Spying on clients or something sinister going on?

Frankc

Well-Known Member
Joined
Dec 21, 2005
Messages
242
Reaction score
3
A very important feature for high end security is IP address validation to make sure someone don't hack a live logged in session.

1) User logged in 2) Connection IP address logged and if that IP address changed, the security system will log the user out and display a message "IP address changed, please log in again".

Recently this now happen with almost ALL loggins via TELKOM Mobile and it seems that there may be secondary or third-party interference with and during the connection.

- It only happens with Telkom Wifi (Huawei)
- It happens with even different browsers (via telkom connection)
- It happens with many different logins at many different places (via telkom connection)
- It happens with different PC's/ Laptops (via telkom connection)
- It happens with even default factory resetted settings on the Huawei Wifi
- It happens with even different Telkom Sim/s on same or different wifi modems (even vodacom wifi modem)

- It don't happens with any other wifi and other network
- It don't happens after manually changed the default APN for the wifi modem

- Checked public IP before and after the "IP address changed" message and it's still the same, so there is no reason for such security message unless there are secondary / third-party interference.

Any ideas to further check / test things to get to the bottom of this please?
 
Nope, I live right next to Telkom tower and already checked that too
 
The change to APN was from usual "internet" etc to rather unusual "unrestricted" as someone suggested and that fixed the issue.

It's clear that with "unrestricted" APN the connection is different and have to lookup many domain IP addresses at first (so it was not cached as would be the case with regular used network points) In fact it even take several seconds for THIS connection/network to lookup FACEBOOK so its definitively uhmmm, well as the APN name suggest an "unrestricted" connection.

Even while that solve my issue, it still don't explain why the normal Telkom APN and network cause the "IP address changed" issue.
 
This is (and has been for a while now) 110% normal for telkom on their normal APN. On some systems I can almost forget to try and do something while on their normal APN. It has something to do with their Carrier-grade NAT afaik. The unrestricted APN is nothing odd or unusual and is also offered by other networks. Someone please correct me if I am wrong...
 
This is (and has been for a while now) 110% normal for telkom on their normal APN. On some systems I can almost forget to try and do something while on their normal APN. It has something to do with their Carrier-grade NAT afaik. The unrestricted APN is nothing odd or unusual and is also offered by other networks. Someone please correct me if I am wrong...

I doubt that it's NORMAL in both security and international context just like state capture and billions of rands for cronies is not normal in a normal society even while the majority of South Africans regard it as "normal"

Do you really regard it as normal that high-end security systems at banks, ISP's (I am one) etc must ditch security measures because Telkom can't offer secure connection standards (while MTN, Vodacom, CellC can do that)
 
I doubt that it's NORMAL in both security and international context just like state capture and billions of rands for cronies is not normal in a normal society even while the majority of South Africans regard it as "normal"

Do you really regard it as normal that high-end security systems at banks, ISP's (I am one) etc must ditch security measures because Telkom can't offer secure connection standards (while MTN, Vodacom, CellC can do that)

Telkom is a dinosaur that has never learned (or had any inclination) to play nice with the other kids.
I understand you might be stuck with them for lack of other options but if you are able to, stop enabling them and vote with your wallet.
 
The APN "Unrestricted" is by the way crab, very slow and problematic with some things like FTP that don't work
 
Carrier Grade NATting. RAIN have been doing it almost since launch. With the “unrestricted“ APN it ”mimics” ADSL where the IP address changes once a day or so. On the “internet” APN, it uses any route and the public IP changes constantly. The idea is to limit inbound traffic like hosting or using Dynamic DNS hosts. Most users need LTE for just streaming or browsing and Carrier NATing works just fine.
Dont think its anything sinister.
 
IP address change only day or so? Yet this whole issue is because the IP ADDRESS CHANGE within seconds and IN SECURE SESSION if you understand that.

If the IP address don't change, as it seems, then there are INTERFERENCE from OTHER IP during such SECURE session that trigger the "alarm bells"

Much like a presidental secure line to ensure exclusive communication between A and B and if there is any interference the call is no longer secure and end to prevent spying ears.
 
The idea is to limit inbound traffic like hosting or using Dynamic DNS hosts. Most users need LTE for just streaming or browsing

Hosting = streaming and browsing since it's hosted somewhere so above don't make sense.

SECURE connections don't use dynamic dns hosts so above also don't make sense
 
Yesterday when I downloaded a website folder via ftp, it was very eratic with several disconnections and at one stage the ftp program (or windows) threw error that the file name is too long.... Very long name with strange characters...

Initially I thought oh **** the account was hacked but when I checked, testes, scanned and downloaded compressed backup as well as the folder as is a few times, I find nothing except the eratic disconections.

Now where the hell did that file comes from if it WAS AND IS NOT on the server???

Seems pretty much like injection / interference from outside doesn't it?

I don't say it's Telkom, but what about Huawei or linked network?
 
Nope I don't use any VPN or any kind of internal network. Plain Laptop (2 different ones, one year not in use) to connec tto telkom broadband via wifi modem.
 
Same issue with my Telkom connection. Spend much of the day logged into a cloud SaaS and it would do the same. For no discernable reason it stopped doing this about 2 months ago and no problems since.
 
Note to self.

Don't use LTE from Telkom or Rain, it's not for developers or cloud infrastructure jobs.
 
 
They're probably doing some form of pooling and your traffic routes via multiple IPs instead of one at the ISP end. Always going to be problematic with some sites. I've seen this on a LAN where connection bonding is in use... I.e. 4 fixed lines out being pooled at the router... Each line with a different IP. Traffic is potentially routed across a different IP continuously. Causes havoc with some websites.

That makes the most sense thank you and after reading up it seems it's sort of what Carrier Grade NAT does.

Don't affect high level bank security so far I can see but still problematic that it denegrades security measures on many other websites.

This however don't explain the ftp issue I experienced..... (I offer web hosting services for past 14 years and the file name (Only saw it for few seconds but easily 100+ strange chars long) immediately ring "hacker" alarm bells, yet I can't find ANYTHING on the specific folder or even whole domain so it comes from somewhere, somehow.....
 

Threat to security? More like a threat for enforcement.

Context: "Eurpol, the European Union Agency for Law Enforcement Cooperation, has identified that CGN is an impediment to investigating online crime, and is therefore consulting the Internet community on how network operators can be encouraged to deploy IPv6. "

This however don't explain the ftp issue I experienced..... (I offer web hosting services for past 14 years and the file name (Only saw it for few seconds but easily 100+ strange chars long)

You are pushing that sinister/hacking angle hey? Could you try and capture the 100+ strange chars long filename by any chance? Some ftp clients should surely have a verbose debugging log of sorts that shows this?
 
You are pushing that sinister/hacking angle hey? Could you try and capture the 100+ strange chars long filename by any chance? Some ftp clients should surely have a verbose debugging log of sorts that shows this?

This one was unfortunatelly not enabled

I rather ask questions than to live with my head under the sand and become another statistic and besides, sinister/hacking or the not, any software, network, configuration of whatever on national scale that ignore or don't adhere to security features that's an international accepted norm deserves some investigation.
 
Top
Sign up to the MyBroadband newsletter
X