Re: strange problems with some gentoo sites as seen from Russia

Jaco Kroon <[email protected]>
Newsgroups gmane.linux.gentoo.devel
Message-ID <[email protected]>
Hi Sam and Dale in particular,

On 2026/05/26 12:19, Sam James wrote:
> Sam James <[email protected]> writes:
>
>> Dale <[email protected]> writes:
>>
>>> On 5/25/26 11:06 PM, Sam James wrote:
>>>> Dale <[email protected]> writes:
>>>>
>>>>> On 5/19/26 5:37 AM, Jaco Kroon wrote:
>>>>> [...]
>>>>> If you don't like VPNs, don't use one.  That is your decision to
>>>>> make.  However, my decision to use one is mine and you shouldn't tell
>>>>> me not use one because you don't like them.  Would you want someone
>>>>> who tried Gentoo but found it to be to difficult to maintain to say no
>>>>> one else should use Gentoo either?  Would that seem fair to you?
>>>>> After all, Gentoo is a bit more work to maintain and some just might
>>>>> think that is to much work.
>>>> Yes, but this thread has discussion of VPNs meaning people have trouble
>>>> and then bother us with it.
>>> I only posted so it would be known this was a problem that affected
>>> more than one person and more than one country as well.  It was an
>>> attempt to give additional info, not a request for help or bothering
>>> anyone.
>> I didn't say *you* were. I'm saying that Jaco's complaining about VPNs
>> was because of people using dodgy providers, and then they complain.
>>
>> That is exactly what I was talking about at
>> https://public-inbox.gentoo.org/gentoo-dev/[email protected]/,
>> which is how we got here.
> That is, we've had other people say exactly the same thing, which is how
> I sent that message to begin with. Even if you're not complaining,
> people have had trouble with VPNs.

I think to try and close the loop, we're all saying VPNs have their 
legitimate uses, yours (Dale) may be legit - I'm not in a position to 
judge your specific use, nor do I actually care.  Many others certainly 
are not.  This is another long writing, and I sincerely hope my last 
"contribution" to this discussion.  I'm hoping I managed to provide a 
more fair/objective view this time around.  But I suspect I'm still 
skewed on the service provider side (since that's where my experience 
lies).  I'm hoping that it provides sufficient perspective as to what 
the real problem is and maybe, and just maybe, someone will point out 
something that leads to a good solution.

My *personal* gripe was with the way in which it was blanket 
assumed/stated/implied all ISPs sell data.  Stating it that way, may not 
have been your intent, but I did find that more offensive than I thought 
I would.  Perhaps knee-jerk as to some of our own (fortunately in the 
far minority) customers who insist they must use a VPN to "anonymise" or 
"hide" their traffic, but then complain to us (ISP) because they're 
having a terrible user experience.  That's not on you, that's just my 
history and context, and that's on me.

Sam's statement that a VPN is just another ISP is (imho) a crude but 
accurate one.  Which means all you're doing is moving the point of 
trust.  You may not trust your local connecting ISP, so you tunnel 
through them to another point of connection (VPN).

Those VPNs, with IPv4 depletion fast getting worse, is almost certainly 
using a form of Carrier-Grade or Large-Scale NAT. (CG-NAT or LSN - 
depending on your lingo preference.)  This means potentially 10s if not 
100s or 1000s of users behind small blocks of IPv4 addresses.

The prevalence of VPN use also has the side effect of accelerating the 
IPv4 depletion rate in that an already scarce resource is made even more 
scarce for (from my perspective) no real benefit in most, or at least 
many, cases.  I'm not sure even to the real benefit related to 
protection of personal data even to be honest that seems to be the big 
selling point/marketing perspective coming from the VPN providers.

Just because a VPN provider will publicly refuse to provide customer 
details to a .gov does not mean they don't use those same details either 
themselves or some related party for nefarious purposes.  Trust isn't 
just about one factor, it's about a much larger picture.  You're 
complaining about your ISP selling data, but how do you know your VPN 
provider isn't sniffing your traffic looking for plaintext usernames and 
passwords in the traffic (End to end encryption ... really is a must for 
anything so sensitive)?  Or also selling your data for that matter, just 
in a less obvious way?

Similar arguments for using "public" DNS services such as quad-ONE, 
quad-EIGHT or quad-NINE.  And even DNS over HTTPS.  It just moves the 
point of trust from one place to another.

The real problem you're facing is that just because you're not using 
your provider for nefarious purposes, does not mean others behind those 
same masqueraded IPs and IP blocks aren't doing nefarious things.  Any 
VPN provider that refuses to share details with .gov (and law 
enforcement by implication) is going to be gravitated to by "black 
hats", it's obvious there will be a certain attraction of these entities 
towards such contemplated VPN providers.

It is thus not entirely unexpected that VPN services gets blocked, even 
though the intention may not be to block VPN use specifically (The only 
entities I'm aware of that goes out of their way to block VPN services 
is media streaming services that has to prove compliance with region 
release rules - if those rules goes away, so does the motivation for 
streaming services to provide different content in different regions, 
and VPN use will likely decline by several factors).

I don't think you can blame any service provider for protecting 
themselves from detected "bad activity".  If I could tell you the things 
service providers do to detect and block these unwanted activities, and 
how much money, time and effort we spend on it ... I suspect many people 
would be shocked.  Without blocking these I suspect we'd probably be 
burning several kW extra on power just servicing brute-force password 
authentication attacks - not to mention facing a greater risk of data 
breeches happening.  The amounts of CPU cycles we spend on filtering 
illegitimate use of our services probably exceeds the legitimate use by 
a factor of 3 to 5, quite possibly more.

Please note:  I'm in zero position to judge you, your ISP, or your VPN 
provider.  Nor am I trying to.  The above, and my previous writing, is 
just my general perspective based on historic experiences.  Aimed at 
providing context as to why VPN use may end up resulting in getting you 
denied access to certain services.

As to what Gentoo can and should do to grant you access through the VPN 
of your choice, I do not think my opinion counts for much in the bigger 
scheme of things, I believe that the first obligation is to protect the 
infrastructure itself.  Granted one aspect of security is availability - 
and right now that availability is obviously not at 100% (as measured by 
"people with access / people who want access"), but without protections 
in place, it could drop to zero - which is a far worse position to be 
in.  I know others are in a better position to comment or make decisions 
on the matter compared to myself.  I also firmly believe that if there 
are practical suggestions as to how to improve this availability 
measurement you'd certainly have the attention of a significantly larger 
crows of people than just this mailing list.

As per one of your emails you weren't specifically asking for help, and 
just looking to add more information to get to a resolution, and I 
respect that - I don't think you were off the reservation there.  
Unfortunately the discussion has derailed a bit, and I'm really hoping 
we can put it to rest.  I suspect if you're (not you specifically as an 
individual, but any given person) going to be using a VPN chances are 
unfortunately good that unless you've got dedicated v4 space you're 
going to be grouped into the general blocks due to others abusing the 
system. And the moment you have dedicated v4 space assigned to you, 
you're no longer as anonymous as you think.  You end up being in a 
catch-22 situation and I'm not sure there are good solutions.

The AI situation described by Duncan also honestly doesn't help much.  
The additional load placed onto third parties by this (usually) 
unauthorised use is tremendous.  And he's right, things are extremely 
unlikely going to be getting easier/better/simpler any time soon.

And I'm sorry - I got the impression you felt attacked by my previous 
writing - that most certainly was not my intent.  From same I certainly 
derive that you have had some terrible experiences with your trust being 
abused in the past, it sucks big time that you had to go through some of 
those experiences that you've expressed, and that certainly provides 
perspective as to your viewpoints.  Thank you for that.

Kind regards,
Jaco
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.