Re: strange problems with some gentoo sites as seen from Russia
Dale <[email protected]>
| Newsgroups | gmane.linux.gentoo.devel |
|---|---|
| Message-ID | <[email protected]> |
On 5/19/26 5:37 AM, Jaco Kroon wrote: > Hi, > > Gentoo hat off. ISP hat on. This is a "sensitive" topic for me that > hits close to home. Sorry. Not aimed at you, unfortunately I do see a > trend that I feel do need to be addressed. Which I could post this to a > much larger audience. > > On 2026/05/19 10:30, Dale wrote: >> On 5/19/26 2:33 AM, Alexey Sokolov wrote: >>> 19.05.2026 02:19, Eli Schwartz пишет: >>>> A self-hosted VPN is also useful for connecting to your work intranet, >>>> since inside the work's own self-hosted VPN, you are in practice >>>> "inside" the work intranet. Working-from-home might need this. >>>> >>>> Funnily enough, no VPN companies advertise this intranet use case. >>> That's because they don't usually provide such services. Why advertise >>> what they don't do? >>> >>> Normally this use case requires the work to host their VPN server. For a >>> separate VPN company to do this, they'd need to route their clients in >>> some other way than just to internet through their servers. >>> >>> There are some VPN companies which do this though, but it's not as >>> common. >> My problem is that I don't trust any ISP. My previous ISP was sharing >> info with others about customer traffic without any legal orders to do >> so. I don't recall how that was discovered but it was a massive >> thing. They were not alone tho as a lot of ISPs do that. After all, >> for the Govt, either share data or we shut you down or some other >> threat. Sure, they can fight it in court but in the meantime, they >> down until a court reverses the order, even if the original order is >> illegal. >> >> What gets me tho, most all VPNs does the same thing, even use the same >> software quite often. People say one is bad but the one they use is >> the only good one, sometimes with a financial interest in the claim as >> well. Given almost all of them work the same way, there really isn't >> one that is that much better than the other except maybe for customer >> service. That would likely be the biggest difference. I've had to >> reach out to customer service a few times with mine. It's not the >> fastest response but it is pretty good and they are very helpful. >> Thing is, I don't need it much once I got it set up and working. > As per Eli, all you're doing is moving the point of trust. As someone > that works for an ISP (Operate the core network, both IP and Voice - and > use an insane amount of Gentoo in performing those duties) I am inclined > to take huge exception to this blanket statement that we're all > participating in this, what I personally consider to be highly > unethical, behaviour. But I won't because frankly, I do see the trend > and to an unacceptably large degree have to concede your point. > > Please don't think VPN providers are benevolent. Everything but. > > From a technical and "anti VPN" perspective, the number of support > calls we've had to deal with about "shitty internet" just to find that > users are tunnelling all traffic through a VPN that sits 200ms or even > 450ms (round-trip) away ... because you cannot trust your ISP (But sure, > you can trust some VPN provider in some other jurisdiction more ...) ... > and then complaining that their gaming ping is terrible ... or that > their streaming services are experiencing major packet loss. > > All I'm asking is to please condemn the behaviour, but not assume the > blanket position that we're all participating in this behaviour. > > What you really should push for is end to end encryption. Sure, even > that has side-information leakage, and if I were so inclined, I'd still > be able determine or at least infer which sites your visiting, and if I > really wanted to, how much bandwidth to/from each site ... whatever, > that information is only useful to us to optimise bandwidth paths to > ensure that customers have the best possible experience. I'm inclined > to say "with great power comes great responsibility". Reality is that > the only real bandwidth data we as ISPs care about answers the following > two questions: > > 1. To which remote ASNs are we transmitting, at which rates, and is our > egress paths as optimal as it can and should be? > 2. From which remote ASNs are we receiving traffic, at which rates, > which ingress links is that traffic arriving, and is that as optimal as > it can be? > > Then it becomes a matter of balancing costs and optimality. If we're > receiving 10GB of traffic from a remote side per month, probably not > worth the cost or effort to optimize, but turn that into 10TB and > suddenly the sum looks different. > > We really don't care what you do with your access - we're not law > enforcement. We don't care how much data you use - we care that you > have a good experience. > > You did touch on two aspects, which I think is relevant, and not always > in line and should be measured separately: > > 1. Ethical behaviour (ie, Trust). > 2. Customer service. > > These two topics are independent. Obviously there are a bunch of other > technical merits like reliability etc ... but I don't think their > applicable in the context of the discussion. > > Rant done. > >> I do want to tackle the tunnel thing one day tho. > Towards what purpose? We use tunnels ourselves for certain network > monitoring aspects usually, and for providing weird network access > fulfilling specific customer requirements, but a tunnel is a tool, like > any other, including VPNs (Heck, from my perspective a tunnel is a form > of VPN). It has it's uses, it's time, and it's place. Use it where > it's needed, but don't force it into every possible situation like > trying to fit a round peg into a square hole. > > Kind regards, > Jaco > First of all, I said a "lot" of them do this. When a Govt who has the ability to shut your business down while they defend saying 'no', a lot of companies will comply with every request, more like demand, for info. They do so because they want to stay in business. While on one hand I can't blame them, on the other hand, it causes customers to not trust them to keep their info secure without going through a legal process, which for the Govt is already easy enough. Some will do it without a threat at all because of their politics. I strongly suspect that is what mine did but I have not researched it enough to know it for sure. Either way, it caused a serious distrust with ISPs for me. If you don't like VPNs, don't use one. That is your decision to make. However, my decision to use one is mine and you shouldn't tell me not use one because you don't like them. Would you want someone who tried Gentoo but found it to be to difficult to maintain to say no one else should use Gentoo either? Would that seem fair to you? After all, Gentoo is a bit more work to maintain and some just might think that is to much work. As to connection problems, if I have a problem with connections, I turn off the VPN and retest. If it works then, it is a VPN problem and not my ISP and I report the problem to the VPN provider. If I still have that problem, I would send the needed info to my ISP while not using a VPN to have them look into it. To be fair tho, the only problem I ever had was when they were first being set up for all the new customers as this was a new service being built from scratch. They had speed problems and they acknowledged they did. Their equipment was newly set up and they were working out the kinks and bugs. Within a couple weeks, the speed was what it should be and I have not had a problem since. Also, only had one scheduled outage for them to add new equipment. Uptime is awesome. As to trusting my VPN. I have every reason to trust them because there is a history of them refusing to share info with anyone. It has been tested by a 3rd party. I've also read in other places about customers who use the same VPN and them confirm they have never had any reason to even think their info was shared. There is also 3rd party reviews that speak highly of them with most only talking about the high monthly cost as a common negative point. I use the 2 year plan myself so that is not a problem for me. I might add, their customer service is really good. I email them with a problem and they reply pretty quick. Sometimes, they even already addressed the problem or they can share how to fix it on my end. Once it was because of the files being out of date. I simply downloaded the new files for openvpn and restarted. My biggest problem is websites that block users just because they use a VPN even tho that person, or IP address, has never abused anything. People always talk about doing things to secure their data but when people do it, then they complain about the increased security because it doesn't allow them to track everything the user does. I take a lot of precautions with my data, both that is in transit as well as what is stored locally. I have encrypted file systems here for most of my personal data. I use password tools to manage and generate passwords. That said, some websites still require actions that I don't need. The chances of someone getting my passwords is about as close to none as it gets. Heck, I don't even know the password to access my bank. Bitwarden generated it, stores it for me and my master password is not something anyone would guess. It took me several months to come up with that password. Still, because of people who use their pet's name, which is posted all over social media, as a password, I have to jump through extra hoops to access my own info. Those people are the problem, not me using a VPN, password manager, encrypted file systems etc etc to secure my info. They need to move over to my way of doing things. I certainly don't need to move to their methods. As to end to end encryption, that just moves the entity the Govt would demand info from, which may even be worse. Plus, I don't have any influence over what some obscure website I use that is free to all anyway. What do they care what I think? Heck, a company I was paying to protect my info shared it without my consent and without the proper process. Why would I expect a free website to care what I want other than having content I want to see? So, I'm using a VPN. That's settled. I do my part, and then some, to protect my data. If others did the same things, maybe ID theft wouldn't be such a problem. Maybe a whole lot of things wouldn't be such a problem. But because most people don't, the rest of us have to deal with the solutions to their problems as we already protected ours. Back to my hole now. Dale :-) :-)