Live data from Hacker News

CenturyLink is blocking customer internet, saying Utah legislators told them to

richsnapp.com

1–10 of 294 posts

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#2
Senior network engineer for an mid sized ISP here: These people should be ashamed of themselves. I honestly don't care even the tiniest bit about whatever sort of excuses or justification they put up.

It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile, and develop workarounds like VPN tunneling their traffic, such as I would do if I found myself using an ISP in Turkey for a month.

This bullshit of injecting content into pages has been tried before, a long time ago by Comcast. I really don't see the point to it in an era of LetsEncrypt and nearly everything worthwhile moving to TLS1.2 or better end-to-end.

https://arstechnica.com/tech-policy/2009/08/comcasts-dns-red...

Also you absolutely should not mess with DNS returns from your client-facing recursive resolvers. Various ISPs have tried things like redirecting nonexist results to pages laden with "suggestions" and "advertising".

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#3
post #2

Senior network engineer for an mid sized ISP here: These people should be ashamed of themselves. I honestly don't care even the tiniest bit about whatever sort of excuses or justification they put up. It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile, and develop workarounds like VPN tunneling their traffic, such as I would…

Unfortunately enough ISPs have abused their position that treating them as hostile is where we're going.

VPNs are a stopgap. The future is end-to-end encrypted protocols like QUIC that obscure even connection state information and prevent anything from being modified in transit at all, DNS over HTTPS, etc. Everything has to be encrypted and authenticated end-to-end.

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#4
And here we see the disconnect between what politicians say, and what they write into law.

The bill's sponsor's response to the blog authors query:

SB134 did not require that ...They were only required to notify customers of options via email or with an invoice.

And here is the text of the statute that was written:

    (ii) A service provider may provide the notice described in Subsection (2)(b)(i):
     (A) by electronic communication;
     (B) with a consumer's bill; or
     (C) in another conspicuous manner.
Note the difference in language breadth. Bill sponsor: "via email" - text of statute: "by electronic communication".

And note clause (C): "in another conspicuous manner".

Century link is notifing by: "electronic communications" (DNS hijacking to force viewing of the page is "electronic communications") and/or by "another conspicuous manner" (it is definitely "another" and it is clearly "conspicuous" (one will not miss it)).

So, the fault here lies with the politician. He wrote a law that allowed Century link too much leeway to "do whatever they wanted to do to notify". If they were really only required to "notify ... via email or with an invoice", then clause (A) should have said "via email" and clause (C) should not have been present.

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#5
post #3
post #2

Senior network engineer for an mid sized ISP here: These people should be ashamed of themselves. I honestly don't care even the tiniest bit about whatever sort of excuses or justification they put up. It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile, and develop workarounds like VPN tunneling their traffic, such as I would…

Unfortunately enough ISPs have abused their position that treating them as hostile is where we're going. VPNs are a stopgap. The future is end-to-end encrypted protocols like QUIC that obscure even connection state information and prevent anything from being modified in transit at all, DNS over HTTPS, etc. Everything has to be encrypted and authenticated end-to-end.

Yes, I agree. If the global internet community is developing software to deal with threat models that deal with a worst case scenario (the government of Uzbekistan ordering ISPs to randomly block things), the Chinese great firewall, and so forth, we absolutely need technology like encrypted SNI in TLS1.3 and similar.

If we develop software with end-to-end crypto to deal with repressive-regime threat models, its crypto should also be inherently sufficient to deal with more normal traffic interception and modification attempts.

A lot of non democratic regimes in places outside of North America take a very blunt approach, of having government agencies order all of their domestic ISPs to simply null route huge chunks of the Internet (like, entire ipv6 /16s belonging to Azure and AWS) in order to ban politically objectionable sites. Or to order all ISPs to be singlehomed to, and downstream of the government state run telecom. There is one ASN in Iran which is allowed to have international IP transit connectivity to other non-Iranian ASes, for instance.

https://bgp.he.net/AS12880

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#6
post #4

And here we see the disconnect between what politicians say, and what they write into law. The bill's sponsor's response to the blog authors query: SB134 did not require that ...They were only required to notify customers of options via email or with an invoice. And here is the text of the statute that was written: (ii) A service provider may provide the notice described in Subsection (2)(b)(i): (A) by electronic com…

[deleted]

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#7
post #4

And here we see the disconnect between what politicians say, and what they write into law. The bill's sponsor's response to the blog authors query: SB134 did not require that ...They were only required to notify customers of options via email or with an invoice. And here is the text of the statute that was written: (ii) A service provider may provide the notice described in Subsection (2)(b)(i): (A) by electronic com…

I agree that the fault lies with the politician, but I would argue that the real issue is that they forced all ISPs to send notice to customers. If a politician wants something communicated, they can fund a public awareness program, not force it on ISPs. That fault doesn't exonerate CentryLink's action.

edited to add CentryLink responsibility

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#8
post #4

And here we see the disconnect between what politicians say, and what they write into law. The bill's sponsor's response to the blog authors query: SB134 did not require that ...They were only required to notify customers of options via email or with an invoice. And here is the text of the statute that was written: (ii) A service provider may provide the notice described in Subsection (2)(b)(i): (A) by electronic com…

But given the options, it's absolutely CenturyLink's fault for choosing the option they did.

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#9
post #4

And here we see the disconnect between what politicians say, and what they write into law. The bill's sponsor's response to the blog authors query: SB134 did not require that ...They were only required to notify customers of options via email or with an invoice. And here is the text of the statute that was written: (ii) A service provider may provide the notice described in Subsection (2)(b)(i): (A) by electronic com…

Politicians don't actually write laws, they have legislative assistants (that work for the body itself usually). I think the entire law is stupid, but how is it his fault that CL took the law and notified its customers in the most obnoxious way possible?

Re: CenturyLink is blocking customer internet, saying Utah legislators told them to

#10
post #3
post #2

Senior network engineer for an mid sized ISP here: These people should be ashamed of themselves. I honestly don't care even the tiniest bit about whatever sort of excuses or justification they put up. It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile, and develop workarounds like VPN tunneling their traffic, such as I would…

Unfortunately enough ISPs have abused their position that treating them as hostile is where we're going. VPNs are a stopgap. The future is end-to-end encrypted protocols like QUIC that obscure even connection state information and prevent anything from being modified in transit at all, DNS over HTTPS, etc. Everything has to be encrypted and authenticated end-to-end.

Yes, men in the middle cannot be trusted. Especially ISPs. Most mean well but are incompetent. Some don't mean well and are incompetent. ISPs that mean well and actually know what they are doing are relatively rare.

If you have a device with wifi, most of the time you are on untrusted networks. So, it makes no sense whatsoever to default to some random isp's DNS just because the wifi you are on is suggesting that you use it.

Post reply on HN