7 ms·
Why I quit this battle
- chris_wot 4y agoWho is this Kevin from DSLReport?
- codr7 4y agoSemi-famous camera guy, read a few of his camera reviews. He seems to know what he's talking about, but is also invested enough to become a potential sell out.
- danachow 4y agoWell from reading the thread on DSLreports he seems quite knowledgeable. The same frankly cannot be said for the badmodems site operator. This guy makes a self deprecating comment (he called himself a moron) and is offended when it is repeated back to him. The comment from kevinds about "grown-ups" was not the most polite comment ever - but really if that was all it took this xymox dude definitely needed a change of scenery - for whatever reason he has ended up with a few screws loose.
- buttocks 4y agoI have participated in the forums of dslreports.com for years and kevinds is one of the more knowledgeable in various areas. The badmodems guy seems to be upset that he is outsmarted, honestly. Thanks to him for the good he has done, but if he can't handle being in a room with others smarter than him, this departure is for the better.
- joebob42 4y agoThe guy comes off as kind of childish and the people on the site he links appear to know what they're talking about which makes me a bit skeptical.
- joshenders 4y agoThe way he discusses performance analysis in his YouTube video also does not inspire great confidence in his technical or analytical abilities I’m sorry to say.
- jolux 4y agoYeah he doesn't seem to understand DHCP or what the difference between a gateway or a modem is.
- BlueTemplar 4y agoYeah, not to mention that the part about > Then,, KevinDS on DSLReports was just a incredible ass to me. It was epic. I believe he also lied to me in PM when i tried to get him to help. I was already unhappy with the future that I was looking at. He then just said nasty things. I was done. Seems to be partially self-inflicted ? xymox1 wrote : > You know morons like me should not use Wireshark.... kevinds responded : > I was thinking more along the lines of, > Morons like you shouldn't be telling the grown-ups how to secure their networks... > Sorry, not sorry.. ;) Now the "grown ups" part is clearly not nice (but then what do you expect when you're starting to lay blame even though you don't know how Internet networking works?), but the "moron" part is clearly mirroring his initial self-deprecating remark, rather than a direct insult. Also, as cramer says : > (If anything, he doesn't understand the magnitude of the windmill he's charging.) ---- Wait until he learns how consumer routers typically have the IPv6 firewall off by default (if any), and there's no (need for) NAT (which has never been supposed to be used for security anyway, and also properly set up IPv6 suffixes are too big to be scanned), so "internal/home" devices are "directly" on the Internet !
- rocqua 4y ago> but the "moron" part is clearly mirroring his initial self-deprecating remark, rather than a direct insult. Mirroring someone's self deprecating remark, adding an insult, and adding "sorry not sorry" is being an ass. Or at least, it takes a lot of familiarity before it is not being an ass.
- that_guy_iain 4y agoThe thing is the site probably would have been more valuable if he kept it up. The domain itself probably isn't as valuable.
- m-p-3 4y agoAt least there's a copy on the Wayback Machine of a good portion of it. https://web.archive.org/web/20211002154145/https://www.badmodems.com/ https://web.archive.org/web/20211002154145/https://www.badmo...
- croutonwagon 4y agoI can understand some of the concern. And while I will admit havent dove too deeply into the minutia how many of these DOCSIS manage modems at scale, after watching his presentation i felt most of that could or should be inferred. For example: I was well aware that you needed to get a MAC address whitelisted and then from there a config, including your speed tier would be pushed. I somewhat assumed DHCP reservations were used for that, on a management network, with TFTP for the config file. It makes sense. This was also solidified by that fact that in most cases during an internet outage, my routers IP would revert back to an RFC1918 address. Ive never used "landline" services from these providers so SIP wouldn't really be in scope but its not surprising that would be on a separate network and there may be some ability there to "sim-ring" calls. Thats standard in a lot of SIP implementations and probably a feature even a home user would want (ie: ring my cell phone and allow it to connect if phones on the modem dont work). Things like redirecting traffic etc would get noticed with a ton of stuff being SSL/TLS encrypted. But i would agree some/a lot of this should be using TLS as well. That said I have never mucked with any of it because. 1. I consider the modem, which i own, to be untrusted and while its inside my DMARC, its outside my security perimeter. Its not directly managed or controlled by me. Anything on it or passing through it should be considered hostile and subject to inspection or filtering. 1a. This is 100% of the reason why i run my own firewall, separately, from a device managed by the ISP and why i avoid AIO style modem/router/firewall devices. 2. I am unsure what mechanisms an ISP may employ to ensure certain things (like upstream/downstream configs) are not tampered with. This could be as simple as a hash check monthly or when billing rolls over to ensure my version is the same as theirs on their servers. Changing that could get be out of bounds with the TOS and canceled, which i have few other options. So its incumbent of me to basically mind my business. I can also see me "unleashing" my speed tier could impact others on my node, which may cause calls from other customers and an investigation shows that theres a sudden over subscription outside of their norms/standards. Again could be considered malicious and cancel my service/blacklist me or the address. WITH that said, i do understand the concern with respect to AIO style devices. But again i would consider anything on the ISP network to be "red" and no different from the relative hostility of the greater internet. But i dont see the concern with DHCP traffic and arp traffic, that seems normal, even on a ISP net, its how devices get online and authenticate and find the next hops on the network. ISP's should do better about segmenting that though, and should probably not provide an AIO solution in general or if they do have one with actual phsyical segementation (ie a box with 2 boards independent of each other connected the same way a modem and router would separately) but I understand why they may want to have simpler setups as well from a customer support standpoint considering the average technical prowess of their userbase.
- jfalcon 4y agoNotes for those pushing forward - the last working wayback machine snapshot before he FFR'ed the website and let the blue smoke out of his fight: http://web.archive.org/web/20211002154145/https://www.badmodems.com/ http://web.archive.org/web/20211002154145/https://www.badmod... --- I feel bad for him. Fighting for good security or even a better product shouldn't cost people years of their lives but as long as it doesn't come at the expense of the product's bottom line, there is little reason to compel change as it doesn't impact the bottom line which is what decides whether something is made for most big corporate outputs. The same argument could be said about "Tech Debt" or non-UL labeled products and a myriad of other causes. Zero fucks will be paid to anything not socially cool even if it is the responsible thing to do. That's why we live in the world we live in now. It doesn't take a rocket scientist to figure out why the world is crap. But for the most part, it takes that "title" just to have a microphone loud enough to move the needle. This little part of life is what I'm currently struggling with in my post-Covid decision making.
- postingposts 4y agoThe optimistic side of me was briefly elated that, perhaps, since all modems had since become good, there were no longer any bad modems! Alas, reality.
- rob_c 4y agoUnfortunately Ive seen a few other FOSS projects go the same way. Troll/bad-actor management is difficult and time consuming and takes a toll. Thanks for all the fish!
- fouc 4y ago"What is the issue?" https://web.archive.org/web/20210506114456/https://badmodems.com/Issue3.htm https://web.archive.org/web/20210506114456/https://badmodems... > Some chip makers have hidden latency and jitter issues from common tests that are in use by consumers and even ISPs. Ping CANNOT be used reliably to test for latency or jitter.
- pdonis 4y agoIt's very frustrating because nowhere on that page is there a list of which modems have the bad chips and which don't. Which doesn't help at all with the most obvious way to fix this problem: stop buying modems with the bad chips. Many people (myself included) don't trust the cable modems our ISPs provide, or don't want to pay a monthly rental on one, when we can just buy one for ourselves. If people like me had information on which modems not to buy, we could help to exert market pressure. Why do people think that the only way to fix a problem like this is to complain to the company that created it in the hope that they'll fix it out of the goodness of their hearts? When has that ever actually worked?
- BlueTemplar 4y agoPreviously, this website had an "Affected Modems" fake-tab, linking to the website forum with a list : https://web.archive.org/web/20210806220209/https://badmodems.com/Forum/app.php/badmodems https://web.archive.org/web/20210806220209/https://badmodems...
- pdonis 4y agoIt looks like at least one other site sees the same problem--and, helpfully, provides information on which modem models have it: https://approvedmodems.org/bad-modems/ https://approvedmodems.org/bad-modems/
- tedunangst 4y agoWhat kind of latency issue is both noticeable and untestable?
- 4y ago
- exikyut 4y agoLast snapshot on Oct 02 2021 before page was changed: https://web.archive.org/web/20211002154145/https://www.badmodems.com/ https://web.archive.org/web/20211002154145/https://www.badmo... The site seems to be focusing on latency/jitter issues: https://web.archive.org/web/20210506114456fw_/https://badmodems.com/Issue3.htm https://web.archive.org/web/20210506114456fw_/https://badmod... I'm not entirely sure what to make of the information presented. The page above includes an embedded video demonstrating a difference between ICMP and TCP load-testing: https://www.youtube.com/watch?v=15cJ400yR_E https://www.youtube.com/watch?v=15cJ400yR_E I'm not knocking that there is interesting data, I'm rather trying to consider potential confounding factors that could call the conclusions being drawn into question. In particular, I have two questions: - This doesn't talk about "bufferbloat" (https://en.wikipedia.org/wiki/Bufferbloat https://en.wikipedia.org/wiki/Bufferbloat) or internal buffering happening inside the modem, only latency/jitter. I'm honestly completely naive about the relationship between the two concepts, but I thought they had reasonable overlap, and could even potentially go some way to explaining the dynamics of what's going on. Why not? - The video seems to just be TCP- and ICMP-pinging 8.8.8.8. Surely that address is sufficiently hammered that it probably implements fairly aggressive rate control algorithms...?
- bsagdiyev 4y agoThis was a pretty well known issue on the Intel Puma chips, it could happen with a small stream of packets being sent at the user, nowhere near saturating their connection.
- javajosh 4y agoMaybe it would help the OP if he imagined that his antagonist was hired to disrupt his efforts, and so by reacting in this way is giving his opponents exactly what they want. This story is evidence of how vulnerable passion projects are to influence.
- BlueTemplar 4y agoPrevious discussion : https://news.ycombinator.com/item?id=15781474 https://news.ycombinator.com/item?id=15781474 > Some chip makers have hidden latency and jitter issues from common tests (badmodems.com) 220 points by based2 on Nov 26, 2017 | hide | past | favorite | 42 comments
- SamPatt 4y agoI don't know the background but the dude seems both passionate but also honest about just being done. Sometimes you're just done. Makes sense to be clear to everyone involved and put it behind you.
- austinshea 4y agoI really appreciate the passion of this person. I truly hope they can feel proud, without any guilt.
- tyingq 4y agoI don't think he's going to be happy, given this: "Badmodems.com is worth something, so, with medical expenses in front of me, its time to cash it in" I think his efforts to publicize the issues with bad modems was worth something to modem users. But there's nothing to cash in.
- fsckboy 4y agoor worse, a player like Intel will buy badmodems.com and reenter the business
- squeaky-clean 4y ago> But there's nothing to cash in. He's selling the domain name
- tyingq 4y agoI would be surprised if that was worth much.
- twblalock 4y agoLooking through the site and the history around it, the level of obsession, the conspiratorial thinking, the grandiose claims of "defeating" Intel -- this guy probably needs help with some mental health issues.
- droopyEyelids 4y agoThe original issue he made this page to deal with was actually _that bad_
- nexus7556 4y agoAgreed. I was plagued by the issues with the puma chipset. I couldn’t figure it out, Comcast was clueless. I eventually found the threads on dslreports, bought a non-puma modem and all the problems instantly went away.
- legalcorrection 4y agoOh I’m sure that Comcast the company knew about a serious issue plaguing a huge percent of their modems. It’s likely they just decided to play dumb so that they didn’t have to do anything about it. A calculation was done and fixing or even acknowledging the issue would have been more expensive. So don’t even tell the front line support people about it.
- ikiris 4y agoComcast will never have to play at dumb.
- 0xbadcafebee 4y agoI'm not sure it was "playing"... they often are actually just dumb. But most likely is that they heard the complaint, created a backlog ticket, and went on with regular feature work.
- 4y ago
- manacit 4y agoI don't know the new context, but I will always be thankful to badmodems.com for highlighting the original Puma 6 issue. I was given a modem by my ISP that had a Puma 6 chipset and it was a nightmare - it would completely cut out multiple times per day, latency was all over the place, and it was a truly terrible experience. Doing a bit of digging I was able to short-circuit a lot of troubleshooting and replace the modem, which immediately solved the problem. It truly was negligent how bad those chipsets work - even for basic tasks it was nearly unusable.
- walrus01 4y agoAs an ISP anything that is a shared access, contended media like a copper coax segment (DOCSIS3) is a nightmare waiting to happen. The amount of problems that are caused by one person with a leaky/bad connector and line, or things that have gone screwed up at the RF modulation level of the cable plant between the cablemodems and the CMTS. Imagine hundreds, or thousands of houses out there all with 25+ year old coax jacks in walls, 4-way splitters jammed into ceilings, leaky outdoor connectors that have been chewed on by squirrels, etc. It's a miracle that DOCSIS3 works at all. I'm vaguely familiar with the issue that the axe-grindy guy in the original webpage referenced here is complaining about, specific to some series of chipsets used by a popular cheap cablemodem for a few years of manufacturing run... But what he's found is actually a tip of an iceberg of terrible about why maintaining last-mile copper last wireline infrastructure (POTS wiring/DSL or coax for cablemodems) is a losing bet in the long run.
- girvo 4y agoCopper needs to die. The Australian NBN is a mess because of it. Sigh, what could've been...
- BlueTemplar 4y agoWell, copper at least has the very nice property of only requiring electricity at the central phone node, and still have working communications. This makes it the best option by far for communication in hour-long blackouts when, for instance, cell phones and cellphone towers would have ran down their batteries.
- Frummy 4y agoI don't know about the work he's been doing or what fight he's been part of. But the text itself seems bitter and psychotic, it's good that he leaves the battle behind and takes a break. I know that too much truth can be tough to handle, but don't singlehandedly try and fix the bad corners of the world. I'm just typing my honest opinion at risk of sounding insensitive, but it truly is great to just let go and move on.
- artifact_44 4y agoI disagree. That text doesn't sound psychotic to me.. bitter, yes.. but I think HN users are all too familiar with being passionate about an issue at the expense of personal time and other pursuits, and I respect that.
- wnoise 4y agoI'll echo the dead commenter. The text is quite bitter, but nothing about seems "psychotic".
- Frummy 4y agoGood angle. I'm just projecting my own experiences. I feel that I have a lot in common with him.
- brigandish 4y agoMe too. Not sure why artifact_44's comment is dead so I vouched for it, I don't see what is gained by throwing around psychiatric terms, used pejoratively, for no good reason (could there be a good reason on HN? I doubt it but I don't see one here).
- Frummy 4y agoSo I think it's wrong of the author to flame other people publicly. I really denounce that. I shouldn't have gone for the jugular, using a word for a real illness. I apologise for that. That was wrong. The reason I wrote that was to convey my feeling that the author is doing something bad, writing an unstructured misspelled text bullying people with allegations that are also not verifiable. I should have thought about what actually bothered me before I commented. "Then,, KevinDS on DSLReports was just a incredible ass to me. It was epic. I believe he also lied to me in PM when i tried to get him to help. I was already unhappy with the future that I was looking at. He then just said nasty things. I was done. It would be a thankless battle I would wage on my own and I was unwilling because of people like him. So KevinDS take a bow. CableLabs loves you, Intel loves you, Arris loves you.. I was a huge thorn in thier side. The Badmodems.com site gets 700 uniqui IPs a day. 380,000 unique since the start. 16 million hits. So KevinDS, you pushed me enough at the right time to end all this. I will NOT spend the next 5 years in a new battle that is thankless and filled with people like you." The content above doesn't belong on the front page, simply put. It's very negative, and I'm sorry that I just continued with the negativity.
- unixhero 4y agoWhy doesn't he instead get s job at a consumer watchdog agency to run these sorts of thing.
- gennarro 4y agoWhat would a domain like that be worth? The lack of the content seems like it would hurt the value considerably.
- k8sToGo 4y agoI am sure some scammer / spammer will buy it.
- throwaway892238 4y ago"Flounce, v. To leave an internet group or thread with exaggerated drama; deleting posts, notifying mods and or group users, and cross-posting on other groups to draw attention to the drama. Comes from the original use of gathering up skirts and petticoats and leaving in dramatic, impatient and exaggerated movements." - https://www.urbandictionary.com/define.php?term=Flounce https://www.urbandictionary.com/define.php?term=Flounce
- Jaruzel 4y agoTIL, I have a history of 'Flouncing'. :)
- janandonly 4y agoSad but true, we need wackos/mentats/obsessed people to help us all, because we don't have the stomach for it. Society progresses, one battle at the time...
- enw 4y agoI'm so confused, what is he on about?
- chaps 4y agoHis experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations. I ended up making a big stink elsewhere and they got the repo down. Funny enough, their heads of security told me they'd use my disclosure to push the execs into building a big bounty program. Long story short, their CISO told me on the phone that what I found wasn't a "bug", and that if they did a bug bounty program, they'd go bankrupt.
- encryptluks2 4y agoComcast is the worst! Seriously, just a terrible company all around. How long ago was this BTW? I think they've had an undisclosed security breach, but this may help prove it.
- chaps 4y agoProbably back in 2016.
- encryptluks2 4y agoAh, thanks but nevermind then. This disclosure would have taken place around November or December of 2021.
- Cthulhu_ 4y ago> if they did a bug bounty program, they'd go bankrupt. I appreciate the honesty! I do think that any company that offers a bug bounty program already has their security in order, to the point where they can no longer find any obvious issues themselves anymore. Not having a bug bounty program implies they don't really trust themselves yet, or haven't reached that level of maturity yet. That probably covers most companies though. I know the codebase I inherited at my current employer wouldn't pass even the most superficial security check. Its only line of defense is that it's only on private networks. Until it isn't. I wonder if I should do a google to look for any public instances... just did, I'm only finding a lot of search engine spam thankfully.
- _8j50 4y agoAs a default, you should not consider your gateway network device in your trusted zone. This is one of many reasons why you should VPN (including personal, commercial, Tor, whatever your cup of tea) all traffic elsewhere. You might think "that only moves the attack surface" , you are both right and wrong. Technically it is moved but you eliminate LAN based, wireless (think wpa) and untrusted network devices from the equation and reduce them to one attack surface. Not only that, the threat actors most relevant to most people's threat models are not able to operate or operate with reduced capability to the most part when the attack surface is not a home network/device managed by individuals (and crappy vendors,isps,etc...). It can pay for itself, don't worry about network device security, just get the cheapest yet fastest stack amd VPN through it.
- _8j50 4y agoI forgot, VPNs are unpopular on HN because? Someone popular said so? Lol. This includes wireguard to your vps too if that helps. Anything but nude networking as I call it.
- salawat 4y agoIt's unpopular from my standpoint because it "necessitates/assumes the trustworthyness of an external provider of compute service". It being considered a default implies you waive 4th Amendment protections. Whereas securing your own network keeps them intact within your infrastructure. Cloud is not always the answer. Learning to network and compute, is.
- _8j50 4y agoNot at all, the external provider (cloud/tor) is still untrusted, I never implied that. It is a risk reduction strategy. If you care about security you must define threat model and risk boundaries.
- jfalcon 4y ago>It's unpopular from my standpoint because it "necessitates/assumes the trustworthyness of an external provider of compute service". It being considered a default implies you waive 4th Amendment protections. This is why we should learn from what Ed Snowden presented as just about all of the data gathered by NSA and their contemporaries utilized the concept that encryption and security should only exist at the edge and they were capturing network traffic inter-network and intra-DC. There were reasons why companies like Google took his whistleblowing seriously and changed their infrastructure accordingly because none of them feel safe leaving their "secret sausage recipe" exposed while still technically out of band from the customer paths.
- barbegal 4y agoDo people have issues with these modems in real use cases? The code that makes these devices fail uses up lots of UDP ports which suggests that the issue may be with the NAT implementation. I have done some searching online but haven't got a definitive answer on what exactly the issue is (other than it causes latency and hitter under certain conditions). I'm slightly sceptical these modems (really modem routers) are as bad as this site previously suggested. It seems like the only use case that breaks them is some specific games where there is a huge amount of latency critical UDP traffic.
- johnklos 4y agoI agree with many other takes here: this person really is getting too worked up, and therefore should take a break. On the other hand, it seems the issue that was the straw that broke the camel's back is saying that ICMP equals access, and access could mean just ICMP to some (I can access this thing via ICMP), or access could mean full takeover to others (now I know it's there, and therefore it's exploitable to anyone with time & energy). It's really stupid to get upset about self-proclaimed security experts arguing about stuff where they haven't even clarified what they're arguing about. Honestly, though, it's a non-issue. Some ISPs use RFC 1918 addresses, and some of those addresses are reachable (via ICMP) from consumer endpoints. So what? That's no less and no more secure that any other set of intermediate hops in ISPs' networks.
- eljimmy 4y agoI remember reading about his discoveries on the Puma chipset and that was actually really useful information when I was debugging cable issues myself. No idea what his most recent issue is but hey, thanks for your work bud, it was useful to many. Time to take a break!
- JohnClark1337 4y ago
- Xymox 4y agoWowee... So I am the Badmodems.com guy. I started getting emails to the badmodems email and I came looking for this thread. I did fight the good fight. I took out a whole division of Intel. They sold off the connected home div and the Puma. Then the Puma has now pretty much died out. That last battle tho, with the cable co admin network. OMG. That was some crazy shit. My health is better now and putting all that crap behind me was the right thing to do for my sanity.. My fav part of the whole Intel battle was when i did a 6 hour deposistion in the class action lawsuit. Arris lawyers and Intel battering me for 6 hours. All under oath and videoed. That was SO AWESOME. It was a intense battle. I won all of it. They never pinned me down once. I can also now discuss it and Intel did internal testing and even hired a outside testing lab. They did this really early. The discovery process got emails that confirmed horrendous performance and in email they decided to keep selling it with defects they knew they could not fix. The cable co admin network thing,, oh gawd what a mess. There was a HUGE comcast network faceplant right when I was working with a guy in europe and with Comcast. Comcast as a whole pretty much fell over in most cities. I never found out what happened. I think Comcast was trying to patch holes and borked their own network. I am glad to hear people got something from all my efforts. I did save everyone on cableCo systems worldwide from the Puma/Intel. They literally had plans to dominate the world and take over the home while destroying the only competition, Broadcom.I did, pretty much single handed, prevent really nasty devices from polluting the world and now have sent that whole chip into a grave.