90s Internet: When 20 hours online triggered an email from my ISP’s president
arstechnica.com
arstechnica.com
Eventually I got a letter from my ISP and it was a thick binder with "netiquette". How to behave online. And a letter saying basically "we see everything you're doing, cut it out". They probably had complaints on the abuse address of my home IP, since I was a total moron.
I grew up in a supremely rural area. We were not at all wealthy but still one of the few households that could even afford a computer. The computer came with a modem and I wanted to use it to connect to the world. The problem was that every phone call beyond a 1-mile radius or so counted as "long distance," so calling virtually anywhere cost a certain fixed rate per minute. We experimented with CompuServe and Prodigy at various points but the long distance charges alone made it not worthwhile.
I eventually got to learning how physical phone lines worked and figured out that the same telephone box next to the road served both my house and the payphone for the store nearby. Long story short, I bridged the payphone's line to an unused pair at my house and started calling BBSes around the nation that way. I was always careful not to use it during the day, when someone might actually need to use the payphone.
Of course, it only took a couple of months for the phone company to figure out something was amiss. They undid my handiwork and put a lock and seal on the box. They COULD have charged my parents with theft of service or at least delivered a stern warning but evidently they did not or I certainly would have gotten an earful over it.
About a year later, the phone company brought in local dial-up Internet to the town.
Footnote: I found a list of toll-free BBSes somewhere and there were HUNDREDS of numbers listed. I tried them all. Only maybe a dozen were actually free BBSes that you could create an account and log into, the rest were either dead, fax machines, or systems for some specific purpose. Aside from one fairly popular message board that eventually got shut down, it turns out there wasn't much to do on any of them.
Instead of going a couple weeks without a phone line, my dad went to the phone box and rerouted our old condo's line to the new one.
Some weeks later when the old condo had a new tenant move in a tech came to our door to ask wtf was going on. He was like "the people who used to live there have been unknowingly paying for your phone service. You're stealing"
Yeah, they (we) don't mind, lol.
This is how it worked in the UK. Calling anywhere cost per min and I racked up HUGE phone bills in the early days.
I'd bet dollars to donuts the tech that fixed it knew what you were doing and let it slide unless you came back and broke the lock to do it again.
Or you got lucky and he though someone on their side made the mistake :)
Good times!
I got my first job at a local ISP after the owner busted me for running "John the Ripper" password cracker against his system that I had a shell account on.
As completely careless and reckless as I was, this kind of interest in hacking was my saving graces in terms of employability, because I failed out of highschool and never went to college. I work at a FAANG, miraculously.
I remember hitting a point where there we no more local ISPs who would give us an account, so we’d go to the library and use BO to steal dial up accounts from random companies (always targeting local companies we hated at the time), which we’d keep in a txt file via an IRC fileserv and rotate through. Kept us online until we got better at not getting caught.
Of course all that these days would get you put in prison but back then even when we got caught it was more of a “silly teenagers, don’t do that again or we’ll tell your parents… by the way, can you help fix our printer?”
Love ya, mom. Sorry I was an idiot.
Simpler times of experimentation…
I don't know if the company is still operational, but their website sure is! https://www.eskimo.com
The site that reported me was the owner of hax0r.com (or .org? Cannot remember) and various other stupid vanity domains (used and leased, purposely mind you, for IRC bots and things like that). I think they were just mad because their shell account was passed around IRC like the most popular whore in town.
Bleh, what a boring response from the CEO. It's always interesting to look back and where we were to appreciate how far we've come. Also, there's the nostalgia of 'simple times'.
How boring do you have to be to have run an ISP, have a user contact you 25 years later, and reply with that?
And specifically, why do a job that you apparently cared about that little?
Surprised he didn't take the email as an opportunity to chastise the author about misuse of the email system for frivolous contact.
We were paying for an unlimited connection, and then they tried to tell us that if we wanted to be connected for more than 4 hours/day, we'd have to upgrade to a business account that was like 4x the price. My dad told them to pound sand and we switched ISPs.
Pretty sure between 1995 and 1997, we switched dialup ISPs like 4 times because each tried to tell us we were abusing the "unlimited" access. And then at some point, cable modems came out and the entire thing became moot.
1) The ISP a monthly charge
2) The ISP a per-minute charge (these were things like cix, compuserve, aol, etc)
3) the phone company a per-minute charge
Later we had ISPs that didn't have a per-minute charge (Demon and the like), so it was just the monthly charge and the per minute charge to the phone company. Even later than that ISPs which were just a per-minute charge to the phone company came along. In the late 90s I think the phone company per minute charge was about 4p/minute in the day, so for anyone in the UK that would be about 9p per minute today, or if you ran your modem full pelt, about 36p per Megabyte.
Towards the late 90s you could have a flat fee phone charge, then dsl and cable came along.
2 TB would have taken me nearly 16 years, and cost as much as a house.
I'm in a suburb outside Portland, OR and have Ziply Fiber which sells me symmetrical gigabit with no data cap for like $80/month.
Nowdays we have Aussie Broadband, which has an active tech community on Whirlpool (AU Broadband forums, fondly called Whingepool). Phil Brett as their cofounder made this an incredible company, and he recently left.
I pay $149AUD/month for "1000/50Mbps Unlimited", which I haven't had an email yet for my usage (I use around 4-10tb/month).
I hadn't known about Internode going downhill either. I'm still using them as their support is great. Price-wise looks like they both charge the same. Unfortunately no great connection here, so it ends at $100AUD for 100Mbps on a good day.
Our business is with Superloop 1000/50 ($109, and actually gets 1000Mbps solidly). Used to be with MyRepublic and would get between 300-700Mbps depending on time of day.
At home we just use a cheap provider - Spintel. It seems that for the lower speeds (we're on 50/20) you don't run into CVC issues like you used to.
I also like to think of it as doing my bit against the enshittification of everything. Cheap internet is a race to the bottom and it's not pretty.
But Aussie Broadband looks pretty promising. I like that they are open about CVC issues. Will consider them next time we move.
I'm amazed you throw these ISP names out there that I never heard of before. Probably not doing advertisements and bill boards and stuff. Maybe the internet situation in Australia is not as bleak as I always thought :)
eg:
Choosing an ISP https://forums.whirlpool.net.au/forum/92
RIP Broadband Choice tables: https://bc.whirlpool.net.au/
One afternoon at lunch break at school I went down to the local elections store and used 2 days worth of lunch money to buy a secret RJ9.
After mum went to bed I'd sneak out my cable and dial up, spend all night online and hide it again in the morning.
Well... I ran up a 500 pound bill, I came home from school at the end of that month to a furious mum crying because we certainly couldn't afford it.
Mum called BT and explain what I'd done, and that it was unauthorized use, thank god BT nulled my contraband internet usage but it was a valuable lesson in doing as your parents say.
Really really really greatful freeserv popped up, although they eventually banned me for abusing "unlimited" (then I just got my uncle to create a new account for me).
The insult was followed no less than 3 days later with a similarly large electricity bill for the skip dived fully stacked Sun 1000E and disk array I was running 24/7 as a workstation. Stupid machine - had to sleep with ear plugs in.
When fired from the hospital my mother was very happy I survived everything but she looked also very angry. I was very confused. Only found out later that the phone line was really at a premium and racked up, converted, a 2000 euro bill.
For anyone else that stumbled over that for a second - "fired" is of course synonymous with "discharged". English is a weird language!
"Discharged a gun", "Fired a gun"
But, lots of ISPs made it very easy to get online with accounts paid through the dial-in number, so I didn’t need parent credit cards. Could just dial in and get access.
Then we got a second line as soon as ISPs offered an 0800 freephone number to call and she realized that the tenner a month for the ISP and a tenner for a second line was far cheaper and easier and she’d get internet too.
"Good" ISPs had a 10:1 user:modem ratio. Crappy ISPs had a 13:1 ratio. Get much over 10:1 and you start risking busy signals. We didn't really track user sessions but we'd occasionally hop onto one of the Lucent Portmasters and if someone had an egregiously long session, you might reset their port.
I was logged in all the time from my family home because we had a 2nd phone line leftover from the 1 year my dad had a home business. I ran the line down through some ductwork into my bedroom, and had switch boxes so I could switch which line went into the modem if I had to. From 1995 I had a Slackware Linux box online 24x7 and also (later, I guess) setup ipmasq and an ethernet interface so I could provide internet service to a 2nd computer we got in the late 90s (since, after all, the family computer had been co-opted by me, put in my bedroom, and Linux installed on it.
It was always via modem, we could never get ISDN or DSL until much later (like 2002 later).
A funny anecdote about leaving your modem online in those days. We had 2 phone lines coming into our demarc box, and the ringers of the phones had a strong current draw that required a capacitor (?) in the demarc box be topped up. We started having issues with quiet/silent phone rings on the "voice" line, and the modem dropping at the same time. Turned out having the modem on all the time didn't allow the capacitor to charge up, so when the phones in the house tried to draw a ton of current to ring the ringer bell, you'd basically get no current to anything, and the modem would fall over. Funny how primitive that sounds to describe it. Then again, the phone system wasn't exactly cutting edge in the 90s.
I don’t know what’s wrong with Gene Forney, I can’t imagine why anyone wouldn’t want to reminisce about those times - even if only as a reminder of how far we’ve come since then!
150MB in 95 was a huge amount.
https://en.wikipedia.org/wiki/History_of_Gmail#Internal_deve...
In 2004, 9 years later the idea of 1GB of email was though of as insane
>Advanced search capabilities eventually led to considerations for providing a generous amount of storage space, which in turn opened up the possibility of allowing users to keep their emails forever, rather than having to delete them to stay under a storage limit. After considering alternatives such as 100 MB, the company finally settled upon 1 GB of space, compared to the 2 to 4 MB that was the standard at the time.
So yea, no surprise your host kicked you.
*I realize this is space versus bandwidth, but they do correlate. Your ISP at that time may have only had T1 connectivity
I bet you’re definitely right about my ISP being on a T1. What was bandwidth on those, 1.5 Mbps? I don’t blame them for kicking me off either.
FWIW around that time I was still using a BBS, and that place had a download limit of one 3.5" floppy (1.44 Mb) per day per user.
Not many users....
Yeah, we don't have a copy of the email that was sent to him but the response indicates that he mistook it for some kind of argument. Very strange.
A standing instruction was to, as time allowed, manually look at usage across members and force resets on any long standing connections! Mainly this was because it was a small company and this freed up the number of possible incoming connections to avoid busy signals.
I was very junior and cringe at how naively unaware I was of any ethical considerations!
You can either let the person who stays connected for weeks stick around, or free up space for less frequent users who are also paying customers.
If it comes down to kicking people off, you need to reimburse them for their payment and say 'don't come back' and keep only the 'good' customers, or you need to invest in more phone lines and hope you make the money back.
The solution is not to advertise one thing then appeal to 'but we actually meant this other thing' when it doesn't work out the the way you think it should.
Seems like if you're advertising unlimited service the least you could do is deliver it as much as possible for extreme users and only bump them when they might be denying other customers access to the service.
If it's something that happens routinely you need to expand your capacity to make good on your advertised offering.
There's clearly an incentive to skimp here and resort to underhanded tactics. If you've promised unlimited use to the customer, it's definitely unethical.
It's not an all-or-nothing switch. Obviously the less ethical/more greedy players overcommitted more than others.
The parent clearly explained physical constraints of small dial-up ISP's and their Telco providers.
The early internet and it's ISP's were vastly different than today. It wasn't uncommon for your local city to have several, or dozens of small startup ISP's available. Few, if any, were big enough to just let anyone do whatever they wanted - these were tying up phone lines, a more-or-less physical resource at the time.
I was an intern at a large tech company (rhymes with bun) at the time, and one of my tasks was to reset idle ISDN connections that were eating the capacity of our POPs.
My friend refuses to purchase a broadband connection for the house, because she says she believes that her roommate would violate copyright on a massive scale. She uses her iPhone for everything and has no desktop/notebook. So she keeps her roommate on a dial-up modem line.
And the ISP does become upset when roommate is online for long periods of time or downloads a lot of data or something. Apparently the roommate is into RPGs and forums of whatever kind.
I've encouraged her to give in and get that broadband. Her wireless voice calls are spotty and sometimes I can't understand her. But she's good with the status quo.
In the USA?
Wtf is going on in Arizona? (Or perhaps _not_ going on)
edit: Oh, apparently there's still a handful here? https://www.teltarif.de/internet/by-call/einwahlnummern.html
Is this referring to you, or to your brother? That wording is highly confusing in English. If it were you, it would be "my dad got a call at work because his son was...", and if it was your brother it would be "my dad got a call at work because his other son was..." . You would never say "my dad's son" to refer to yourself.
But the excitement back then was way more than what I feel today, what a crazy period.
Except Comcast and the other shitty ISPs (including mobile carriers) which implement data caps, despite there being no technical reason for it*. At least back in the day there was an actual limit to the number of active simultaneous connections an ISP can handle.
* even for mobile, data caps don't make much sense, as they are monthly and per-user while network congestion is temporary and local. Better sell unlimited data plans with different speeds (priced accordingly), and only apply those speed limits if the local cell becomes congested.
All mobile carriers are offering plans with soft caps, meaning you may be derated to a lower speed after a known amount of data and (usually) there are bandwidth limitations in your area.
The last mile is very local, limited to a single cell, whose size depends on the planned capacity (cells are smaller in cities). Congestion is therefore limited to specific cells. Furthermore, congestion is often very temporary, limited to peak hours or special events. A congestion event could last just minutes.
A global monthly data cap doesn't actually address congestion very well. You can still have a sudden influx of users with available quota overload a cell, meaning they aren't getting the service they paid for as they are getting degraded speeds. On the other hand, someone who used up all their monthly quota is still getting no or degraded service (or is charged overage fees) despite being on a cell with lots of available capacity - in this case both energy and spectrum is wasted because there is an idle cell that's not being used to its full capacity despite there being demand for it.
> soft caps
Soft caps are, at least in some carriers, either non-existent (you get a hard block or are charged insane overage fees) or are throttled to near-unusable speeds. Furthermore, even if soft caps are implemented, they are still global (and reset monthly) as opposed to being limited to congested areas.
The real reason for data caps isn't network congestion but to scare people into paying for more than they really need (which conveniently resets every month, so they can't accumulate their allowance either) and/or charge them huge overage fees if they dare exceed their allowance. If this was purely about congestion control and efficient spectrum usage, there are better ways such as the one I described in my original comment.
Unfortunately in an oligopoly controlled by a handful of equally-mediocre players who have no incentive (nor capability - there is no engineering culture to enable innovation) to compete with each other, there is no feasible way to fix this.
To play devil's advocate,
- With data plans based on minimum speed, there would still be a possibility of service being degraded below the paid-for minimum speed during times of high usage at a cell site. There would have to be an asterisk in the contract to the effect that minimum speeds would only be supplied while possible. And, ideally, some regulatory oversight to ensure sufficient cell site capacity is installed based on the cumulative speed of the plans sold, if that makes sense.
- I wonder, to what degree is the structure of cell phone data plans constrained by regulation and private agreements? IOW, are carriers allowed, under current regulation, to sell minimum-speed plans? How complicated and time-consuming would it be to unwind inter-carrier cell-site-sharing agreements?
I remember arguing with my family as I was trying to play Ultima Online on our 28.8k connection and someone wanted to use the phone. Salt in the wound was when the phone call wasn't urgent but rather just a normal chin-wag with a friend. Was always a thrill to discover if during that sliver of time after school and sports, and before homework and dinner, and nobody was using the phone (and I hadn't used up my current allotment of our shared home PC as well), I could log into UO Sonoma and play for a short but glorious time, and hopefully avoid getting grief-killed as well.
Really fun times and good memories.
My favorite by far is basicISP:
https://www.basicisp.net/About/BasicServices.aspx
This is a time capsule of a website (and company for that matter!) that apparently is still actively maintained!
Worked out well in the end I guess, I met her on irc 25 years ago.
As for me, well, when I was on dialup I had a brutally effective means to keep connection times short: an irate dad yelling "Get off the damn line! I need to use the phone!"
And it wasn't even 56K because our phone lines were crap. I would get about 28K on a good day.
I looked him up recently. He's a big player in SV now.
[0] little demonstration that their Windows domain shouldn't be on the same subnet as their users.
Back Orifice 2000 was a widespread script kiddie Trojan that gave clients a menu of mischievous features like changing people's desktop wallpaper or ejecting their CD tray, and malevolent ones like deleting files or dumping their stored passwords.
I thought I was invincible because I got away with wardialing all through the 90's and tried to keep my hat grey by not pulling any of the malevolent tricks, but boy did I ever hit that "eject CD tray" button every single time I found a BO2k server.
Fortunately for me I answered the phone when they called instead of my parents, and they were content with reminding me it was a TOS violation and letting me off with a warning.
In hindsight it was probably unusually civic-minded of them to run a honeypot and use it to catch kids and just tell them to knock it off if they wanted to keep their dial-up access.
It sort of implies that's not possible, but really? I can't imagine how you could be doing the routing, monitoring the connection, and yet unable to terminate it?
So I suggested him he could exceed the limit through downloading some [i]stuff[/i]. Knowing him, he went overboard and racked up a good bill. Think of someone's earnings of working for half a year, full time, at the minimal wage at the time.
ISP didn't budge but they eventually found a way to upgrade to an unlimited plan and drop the bill for going over. Two happy kids...
It’s not uncommon (even today) for insulation to fail somewhere on the line, which allows for water intrusion and transient shorts.
It remained online as long as I could thanks to a Viacom Internet Gateway, featuring Darko the Setup Wizard. We called it Drunko the wizard just for fun.
No nasty emails because I worked at the ISP. :)
Don't remember if packages were unlimited or not, but phone line definitely wasn't. I still remember how my mother was unhappy with 1200NS phone bill (almost minimal salary at this time frame)
I remember during that time first switching over to cable internet, and how my provider was adamant that you not run a web server, and their tech support would drop you like a hot potato if you mentioned that you used a router. Such a different world.
That was a fun article, thanks for posting!
What was happening is that my script to detect the connection being down was finding that and reconnecting before their system could mark the disconnection. Then my computer would reconnect and they'd never see the original disconnection, and so they'd think we had concurrent sessions and charged us accordingly. I remember them being surprised when they figured out that bug in their stuff. I think it helped that all of the connections came from the same phone number.
There was some software that would use windows API to iterate public chat rooms listbox and collect screen names for later use.
After that list was pretty full and both parents went to work, the magic happened: each dial into AOL allowed 3 attempts at login before it would hang up.
Adding *67 to each AOL dial maybe prevented it from banning the incoming calls?
There were no password rules back then, this software would try the letters and numbers from the screen name along with asdf, love, monkey, etc. If I got lucky, there would be a fresh account or two to use until the owner couldn't login and changed their password.
This worked until I could afford my own connection. It taught me VB6 in the process. Fun times.
If you first connected to another dialup company like Earthlink you could then change AOL's connection settings to TCP/IP instead of dialup which let you go from the AOL sign-in window to completely logged in just in a few seconds. That means you could skip the entire dialup process when having to re-connect to AOL after either getting a successful crack or disconnected from the guest login screen for too many invalid guesses. Later on some guys figured out how to make "winsock crackers" that were actually really fast but would get patched when too many people started using the different methods people were finding.
I wouldn't call that a vulnerability, even if lets you attack passwords 2% faster.
https://www.docdroid.net/1JrYKEd/jacked-readme-2001-pdf
You could install some ISP adware, dial in once, uninstall, and then stay connected 24/7 with no ads or restrictions. That worked for at least a year, until DOCSIS reached our area. 1500/128 kbps was massively better than 26/26 kbps over miles of copper.
Combined with AllAdvantage and a mouse mover bot (custom VB6 named notepad.exe to evade detection), you could "earn" like $8/month via questionable ethics.
The ISP consisted of two PCs running Slackware, a Livingston Portmaster, two dozen Hayes 56K modems and a single T1.
I would have been the person reviewing access logs each morning and would have noticed someone connected for 20 hours that hadn't been sending any traffic.
Yet, I don't recall every having to send such an email. We _may_ have auto-disconnected sessions after a period of time to let other callers connect, but I don't recall.
Encryption was seldom used there for POP3/IMAP/SMTP because hey you're on the same ISP network and not crossing the Internet. Further it was pretty easy to hop on a terminal server like a Portmaster and do a debug/packet dump of individual dialup connections if somebody really wanted to see what somebody was doing.
Like when you could register restricted AOL/AIM names by simplying changing <input name="screen_name" value="restricted_name_here"> in the form's code before submitting.
Anyone that accidentally dialed into a "long-distance" ISP or AOL number found this out the hard way.