Hyposcalers - Introduction to Consumer Internet Networking
Gotta Start Somewhere
Having broadband access to the Internet is ubiquitous in most households in Europe. The setup usually comprises of a device provided by ISP (Internet Service Provider) - commonly known as router - which connects to ISP's infrastructure over fiber or coaxial cable, and provides Internet connectivity to devices on home LAN (Local Area Network) connected to it. A router usually provides a few LAN ports for plugging wired devices such as desktop computers, as well as WiFi network to which wireless devices such as laptops, tablets, mobile phones, and increasing number of other types of appliances connect by means of selecting provided WiFi network and typing in its password. Once connected, one can browse webpages, engage in social networking, send and receive emails, watch movies and listen to music on various streaming platforms, play online games, chat by means of text messages, audio or video calls, do online shopping or banking or any of other things that people usually do "on the Internet". Most people can't be bothered to try to understand actual mechanisms which give them access to the "Internet". Recently, however, I have noticed that more and more people around me begin to understand that Internet isn't just a thing they access and use. They start to intuitively feel that Internet is also accessing and using them, sometimes to their disadvantage, and they start to ask me how it does that and how can it be prevented. Answers to those questions exist, and are quite exact, but they require quite a bit of reading and understanding. The following article tries to explain most basic terminology of home networks.
How computers communicate on the Internet
All the devices on the Internet communicate by means of IP addresses. Visiting a webpage in a browser is not that dissimilar to a traditional mobile phone call. A caller with a phone number X dials receiver's phone number Y. Receiver sees caller's number, picks up the phone, says "Y here". Same goes with computers. Website visitor types webpage address into browser on their computer. Computer which hosts webpage - usually called server - sees viewer's IP address, sends webpage contents to it. Keep in mind that although greatly simplified, this example describes the process quite accurately. Also, when I say "computers" I don't mean just desktops and laptops, but any devices which use the Internet - phones, tablets, TVs, gaming consoles or even some models of light bulbs, refrigerators, microwave ovens etc.
How computers get their IP parameters
Computers can have their IP addresses configured manually by a human operator, or automatically by another computer. The latter is the common way on home networks. Most computers are preconfigured to accept IP addresses offered to them by other computers provided they are on the same network. This process is called DHCP - Dynamic Host Configuration Protocol and can be simplistically described as follows:
Computer1 (shouts): I have no IP address, anyone here to provide me with one!?
Most other computers on the network (each to itself): I don't know how to do it, I better keep my mouth shut.
Computer 74 (to Computer1): Give me your MAC address and I'll provide you with IP parameters.
Computer1 (to Computer 74): Here goes - 8e:b6:0c:a8:f4:cd.
Computer 74 (to Computer1): Ok 8e:b6:0c:a8:f4:cd, configure yourself with IP address 192.168.0.114, subnet mask 255.255.255.0, default gateway 192.168.0.1 and DNS server 192.168.0.1.
Computer 74 (to itself): I'll remember Computer1 by its MAC address for a little longer and give it the same IP parameters if it contacts me again before I forget it.
DHCP service is included and preconfigured on most home routers provided by ISPs. It is very convenient, but it also collects information about MAC addresses which are usually permanently tied to devices' NICs - Network Interface Cards. The first half of a MAC address is known as OUI (Organizationally Unique Identifier), and is assigned to specific manufacturers by the IEEE (Institute of Electrical and Electronics Engineers). The second half is assigned by the manufacturer to uniquely identify each device they produce. DHCP service provides its operators with information about manufacturers of devices requesting their IP addresses, as well as about their unique identifiers. As most home networks have DHCP service provided by ISP-owned router, this means that ISPs can - and probably do - collect information about devices on their clients' home networks. It is relatively trivial for an ISP to aggregate all this data into single dataset and use advanced analytics techniques to get valuable insights. For example, ISP can make assumptions about home network owner's financial status just by looking at number of devices they have on their network (more devices cost more), or by looking at devices' vendors (fancy "smart" refrigerators or gaming consoles). Moreover, they can track exact time at which a smartphone with specific MAC address connected to any of home networks they provide.
Some devices, usually smartphones, include MAC address randomization functionality which eliminates the possibility to track them by means of MAC addresses. Unfortunately, they also usually include much more accurate tracking mechanisms.
Here's an example of a record of a DHCP lease as recorded in OpenBSD's dhcp.leases file:
lease 192.168.0.114 {
starts 6 2025/11/29 13:25:35 UTC;
ends 0 2025/11/30 01:25:35 UTC;
hardware ethernet 8e:b6:0c:a8:f4:cd;
uid 01:8e:b6:0c:a8:f4:cd;
client-hostname "Snezana-s-A52";
}
Provided ISP had access to this data, they could see that certain Snežana uses cellphone model Samsung A52, possibly uniquely identifiable by its MAC address 8e:b6:0c:a8:f4:cd, and that aforementioned cellphone obtained IP address 192.168.0.114 on 29th of November, 2025 at 13:25:35 UTC. As ISP knows physical location of home network where router with DHCP functionality resides, they know that Snežana, or at least her smartphone, was physically present at that particular location at that particular time. Aggregating this data with data from other DHCP servers on other home networks in their possession they can track Snežana's movement quite accurately. Luckily, it is relatively easy to disable DHCP service on most ISP-provided routers and set it up on another device. We will come to that later.
In previous section I said that all computers on the Internet communicate by means of IP addresses, but in this section we saw they also communicate over MAC addresses. There's no contradiction here. Before computers get configured with IP addresses they can use MAC addresses for communication, but only on the same network (LAN), and for certain purposes such as obtaining IP parameters. For communication with other networks including Internet - the network of networks - they will need to use IP addresses.
The Domain Name System - DNS
Those as old as me will remember the days when remote communication with our friends started with turning a rotary dial on an analog phone. We knew most of our best friends' phone numbers by heart, but we had to write down numbers of new contacts we didn't memorize yet into a physical address book. Once cellphones arrived, they introduced address book functionality where one could add a contact so it could be called just by selecting its name, without knowing the actual phone number. DNS works on similar principle. It provides distributed, decentralized global address book which maps names of computers which can be contacted over the Internet to their IP addresses. Thanks to DNS, we can order our computer to contact other computers by their name, without having to know their IP addresses. In order to access homepage of my favourite operating system I can type http://www.openbsd.org/ into my browser's address bar, without having to know IP address of the computer which will show it to me. However, I could just as well type http://199.185.178.80/ and get the same result (this is one of rare examples where it actually works as contemporary Internet involves many complexities such as higher-layer protocols, name-based virtual hosting, SNI etc.; explaining those will have to wait for much more advanced article). Keep in mind that computers still need to know actual IP addresses in order to communicate, just as cellphones still need to know phone numbers. It is just that people who use computers do not need to know the IP addresses of computers they wish to communicate with as long as computers they use get configured to ask DNS servers to resolve names into IP addresses.
As described in previous section, computers on home networks are mostly set up with their DNS servers by means of DHCP, but they can also be configured manually. DNS service is included and preconfigured on most home routers provided by ISPs. DNS is decentralized and hierarchical. Each Internet domain owner publishes records specific to their domain - service names and their corresponding IP addresses - on their own (or lately increasingly rented) authoritative DNS servers, and allows (mostly) anyone who have set up caching DNS servers to query them. In other words, our computer will ask a caching server to resolve some computer's name into an IP address, and this caching server will find out which authoritative server can give it the answer, get the answer, and relay it to our computer. Caching servers will remember the answers for some time so they don't need to ask authoritative servers same questions again if they already know the answer. If configured so, they will also log client queries.
Almost every contact of computers on home network with computers on the Internet starts with a DNS query to a caching DNS server. Similar to DHCP service we talked about in previous section, caching DNS service is included and preconfigured on most home routers provided by ISPs. It is very convenient, but it can - and usually does - collect information about LAN computers' queries about Internet computer's names.
Here's an example of some records of DNS replies as recorded in OpenBSD's unbound.log file:
Nov 29 13:30:02 unbound[15410:0] reply: 192.168.0.114 www.coolinarika.com. HTTPS IN NOERROR 0.092380 0 123
Nov 29 13:34:07 unbound[15410:0] reply: 192.168.0.114 bonapeti.rs. HTTPS IN NOERROR 0.064177 0 127
Nov 29 13:39:24 unbound[15410:0] reply: 192.168.0.114 glovoapp.com. HTTPS IN NOERROR 0.070880 0 125
Nov 29 13:41:37 unbound[15410:0] reply: 192.168.0.114 glovoapp.com. HTTPS IN NOERROR 0.087921 0 129
Nov 29 13:43:19 unbound[15410:0] reply: 192.168.0.114 www.mcdonalds.rs. HTTPS IN NOERROR 0.118459 0 189
Nov 29 13:46:18 unbound[15410:0] reply: 192.168.0.114 glovoapp.com. HTTPS IN NOERROR 0.057693 0 114
Nov 29 13:50:52 unbound[15410:0] reply: 192.168.0.114 intesamobi.bancaintesa.rs. HTTPS IN NOERROR 0.038287 0 59
Nov 29 14:29:48 unbound[15410:0] reply: 192.168.0.114 www.netflix.com. HTTPS IN NOERROR 0.479517 0 131
Provided ISP had access to this data, they could see that device with IP address of 192.168.0.114 browsed some cooking websites around lunch, but after some 20 minutes ultimately caved in, ordered delivery and paid for it online. Combining this data with data from DHCP I showed in previous section, ISP knows it was Snežana on her Samsung A52. Four years old cellphone, on the cheaper side, fantasizes of cooking but easily steered to junk food delivery, probably by ads on cooking sites, has account in certain bank, has no reservation regarding online payments, enjoys netflix content. Aggregating this data with data exchanged or traded with other ISPs and data brokers they probably know about Snežana more than she knows about herself. And this is just from DHCP and DNS - we haven't even touched web server logs, much less javascript, tracking pixels and others. Luckily, similar to DHCP, it is relatively easy to disable DNS service on most ISP-provided routers and set it up on another device. We will come to that later.
WIFI
We all use our home wifi networks extensively. Many, if not most people don't even have wired devices in their homes anymore as most of their Internet activity is done on cellphones, tablets and laptops. Many don't shy away from connecting to public wifi networks in shopping malls, restaurants etc. in order to save on mobile data plans (which aren't any better from privacy point of view). However, connecting to wifi networks gives their operators quite some information about connected devices, as well as about their owners. As most users use wifi access point bundled with router provided by their ISPs, they provide ISPs with additional personal data.
Here's an example of data that can be seen in unifi network controller's logs:
Nov 29, 2025 at 1:25:34 PM Snezana-s-A52 connected to petrovici on ubnt233921. Connection Info: Ch. 36 (5 GHz, 40 MHz), -57 dBm. IP: 192.168.0.114
Nov 29, 2025 at 7:39:57 PM Snezana-s-A52 disconnected from petrovici. Time Connected: 6h 14m. Data Used: 215.56 MB (up) / 18.89 GB (down). Last Connected To: ubnt233921 at -88 dBm.
Not too much, but combined with data from DHCP and DNS, ISP can figure out from wifi network name seen in the logs that Snežana's family name is Petrović, and from amount of downloaded data combined with DNS requests that she spent all afternoon watching Netflix. Over longer periods of time ISP can make pretty accurate profile of some home network user. This data is mostly used and sold to other interested parties for targeted advertising which is arguably already bad enough, but things can get much worse if it falls into the hands of even more malicious entites, possibly by their intrusion into ISP's internal information systems, or directly into unpatched vulnerable all-in-one home network routers. As with DHCP and DNS, disabling wifi on most ISP-provided routers and setting it up on another device is not only possible but also quite doable. We will come to that later.
Gateway
As opposed to DHCP, DNS and wifi, the only thing we can't avoid in our relationship with an ISP is the need to relay traffic between our home network and the Internet through their routers. After all, this is their main purpose - providing Internet service. This doesn't mean we have to use their all-in-one home network router for the purpose. Some ISPs will allow complete removal of their home network router from the equation and let clients connect upstream cable directly into router of their choice. This setup is commonly known as Direct IP. Others will agree to reconfigure their home network router into bridge mode so that client's router does actual routing. This setup is commonly known as PPPoE - Point-to-Point over Ethernet. Both setups are good enough, Both need additional client-provided devices on a home network worth some €€€, but anyone who cares about their privacy, wants to invest some time in learning and some money in gear should definitely consider moving away from ISP-provided all-in-one home routers. Most ISPs I encountered had no objections to provide me with direct IP or PPPoE once I asked politely over email (usually forwarded to advanced tech support).
Hopefully this article will soon be followed up by another, more hands-on one, where I will try to explain all the steps needed to roll our own OpenBSD-based router / firewall which will replace all the functionalities of ISP-provided one while increasing our privacy. Once we learn how to start accessing Internet services more privately and securely perhaps we can even move on to start offering some private and secure services to the Internet ourselves. Stay tuned.




