I think my home network may be compromised, please advise - eviltoast

When I go to iknowwhatyoudownload.com, a bunch of stuff shows up for my IP that’s definitely not being downloaded by anyone in my house (foreign language torrents). Aside from that my router (AT&T Arris BGW210) needs to be restarted about once a week, due to some kind of dhcp issue. The most recent event seemed bad - none of my devices had internet, they could all talk to each other, and my ONT activity light was flickering steadily. During this time I had no access to the router, even plugged in directly to LAN. Fixed by a restart but no idea what was going on.

The DHT torrent thing has been happening for months and the router thing could just be that AT&T sucks. I have no other evidence that something is wrong.

I could buy a firewall and put it downstream of the AT&T equipment.

I could switch internet providers, get a new IP address and router, and see if that fixes it.

Should I try to figure out what’s going on or just keep restarting the router once a week and ignore the DHT hits from my static IP?

  • antlion@lemmy.dbzer0.comOP
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    3
    ·
    7 months ago

    I know what my public IP is, and it’s static, and listed correctly on IKWYD. The premise of the site is that torrent magnet links use distributed hash tables (DHT), which gives a public list of IP addresses who have participated in a particular torrent. Given that I have a static IP address, I’m not sure how it would be possible for my IP to show up, unless somebody is using my router as a proxy.

    • peto (he/him)@lemm.ee
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 months ago

      I don’t know how the tech works, but could the DHTs be deliberately polluted with false data to make this kind of snooping useless?

      • antlion@lemmy.dbzer0.comOP
        link
        fedilink
        English
        arrow-up
        2
        ·
        7 months ago

        The DHT is what the torrent client uses to connect to peers. Any invalid IP entry should make that peer unreachable. But maybe some clients have a way to start a download connection, while providing a false IP for the upload connection. I’m not sure how it works exactly.