>and it’s on secure networks
No it’s not, my home networks are behind strong firewalls and things like pie hole. Do you not see the problem with all of my families devices “preferring” a neighbors network over mine?
I have T-Mobile. T-Mobile maintains agreements for Passpoint networks at random places like airports, T-Mobile stores, or (I recently found out) Home Depot. These networks are encrypted and authorized against a RADIUS server.
My SIM has them programmed into it. I can't just stand up the "t-mobile" or "Passpoint Secure" SSID from my home network and my phone automatically connects to it. That's not how it works.
Based on the fact that your devices are showing preference, I'm gonna take a wild guess and say you have Xfinity/Spectrum/Optimum Mobile. The cable co. MVNOs maintain their own WiFi networks which are (again) connected to via Passpoint and authorized using RADIUS. However, the cable company WiFi networks extend far into neighborhoods and are broadcast from CPEs. Your devices prefer them because that's part of the network you signed up for.
Just VPN back to your home network if you're not confident in their security.
I’m sorry but wtf?
You’re saying that, in my own home, I should just accept that my devices connect to an external wifi against my will and VPN back into my own home… while in my home?
Seriously?
Yes. You signed up for a cable provider mobile service. A huge part of their whole value proposition for their service is "get access to millions of cable WiFi hotspots!" That's their product. They plaster it everywhere in all their ads.
Your situation with Pi-hole and firewalls etc. is a niche use case. Their service is made to appeal to people who are 1) cable company customers and 2) want cheaper service. The majority of people who fall into those categories have an Xfinity router at home that broadcasts the Passpoint SSID. The phones connect to that SSID and have service. Passpoint is going to be more secure than any WPA2/3 network anyway.
If you don't want that to happen, then get a different mobile provider. This one is not for you.
Absolutely no where did I consent to have my devices (yes, my owned devices not leased/payment planned) suddenly lock me out of basic networking settings.
This is almost as stupid as buying a Walmart keyboard and finding out plugging it in disables eth0 because you might load Amazon.
Xfinity customers using xfinity wifi on their android device NEVER experience conflict from dancing between AP with xfinitywifi in their home or from their neighbors unless they explicitly connect to adjacent networks and if they do so they can correct the issue by long pressing on the undesired AP name and selecting "forget".
Nobody cares what a company thinks they signed up for. They give essentially two shits. They pay tech companies to solve their problems and expect solutions that work. The situation as described doesn't work for normal network conditions and equipment. The fact that it also breaks niche stuff that techies like is just diarrhea icing on a shit cake.
Why can I grant fine-grained access to my photos, location etc., but not just outright denying network access to an app that works offline, which would make all of the other concerns mostly moot?
No I didn’t. I bought cell service, they advertise that they also offer hotspots but all the carriers do that.
Nowhere did I sign up for unauthorized modifications of my owned devices wifi stack.
I did build my own network, and my ability to connect to it was forcibly overridden with no way to opt out.
That is entirely the point.
Edit: rulebreaking removed.
Their job is to get my phone on a 3GPP network, and (already a stretch) to possibly offer a reasonable default of autoconnecting to secure Wi-Fi networks that can alleviate mobile network load in crowded locations, but never in preference over my home network, and never ever without a way to opt out of all of it.
This bullshit is exactly why Stallman was right.
If I make a decision, the device should obey me and no one else.
You've got no consent whatsoever to overrule the user's decision.
There's obviously limits to this, and in fact network traffic management is commonly agreed to be one of them. You can't tell your iPhone to blast on the channel of an operator you have no contractual agreement with.
The same goes for Wi-Fi on 5 GHz: You get to use these frequencies, but by law, device manufacturers are required to implement an algorithm that gives the primary user (weather radars important to aviation safety) priority. Patching out that algorithm could actually cost lives.
Where exactly your freedom ends, and that of the general public begins, is a fascinating and important conversation: Should you be allowed to skew your 802.11 or TCP implementation's congestion management algorithms to get priority for the data you send, for example? (All it takes is changing the multiplicative decrease factor up, or the random waiting time after a collision down a bit!)
What's the boundary of where your device ends: The baseband? The 802.11 hardware radio? The kernel, running your 802.11 soft-PHY driver? Userspace? I don't think it's a purely technical question with an easy technical answer.
Personally, I'm fine with my phone coming with a default setup to trust my operator's Wi-Fi networks, but only if the device vendor can absolutely make sure that my home network will be preferred, and in any case with a clear opt-out switch.
Why shouldn't I?
Sure, if I do so, I'll end up with a massive fine from the BNetzA, FCC, or equivalent local authority, but that's still my problem. I agree that freedoms are limited, but you can't enforce social restrictions with technological solutions.
The device should obey me, nothing else. I'm not going to accept devices becoming ever more locked down.
And it's not like it helps, either – I can just as well take an SDR and do the very same myself without any restrictions.
> The baseband? The 802.11 hardware radio? The kernel, running your 802.11 soft-PHY driver? Userspace?
Kernel, drivers, userspace have to be 100% under control of the users. Ideally, hardware should also be entirely under control of the user.
It's already so much work to custom patch the firmware on my cameras to e.g. allow using certain file formats without requiring the storage medium to have been certified by the manufacturer.
I'm already transplanting ICs from the manufacturer's original toner cartridges for my printer to circumvent the shitty DRM brother now introduced as well.
I've already got to use custom devices to strip HDCP so I can watch movies on my PC. My secondary monitor is a really high quality one from 2004 which is still better than many today, if I was bound by some shitty limitations I'd have to turn this into e-waste.
I’m already building customized kernel drivers for some of my WiFi cards because the official ones apply US channel restrictions even outside of the US, which means I've got less spectrum available than I should have.
I want this to be reduced, not increased. I want to move into a future where I need to make less such changes and devices obey me without question.
- Remote access point doesn't provide access to desired resources
- Have acceptable performance
- Have acceptable security parameters according to users needs
Most users can't stand up a vpn inside their network and configure it to alleviate the self inflicted wound of having their phone decide that the user isn't qualified to select the wifi access points it prefers to connect to. You may as well ask them to grow wings and skip Delta. Instead they will be placing irate calls to their ISP about why their wifi sucks so much and I will be silently cursing Apple.
So you expect the average user to be able to set up a Zeroconf/mDNS-proxying VPN, since that’s the only type that will allow things like Google Cast or AirPrint to still work?
Home networks are not just about security or speed, some people have devices on them they can otherwise not reach.
That isn't what Apple says - https://support.apple.com/en-us/HT202831
At least according to the support doc, the most preferred network should be joined first, other private networks are the next priority, and public networks (including EAP-SIM, the subject of this thread) are the lowest priority.
They can say what they want about “being given the lowest priority”, but but they clearly are competing with my home network and winning some fraction of the time.
If you are walking towards your house and it sees one of these 'sponsored networks' it will autojoin it, when you walk into your house it won't switch. It saw the 'sponsored networks' beacon first.
I‘d hope that the iPhone would at least periodically rescan for higher priority networks.
Great point. Wouldn't that mean it "beacons" to your neighbor when you drive home? Then stays connected as you go inside?
Wifi is tricky, if a momentary loss of your main SSID results in your device hopping to the next-available SSID your phone is basically always at risk of jumping LANs
When your phone is on 5g it is not behind a strong firewall, or any firewall at all. It's sitting directly on the internet. I can run a webserver on my phone and you can browse it.
> Do you not see the problem with all of my families devices “preferring” a neighbors network over mine?
If you've been laboring under the misconception that your phone is safe on your home network then perhaps this is a shock. But having your phone connected to a carrier means the carrier is responsible for providing a network.
Normally your phone is connected both to the carrier network and to whatever wifi network the user prefers, if wifi is available.
It seems like the major usability problem here is that instead of connecting to both networks, the carrier network supplants the user's network -- which breaks expectations when near user-run wifi.
I‘d be surprised if that’s true for most operators.
And even if there really is no stateful firewall: On IPv4 you’ll be behind carrier-grade NAT (so no inbound connections), and on IPv6 (including NAT64/DNS64), successfully guessing somebody‘s IP address seems extremely unlikely. (A server that you’ve visited might "dial you back", though.)
And for most users, the most visible effect will probably be that they can’t connect to their Chromecast, smart speakers, AirPrint etc, not decreased security.
It's true for the operators I've tested so far
> On IPv4 you’ll be behind carrier-grade NAT (so no inbound connections)
Sometimes, but often still not the case.
> on IPv6 (including NAT64/DNS64), successfully guessing somebody‘s IP address seems extremely unlikely
Guessing a specific person's ip is a very different threat model from being hit by a random scan.
The mall had WiFi but there was a portal which required SMS authentication and was time limited (the same as every other hotspot, it was rules of the country), so I didn't bother using it on my phone. Plus the carrier had a modern LTE deployement, where I'd often get over 50mbit download speeds - which was faster than my home internet. The network was named something like "<carrier> offload" so I assumed they had a kind of WiFi deployment to limit cell tower load, and it was added by the carrier settings profile.
I can't remember if I was able to disable or delete the network (it worked, so I didn't care). I'm wondering if this feature has been there for a while, but OPs ISP has only just decided to use it (I imagine some exec had an OKR to increase adoption of their public WiFi hotspots).
Well, we know NOW and it's not ok.