IRC log of #maemo for Monday, 2016-11-28

totalizatorhi guys, I'm looking for a cheapest possible e-ink pc display - any ideas?00:35
totalizatorand this a33 tablet - gosh - like I haven't spent too much this month already00:36
Wizzuptotalizator: they're like 50 euro or so00:37
totalizatorthe tablets?00:38
KotCzarnytotalizator: i think i saw allwinner tablets with eink displays, might be interesting i fyou plan on anything other than android08:13
warfareGreat, we're hit by a kernel bug.
KotCzarny3.16 seems old?10:22
warfareApparently this is still present in 4.8.10..10:22
warfare"igb 0000:02:00.1 eth1: Reset adapter"10:23
*** N-Mi_ has joined #maemo11:58
warfareSorry, more maintenance going on..19:59
siceloon which resources?20:03
warfareI'll post a detailed writeup to the whole fuckup with hardware when it is solved. Please be patient with us, our servers don't seem to love us at the moment.20:14
sicelothanks for the work20:20
warfareIt's even harder when there are 8kgs of tomcat requiring cuddles on your desk..20:24
warfareI think everything should work now. I'll post a complete post-mortem later.20:25
DocScrutinizer05I hope you all deactivated TR-069 in your routers21:38
DocScrutinizer05 what a terribly broken-by-design concept22:00
L29Ahwhat's wrong with tr69?22:00
* L29Ah is a proud implementer of this xml shit22:01
DocScrutinizer05remote administration without any individual control22:01
L29Ahthere's individual control: cpe tells the server its id22:01
DocScrutinizer05HAHA yeah22:02
DocScrutinizer05like phones tell BTS their ID22:02
L29Ahwhat's wrong?22:02
DocScrutinizer05the idea that the server/BTS is trusted22:02
L29Ahoh, this thing22:02
L29Ahyes, tr069 means the cpe is owned by your isp22:02
DocScrutinizer05or your friendly hacker22:03
L29Ahit's not inherently mitm'able22:03
DocScrutinizer05not inherently but *very* prone22:03
L29Ahjust like any other http22:03
L29Ahhttps, even22:04
DocScrutinizer05just nobody within a sane mind dares to remote-admin stuff at such pathetic authentication level22:04
L29Ahit may be configured by dumbasses, i agree22:04
DocScrutinizer05and obviously the implementations are buggy like hell22:05
DocScrutinizer05900k pwned devices, in TELEKOM alone22:06
DocScrutinizer05thank you TR-06922:06
L29Ahyou're talling it like there are better alternative22:06
L29Ahs/are/is a/22:06
infobotL29Ah meant: you're talling it like there is a better alternative22:06
DocScrutinizer05the whole thing is basically useless22:07
L29Ahyour grandma doesn't know shit about network configuration, what would she do if her isp must change some intricate details of the communication channel?22:07
L29Ahlike the vpn solution they love to use due to the cheapness of dumb ethernet switches22:08
L29Ahand i guess dsl stuff has a lot config of it's own, never touched it22:08
L29Ahalso docsis shit22:09
L29Ahnot everyone is lucky enough to have ip over ethernet these days22:09
DocScrutinizer05there were DSL routers (and even [USB-]modems) *before* invention of TR-069, and that worked and still works22:15
DocScrutinizer05TR-069 is absolutely optional, just for convenience of the ISP22:16
DocScrutinizer05I deactivate it whenever possible, not only on my devices but also whenever I do service for others22:18
L29Ahconfig files are absolutely optional, just for convenience of the admin22:20
L29Ahi disable them whenever possible and write my configuration in the source code22:21
DocScrutinizer05I bet you'd better do that, since *I* am YOUR ADMIN22:27
* DocScrutinizer05 magically changes L29Ah's IRC client's config files, with immediate effect on the client executable's behavior22:27
L29Ahi'm not your grandma :P22:28
DocScrutinizer05you are22:28
DocScrutinizer05neither me nor my clients are the ISP's bitch22:28
xy2_hey DocScrutinizer0522:28
DocScrutinizer05and honestly nobody should be22:28
DocScrutinizer05there's *absolutely zilch* the ISP needs to configure on *any* DSL router22:29
L29Ahcpes are no big deal22:29
warfareDocScrutinizer05: SIP settings.22:30
L29Ahalso there are isp-owned cpes that sell wifi to other users22:31
L29Ahso you can have a cheaper internet access22:31
L29Ahand they can have wifi virtually everywhere in a city22:31
DocScrutinizer05that's exactly the attack vector how "hackers" get my grandma to pay 1000s of bucks for phone calls she never initiated22:31
L29Ahpeople can steal your credit card and buy stuff with it22:32
L29Ahlet's trash credit cards22:32
L29Ahfuck burglars22:32
DocScrutinizer05no, nobody ever stolen my credit card, and even then they wouldn't have a way to use it since we have PIN for it here22:33
L29Ahdon't worry, there're skimmers for that22:33
DocScrutinizer05no, none I'd not notice22:33
L29Ahppl even modify the internals of atms for that22:34
L29Ahso you won't notice it22:34
DocScrutinizer05ok, POS are immanent threat for skimming but then, I don't care since my CC doesn't get stolen22:34
DocScrutinizer05HAHA here all people can do to ATM is blow then up with gas22:35
L29Ahhave you erased that magnetic strip on your card?22:35
DocScrutinizer05why would I? even if it's getting copied at a ATM I'm not responsible for the fraud22:35
L29Ahsame for isp bullshit22:36
DocScrutinizer05yeah sure, you already have fought that battle against your ISP / SIP provider, right?22:36
DocScrutinizer05and won22:36
L29Ahofc not, i'm not your grandma w/ docsis and tr06922:37
L29Ahi leave this pleasure for ppl who find it more fun than computer networking knowledger :P22:38
DocScrutinizer05you won't convince me TR-069 is something useful, great, needed22:38
L29Ahi haven't planned to do this22:39
DocScrutinizer05not even my grandma needs that crap22:39
L29Ahit's a shitty kludge indeed22:39
DocScrutinizer05>>The session is always started by the device (CPE)...<< is a first but insufficient step to secure TR-069. And the today's (yesterday's) attack seems to have exploited implementation flaws by connecting to CPE port 7547 from extern22:55
DocScrutinizer05why would anybody run a crappy insecurely implemented and buggy service on their frontend device, when such service doesn't provide *any* benefit to them?22:56
DocScrutinizer05*sometimes* when I feel lazy, I connect a new router to DSL with TRY-069 enabled, to get provisioning automatically so I save me all that typing, but then I *always* disable that service since it's no longer needed22:57
warfareThe S in IoT stands for security.22:58
DocScrutinizer05I see ;-P22:59
DocScrutinizer05when ISPs would care about their customers' security at all, they'd ship preconfigured DSL routers instead of running a TR-069 infra22:59
DocScrutinizer05but that costs them a non-recurring-expense 5 bucks more per customer23:00
warfareYou don't want that. Especially not when doing triple-play.23:00
DocScrutinizer05triple-play is a brainfuck anyway in my book23:01
DocScrutinizer05sending digital video over TCP-IP internet over TV cable, go figure!!!23:03
DocScrutinizer05broadcast per definition of the thing and word is a one-to-many transmission, abusing a one-to-one infra for that is a huge idiocy23:04
warfareDocScrutinizer05: That's why dtag is doing multicast for iptv.23:05
DocScrutinizer05I know there's stuff like video on demand etc, but then there's also youtube and flickr and whatnot which don't need any triple-play23:05
DocScrutinizer05I'm quite sure they _need_ multicast to pull of that braindamaged stunt23:06
DocScrutinizer05otherwise for 10 million households you'd need 1 million servers and all of them need their own fat backbone23:07
DocScrutinizer05pull off*23:08
bencohmulticast actually works only for live streams, btw23:11
bencohyou still have the issue for VOD services23:11
DocScrutinizer05...and tbh I don't know a single friend or customer of mine who actually uses that IPTV stuff23:11
bencohDocScrutinizer05: have a look at the french market :)23:11
bencohpretty much everyone sell so-called-triple-play services nowadays23:12
DocScrutinizer05thus I never felt like any of the routers I service or serviced needs TR-05923:12
DocScrutinizer05and nobody called me today complaining that their phone, internet, or TV doesn't work anymore :-))23:13
L29Ahif they don't, isps wouldn't have used it23:15
L29Ahbut in fact they're paying me to implement it for them23:15
L29Ahnot all of them ofc23:16
DocScrutinizer05DTAG/TELEKOM for a long time offered VDSL (50MB) *only* bundled with IPTV and by redoing their calculations you can see they charge you premium for the IPTV stuff even when you don't want it. So for ISPs it's more been a matter of maximizing their margin than anything else, Customer demand had to be created for the product, and it's still low23:19
L29Ahyeah who needs this iptv bullshit when there's youtube and piratebay23:21
L29Ahyour grandma probably23:22
DocScrutinizer05no, my grandma still uses radio frequencies to watch TV23:22
DocScrutinizer05meanwhile DVB-T23:23
DocScrutinizer05she never fell for the "awesome new user experience to watch TV in HDTV"23:23
DocScrutinizer05she couldn't even tell the difference ;-)23:24
DocScrutinizer05otherwise she could use instead of piratebay23:30
DocScrutinizer05no need for IPTV at all23:31
DocScrutinizer05IPTV is just a way to circumvent net neutrality and offer customers (and providers?) premium bandwidth23:33
L29Ahnet neutrality is a joke anyway23:34
DocScrutinizer05read: force them to use23:34
DocScrutinizer05and of course pay for23:36
