Re: strange problems with some gentoo sites as seen from Russia
Jaco Kroon <[email protected]>
| Newsgroups | gmane.linux.gentoo.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, Gentoo hat off. ISP hat on. This is a "sensitive" topic for me that hits close to home. Sorry. Not aimed at you, unfortunately I do see a trend that I feel do need to be addressed. Which I could post this to a much larger audience. On 2026/05/19 10:30, Dale wrote: > On 5/19/26 2:33 AM, Alexey Sokolov wrote: >> 19.05.2026 02:19, Eli Schwartz пишет: >>> A self-hosted VPN is also useful for connecting to your work intranet, >>> since inside the work's own self-hosted VPN, you are in practice >>> "inside" the work intranet. Working-from-home might need this. >>> >>> Funnily enough, no VPN companies advertise this intranet use case. >> That's because they don't usually provide such services. Why advertise >> what they don't do? >> >> Normally this use case requires the work to host their VPN server. For a >> separate VPN company to do this, they'd need to route their clients in >> some other way than just to internet through their servers. >> >> There are some VPN companies which do this though, but it's not as >> common. > > My problem is that I don't trust any ISP. My previous ISP was sharing > info with others about customer traffic without any legal orders to do > so. I don't recall how that was discovered but it was a massive > thing. They were not alone tho as a lot of ISPs do that. After all, > for the Govt, either share data or we shut you down or some other > threat. Sure, they can fight it in court but in the meantime, they > down until a court reverses the order, even if the original order is > illegal. > > What gets me tho, most all VPNs does the same thing, even use the same > software quite often. People say one is bad but the one they use is > the only good one, sometimes with a financial interest in the claim as > well. Given almost all of them work the same way, there really isn't > one that is that much better than the other except maybe for customer > service. That would likely be the biggest difference. I've had to > reach out to customer service a few times with mine. It's not the > fastest response but it is pretty good and they are very helpful. > Thing is, I don't need it much once I got it set up and working. As per Eli, all you're doing is moving the point of trust. As someone that works for an ISP (Operate the core network, both IP and Voice - and use an insane amount of Gentoo in performing those duties) I am inclined to take huge exception to this blanket statement that we're all participating in this, what I personally consider to be highly unethical, behaviour. But I won't because frankly, I do see the trend and to an unacceptably large degree have to concede your point. Please don't think VPN providers are benevolent. Everything but. From a technical and "anti VPN" perspective, the number of support calls we've had to deal with about "shitty internet" just to find that users are tunnelling all traffic through a VPN that sits 200ms or even 450ms (round-trip) away ... because you cannot trust your ISP (But sure, you can trust some VPN provider in some other jurisdiction more ...) ... and then complaining that their gaming ping is terrible ... or that their streaming services are experiencing major packet loss. All I'm asking is to please condemn the behaviour, but not assume the blanket position that we're all participating in this behaviour. What you really should push for is end to end encryption. Sure, even that has side-information leakage, and if I were so inclined, I'd still be able determine or at least infer which sites your visiting, and if I really wanted to, how much bandwidth to/from each site ... whatever, that information is only useful to us to optimise bandwidth paths to ensure that customers have the best possible experience. I'm inclined to say "with great power comes great responsibility". Reality is that the only real bandwidth data we as ISPs care about answers the following two questions: 1. To which remote ASNs are we transmitting, at which rates, and is our egress paths as optimal as it can and should be? 2. From which remote ASNs are we receiving traffic, at which rates, which ingress links is that traffic arriving, and is that as optimal as it can be? Then it becomes a matter of balancing costs and optimality. If we're receiving 10GB of traffic from a remote side per month, probably not worth the cost or effort to optimize, but turn that into 10TB and suddenly the sum looks different. We really don't care what you do with your access - we're not law enforcement. We don't care how much data you use - we care that you have a good experience. You did touch on two aspects, which I think is relevant, and not always in line and should be measured separately: 1. Ethical behaviour (ie, Trust). 2. Customer service. These two topics are independent. Obviously there are a bunch of other technical merits like reliability etc ... but I don't think their applicable in the context of the discussion. Rant done. > > I do want to tackle the tunnel thing one day tho. Towards what purpose? We use tunnels ourselves for certain network monitoring aspects usually, and for providing weird network access fulfilling specific customer requirements, but a tunnel is a tool, like any other, including VPNs (Heck, from my perspective a tunnel is a form of VPN). It has it's uses, it's time, and it's place. Use it where it's needed, but don't force it into every possible situation like trying to fit a round peg into a square hole. Kind regards, Jaco