Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] public wifi blocking ports
Date: Thu, 25 Dec 2014 09:35:27
Message-Id: 201412250935.15117.michaelkintzios@gmail.com
In Reply to: Re: [gentoo-user] public wifi blocking ports by Bill Kenworthy
1 On Thursday 25 Dec 2014 08:43:23 Bill Kenworthy wrote:
2 > On 25/12/14 15:43, Joseph wrote:
3 > > I've installed "zoiper" (this is an softphone app to connect to my
4 > > Asterisk server) on my old phone and it works on my private network over
5 > > wifi.
6 > > I'm using standard IAX port 4569 to register, so this port is open on my
7 > > firewall.
8 > >
9 > > But when I catch an open public wifi network in a Mall or a Tim Horton
10 > > "zoiper" failed to register.
11 > >
12 > > Do they block outgoing ports of public WiFi networks? What are my
13 > > alternatives?
14 > >
15 > > I can open any port on my DD-Wrt and redirect it to my Asterisk server.
16 >
17 > Quite often happens in this part of the world. I run an openvpn ssl vpn
18 > on port 443 with an ssl multiplexor on the server end - route all the
19 > voip traffic through the vpn. Doesnt work well if bandwidth is really
20 > constrained but its the difference between having at least something or
21 > nothing at all.
22 >
23 > BillK
24
25 Most public WiFi hot spots in Europe, especially in multinational coffee shop
26 chains, not only block privileged ports to thwart SOCK proxies, ssh, ipsec, et
27 al., but also use deep-packet inspection and Man-In-The-Middle attack to
28 decrypt your TLS connection to http, https, IMAP4, and POP3 and check your
29 payload. They do this to make sure that you are not some unsavoury character,
30 using their Internet connection for questionable activities. A number of
31 companies (like Websense) offer this kind of helpful services to those who
32 need to spy on our private communications.
33
34 If you check the SSL certificate that is returned from e.g. gmail, you'll see
35 that it has not been issued by gmail, or their CA. Most client applications
36 should warn you when you try to connect to a website over TLS. In such cases
37 I would consider your communications over this channel compromised, should you
38 decide to proceed.
39
40 --
41 Regards,
42 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature