Excitel is spying on customers with their Fiber ONU (PPC Belden)

  • Thread starter Thread starter abX
  • Start date Start date
  • Replies Replies 36
  • Views Views 9,603
My post was not intended against TR069 in the first place.
First, you say this
But then you turn to this.
unlike some ISPs who are bundling spyware / crapware
Does having www.excitel.com as an SSID in your ONU spyware?
Regardless, I am yet to see ISPs adding something like that.
There was once an adware BSNL incident, but nothing else like that ever with anyone.
 
First, you say this
But then you turn to this.
You don't seem to know what defines 'intent'. Nevermind.

Does having www.excitel.com as an SSID in your ONU spyware?
Anything which is outside the scope of any contract is unintended. I have paid for Internet service, nothing more and nothing less.
Having an SSID with a password presumably known to the general public does pose a security risk, even if not exploited by the company; but can still be exploited by unpatched vulnerabilities on their crappy Chinese ONU.

I appreciate your advocacy for the ISP though.

Regardless, I am yet to see ISPs adding something like that.

Thats your PoV.

There was once an adware BSNL incident, but nothing else like that ever with anyone.

Everyone knows about airtel injecting JS unauthorisedly. And DPI in Jio 🙂

That BSNL case was possibly an unintended attempt of redirecting users to their ngn service.
And yeah, PSUs are never behind your data. THEY STILL ALLOW OPEN MARKET ONUs

-------------

Just like when we want to have full control on our brand new car, without the influence of the manufacturer ; or may be having full control over my new apartment outside the interference of the builder, the same is analogous to having full control on my network and devices, without the influence and unauthorised control by the ISP.

My post was to raise awareness. Cheers!
 
Last edited:
Privacy is a topic which is like two sides of a coin... It just loops back to Infinite argument.
 
  • Like
Reactions: abX
True that.

We need to become more sensible and concerned regarding our digital presence as much as the country is in dire need of privacy laws.
 


As more & more people are getting aware of privacy and all I guess it'll take some time but eventually we'll get there.
 
  • Like
Reactions: abX
I am trying to connect with that SSID through different passwords but unable to connect to it. 11223344 is the most common one but it's not connecting.
 
Unfortunately, Indians in general are expert at spying on neighbors, kids, grand kids, some else kids, facebook spying, insta spying. They don't care about privacy that much.

If you have nothing to hide, why worry?

That is the motto.

So, nothing is going to happen for about 100 years with regards to data privacy.

Most of delhi is funded by old people scammers who scam Americans with gift cards by stealing their data and phone numbers. It is a multi billion dollar scam industry in Delhi. joking.
 
I can confirm that excitel spy's on customers but only who has their newer WiFi onu's.

I can confirm because I applied for their customer care service job but I pulled myself out on the last day of the training. The company's work ethics are total shit.

They use TR069 to monitor literally everything (except browsing history/connections/queries made)
They can check when the device was up, connection made, how many WiFi or LAN devices are connected, what ports are they connected to, WiFi SSID and passwords, internal and external IPS, real time data transsfered/received, how far a wireless devices is (using signal strength) and maybe much more.

They can also modify any setting at any given time as they access your ONU with the same password you use or either a separate admin account on it.

I'm not sure if changing the password of the device will stop them from accessing but I'll do it anyways. And also they know about the hidden SSID they use to promote their so called "ISP" and I'm pretty sure its hardwired in the custom firmware.
 
In a day and time when all sites are via HTTPS and, depending on the configuration i.e. bridged mode or not, even DNS queries are encrypted they may be able to see very limited information. Now this information could be for the sake of data gathering under rules framed by the Govt or by Excitel itself. We don't know for sure.

Thing is if you're so paranoid shift away to a provider who gives you bridged mode, use your own router, switch to encrypted DNS and use a VPN on the router to make absolutely sure your nosey ISP gets limited data. Still paranoid? Disconnect from the internet and find yourself something to do that does not require an internet connection. 😉 I've seen people on other security forums who go to extreme lengths to prevent hacking by the FBI and CIA. You need to know where to draw the line. ISPs and authorities will do what they want to do..like it or leave it. At least till privacy laws are put in place.
 

Top