Cox Hotspots with Panoramic Wifi
cox.com
cox.com
The security of sharing your service with others is questionable, for starters, and Cox does not have a good security history. Every "reset" of the modem (where they remotely check in on it) will turn off your preferences, and many people have reported disabling this wifi "sharing" only to come back to see it re-enabled.
Cox, or any ISP, having access to your internal network by virtue of having administrative access to your modem / NAT router is problematic. People can be bought or are sometimes evil. People click on links and get compromised. It's better that they stay outside of your home network, where they belong.
Cox rents this modem / router device for $12 a month. That's $144 a year. A high end DOCSIS 3.1 modem would pay for itself in less than a year, plus you can get a NAT router / wifi access point of your choosing, keeping the function of the two devices separate. This means that if you want to upgrade wifi later, you're not paying to replace everything. Or if there's a security issue that the vendor isn't going to fix, or is in hardware, like the Intel Puma chipsets, you're only replacing one of the devices.
This is true of all ISPs, really.
You’re going to need: A new modem A new router
You’ll need to talk to Cox and give them the HFC ID and Serial number.
Then, you’ll need to connect everything, and configure your router so that it’s secure.
That’s a nebulous word, ‘secure,’ because my security might be different than yours, but you’ll want to make sure the router is locked down so outside attacks are avoided, and the neighborhood isn’t using your services.
So, take that in consideration.
What are some key settings you would recommend to prevent these exact things? It's a bit challenging to grok all of the advanced router settings, and I don't think mine comes with "locked down against outside attacks" presets.
https://www.cox.com/residential/support/cox-certified-cable-...
I had a bit of an issue with such a modem. It took a couple of support chats calls to get it going but it's been fine ever since. I did seem to be related to the MAC, but the expectation was that it should have just worked.
I’m not sharing your reservations on security or sharing your personal bandwidth. But I do share your concern over cox handling security. Ha.
Are you aware of project like Althea or Helium. Or libreMesh if you want to weed out the blockchain aspect.
Anyway, I was surprised how those stack seems ready to “disrupt the last mile delivery of bandwidth/broadband.” (Sorry for the use of “disrupt” )
Found one: https://msol.io/blog/tech/how-i-doubled-my-internet-speed-wi...
The more annoying part is if your cell service is with Xfinity Mobile - their sim makes your iPhone automatically join Xfinity public hotspots, and there seems to be no way to turn it permanently of. It comes back on periodically.
The performance on these hotspots is terrible.
It's actually even worse if you work in the ISP industry and see how the sausage is made.
Nobody cares as we have optical fiber in most of the places.
Main problem: when you're in a public transport in the city and your phone tries to associate with the random access point it can hear, leading to a potential disconnection as you're too fast anyway.
Interestingly Spectrum had two authentication mediums, you had a SpectrumWiFi open SSID (which they advertise on a map: https://www.spectrum.com/internet/wifi-access-points) and a SpectrumWiFi Plus which is not open and requires a mobile profile to authenticate. More info here: https://www.spectrum.net/support/internet/spectrum-wifi/
Highly recommend you try to find profile-authenticated alternatives if you ever find yourself needing a hotspot in the wild.
In France, Free has been doing this for years although I don’t remember if it was something you could disable because IIRC it was a big chunk of their mobile cell operator strategy, that they had fallback to Wi-Fi hotspots all over cities like Paris, Lyon, Marseille, etc.
https://forum.openwrt.org/t/askey-rac2v1k-rt4230w-rev6-suppo...
It's a feature on their residential modems. Therefore, the coverage is only there where they have residential subscribers.
Virgin's thing never seems to work though.
> The Cox Hotspots data stream does not impact your home network data stream, so it will not impact your household's data usage or speeds. The usage and activities of guest users are associated with the guests’ accounts and therefore do not impact you.
A few months ago I thought of the following crazy idea, which I dismissed after realizing it probably wouldn't scale too well. Maybe I'm wrong and it's worth pursuing (obviously for free).
Here's how it would work. Is this a good idea?
- A connection request broker functions as a central hub
- Nice users configure their ISP access credentials in a small Win32/Linux/macOS daemon that connects to the hub and idles waiting for connection requests
- At some point a wild device wants to connect to an ISP-provided Wi-Fi hotspot, and starts a companion app
- The app a) initiates a Wi-Fi connection to the network in question, which should result in a captive Wi-Fi situation requiring a login, b) opens a TCP connection to the captive login server, and c) sends a connection request to the broker over a pre-existing cellular link, providing a reference/handle to the opened TCP connection.
- The broker selects a random daemon then sends a connection request event to the selected daemon. The resulting handshake provides the daemon with a handle to the TCP socket the app opened.
- The broker now functions as an intermediary, passing raw TCP packets back and forth between the daemon's socket handle and the TCP connection opened by the app.
- The daemon is now able to reach through the just-in-time proxy connection that has been established to perform whatever ISP-specific magic is needed to get past the Wi-Fi captive login page.
- ___IF___ your ISP uses HTTPS for its Wi-Fi login, the daemon will thusly be able to send your ISP login credentials directly through an encrypted tunnel (the HTTPS link) without even a malicious app user ever being able to access your password.
IMHO the connection broker should definitely marshal requests between apps and daemons, so malicious app users can't get daemon IP addresses (which would only work out badly).
In any case, for something like this to work out scalably, people would need reassurance that the risks are low and the benefits are high.
And the main problem, at the end of the day, is that you're all but running a Tor node if you do this. :/
You probably wouldn't add this to the Raspberry Pi you've already got running at Grandma's house for whatever reason, because it's simply too open-ended.
But before even that, there's the problem of network effects: this would only work if thousands of users provided ISP access credentials, either via the daemon approach or by simply providing their ISP access credentials to the central hub directly (!).
Maybe there are people out there that would be willing to do this though...?
Technically this is sadly (lol) one of my better ideas, but practically it's.... just a tiny bit... ._.
---
For completeness, Telstra in Australia also provide a pretty much identical feature called Telstra Air. You select the special modem option, it creates a Telstra Air hotspot, your account gets the "can access Telstra Air on others' hotspots" flag enabled. Telstra Air access points also hide inside specially marked payphones (https://www.google.com/search?q=telstra+air+payphone&tbm=isc... - the top is pink and/or has a Wi-Fi symbol on top).
On the OP page, there's a similar question:
> Is there a limit to the number of devices that can connect to Cox Hotspots at one time?
> Cox Hotspots is limited to five devices simultaneously connected so that users can enjoy a better experience.
FWIW, as per https://crowdsupport.telstra.com.au/t5/broadband-nbn/telstra...,
> only a maximum of 3 devices can connect to the Telstra Air Network in Australia at any given time.
(That is so poorly worded :D - sounds like it's applying to the entire nationwide network lol)