I don't even have an alternative in my area.
I don't even have an alternative in my area.
`Monitoring and Recording. You agree that Comcast and its agents may monitor and record any telephone calls or other voice, data or image communications that are transmitted between: (1) Comcast and its agents and (2) you, your agents, any user of your Service(s) or Equipment, or any user of any phone numbers associated with your account.`
IANAL, but this seems like clever lawyering to make consumers think they're only referring to customer service calls.
[0]: https://www.xfinity.com/corporate/customers/policies/subscri...
I read that the wire is owned by Comcast. Its agents roam free and everything traversing that wire is monitored. 100%.
The numbering and the "and" clearly mean that one of the two endpoints must be "Comcast and its agents." The language is there to allow them to record customer service calls because otherwise in some states that would be a violation of wiretap consent laws.
I agree that it seems to be worded to imply that it's just CS monitoring but I don't believe that `transmitted between` would necessitate that the party be the intended endpoint.
"We do not proactively monitor what content you download or access, however, we must act on lawful requests for information and/or interception as well as infringement notices which we receive under the Copyright (Infringing File Sharing) Amendment Act 2011. This action may include sending you an infringement notice"
I'm curious where you are located [if you don't mind sharing]?
Thanks, I needed a good laugh this morning.
The complaints likely won't go anywhere anytime soon. But when Pai's successor is working to repair the damage, there's a decent chance that one of the things they'll have to do is go through the agency's records to figure out what was ignored. Having a record of the complaint will at least give them options in the future.
So file the complaint, even if it's unlikely to matter in the short-term. :)
In fact, the FCC's response to the bot activity was to point out that they aren't permitted to delete the comments, though a former FCC special counsel was quoted as suggesting that the FCC "might have an obligation under the Administrative Procedure Act to remove fake comments from its consideration."[1] But "removing fake comments from its consideration" isn't the same as actually deleting them, so I'd imagine that just means labeling them as "likely fake" and ignoring them in their deliberations. The same would apply to official FCC complaints. The FCC might ignore them, but they can't outright delete them without violating the law.
0. https://www.law.cornell.edu/uscode/text/5/553
1. https://www.wired.com/story/fccs-broken-comments-system-coul...
Comments are collected in case there are scenarios the regulatory agency didn't consider. They considered them, and decided a way you didn't like.
Don't worry, I'm not promoting DirectTV Now because it sucks balls. I have ad blocking at the router level at home and DirectTV basically won't work because of it. Even when it does work the picture quality is awful, you can't easily skip commercials, changing channels is painfully slow. And there are ads everywhere.
But, my main point is that a few weeks after getting it, I get a mailer from Charter asking me why would I want to pay for channel bundles (I get only internet from Charter)... the only way that mailer makes sense is if they were watching my traffic and seeing that I'm a subscriber to a channel package from their competitor. (I've never gotten a similar mailing and it doesn't make sense absent spying, otherwise they're kind of arguing against their own main cable service.)
It really made me want to get VPN setup whole-house.
If that isn’t enough, your next option is a VPN or Tor.
Hm, thinking about it as I write, I could see how encrypted DNS plus everything being encrypted and served via CDN could actually cut down a lot on what carriers can see. Still far from perfect, but not quite as bad as I was originally thinking.
Edit: I wasn't familiar with Server Name Indication (destination hostname is unencrypted even though the rest of the URL and session are encrypted).
With encryption (https), they can see who you talk to, the rate, the frequency, from where and when. They can't see the actual URL (just the hostname) or data (encrypted).
With VPN, they see you are talking to a VPN, the rate, the frequency, from where and when. VPNs cut down on knowing who you are talking to (assuming they aren't logging or being monitored which they could easily do).
Other services could be added to obfuscate rate, frequency and when I would assume, but even then those services would only be additive obfuscation (unless you cache packets for a short term... just thinking as I type).
Someone check me if i'm off on this these points...
One simple technique is to always transmit X packets/sec where Y packets/sec are real and the other packets are dummy packets (Y < X). If the channel is encrypted, it's impossible to distinguish the dummy traffic from the real traffic, and if you're over a VPN, it's difficult to identify the destination.
A slightly more sophisticated approach is to vary X over time, to make it shaped like streaming video, for example, to obfuscate the fact that you're using traffic analysis countermeasures.
It’s similar to differential privacy where even with a bunch of bogus data patterns in aggregate can be determined.
One approach that could work around this in many cases is to run a VPS with a private VPN server on a cloud provider. This is beyond the technical ability of the average user though and costs more than most VPN services.
I had to disable router-level vpn for exactly this reason, which is frustrating.
Amusingly enough, when I did have it on, my Chromecast showed weather data for the vpn endpoint so it's using IP-based geolocation for weather. It could be smarter.
That is pretty awesome. I feel your pain and that is why I haven't gone and flashed my router even though I finally bought one that will let me.
Next you can choose a cloud provider, which is metered (GCE, AWS, etc), or non-metered like OVH, or Digital Ocean(they don't charge you if you go over the 1TB for now).
Or you can choose a VPN service provider like Mullvad who have wireguard option (PIA should be getting it soon), if you trust them.
Be careful in choosing your provider since you might be annoyed with the latency over time, or just get used to it.
There are tutorials for all this.
A personalized router is very powerful.
Also, why Bind9? I don't see what's wrong with dnsmasq, and changing hosts file for blocklist. Also, I often advise against network wide blocklists unless you're the only one using the network, since subtle things break.
Here's what I do: https://news.ycombinator.com/item?id=14780738
The only thing different is that I use wireguard and dnsmasq now.
Bind9 seems to be better for blocking. RPZ is made for it. I don't think dnsmasq supports RPZ though projects like Pi-Hole use dnsmasq. I'm not positive, but I think RPZ is more flexible. Bind9 seems to do anything you like. I may want to resolve DNS myself and not just forward.
I'm starting to look into configuring Bind9 to have different blocking per user using "views." Some want Facebook, some don't, so I can block accordingly. I'm not sure you can do that in dnsmasq. I did discover subtle things break, like you can't block Facebook and still access Instagram, thus the "views" approach. I don't want to change hosts file on every device, especially mobiles, and can even provide some protection for guests this way. I might do a captive page for a blocked domain and let people bypass in their view if they like, then I can have a "block-first" approach.
I do like network-wide blocking for the malware lists - if anyone acquires malware, it can't phone home (if it's on the list) and I can detect via logs. DNS as firewall seems to be a trend. I'm looking into blocking IPs via iptables as well using public lists. Maybe I'll even setup Snort or Bro. The possibilities are endless.
Doesn't that mean your ISP will now see what domains you are looking up?
(the VPN comment was several levels up so some might miss it)
"In order to server our customers better and provide the best possible experience, VPN services will be blocked and will require a Business Tier service. We feel that unless you have a legitimate business reason to anonymize your network traffic we will provide this service in order to protect our subscribers and network integrity. Click Here to Speak to our Sales Representative"
If they're transmitting properly over TLS then no patient info would be divulged.