CenturyLink is blocking customer internet, saying Utah legislators told them to
richsnapp.com
richsnapp.com
Fast forward to yesterday and we had a modem in the mail a $200+ bill for our landline that should be <$60. She called and the guy on the other end was very helpful (surprisingly). He went through the bill line-by-line and almost every time said something to the extent of, "Why is that here?" "I'm going to have to talk to {previous sales lady who 'upgraded' us}". Some of the items he didn't even know what they were and couldn't remove them, so he instead gave us a permanent $10/mo discount or whatever it was billing.
About the modem, he said, "You can keep it or mail it back. I can make a note on our software that you didn't want it and it shouldn't bill you for it. However, I recommend you mail it back because sometimes that note will disappear from our software and start charging you again".
Wait... what!? Did he just acknowledge what some of us has suspected all along? That their software has intentional "bugs" that don't remember to stop billing someone for something?
The whole thing feels like a scam to me. I don't trust them at all. This isn't the first time and won't be the last either.
The reason we haven't canceled? No other traditional landline offerings in our area. Everything is VOIP or Cell. My wife wants something independent for emergencies. She's starting to question the value of it all though.
Thankfully he lives in one of the few places with multiple providers, so he told them to stuff it.
If companies could just send you things and bill you without you ordering anything, we'd all be buried in mountains of garbage and steep debt. Keep the modem as a gift courtesy of CenturyLink. Watch your bill and if they charge for anything you haven't received, if you've got the time, file fraud claims in small claims court to recover the money.
If they intended for you to receive it but believed you were expecting it (and understood that you'd have to pay for it), then I expect that would also qualify.
In order to count as "unordered merchandise" it seems reasonable that the sender must be aware that it was unordered.
See: 39 U.S. Code § 3009 - Mailing of unordered merchandise
https://www.law.cornell.edu/uscode/text/39/3009
If you're mailed merchandise that you did not expressly request or consent to, it becomes your property to do with as you will, and you cannot be billed for it. There are no exceptions for accidents.
If you receive a package that was not intended for you, that's an accident, and you are not entitled to that package. That's my core point.
If you receive a package that is intended for you, but it was a bona fide mistake on the company's part, you'd have to ask a lawyer as to whether that counts as "unordered merchandise" or not. I certainly wouldn't simply assume it is.
If it was addressed to you, whether intended or not, the law expressly states it is yours; the relevant code section has no mental state precondition.
If it's got your address on it, but someone else's name, it's not your package and you're not entitled to it (in fact, you can't even open it).
If it's got your name and address on it, but the company meant to send it to someone else named dragonwriter instead of you, it's also not your package and you're not entitled to it.
If you order item A and the company accidentally sends you item B instead, that's not "unordered merchandise", that's a mistake, and you're not entitled to treat item B as a gift.
The reason is, the common con game where criminals would send expensive items to someone, often a recently deceased person, and demand payment. The surviving family would assume that good ol' Dad had ordered it and pay up.
The item was usually junk but with a high price tag. So the con had little to lose.
Anyway, items mailed to you without being explicitely ordered are yours to keep, legally.
I'm not sure what you mean by “accidental package”; specifically what kind of accident is involved.
> If it's got your address on it, but someone else's name
Then it isn't addressed to you (the verb address and noun address are related, but not in the use directly corresponding), and isn't what I was talking about.
> If it's got your name and address on it, but the company meant to send it to someone else named dragonwriter instead of you, it's also not your package
This is both generally incorrect and objectively unworkable (it would require an inquiry into the mental state of the sender before one could decide what to do with a package.) There are special cases where things would be different (e.g., there actually is another dragonwriter at the address, who actually did order the merchandise, in which case it is, obviously, not unordered merchandise that they have caused to be delivered to the first dragonwriter. But that's not even an accident or mistake on the sender's part.)
As well as the statute referenced above, the FTC provides clear and explicit guidance: if you receive it, and you didn't order it, it's yours and you may keep it. Intent of the sender is not an issue.
https://www.consumer.ftc.gov/articles/0181-unordered-merchan...
“Q. Am I obligated to return or pay for merchandise I never ordered?
“A. No. If you receive merchandise that you didn’t order, you have a legal right to keep it as a free gift.”
Holding a package intended for someone else may well be theft (depending on particulars), just as keeping something that fell in the street is theft.
The sad truth is that these telcos will systematically screw millions of customers with shady fees and fraudulent billing practices, but when the FCC gets involved, they are facing potential fines of tens of thousands for each infraction, so they'll bend over backwards to get you to drop the complaint.
Try it sometime, it sucks that it's necessary, but you'd be amazed at the results.
[0] https://www.elliott.org/company-contacts/charter-communicati...
Other tips: * Take the time to find the correct regulator... It might be in a different state than yours * Prepare a complete document with as many facts and scanned copies as you can * Clarify your desired outcome * Send everything certified mail * CC the CEO of the company with which you are fighting * If sending a follow-up letter, included scanned copies of the certified mail receipt(s) from previous communications - they cannot then argue that they did not receive your previous communication.
Nobody wants a call from the AG or a Financial Regulator!
Yes, it is terrible that this needs to be done, but it works wonders.
This , I had to do this with Comcast because of their craptastic service ,BS, and invalid billing. Trying to cancel them I kept being passed around to ALL the wrong people and departments, hung up on, refusal to give confirmation that the service was actually cancelled. Finally figured the only way they would cancel my service was to write a complaint to the FCC.
Sure enough just a few days later comcast called and apologized and cancelled my service as requested and fixed the hundreds of dollars of wrongful billing.
When I've tried dealing with someone in their call center, it's been much more frustrating.
I went to the store to return the box and they said I'd have to take a number.
I said "Nope, here's the box I'm returning, we're done here". Took some pictures and got the F out.
Returning something shouldn't take more than 30 seconds. And it wasn't going to take more than that for me.
Although I have done a bit of a chaotic neutral thing myself: Comcast sent her two new boxes instead of one after we switched her to a cheaper box. They wanted us to drive all the way back to service center. Grabbed their UPS account # from the tracking code, filled out the web form and had it sent back with pickup billed against Comcast’s acct. She never got billed a cent.
At the time of writing this, they think I'm just dandy, because I didn't respond but didn't attack them when they tried to shake me down. It'll be interesting to find out if they respond to this post ;)
Yelp would also work, if the business concerned cared a ridiculous amount about resolving complaints there. That's the only value - that these particular companies care an awful lot about resolving complaints left with the BBB.
Got bullshitted by Comcast phone rep, skipped straight to BBB complaint since I didn't want to deal with Comcast for hours/days, less than a week later I had their VIP Customer Service department calling/emailing daily until they (not me) got the issue resolved.
Perhaps an FCC complaint results in the same result, but it worked out perfectly for me.
What is important is that those companies care about BBB and are quick to fix the issue. If they didn't care about BBB I wouldn't have gone that route.
Same with Twitter. Some companies can be shamed into helping by posting on Twitter. If they didn't care about Twitter, it doesn't nothing using that medium to get help.
https://publicutilities.utah.gov
I've reported to them in the past for things Qwest did. Seemed to be effective.
Have you considered ham radio?
By the way, back when I took the exam, I made a tiny web app to help me with the question pool: https://hamradio.zhimingwang.org/. It basically lets you quickly go over the questions, hide the ones you're confident with, then go over the rest again, rinse and repeat. The question pool might have been updated though.
At collections, it continued like this for months, I sent photos, I even had a recording of a comcast manager saying "we shouldn't have billed you, and will remove the charge".
After 18 months of fighting this $300 charge and around 30 hours of debates... I just paid the bill
That's basically what I did with a shady property management company (AMC LLC, one of the largest in the US tried to steal my security deposit) and won, but I've heard that huge corporations like CenturyLink will even immediately follow up with a settlement offer to avoid spending an executive's time.
1. If you sue the company, any non lawyer rep can show up.
2. If you can sue the CEO over a corporate matter to force a settlement, why isn't everyone suing every rich person over everything?
2. Your guess is as good as mine.
My advice to anyone moving into the Utah area is check the internet service provider options first. Last thing you want is to be in an area serviced only by CenturyLink.
This happened to all of Australia with Telstra/Foxtel and the NBN. We were all going to get gigabit fibre, then Rupert Murdoch and the incumbent corporations got involved. Now the 80% of us that didn't already get fibre yet are getting DSL or HFC that drops out ten times a day and can't reliably hit 15Mbit. That's right, new DSL being installed in the year 2020.
https://www.consumerreports.org/cro/news/2009/05/update-abou...
Inactive lines are not equal to lines with no telephone service. IF there is no telephone service, 911 probably won't work. If your phone is temporarily disconnected (say for non-payment of a phone bill or the disconnect they do for folks that live in FLorida for the winter and up north for the summer), 911 will work for you.
This was definitely true for some of the states on the list provided.
I've long thought this was a sad state of affairs. Anyone with a physical phone to plug into a jack should, theoretically, be able to dial 911. I'm happy that cell phones generally allow this.
Setting an expectation of free 911 service is fine in the cellular world where its a minor nusiance to support, but in the context of a rapidly shrinking customer base (for incumbent telcos) its a very expensive burden.
These are things that let folks call 911 for a dangerous, possibly drunk driver. House fire, abusive husband, neglected kids next door. I've personally used it for car accidents, violent customers (one decided to huff canned air in a pharmacy), hurt co-workers, and random folks off the street needing an ambulance.
911 provides a public safety service. If it means that phone companies have to provide access from their equipment or their lines, I'm OK with that. Im OK with all or part of that being reimbursed, with the main exception of requiring a new mobile to be compatable with emergency services (no worse than requiring autos to have seat belts).
Lifeline service is a public good, but funding should not come from taxing shrinking telephone bills, but instead from a different revenue source that isn't in the process of notably shrinking every year.
That said, I'm not sure how cell phone taxes wind up looking on a bill, honestly. I have weirdly never had contract telephone service. I've never been able to justify the costs. For years, I had prepaid plans (that kept getting better) in the US, then moved out of the country.
It's malicious. Some of us reps try to help you out and get it all reversed. Others don't give a shit at all.
The main thing you can consider is not paying, blasting them on social media, or just keep calling until you get a nice rep who will fix it, hopefully permanently.
Our system deliberately renews/adjusts prices per gallon and service contracts to pretty much whatever price the company feels like extorting. I've seen customers charged $4000 instead of $2000 countless times. Some even pay it.
While I’m the last person to trust big business, it’s hard for me to believe that whoever is over the developers who create the billing system would put that in a spec - to deliberately overcharge people.
I’m more inclined to believe incompetence and deprioritizing known bugs to create new features.
How does intentionally writing buggy software even get communicated to the front line developers?
Who's to blame for this? The CEO and CTO I would say. They want to generate as many inflated bills as possible and then make it really hard for the customer service rep to submit an approval for it to be adjusted.
They train the reps to say, "sorry sir, this is what my computer is telling me your balance is."
The customer then either pays or leaves the company, at which point they are charged an early terminaton fee and threatened with small claims court.
So yeah, I really feel this corporation directly desires a complex and costly process since it has a near monopoly on the market and the cheaper competitors are plagued with product quality issues as opposed to service/billing issues.
For instance, you make a 12 minute, 5 second call (12.1 minutes with 6-second billing which means 60 seconds is billed in tenths of a minute) - the software records it as say, 12.6 minutes.
“They thought it was the only way to satisfy the law” also doesn’t make sense. There’s no reasonable way to get that from the law, they didn’t confirm it was necessary, and they didn’t publicly fuss about being forced into a large expenditure.
Today is, by the way, the one year anniversary of the repeal of net neutrality. ISPs, including CenturyLink, were viciously fighting to end rules preventing the sale of selective internet access, and won. In order to sell selective internet access, you need exactly the system that just showed up. This system would take a while to build—maybe a year. And once it’s built, you would want to test it. The test would put your capitalization on the lack of net neutrality in the spotlight—unless you just serve a legal notice, and pretend you thought you had to. For that to work, you need to make sure people know the “legally required” part; for a legitimately legally-required notice, companies typically don’t say as much. CenturyLink literally highlights it.
2) There's likely a profit motive here as the software that is being advertised via this injected message costs money. They're likely getting a commission/affiliate fee from every customer that installs said software via this notice.
No, you choose the most self-interested option. That type of criticism is usually levied against laws that provide an incentive to enforce it in a self-serving way.
In this case what CenturyLink did should itself be illegal. CenturyLink knows fully well this was a self-serving move and they likely only did it because they're betting they can avoid lawsuits by blaming the law.
Interfering with traffic on a paying customer's active account should be illegal so there is no option to do this for any reason.
Did this require building a new communication system? Comcast has a similar injection system for reminding you to pay your bill, or to notify you that you've been accused of piracy.
Maybe this was done using hardware and software they had lying around.
The bill's sponsor's response to the blog authors query:
SB134 did not require that ...They were only required to notify customers of options via email or with an invoice.
And here is the text of the statute that was written:
(ii) A service provider may provide the notice described in Subsection (2)(b)(i):
(A) by electronic communication;
(B) with a consumer's bill; or
(C) in another conspicuous manner.
Note the difference in language breadth. Bill sponsor: "via email" - text of statute: "by electronic communication".And note clause (C): "in another conspicuous manner".
Century link is notifing by: "electronic communications" (DNS hijacking to force viewing of the page is "electronic communications") and/or by "another conspicuous manner" (it is definitely "another" and it is clearly "conspicuous" (one will not miss it)).
So, the fault here lies with the politician. He wrote a law that allowed Century link too much leeway to "do whatever they wanted to do to notify". If they were really only required to "notify ... via email or with an invoice", then clause (A) should have said "via email" and clause (C) should not have been present.
edited to add CentryLink responsibility
You're entirely wrong.
It is the politicians fault for writing a law that was so broad that it allowed CL the potential leeway to be able to choose the awful option they selected.
I don't think the bill's author/sponsor is fully to blame (they aren't guiltless either). Centurylink certain did not have to implement this requirement in the way it was done. The most depressing aspect to this is the lack competition. The author is unable to move to a competitor which did not behave this way.
If they put email, then that would have required the use of email. That's certainly more narrow than they intended, as it would exclude other acceptable methods such as sending a physical letter, including a notice with the invoice, etc.
This is 100% on CenturyLink.
How is the bill's author/sponsor at all to blame for centurylink doing this? They could just as well be doing this without the bill existing.
That being said, this law already had a specific expiration date, and there was little fear that email would be an old technology by the end of this month.
They should have written a better law.
Exactly right. This is why fax machines still exist today. There are some laws that _require_ certain documents be faxed (not emailed) to healthcare providers. If the law was worded more abstractly, they could be using email or a smartphone app now. So to me this new language makes sense, but it can open up risk to being abused.
If the law is abused, the company should have it's day in court, and the courts can decide what to do.
I would really love any links to the implementation side of this bill. The text of the bill itself is vague with words like "good faith" and "generally accepted".
I disagree: the claim by CenturyLink that this particularly intrusive, access blocking method is mandated is simply false. It's true that it is permitted by the state law (just as it would be permitted without any specific law on the topic at all), and even arguable that it is one means of complying with the law. (Though since the notification is not presented to some users, it's arguably not even fully compliant.)
But, even if it were fully compliant with the law, it's not any lawmaker’s fault that CenturyLink chose to implement pretty much the most user-hostile method imaginable (short of, say, posting sings on its customers lawns, facing the windows of their home, illuminated with burning crosses—which would likewise be “another conspicuous manner”) to fulfill the notification requirement.
Agreed - also not the point I was making.
> it's not any lawmaker’s fault that CenturyLink chose to implement pretty much the most user-hostile method imaginable
Oh but it is the lawmaker's fault. It is the lawmaker's fault by writing a law that was so broadly worded as to allow Century Link to be able to perform this "user-hostile method" under cover of being within the wording of the law.
If the law maker had written a more narrow law, and written what he actually intended, then CL using this method would have been in clear violation of the law, rather than being able to hide behind "we are permitted this method by the law".
A service provider *may* provide the notice [...]
That does not seem like a hard requirement. Or is this a case where legalese differs from commonly-understood grammar?The portion before the selection list (which I did not quote, as it can be read in full in the actual article) begins:
A service provider shall, before December 30, 2018, notify ...
This clause says they "shall" notify. So it is mandatory they notify. It is not mandatory that they perform the notification via the means they selected to perform the notification. The method is awful, but the method is allowed by at least clause (C) of the statute.
Which was my original point. The bill sponsor replied that their intent was "by email" or "with the invoice". But what they wrote as the statute not only encompasses that intent, but allows choosing a huge number of other, many very awful (as is this one), ways of 'notifying' as well. If the sponsor's intent was "email" or "with invoice" then their statute should have said "by email" or "with invoice".
Even if the law said that this notification must be delivered via certified mail, that would obviously not prevent Centurylink from also doing this.
Why is it that you so badly want to blame lawmakers for this?
It shouldn't be the lawmaker's job to specify how businesses go about doing their business. The law was written generically enough that any sensible option would satisfy it; email, postal letter, addendum to your bill, or some other "electronic communication" that the lawmakers aren't qualified to specify. This is how laws should be written.
There's absolutely no justification to CenturyLink choosing DNS hijacking over a simple email in this case, and "the law made me do it" is a particularly weak excuse.
DNS spoofing by an ISP a clear violation of the law? Since when?
Just because the law makers don't say email doesn't mean they mean to hijack DNS.
If someone asked you to pick up some food for them on the way home, are you doing to bring leftovers from two weeks ago because they didn't specify from where and exactly what they wanted?
Blaming this on the lawmakers doesn't make sense. ISP had a broad way to use "electronic communications" and they chose a HORRIBLE one.
The law doesn't require or even encourage CenturyLink to notify customers in this way so what is the politician responsible for? For writing a bill that wasn't impossible to interpret maliciously?
As users of streaming devices will attest, HTTP is just one part of the internet, so many would consider it to be a matter of not delivering the service that was promised if an ISP blocks access for any reason (other than by request from law enforcement or breach of the service agreement by the customer).
If a cable TV provider were to block all access and put up a message on an obscure channel that someone might never see explaining how to re-enable the service, I think it's reasonable to assume that most customers would call and complain that their cable service isn't working (and they'd be right).
It shouldn't matter if someone can use a specific type of internet-connected device (among many) and open a specific type of application (among many) on that device to communicate over a specific protocol (among many) to re-enable their service. For practical purposes and in the broad context of what "internet access" means, CenturyLink is simply cutting off service to its customers without justifiable reason. Customers should hold them to that and threaten legal action if the company doesn't want to deliver the expected service.
What we need is a separate net neutrality law that bans all DNS hijacking and the like. Furthermore, it costs more for CenturyLink to set up DNS hijacking (unless of course they have bigger plans for it) than to quickly throw out a mass email or slip a note at the bottom of the next bill. So we all know this had nothing to do with compliance with the law.
No. The fault lies with CenturyLink. They're the ones who decided to implement this in the most repulsive way allowed by law.
The law only required notification using normal communications methods, not disruption of services. CenturyLink is the one who chose disruption of services.
For example, they could all wear yellow vests and block the entrance to the CenturyLink parking lot.
If a consumer is abused by their vendor and continues to fund their abuser, who should be blamed? Obviously the abuser is to blame for the abuse. But shouldn't the person funding the abuser also get some blame? Or is it all the government's fault? Blame the police.
It seems to be a common response to consumer abuse to blame the government while continuing to fund the abuser. That strategy has made Wells Fargo number one. And Century Link number one. And Facebook number one. And the list goes on.
If you can't live without their service for one week, maybe their service isn't so bad. If you're not willing to lift even the smallest finger the smallest amount, just keep belly aching to the wind. That will fix the problem.
> If a consumer is abused by their vendor and continues to fund their abuser, who should be blamed?
If the consumer does not have a reasonable choice in vendor, then the vendor should be blamed. That's kinda the whole point of this thread.
> If you can't live without their service for one week, maybe their service isn't so bad.
That makes no sense. If you can't live without their service for one week, that says nothing about their service, it just means the product is indispensable.
> If you're not willing to lift even the smallest finger the smallest amount, just keep belly aching to the wind. That will fix the problem.
What choice do people have? If there's no alternative ISP you can use, or if the only alternative is just as bad as what you already have, then there's very little you can do except complain.
Fine. Let's define 5 options as the bare minimum to inspire healthy competition. Now we can decisively say that they don't have that many options, with no squishy words.
Their customers can't do that without incurring ridiculous early termination fees. And many of them don't have any other option for broadband anyway.
Further, I suspect boycotts very rarely work even against companies that aren't quasi-monopolies.
Second, most of them do have other options for broadband and in fact use an alternative provider every day.
Third, well organized boycotts commonly work well. Even a 10% drop in revenue really gets the attention.
Are you sure? I don't know anything at all about the market in that part of Utah, but I do know that in almost every place I've lived, there has been exactly one broadband ISP available. If you don't want to use them, then you don't get broadband.
I can imagine being an engineer in a room of lawyers and having them ask me how can I ensure that all customers see the message. I would say that's not possible, but there are ways to maximize the likelihood it will be seen.
Now, shady DNS spoofing may be one means of complying with the law (though it may violate others), but it was CenturyLink that chose this non-standard approach. They could instead have complied by sending an email, a physical letter, a messenger physically knocking on a customer's door etc., a flier hung on the doorknob, etc.
The intent of the law is clear: customers should be notified that this content exists. The implementation language reflects that. CenturyLink is simply covering its ass: many people don't use ISP-provided email addresses, so if that's all they did they would be open to criticism that they are not actually trying to achieve effective notice.
No it isn't. Though DNS hijacking is certainly compatible with the text of this law, so is email communication. Century Link isn't stupid.
What? That's a ridiculous conclusion to come to.
It's clear what the end goal of the law is, and gives several broad, reasonable ways to comply with the law. Century link is the ISP/tech experts here - they are the morons who chose to do DNS hihacking when they could have just as easily sent out an email or added a notice to the bill for the month.
The cookie banners are probably a bad example: they were made to take advantage of a loophole in the first "cookie law".
I think the intention of the first cookie law was clear as well, it just wasn't clear enough.
Laws are not source code and they assume some level of good faith interpretation because most real-world activities are complicated and change over time. If “email” was written into the law then we'd get some equally silly complaint about how they're using a system favored by old people while younger users want SMS, Twitter, Facebook, etc. notifications or that an important notice was spam-filtered. Stating “electronic communications” leaves those options open so time doesn't need to be spent revising the law later.
this law says you have to notify customers of a thing. century link then did so in a shady way, then claimed the law REQUIRED them to do it this way, which is not true.
why am I having to explain this?
If the law was written to specify e-mail, then the HN crowd would be all over the lawmaker anyway for specifying an antiquated communication method that not everyone uses.
Since laws last generations, and technologies fall in and out of favor at the drop of a hat, the lawmaker was right in making this non-specific.
It's the ISP that decided to be a jerk about it.
So, if there’s a drafting error, it may not technically be the politician’s fault, but it’s not Comcast’s either.
I'm sorry, what kind of ethical nonsense is that? "Bad behavior is OK as long as some authority didn't expressly disallow it" ???
CenturyLink is simply a bad actor here. They're acting in an anti-customer and anti-consumer way. Sure, we should have regulations to prevent abuse where appropriate, but you certainly can't blame the government for failing to imagine how they'd behave when faced with (let's be honest here) a bleedingly obvious and common sense notification requirement.
Attempting to email my state senators to express a political opinion? Freedom of speech: Blocked.
Buying from a company online, located in another state? Interstate commerce: Blocked.
Trying to run an online business? Blocked.
Trying to contact my kids? Blocked.
My elderly grandmother is dying and family was trying to Skype me in since I couldn't make it? Blocked.
The number of constitutional laws, federal laws, and moral laws broken here is mindbogglingly astronomical.
Good luck, CenturyLink.
Not every question on the internet is a thinly veiled attempt to make a statement!
;-)
You can also get Internet access through other means, even if it's less convenient and/or more expensive. There might be a government-sanctioned monopoly on cable, but at least around here, there's also DSL, satellite, cellular data, dial-up, and even third-party fiber. Granted, not every place has all those options, but you'd be hard-pressed to find a place in the US where you can't access at least one.
CenturyLink is a Tier 1 ISP, and 5th largest in the country by customer count. Maybe city folk haven't heard of CenturyLink but they have monopolies over vast swathes of rural copper networks.
The Level(3) name was much more memorable in the carrier/enterprise/ISP field and it feels like they are starting from scratch on brand recognition, because as you said, lots of people haven't heard of Centurylink before.
Edit: And as noted by the thread "CenturyLink is totally shady.", Centurylink's retail consumer reputation is quite tarnished (as are most large consumer ISP companies) and mixing that reputation with Level(3) was a bad decision, IMO.
On the business side, it has quite a bit of premium name recognition which seems to be getting thrown away from the way they are being swallowed up.
They have huge brand recognition in the West, though you're right, little of it's positive. I remember a cover article in my sleepy mountain town's alt/leftist newspaper titled 'Qworst' when I was growing up.
Full disclosure I work at a shop that switched to CL fiber (e.g. Layer3) per my recommendation on coming on. The service quality/uptime is top-notch but the sales/PM process has left a lot to be desired.
I also work for a shop that I recommended Level(3) DIA fiber/Layer 3 services on about 1.5 years ago. Now that it's CL, not much has changed on service or reliability.
The sales people however are still trying to expand their grasp into our organization so it's always a battle there.
In the end I configured my (pfSense) router to forward all data on port 80 (and a small selection of other commonly unencrypted ports) through a VPN to a local VPS. Port 443 HTTPS is still allowed to connect directly.
Makes me feel a lot better. Comcast should be a dumb pipe, not fucking with my data.
What router do you have? Is it just something running OpenWRT, or something fancier? Also, how much do you pay beyond the listed service price (fees, taxes, etc), and can you waive the installation fee?
When I signed up there was no installtion fee, and no problem doing a self-install. But this was years so, so I have no idea if things have changed or not.
I might have to pick one up and see if I can get more SATA through the mini PCIe and have to be a storage server that also routes traffic. I've been hoping for an ARM chip, but with ECC, this might just win out.
Turns out to get rid of that, I just had to call them and complain about it; they pretended to be surprised and asked me for details, but after the phone call the injection stopped. Worked for other people too.
This won't work with DNSSEC or encrypted DNS though.
Encrypted DNS, though, like DoH or DNS-over-TLS or DNSCrypt, stops this cold.
This is a small reason why NET neutrality is important. Total BS. I'll never use CenturyLink. I've thought about it in the past, but after this, H no.
In order to reach the Internet, you have to agree to the hotel's terms of service. The page to accept the terms of service is presented by redirecting any HTTP request from an unauthorized device. But (!) the redirect page was resolved by DNS, and DNS traffic to the Internet is also blocked. Only the local DNS resolver is accessible.
The instant any machine that specifies a specific DNS resolver tries to connect, the attempted redirect fails silently. In order to get things working, you have to clear your DNS settings to use the DHCP-specified DNS resolver, click the "accept" button on the redirect page, and then re-enter your previous DNS settings.
I wasn't so much angry that this was happening, than angry that they did such a ham-handed, botched job of it. If you're going to block outside DNS, you have to redirect to an IP address rather than a DNS-resolved address.
Therefore, when Utah surprised CenturyLink with a new law, they didn't have a way to comply with the law quickly except by changing their packet processing rules. This was the ugly result.
CenturyLink should obviously have some way to add state-specific notifications to customers' bills. I hope they learn that lesson from this ridiculous event.
On my CenturyLink bill in Washington State, I get state- and city-specific notices every month, but even if that's not easily changed, a piece of paper in the mail would have sufficed quite nicely with no packet blocking required at all.
If only there was some relevant piece of data, already required to ensure the bill reaches it's destination, that could help them determine which customers are in which states.
They know billing addresses, and service addresses. They just didn't care.
Same with many hotels. If you are not even using HTTP(S), or DNS, then it won't work, and even if you are using HTTP but not with a web browser program, it won't work (there is a HTTP response code (511) defined for this purpose at least), using nonstandard port numbers, etc.
For terms of service requirements, one possibility to avoid these problem is to make the printed terms of service document with the wi-fi password mentioned in that document.
Imagine waking up in the middle of the night with a need to call 911, but your ISP purposely broke your internet just to sell you a “security offering.”
I have been noticing comments from people in my area on social media over the last month with the recurring theme "Is anyone else's CenturyLink down?" This must have been it.
Finding good VPN provider is tricky though. Definitely avoid free ones. Look for ones providing configuration for native VPN clients, like profile.mobileconfig file for the native iOS / MacOS IKEv2 client. Using native (OS supplied) clients lets you avoid installing third party VPN apps.
+ trusted vpn
- unique IP that only you use, bad for tracking. Your searches and browsing history is linked easily to you.
It should not be necessary for a consumer end user (whether residential or business) of an ISP in the US or Canada to treat their ISP as hostile, and develop workarounds like VPN tunneling their traffic, such as I would do if I found myself using an ISP in Turkey for a month.
This bullshit of injecting content into pages has been tried before, a long time ago by Comcast. I really don't see the point to it in an era of LetsEncrypt and nearly everything worthwhile moving to TLS1.2 or better end-to-end.
https://arstechnica.com/tech-policy/2009/08/comcasts-dns-red...
Also you absolutely should not mess with DNS returns from your client-facing recursive resolvers. Various ISPs have tried things like redirecting nonexist results to pages laden with "suggestions" and "advertising".
VPNs are a stopgap. The future is end-to-end encrypted protocols like QUIC that obscure even connection state information and prevent anything from being modified in transit at all, DNS over HTTPS, etc. Everything has to be encrypted and authenticated end-to-end.
If we develop software with end-to-end crypto to deal with repressive-regime threat models, its crypto should also be inherently sufficient to deal with more normal traffic interception and modification attempts.
A lot of non democratic regimes in places outside of North America take a very blunt approach, of having government agencies order all of their domestic ISPs to simply null route huge chunks of the Internet (like, entire ipv6 /16s belonging to Azure and AWS) in order to ban politically objectionable sites. Or to order all ISPs to be singlehomed to, and downstream of the government state run telecom. There is one ASN in Iran which is allowed to have international IP transit connectivity to other non-Iranian ASes, for instance.
If you have a device with wifi, most of the time you are on untrusted networks. So, it makes no sense whatsoever to default to some random isp's DNS just because the wifi you are on is suggesting that you use it.
https://en.wikipedia.org/wiki/Joseph_Nacchio
https://www.bizjournals.com/denver/news/2015/04/29/joe-nacch...
This isn't really enough. Even with QUIC / TLS your ISP can still know what endpoint you're connecting to, which may in itself be too bad. This is the problem VPNs are solving (or at least moving the trust). There's also the touted alternative of conglomerate everything onto Cloudflare and have encrypted SNI.
Being seen to be using a VPN only labels you as a VPN user. In China, the authorities dislike individual VPN use, and attempt to curb it with technical measures, but for the most part, they don't go around imprisoning people only for VPN use, because there isn't much expected gain to be had from the average VPN user.
On Sprint and ATT Mobility I cannot maintain many TCP connections for long durations - websockets will be killed after a while and require reconnection, long-connected TCP games will drop after a few minutes, quite a handful of HTTPS/TLS sites do not load and immediately hardfail with a TLS protocol error or connection reset, traffic appears modified and periodically injected, DNS is hijacked, images' hash values do not match the server side on plaintext connections, NXDOMAIN DNS values are hijacked, traffic crossing any port will be tampered with as long as it looks like HTTP/1.x, etc.
To answer your direct question: So far pinning in browsers is still just TOFU [Trust on First Use], I think? So pinning alone still works with TLS Interception so long as it is intercepted on Day One.
The Chrome security team has been threatening for a couple versions now that certain pinned lists, including (but not limited to) Google's own sites, would be baked into the browser in such a way that no one should be able to disable them.
I wish they have the gumption to pull that off. With Chrome being the current darling browser of a lot of the same IT groups using TLS Interception, that might actually send a clear message that TLS Interception is a bad idea. Unfortunately, it might just be received as "Here's Google's list of sites that have to be whitelisted or outright blocked from our Interception Proxies so as not to confuse our users", but that would still be a step in the right direction in so far as end-to-end internet security.
It's unfortunate that I have to treat my ISP as hostile, but they are the only high speed provider to my address. I sadly can't even assume that there is anyone in management there that feels ashamed at their hostile practices. It's just "good business" to squeeze free ad dollars from your users as you take advantage of your monopoly position to keep prices as high as the market will bear while doing so.
[0] Even if I didn't prefer Bing, hijacking any of the major search engines just because it might be an "accidental default" and "no one would notice" is just wrong on so many levels.
[1] Scare quotes because it was 90% terrible ads and 10% barely legible search results from who knows what API.
We need strong Regulatory Commissions to hold these sorts of Monopolists accountable, and right now the political climate in states like mine remains that "Regulations are Bad" and "Profit/Greed are Good".
Annoying and pointless conversation. I just cancelled.
https://www.geek.com/news/belkin-routers-misdirect-users-to-...
It should not be, I agree, but the sad fact is that if the ISP is one of the heavy-hitters, then you absolutely have to treat them as a hostile force to be defended against and worked around. Because they are.
Every other business manages to inform customers by e-mail or text message or phone call, but ISPs have these additional options by virtue of the product they provide and they just can't seem to help themselves (at least for the large shitty ones, which they all become eventually).
2. This doesn't meet the requirements of the law. The person using the internet, especially at some arbitrary moment, is not likely the subscriber. The law is that the consumer must be notified, with consumer explicitly defined as the subscriber. Email to the address on record, or an insert in a mailed invoice, or a special mailing, seem the only reasonable ways to meet the requirements of the law.
So there are two problems at play here:
- Laws are technically ambiguous
- CenturyLink and most other large ISPs are awful, incompetent companies
or perhaps a local resolver?
"displaying popup and clicking OK to dismiss" is not as harmful as blocking the internet.
They control all the traffic anyway...
Seriously? I won't trust such ISP to send/receive even one bit of information if I were him. Even if they changed their mind because of this, Don't trust them until all the boards resigned, all the employees implemented this be fired, lost the massive lawsuit from all the customers, and then, after acquired by other sane ISP.
But I'm going to be interested to hear the first real customer's experiences. For example what is the latency they're seeing? Weather outages? How well does it handle peak hours?
Don't misunderstand, the current ISP competition in much of the US is super toxic, and I don't support it. But 5G promises a whole lot, and I cannot ignore the technical side of why it may fall short.
I think these kind of crappy implementations just surface a bigger problem underneath. If you don't choose your own DNS servers, if you don't have proper DNS security, https by default everywhere etc. etc. you don't have a secure connection.