Re: strange problems with some gentoo sites as seen from Russia

Jaco Kroon <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Message-ID <[email protected]>
Hi,

Gentoo hat off.  ISP hat on.  This is a "sensitive" topic for me that 
hits close to home.  Sorry.  Not aimed at you, unfortunately I do see a 
trend that I feel do need to be addressed.  Which I could post this to a 
much larger audience.

On 2026/05/19 10:30, Dale wrote:
> On 5/19/26 2:33 AM, Alexey Sokolov wrote:
>> 19.05.2026 02:19, Eli Schwartz пишет:
>>> A self-hosted VPN is also useful for connecting to your work intranet,
>>> since inside the work's own self-hosted VPN, you are in practice
>>> "inside" the work intranet. Working-from-home might need this.
>>>
>>> Funnily enough, no VPN companies advertise this intranet use case.
>> That's because they don't usually provide such services. Why advertise
>> what they don't do?
>>
>> Normally this use case requires the work to host their VPN server. For a
>> separate VPN company to do this, they'd need to route their clients in
>> some other way than just to internet through their servers.
>>
>> There are some VPN companies which do this though, but it's not as 
>> common.
>
> My problem is that I don't trust any ISP.  My previous ISP was sharing 
> info with others about customer traffic without any legal orders to do 
> so.  I don't recall how that was discovered but it was a massive 
> thing.  They were not alone tho as a lot of ISPs do that. After all, 
> for the Govt, either share data or we shut you down or some other 
> threat.  Sure, they can fight it in court but in the meantime, they 
> down until a court reverses the order, even if the original order is 
> illegal.
>
> What gets me tho, most all VPNs does the same thing, even use the same 
> software quite often.  People say one is bad but the one they use is 
> the only good one, sometimes with a financial interest in the claim as 
> well.  Given almost all of them work the same way, there really isn't 
> one that is that much better than the other except maybe for customer 
> service.  That would likely be the biggest difference.  I've had to 
> reach out to customer service a few times with mine.  It's not the 
> fastest response but it is pretty good and they are very helpful.  
> Thing is, I don't need it much once I got it set up and working.

As per Eli, all you're doing is moving the point of trust.  As someone 
that works for an ISP (Operate the core network, both IP and Voice - and 
use an insane amount of Gentoo in performing those duties) I am inclined 
to take huge exception to this blanket statement that we're all 
participating in this, what I personally consider to be highly 
unethical, behaviour.  But I won't because frankly, I do see the trend 
and to an unacceptably large degree have to concede your point.

Please don't think VPN providers are benevolent.  Everything but.

 From a technical and "anti VPN" perspective, the number of support 
calls we've had to deal with about "shitty internet" just to find that 
users are tunnelling all traffic through a VPN that sits 200ms or even 
450ms (round-trip) away ... because you cannot trust your ISP (But sure, 
you can trust some VPN provider in some other jurisdiction more ...) ... 
and then complaining that their gaming ping is terrible ... or that 
their streaming services are experiencing major packet loss.

All I'm asking is to please condemn the behaviour, but not assume the 
blanket position that we're all participating in this behaviour.

What you really should push for is end to end encryption.  Sure, even 
that has side-information leakage, and if I were so inclined, I'd still 
be able determine or at least infer which sites your visiting, and if I 
really wanted to, how much bandwidth to/from each site ... whatever, 
that information is only useful to us to optimise bandwidth paths to 
ensure that customers have the best possible experience.  I'm inclined 
to say "with great power comes great responsibility".  Reality is that 
the only real bandwidth data we as ISPs care about answers the following 
two questions:

1.  To which remote ASNs are we transmitting, at which rates, and is our 
egress paths as optimal as it can and should be?
2.  From which remote ASNs are we receiving traffic, at which rates, 
which ingress links is that traffic arriving, and is that as optimal as 
it can be?

Then it becomes a matter of balancing costs and optimality.  If we're 
receiving 10GB of traffic from a remote side per month, probably not 
worth the cost or effort to optimize, but turn that into 10TB and 
suddenly the sum looks different.

We really don't care what you do with your access - we're not law 
enforcement.   We don't care how much data you use - we care that you 
have a good experience.

You did touch on two aspects, which I think is relevant, and not always 
in line and should be measured separately:

1.  Ethical behaviour (ie, Trust).
2.  Customer service.

These two topics are independent.  Obviously there are a bunch of other 
technical merits like reliability etc ... but I don't think their 
applicable in the context of the discussion.

Rant done.

>
> I do want to tackle the tunnel thing one day tho.

Towards what purpose?  We use tunnels ourselves for certain network 
monitoring aspects usually, and for providing weird network access 
fulfilling specific customer requirements, but a tunnel is a tool, like 
any other, including VPNs (Heck, from my perspective a tunnel is a form 
of VPN).  It has it's uses, it's time, and it's place.  Use it where 
it's needed, but don't force it into every possible situation like 
trying to fit a round peg into a square hole.

Kind regards,
Jaco
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.