Hacker News new | ask | show | jobs
by phil21 831 days ago
AT&T Fiber in bridge mode is not actually bridge mode. It's some weird 1:1 NAT if I recall, and buggy in certain conditions.

You can get the 802.11x certificates off the gateway itself and auth via your own equipment though if you are sufficiently motivated[0].

I believe there are some newer methods as well, but I haven't kept up on it since I've luckily been able to get a different provider since that doesn't play games with the gateway devices. RCN at least lets you BYOD and is an ONT only.

[0] https://github.com/owenthewizard/opnatt

1 comments

I'm aware of how the AT&T bridge mode works, it makes no functional difference to my security argument. The only issues I've personally seen is overloading the NAT state table, largely from running multiple crypto wallets or multiple torrent clients with wide open connection settings.

You can get the 802.11x certificates off the older gateway for now older firmware versions, but newer hardware doesn't have the same exploits.