5 ms·
>Do you not see the problem with all of my families devices “preferring” a neighbors network over mine? I have T-Mobile. T-Mobile maintains agreements for Pass
by 310260 3y ago
>Do you not see the problem with all of my families devices “preferring” a neighbors network over mine?
I have T-Mobile. T-Mobile maintains agreements for Passpoint networks at random places like airports, T-Mobile stores, or (I recently found out) Home Depot. These networks are encrypted and authorized against a RADIUS server.
My SIM has them programmed into it. I can't just stand up the "t-mobile" or "Passpoint Secure" SSID from my home network and my phone automatically connects to it. That's not how it works.
Based on the fact that your devices are showing preference, I'm gonna take a wild guess and say you have Xfinity/Spectrum/Optimum Mobile. The cable co. MVNOs maintain their own WiFi networks which are (again) connected to via Passpoint and authorized using RADIUS. However, the cable company WiFi networks extend far into neighborhoods and are broadcast from CPEs. Your devices prefer them because that's part of the network you signed up for.
Just VPN back to your home network if you're not confident in their security.
- newZWhoDis 3y ago> Just VPN back to your home network if you're not confident in their security. I’m sorry but wtf? You’re saying that, in my own home, I should just accept that my devices connect to an external wifi against my will and VPN back into my own home… while in my home? Seriously?
- 310260 3y ago(Gonna assume you have a cable MVNO still) Yes. You signed up for a cable provider mobile service. A huge part of their whole value proposition for their service is "get access to millions of cable WiFi hotspots!" That's their product. They plaster it everywhere in all their ads. Your situation with Pi-hole and firewalls etc. is a niche use case. Their service is made to appeal to people who are 1) cable company customers and 2) want cheaper service. The majority of people who fall into those categories have an Xfinity router at home that broadcasts the Passpoint SSID. The phones connect to that SSID and have service. Passpoint is going to be more secure than any WPA2/3 network anyway. If you don't want that to happen, then get a different mobile provider. This one is not for you.
- thedougd 3y agoWiFi isn’t just for accessing the Internet. It’s also for accessing other devices on your home network such as printers. This is a broken implementation with no room for argument.
- newZWhoDis 3y agoI signed up for cellphone service. Absolutely no where did I consent to have my devices (yes, my owned devices not leased/payment planned) suddenly lock me out of basic networking settings. This is almost as stupid as buying a Walmart keyboard and finding out plugging it in disables eth0 because you might load Amazon.
- michaelmrose 3y agoXfinity hardware provides a separate SSID that uses WPA2/3 to secure your connection and a SSID for "Xfinity WIFI". On Android one can and should in fact select which nodes to connect to not merely whether to connect to all nodes but whether to connect to individual nodes. This is essential because in real world non test environments real customers using real networking hardware and phones do not handle adjacent networks well because signal strength varies wildly throughout their space resulting in devices roaming back and forth for no fucking good reason. This is especially true in dense environments like apartment buildings. Xfinity customers using xfinity wifi on their android device NEVER experience conflict from dancing between AP with xfinitywifi in their home or from their neighbors unless they explicitly connect to adjacent networks and if they do so they can correct the issue by long pressing on the undesired AP name and selecting "forget". Nobody cares what a company thinks they signed up for. They give essentially two shits. They pay tech companies to solve their problems and expect solutions that work. The situation as described doesn't work for normal network conditions and equipment. The fact that it also breaks niche stuff that techies like is just diarrhea icing on a shit cake.
- m463 3y agoYou can restrict apps from using the internet in the cellular menu. But with wifi, they can communicate unrestricted.
- lxgr 3y agoThat’s a very obvious omission in the iOS privacy/security settings I‘ve never understood. Why can I grant fine-grained access to my photos, location etc., but not just outright denying network access to an app that works offline, which would make all of the other concerns mostly moot?
- bluehex 3y agoYou explained why this might be happening technically but why are you acting like it's okay? "Just VPN home" is not a solution if the phone is preferring a terrible one bar connection over the home one. Imagine the quality of that vpn connection you're suggesting as a fix.
- 310260 3y agoI invite the WiFi Alliance to participate more in 3GPP meetings and straighten out the standard for handover between LTE/5G and Passpoint WiFi networks then.
- elefanten 3y agoHow gracious. In exchange, I invite all of the 3GPP stakeholders to respect people's technological autonomy and refrain from enabling solutions that force crap down their throats.
- 310260 3y agoThis isn't about technological autonomy. OP signed up for wireless service that is specifically sold as Hotspot WiFi-first. That's one of its main features. It's sold as that very, very clearly. If you don't want their WiFi, go get service from another provider!
- deleted 3y ago[deleted]
- bluehex 3y agoJust because a service is marketed as having a feature doesn't mean they have an excuse to undo a user setting in their OS that explicitly says they don't want to use it. Maybe they do want to connect to the advertised network when traveling but auto connect shouldn't be forced on them. I don't understand why you are trying to defend this so adamantly.
- newZWhoDis 3y ago
- michaelmrose 3y agoHaving multiple adjacent networks enabled is liable to cause customer devices to roam between access points on and off their LAN even when - Remote access point doesn't provide access to desired resources - Have acceptable performance - Have acceptable security parameters according to users needs Most users can't stand up a vpn inside their network and configure it to alleviate the self inflicted wound of having their phone decide that the user isn't qualified to select the wifi access points it prefers to connect to. You may as well ask them to grow wings and skip Delta. Instead they will be placing irate calls to their ISP about why their wifi sucks so much and I will be silently cursing Apple.
- lxgr 3y ago> Just VPN back to your home network if you're not confident in their security. So you expect the average user to be able to set up a Zeroconf/mDNS-proxying VPN, since that’s the only type that will allow things like Google Cast or AirPrint to still work? Home networks are not just about security or speed, some people have devices on them they can otherwise not reach.
- doggy_afuera 3y agoThank you for adding some technical context to this discussion. There's a lot of (sadly) uninformed people in this thread spitting mad prophesying about a topic they clearly do not understand with any technical depth. If only the retail stores replaced their enterprise gear for EAP with a "pi hole". P.S. nice username