this post was submitted on 30 Dec 2023
261 points (94.2% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

54462 readers
274 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

founded 1 year ago
MODERATORS
261
Me vs my ISP (lemmy.dbzer0.com)
submitted 10 months ago* (last edited 10 months ago) by [email protected] to c/[email protected]
 

So I was looking into getting port forwarding set up and I realized just how closed-off the internet has gotten since the early days. It's concerning. It used to be you would buy your own router and connect it to the internet, and that router would control port-forwarding and what-have-you.

Now, your ISP provides your router, which runs their firmware, which (in my case) doesn't even have the option to enable port forwarding.

It gets worse - because ISPs are choosing NATs over IPv6, so even if you install a custom firmware on your router without it getting blacklisted by your ISP, you still can't expose your server to the internet because the NAT refuses to forward traffic your way. They even devise special NAT schemes like symmetric NAT to thwart hole punching.

Basically this all means that I have to purchase my web hosting separately. Or relay all the traffic through an unnecessary third party, introducing a point of failure.

It's frustrating.

I like to control my stuff. I don't like to depend on other people or be in a position where I have to trust someone not to fuck with my shit. Like, if the only thing outside my apartment that mattered to my website was a DNS record, I'd be really happy with that.

Edit: TIL ISPs in the US don't have NATs

Edit 2: OMG so much advice. My knowledge about computers is SO clearly outdated, I have a lot of things to read up on.

Edit 3: There's definitely a CGNAT involved since the WAN ip in the router config is not the same as the one I get when I use a website that echos my IP address. Far as I can tell ~~my devices don't get unique IPv6 addresses either~~. (funnily enough, if I check my IP address on my phone using roaming data, there's no IPv6 address at all). It's a router/modem combo, at least I think since there's only one device in my apartment (maybe there's a modem managing the whole complex or something?). And it doesn't have a bridge mode, except for OTT. Might try plugging my own router into it, but it feels like a waste of time and money from what I'm seeing. Probably best to just host services over a VPN or smth.

Edit 4: Devices do get unique IPv6 addresses, but it's moot since I can't do anything but ping them. I guess it wouldn't be port forwarding but something else that I would have to do that my router doesn't support

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 10 months ago* (last edited 10 months ago) (2 children)

why not bridge the router and use your own?

the router doesn't have one?

which ISP is it?

[–] [email protected] 8 points 10 months ago (3 children)

No matter how much you think you know, there's always something everyone knows that you've never heard of...

That said, if bridge mode is something that you can enable in the config (going to 192.168.0.1 in web browser and all that) then it's not possible.

It's through China Mobile

[–] [email protected] 5 points 10 months ago* (last edited 10 months ago)

You could get an ONU like this

https://www.aliexpress.us/item/3256804134894710.html

Use it to clone every bit of authentication from ur current ONU to it, the realtek chip in it is very customizable.

https://github.com/Anime4000/RTL960x

https://hack-gpon.org/

[–] [email protected] 1 points 10 months ago

Sometimes it’s configurable through the web interface, sometimes it requires a call to the ISP if you’re using their locked-down modem.

I’m not familiar with IT norms in China though.

[–] [email protected] 1 points 10 months ago

I'm honestly amazed the internet isn't locked down even more for you then. I was under the impression that the Golden firewall would be complemented with strict local network rules

[–] [email protected] 2 points 10 months ago (1 children)

sounds like his router is locked down, and even then, if the isp puts him behind nat, there isnt much he can do on his side even if he could theoretically forward those ports.

[–] [email protected] 3 points 10 months ago (1 children)

yes, cgnat is very common in many countries due to IPv4 shortage, bypassing the ISP Router and using your own along with a self hosted VPN Server (for China, Hong Kong or Tokyo works great) is the best choice.

[–] [email protected] 2 points 10 months ago

ipv6 is nice to use too if they dont also NAT it (which looks rare?)