anything that is a shared access, contended media like a copper coax segment (DOCSIS3) is a nightmare waiting to happen. The amount of problems that are caused by one person with a leaky/bad connector and line, or things that have gone screwed up at the RF modulation level of the cable plant between the cablemodems and the CMTS. Imagine hundreds, or thousands of houses out there all with 25+ year old coax j…

Do you expect the same problems with GPON, which also has a shared medium? At least with fibre you don’t get reflection problems from other people’s dodgy terminations, but you are relying on them obeying the TDMA for upstream.

Re: Why I quit this battle

#97

Earlier quoted context omitted.

As an ISP anything that is a shared access, contended media like a copper coax segment (DOCSIS3) is a nightmare waiting to happen. The amount of problems that are caused by one person with a leaky/bad connector and line, or things that have gone screwed up at the RF modulation level of the cable plant between the cablemodems and the CMTS. Imagine hundreds, or thousands of houses out there all with 25+ year old coax j…

Do you expect the same problems with GPON, which also has a shared medium? At least with fibre you don’t get reflection problems from other people’s dodgy terminations, but you are relying on them obeying the TDMA for upstream.

Rogue ONTs either fire out of time slice and break other packets or just stick on and jam the OLT.

The OLT can often pick out which ONT is doing it.

Re: Why I quit this battle

#98
post #63

His experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations. I ended up maki…

> if they did a bug bounty program, they'd go bankrupt.

Ha! Classic Telco. I've seen some in my country and they are an impressive mess of legacy (and many times redundant because of all the M&Âs) applications and undocumented integrations made by an army of low paid outsourced integrators.

Also, low effort mode overall, like your CISO friend there, who probably just wants to survive for sufficient time too jump ship.

His bug bounty speech doesn't hold, as they can start with a very low bounty and increase over time to get the interest of higher skilled people and reach more complex bugs, having total control over spending.

Also, Black hat experts probably have those already mapped and are selling them to the highest bidder, and with privacy regulations getting stricter that "bug bill" will come to them sooner or later.

Re: Why I quit this battle

#99
I remember reading about his discoveries on the Puma chipset and that was actually really useful information when I was debugging cable issues myself.

No idea what his most recent issue is but hey, thanks for your work bud, it was useful to many. Time to take a break!

Post reply on HN