Re: strange problems with some gentoo sites as seen from Russia
Jaco Kroon <[email protected]>
| Newsgroups | gmane.linux.gentoo.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Sam and Dale in particular, On 2026/05/26 12:19, Sam James wrote: > Sam James <[email protected]> writes: > >> Dale <[email protected]> writes: >> >>> On 5/25/26 11:06 PM, Sam James wrote: >>>> Dale <[email protected]> writes: >>>> >>>>> On 5/19/26 5:37 AM, Jaco Kroon wrote: >>>>> [...] >>>>> If you don't like VPNs, don't use one. That is your decision to >>>>> make. However, my decision to use one is mine and you shouldn't tell >>>>> me not use one because you don't like them. Would you want someone >>>>> who tried Gentoo but found it to be to difficult to maintain to say no >>>>> one else should use Gentoo either? Would that seem fair to you? >>>>> After all, Gentoo is a bit more work to maintain and some just might >>>>> think that is to much work. >>>> Yes, but this thread has discussion of VPNs meaning people have trouble >>>> and then bother us with it. >>> I only posted so it would be known this was a problem that affected >>> more than one person and more than one country as well. It was an >>> attempt to give additional info, not a request for help or bothering >>> anyone. >> I didn't say *you* were. I'm saying that Jaco's complaining about VPNs >> was because of people using dodgy providers, and then they complain. >> >> That is exactly what I was talking about at >> https://public-inbox.gentoo.org/gentoo-dev/[email protected]/, >> which is how we got here. > That is, we've had other people say exactly the same thing, which is how > I sent that message to begin with. Even if you're not complaining, > people have had trouble with VPNs. I think to try and close the loop, we're all saying VPNs have their legitimate uses, yours (Dale) may be legit - I'm not in a position to judge your specific use, nor do I actually care. Many others certainly are not. This is another long writing, and I sincerely hope my last "contribution" to this discussion. I'm hoping I managed to provide a more fair/objective view this time around. But I suspect I'm still skewed on the service provider side (since that's where my experience lies). I'm hoping that it provides sufficient perspective as to what the real problem is and maybe, and just maybe, someone will point out something that leads to a good solution. My *personal* gripe was with the way in which it was blanket assumed/stated/implied all ISPs sell data. Stating it that way, may not have been your intent, but I did find that more offensive than I thought I would. Perhaps knee-jerk as to some of our own (fortunately in the far minority) customers who insist they must use a VPN to "anonymise" or "hide" their traffic, but then complain to us (ISP) because they're having a terrible user experience. That's not on you, that's just my history and context, and that's on me. Sam's statement that a VPN is just another ISP is (imho) a crude but accurate one. Which means all you're doing is moving the point of trust. You may not trust your local connecting ISP, so you tunnel through them to another point of connection (VPN). Those VPNs, with IPv4 depletion fast getting worse, is almost certainly using a form of Carrier-Grade or Large-Scale NAT. (CG-NAT or LSN - depending on your lingo preference.) This means potentially 10s if not 100s or 1000s of users behind small blocks of IPv4 addresses. The prevalence of VPN use also has the side effect of accelerating the IPv4 depletion rate in that an already scarce resource is made even more scarce for (from my perspective) no real benefit in most, or at least many, cases. I'm not sure even to the real benefit related to protection of personal data even to be honest that seems to be the big selling point/marketing perspective coming from the VPN providers. Just because a VPN provider will publicly refuse to provide customer details to a .gov does not mean they don't use those same details either themselves or some related party for nefarious purposes. Trust isn't just about one factor, it's about a much larger picture. You're complaining about your ISP selling data, but how do you know your VPN provider isn't sniffing your traffic looking for plaintext usernames and passwords in the traffic (End to end encryption ... really is a must for anything so sensitive)? Or also selling your data for that matter, just in a less obvious way? Similar arguments for using "public" DNS services such as quad-ONE, quad-EIGHT or quad-NINE. And even DNS over HTTPS. It just moves the point of trust from one place to another. The real problem you're facing is that just because you're not using your provider for nefarious purposes, does not mean others behind those same masqueraded IPs and IP blocks aren't doing nefarious things. Any VPN provider that refuses to share details with .gov (and law enforcement by implication) is going to be gravitated to by "black hats", it's obvious there will be a certain attraction of these entities towards such contemplated VPN providers. It is thus not entirely unexpected that VPN services gets blocked, even though the intention may not be to block VPN use specifically (The only entities I'm aware of that goes out of their way to block VPN services is media streaming services that has to prove compliance with region release rules - if those rules goes away, so does the motivation for streaming services to provide different content in different regions, and VPN use will likely decline by several factors). I don't think you can blame any service provider for protecting themselves from detected "bad activity". If I could tell you the things service providers do to detect and block these unwanted activities, and how much money, time and effort we spend on it ... I suspect many people would be shocked. Without blocking these I suspect we'd probably be burning several kW extra on power just servicing brute-force password authentication attacks - not to mention facing a greater risk of data breeches happening. The amounts of CPU cycles we spend on filtering illegitimate use of our services probably exceeds the legitimate use by a factor of 3 to 5, quite possibly more. Please note: I'm in zero position to judge you, your ISP, or your VPN provider. Nor am I trying to. The above, and my previous writing, is just my general perspective based on historic experiences. Aimed at providing context as to why VPN use may end up resulting in getting you denied access to certain services. As to what Gentoo can and should do to grant you access through the VPN of your choice, I do not think my opinion counts for much in the bigger scheme of things, I believe that the first obligation is to protect the infrastructure itself. Granted one aspect of security is availability - and right now that availability is obviously not at 100% (as measured by "people with access / people who want access"), but without protections in place, it could drop to zero - which is a far worse position to be in. I know others are in a better position to comment or make decisions on the matter compared to myself. I also firmly believe that if there are practical suggestions as to how to improve this availability measurement you'd certainly have the attention of a significantly larger crows of people than just this mailing list. As per one of your emails you weren't specifically asking for help, and just looking to add more information to get to a resolution, and I respect that - I don't think you were off the reservation there. Unfortunately the discussion has derailed a bit, and I'm really hoping we can put it to rest. I suspect if you're (not you specifically as an individual, but any given person) going to be using a VPN chances are unfortunately good that unless you've got dedicated v4 space you're going to be grouped into the general blocks due to others abusing the system. And the moment you have dedicated v4 space assigned to you, you're no longer as anonymous as you think. You end up being in a catch-22 situation and I'm not sure there are good solutions. The AI situation described by Duncan also honestly doesn't help much. The additional load placed onto third parties by this (usually) unauthorised use is tremendous. And he's right, things are extremely unlikely going to be getting easier/better/simpler any time soon. And I'm sorry - I got the impression you felt attacked by my previous writing - that most certainly was not my intent. From same I certainly derive that you have had some terrible experiences with your trust being abused in the past, it sucks big time that you had to go through some of those experiences that you've expressed, and that certainly provides perspective as to your viewpoints. Thank you for that. Kind regards, Jaco