Matthew Gamble's Blog
← Back to reflections
Hmmm... Can't Reach This Page

bell

Hmmm... Can't Reach This Page

M
Matthew Gamble

11 min read
"A friend called me two weeks ago because his IPTV app had stopped playing anything, just a spinning wheel and a generic playback error."

A friend called me two weeks ago because his IPTV app had stopped playing anything, just a spinning wheel and a generic playback error. When he pulled up the service's own domain in a browser to see if it was even reachable, he got the real answer: a blank page and "Hmmm... can't reach this page." He'd signed up with a small reseller days earlier, the kind of operation running on a domain barely old enough to have a search index entry, so I told him the obvious thing first: with almost no subscribers yet, there was no way this domain had already made it onto any official blocklist. Then I asked him to run one command, and that's when this stopped being a five-minute favour and turned into six weeks of traceroutes, court dockets, and one increasingly annoyed WHOIS lookup.

Let's get the obvious objection out of the way, because I don't want a single comment on this post arguing about whether pirated IPTV is legal. It isn't, and that's not really what this is about. This is about whether the companies that carry Canada's internet traffic should be the ones deciding what you can reach, under what authority they're actually doing it, and whether an ordinary customer has any way to tell the difference between a court order, a carrier's private judgment call, and a plain network fault. I've been here before. A few years ago I argued Bell Mobility was charging customers extra to unlock HD video in violation of the CRTC's differential pricing framework. The CRTC disagreed with my read of the rules. I still think I was right, and this time I've got a court docket and a control group.

The obvious place to start was T-1127-26, the Federal Court order Rogers, TVA, and six Hollywood studios won on July 3, 2026, naming eight ISPs as respondents. Rightsholders can add domains, subdomains, or IP addresses by affidavit, and if no ISP objects within five business days, the addition takes effect with no judge involved. The order also requires a public Notification Website, except t112726.com was throwing a 502 error both times I checked. TekSavvy posts the actual current list voluntarily: 18 domains, zero IP addresses. My friend's resellers domain wasn't on it, and wasn't old enough to plausibly be. Whatever killed his stream, it wasn't this order.

So I ran a traceroute. Clean at 10 a.m. on a quiet weekday, fifteen hops, the last few running through Amsterdam on Twelve99's backbone before landing on the destination. That evening, with the Leafs and the Jays both playing, the same traceroute made it to hop six and died completely. A VPN through the same IP block worked instantly, meaning Bell's own network was doing the dropping, on a schedule that matched live sports suspiciously well.

That pointed at T-743-24, the dynamic sports blocking order covering NHL, NBA, Premier League, MLB, UFC, IIHF, and FIFA, where a monitoring vendor pushes IP addresses to ten named ISPs over a shared platform with a 30-minute block-and-unblock cadence keyed to live game windows. I had a colleague on Cogeco, also named on that same order, run the identical traceroute at the identical moment. Clean. Same address, same live window, one ISP blocking and one not, when both are legally bound to read from the same list. For those not familiar with how the order is supposed to work, that divergence shouldn't be possible if both ISPs were actually enforcing it.

Three weeks before that order's most recent amendment, the CRTC quietly handed every carrier in Canada a second, much broader blocking authority. Telecom Decision CRTC 2026-140, issued June 18, 2026, lets carriers block traffic they judge to be botnet activity, phishing, or other cybersecurity threats, using "any measure that complies with the guiding principles of necessity, accuracy and consumer privacy." No court order, no public list, just a confidential annual aggregate filing to the Commission. Commissioner Bram Abramson dissented, and he put it better than I could: "Carrier discretion has expanded. Governance of that discretion has contracted." A freshly registered domain with zero traffic history is exactly the kind of target that trips a "looks like malicious infrastructure" heuristic, whether or not anything infringing is actually happening on it.

I could stop there and call it a transparency gap, hand it to the CRTC, and move on. But sitting with this for six weeks changed what I actually think the story is, and it's bigger than which acronym authorized this one block. It's whether we should have built a system where ISPs get to make that call at all.

I want to pick a specific fight here, because it clarified my own thinking. Hugh Stephens, a longtime copyright industry consultant, wrote a defence of site blocking a few years back built on two analogies, and both of them are wrong in ways worth spelling out. On the telephone network, he argues net neutrality "does not mean that they have an obligation to transmit illegal content any more than the telephone company is obligated to put through calls that a subscriber wants blocked." Read that again. In his own example, the subscriber is the one blocking the call, an endpoint choosing what reaches it. Nobody objects to that, I run a spam filter myself. What's actually happening with site blocking is the phone company deciding, on its own authority, that nobody on its network gets to dial a particular number, because of what the company believes is happening on the other end of the line. That's not customer choice. That's the carrier appointing itself the party that decides which conversations are allowed to happen.

The highway analogy fares worse. Stephens writes that "site blocking is helping to maintain good order on the roads and prevent the mass transport of illegal goods over the internet highway," comparing static blocking orders to a permanent stop sign and dynamic ones to rush-hour parking restrictions. It's a tidy image and it doesn't hold up. An ISP isn't a highway patrol officer, and packets aren't trucks with visible cargo you can pull over and inspect. Most traffic these days is encrypted, the infrastructure is shared the way a Hong Kong-registered netblock routed out of Amsterdam turned out to be sharing address space with who knows how many other operators, and blocking a destination doesn't seize anything or take it out of circulation. It just stops one network's customers from reaching it by one particular route, while everyone else on every other network, or anyone with a VPN, gets there in seconds. Calling that "good order on the roads" makes population-scale blocking sound like routine traffic management. The more honest physical-world comparison is a roadblock sealing off an entire address because someone decided unlawful activity might be happening inside, with none of the process that would normally have to precede that.

There's a real irony buried in Stephens choosing a road metaphor at all, because that exact image is usually used to explain the opposite point. The internet's core design principle, laid out in RFC 1958, is that "the network's job is to transmit datagrams as efficiently and flexibly as possible. Everything else should be done at the fringes." The network was built specifically not to care what's in the packets, on purpose, because pushing intelligence and judgment to the edges is what let the internet outcompete every centrally managed network that came before it. Site blocking takes that same road and asks the road itself to start reading the cargo manifest and deciding what gets through. That's not maintaining order on a highway designed to be neutral. It's converting the highway into the checkpoint.

None of this means piracy is fine, and I'm not going to pretend Stephens is wrong that some of these sites bundle malware with the stolen content, because plenty do. But that's an argument for going after the site, the host, the payment processor, or the advertiser funding it, not for conscripting every residential ISP in the country into running a content court on its own network. TekSavvy has said as much every time one of these orders has landed on its doorstep, and it's the smallest of the nine or ten named respondents each time, meaning the compliance cost of building and maintaining blocking infrastructure falls hardest on exactly the independent ISPs that Canadian telecom policy claims to want more of. Enforcement aimed at the actual bad actor doesn't have that problem. Enforcement embedded in the pipe does, and it scales that problem to every subscriber on every network, whether or not they ever went near the site in question.

If you think this is a hypothetical concern, it isn't. In 2005, Telus blocked a single pro-union website during a labour dispute and took 766 unrelated sites down with it, purely because they shared a server. When the CRTC rejected Bell's FairPlay Canada blocking proposal in 2018, over-blocking exactly like that was one of the loudest objections on the record, and the Commission agreed it didn't even have the jurisdiction to run a blocklist safely. Even Friend MTS, the anti-piracy vendor whose monitoring underpins Canada's sports blocking order, has written publicly about Italy's Piracy Shield blocking Cloudflare IPs and taking out a prison volunteers association and a telecoms company along with the intended target. I've written before about Spain blocking Cloudflare's IP ranges so aggressively that ordinary developers couldn't run a docker pull. Every one of these regimes insisted it would only ever hit the intended target. None of them did.

So what can we do about this? Start by admitting how little any of us actually know. I only caught Bell's block because a friend happened to buy service from a brand-new reseller, I happened to know someone on Cogeco willing to run a control test, and I happened to be curious enough to traceroute the same address twice in one day. That's not a monitoring system, that's a fluke, and it means nobody, not journalists, not the CRTC, not the ISPs' own customers, actually knows how often this happens, on which networks, or under which of the two, three, or more legal authorities now available to justify it. What is Rogers doing on its own network? Telus? Cogeco, if it's genuinely under-enforcing its own court obligations rather than over-enforcing like Bell? Right now the honest answer is that nobody has checked, because checking requires exactly the kind of manual, one-off forensic work I just spent six weeks doing for a single IP address.

Other countries have already built the tool for this. The UK's Open Rights Group runs blocked.org.uk, which tests any submitted URL against the country's major ISPs and lets the public see the results. When it launched, ORG had tested over 100,000 sites and found that almost one in five were blocked by at least one provider, including a church, a post-pregnancy health resource, and a Porsche broker, and in a detail I can't make up, BT and Virgin Media both ended up blocking the Blocked! site itself. Globally, the Open Observatory of Network Interference has run the same idea at scale since 2012, volunteers run a probe app that tests for network interference and publishes every result as open data in real time, more than a billion measurements from over 200 countries so far. Canada doesn't have anything like either one. We should. A public, ISP-labelled record of what Canadians actually can't reach, tested systematically rather than discovered by accident, would turn every version of this argument from "I think Bell might be doing this" into a dataset a journalist, a regulator, or a competing ISP could actually check.

Bell hasn't explained, anywhere on the public record, which authority caused this specific block, and there's no indication anyone outside the company could find out even if they asked. That's the whole argument in one sentence. A commissioner is already on record inside the CRTC warning that carrier discretion has outrun its governance, an industry consultant is still out there defending the practice with analogies that fall apart under five minutes of scrutiny, and the actual infrastructure for checking any of it, in Canada, doesn't exist yet. We built the internet on the idea that the network shouldn't care what you're sending. We're now paying ISPs to care, quietly, on their own judgment, with no obligation to tell you when they've decided you don't get to look. That's not routine traffic management. That's asking the road to become the checkpoint, and nobody voted on it.

Comments (0)

Sign in to join the discussion

Loading comments...