Simon

@smrqdt@chaos.social
314 Followers
741 Following
2.8K Posts
Informatik und HoPo BHT. Refugees Welcome. Links. ‍🌈. Virulente Homolobby. 🇪🇺🌍. Verpeilt. DL7SMQ. (he/er) [searchable]
drüben@ioaua
Matrix@smrqdt:nop.systems
Zweitwohnsitzhttps://bsky.app/profile/smrqdt.eu
Today in #ITSecurity gone wrong: I am in Austria as a German. I just received a notification via cell broadcast about a fire in the area. The broadcast contains a URL - but this URL is only accessible from an Austrian IP address. My LTE roaming IP isn’t allowed. So… I guess I just suffocate because I have the wrong IP address, then? 😅
#retrocomputing was fun when Sony made wild personal computers.
@henryk The sync thing is probably true, and I fully understand the announcement thing (also a lot of small broadcasters are participating without complicated broadcasting systems). But I would have though this is a common problem and there would be some value in adding some more information (e.g. which kind of graphics is shown).

How are the graphics for the national phone numbers triggered during #eurovision?

“Graphics in three, two, one, now!”
*lengthy 1 kHz tone*
“Graphics away in three, two, one. now!”

Using an 1 kHz tone on an digital audio track in an MPEG-TS instead of… anything else (e.g. a subtitle track?) seems a little bit odd?

https://www.youtube.com/watch?v=2uAP9pZIBB0

The hidden beeps that control Eurovision graphics

YouTube

"from another service". You fucking liars.

#SoundCloud

Die Karl-May-Spiele in Bad Segeberg locken seit 1952 jedes Jahr Hunderttausende ins Kalkbergstadion – für viele sind Winnetou und Old Shatterhand Kult. Weniger bekannt ist dagegen die Geschichte des Stadions in der NS-Zeit. https://www.ndr.de/geschichte/schauplaetze,kalkberg103.html

10jähriges Nicht-Stattfinden des #CSD in Istanbul.

2015 fand dort die letzte legale Pride statt. Seitdem wurde jeder Versuch mit Tränengas und Massenverhaftungen niedergeschlagen.

I can't believe we're still having to say this in 2025, but would people *please* scroll back to the top of a website when they're finished reading, so it's ready for the next person. We've even got buttons at the bottom to do it all in one go, it's not 1994 any more.
i spent too much time on this
×
Today in #ITSecurity gone wrong: I am in Austria as a German. I just received a notification via cell broadcast about a fire in the area. The broadcast contains a URL - but this URL is only accessible from an Austrian IP address. My LTE roaming IP isn’t allowed. So… I guess I just suffocate because I have the wrong IP address, then? 😅
Sent them an email requesting to have my IP range allowlisted and questioning the general assumption such a service should be limited to in-country IP ranges. Let’s see what happens.
@hacksilon Hmm, interesting. Is it normal to get an IP from the home country when doing LTE roaming? Is this similar to a VPN?
@danimrich @hacksilon most of the time, yes. I have two SIMs from different countries and each data plan identifies me as coming from the country the SIM is from.
@danimrich yeah roaming is ?always? tunneled to your providers original country (at least that's what I've experienced with a lot of providers in a variety of countries)
@hacksilon
How we all imagine it happened:
@hacksilon die Notrufleitstelle Tirol bekommt von deutschen Mobiltelefonen auch keine Standortermittlung. Letztes Jahr für euch in den Bergen getestet.
Die Bergrettung konnte dann aber was mit den per SMS übermittelten Koordinaten anfangen
@HLunke @hacksilon das SMS-Ding is nur eine leere Webseite die den Standort wissen will - ein eher plumper Workaound um das Problem, aber *Leitstellen tun sich manchmal wirklich schwer Verunglückte zu finden.
@HLunke @hacksilon hast du die via 112 angerufen oder über eine andere Nummer?
@nicoduck @hacksilon
Die Kumpels haben das für mich gemacht und ja das muss die 112 gewesen sein
@HLunke @hacksilon hab gerade mal gesucht, Österreich hat die EU Regel wohl (noch?) nicht komplett umgesetzt und unterstützt die automatische Lokalisierung der Endgeräte (AML) weder im Roaming, noch bei iOS Geräten (generell). Roaming scheint aber generell ein Thema zu sein, das unterstützen die wenigsten Länder. Leider.

@nicoduck @hacksilon p

Ah, war ein iOS Gerät und Roaming

Allerdings konnte, oder wollte, der Mensch am Telefon auch auf Nachfrage nix von den Koordinaten wissen. Die Bergrettung war dann froh dass wir die liefern konnten

@hacksilon

If it's a national broadcaster URL, everyone is doing it, UK, Sweden, Poland, Australia.

You don't want non-taxpayers leeching your Comms...apparently.

@n_dimension Nope, this is the province government. @hacksilon
@hacksilon @cm Hallo Max Maass, I have an Austrian IP address (static. Magenta) and see the same error. Looks like the wrong URL was included in the message (i.e. one that is only reachable from within the network vs. a public one)
@QueerNewsat @cm I could actually get it to work when using the hotel WiFi and turning off my custom DNS resolver and using the default. Seems to be a DNS-based block, I think?
@hacksilon @QueerNewsat @cm Reminds me of overblocking (Reddit, ImmoScout Captcha and other) because the IP is listed as
„Anonymous Proxy: This IP address has been identified as an anonymous proxy.“
You can check on www.liveipmap.com

@hacksilon Wouldn't trust the Germans either (and I am one) ;-)

Jokes aside, as a minimum I'd expect the error website to show the IP the server is seeing. This makes debugging so much easier.

@ascherbaum
Tja wir haben halt jedes Jahr viele Touristen aus Deutschland.
Es muss halt auch wieder Platz für Neue sein ;)
@hacksilon
@hacksilon in Nußdorf brennt ein Recyclinghof, der Brand ist riesig und die Rauchwolke konnte man von weitem sehen (ich bin da gestern dran vorbeigefahren…)
@olbohlen jep, ich hab das dann auch über andere Quellen herausfinden können.
@hacksilon oh darn! Hope you are safe! Thanks for the screenshot, I might use this in the future to illustrate impact of Cybersecurity risk controls on (patient) safety risks. This is something the quality manual requires us to evaluate (into both directions). So this here should have been caught when introducing a Cybersecurity risk control as an issue.
@hacksilon GeoIP restrictions are totally a useful tool and not at all just a dumb sham 🙃
@hacksilon Well that's incredibly stupid

@hacksilon Tyrol, of all places. They're not very good at issuing warnings in time. I remember an avalanche accident in 1998, and there was something during Corona too.

How meaningful was the Cell Broadcast message without the website?

@Reemt tbh, the website mostly repeated the cell broadcast message. Not that important.
@hacksilon Why does Austria have ip addresses that doesn't work outside of the country?
Is this a common thing I just didn't know of?
@roseen it’s just regular geoblocking, I assume - they only allow Austrian IP ranges, apparently.

@hacksilon

Austria, the country that doesn't allow Google Street View but has detailed maps of universities (with each prof's room named) available online. At least a few years ago, I don't know if they changed anything...

They have somehow crooked sense of security.

@hacksilon This same type of deal happens all the time. I am U.S. American permanently domiciled in CH. When I travel back to the U.S. and use mobile roaming, a bunch of systems in the U.S. break down with the foreign IP:

1. Most restaurants' digital menus.
2. Most mobile (car) parking applications.
3. U.S. Government web sites.

What is this whole problem class called? Is this an artifact of "home routing" per the LTE roaming agreement: https://i3forum.org/wp-content/uploads/2014/05/i3F-LTE-Data-Roaming-over-IPX-Release-1-FINAL-2014-05-12.pdf?

@matt either that or just regular geoblocking?
@hacksilon Small statehood at its best

@hacksilon

Sure, that's a geoblock and not just another shitlisting of Vodaphone or T-Mobile IP-space?

I would totally understand the later. Traffic from this sources is generally as trustworthy as from public WiFi networks from Bangalore...

@czauner can’t really tell from the outside. Don’t have any other devices on other networks to play with. But using the hotel WiFi while tunneling DNS (but not HTTP) over my home network (via VPN) triggers the same behavior. So, probably DNS-based Geoblocking?

@hacksilon Depends on your 'home-IP'. Some German Networks have a very, very bad reputation (outside of Germany) as they seem to lack decent abuse-handling. It's noticeable when glancing over fail2ban logs (especially some German hosters are a cesspool). So, if your DNS tunnel goes via a hosted machine: There is that.

Usually if geoblocking in place, there is a hint to that. 'Untrusted network' is ljngo for 'on shitlist'. What ever it is, I'm confident that it's not by Tirol itself, there is no knowledge for that.

Likely a booked 'interner security solution', without knowledge of the inner workings by the country itself. Which doesn't make it really better, in any way, shape or form.

Two years ago ago I had the pleasure to address some reachability issues (for Austrian customers of mine), the culprit was a transparent 'web firewall'.