QUOTE(go626201 @ Sep 6 2024, 10:40 PM)
🎼aku tak percaya lagi akan apa - silap-on-se7en
still going to proceed with my own DNS resolver
Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!
|
|
Sep 6 2024, 11:05 PM
Return to original view | IPv6 | Post
#101
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
|
|
|
|
|
|
Sep 7 2024, 12:29 AM
Return to original view | IPv6 | Post
#102
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(Khan92 @ Sep 6 2024, 11:10 PM) Berbayar as in i still need VPS somewhere.Version A1 of completed solution requires root access to install software and related config. Gonna spend some coding time tonight to come up with version B1, to eliminate need for root access. I'm avoiding need for VPN and Bind9-or-similar, as I want it to be universal solution that can run without configuring inside router, and on mobile. |
|
|
Sep 7 2024, 02:34 PM
Return to original view | IPv6 | Post
#103
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(Rhetoric @ Sep 7 2024, 12:13 PM) dia akui diri sendiri bukan pakar IT, tetapi sibuk nak beri komen akan hal yang dia tak ada kelayakan.dia ingat keperluan DNS tak bertapis ni hanya jika hendak buat jenayah. BladeRider88 liked this post
|
|
|
Sep 8 2024, 03:21 AM
Return to original view | IPv6 | Post
#104
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(BladeRider88 @ Sep 7 2024, 09:46 PM) Maybe some people don't understand this, let me rephrase it hey, your parents might blacklist your lover, and your parents might intercept your love letters and hid them from even reaching you altogether.Your lover send you a love letter to your house, but your parents saw it and hide it from you, does it even fair for you especially your privacy! They are invading your privacy and they do not let you see your lover's love letter, heck you might though your lover no longer loves you by stop writing to you 🤣🤣🤣 .... but your parents will not write love letters and later claim it to be from your lover. |
|
|
Sep 8 2024, 03:24 AM
Return to original view | IPv6 | Post
#105
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
|
|
|
Sep 8 2024, 10:09 AM
Return to original view | IPv6 | Post
#106
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
Either TM don't know what does "transparent proxy" means, OR, MCMC does not know what "hijacking" means. Potato. Potahto. Regardless, this heartbreaking state of going-ons is only evident of a serious lack of understanding in the concept of networking and security, which both entities are supposed to grasp. PRSXFENG liked this post
|
|
|
|
|
|
Sep 8 2024, 11:51 AM
Return to original view | IPv6 | Post
#107
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(kwss @ Sep 8 2024, 10:39 AM) I refuse to believe they don't know. Every telco got the memo right. When I first tested Celcom, they did everything to the dot. UDP 53, all addresses, nothing else. transparent proxy means you do it without people noticing.TM network is huge, if people there are this incompetent, I think it would have fallen apart by now. For whatever shit they pulled, ini semua kerja orang gila... this is traight up hijacking. so it means TM went beyond when MCMC say it wants "transparent proxy", or MCMC bodoh don't know difference between "transparent" and straight -up hijacking. bboth bodo. |
|
|
Sep 8 2024, 08:02 PM
Return to original view | IPv6 | Post
#108
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
|
|
|
Sep 9 2024, 01:21 PM
Return to original view | IPv6 | Post
#109
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
and here i am, signed up VPC for heart bypass. luckily it's just <$1/mth BladeRider88 liked this post
|
|
|
Sep 9 2024, 01:45 PM
Return to original view | IPv6 | Post
#110
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
|
|
|
Sep 9 2024, 02:51 PM
Return to original view | IPv6 | Post
#111
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
urrrghhh.... just realised that Android is using DoT, so it will be vulnerable to TM's hijacking.
iOS is using DoH GET, so it's working. |
|
|
Sep 9 2024, 03:00 PM
Return to original view | IPv6 | Post
#112
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(PRSXFENG @ Sep 9 2024, 02:54 PM) Actually, Android Private DNS does support DoH read that earlier. i would imagine it already grown since 2022.Problem: it only supports well known servers those well known servers? Cloudflare and Google only Never heard any more updates after that https://security.googleblog.com/2022/07/dns...in-android.html I personally just use a client like Nebulo or RethinkDNS |
|
|
Sep 10 2024, 08:19 PM
Return to original view | IPv6 | Post
#113
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(hazairi @ Sep 10 2024, 08:12 PM) each Ethernet frame have protocol header.each IP frame have protocol header. each application packet have protocol header. those will take some space in addition to your actual user data payload. unless your router AND LAN card are both capable of 2.5Gbps, at most you can get is 940Mbps. if using Wifi, still have to check whether both sides are capable of communicating at higher capacity. |
|
|
|
|
|
Sep 10 2024, 08:21 PM
Return to original view | IPv6 | Post
#114
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
anyone knows if Unifi Plus Box can be repurposed with mainstream linux distros? don't want those restrictive distros with limited OS packages.
eager to use it for mapping unsecured DNS from dhcp LAN to secure DNS, through IPsec tunnel.. i don't think Play store have app capable of performing the above intent upon every reboot (after power restore). |
|
|
Sep 10 2024, 09:07 PM
Return to original view | IPv6 | Post
#115
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(BenYeeHua @ Sep 10 2024, 08:25 PM) Normally those device got left the JTAG or dev port for connect ADB, check youtube or yourself la. :thumbsup: But I think it need bl unlock, which break DRM L1. QUOTE(PRSXFENG @ Sep 10 2024, 08:25 PM) All I know is the 1st gen Unifi Plus Box is a rebranded Skyworth LEAP S1 with the MicroSD Card Port deleted baaah, i don't have capacity or patience if having to pry open and pin here and there. powered by an Amlogic S905X2, with 2GB RAM and 8GB of Flash also rebranded as the MECOOL KM2 and STRONG LEAP S1 There is little info out there beyond like https://xdaforums.com/t/flashing-strong-leap-s1.4615195/ no time and no conducive working@home enviroment that can support such enthusiastic endeavour. but it is such a waste that i have 2 more V1 and V2 lying idle in store room. would have been good if there's app that can do the pony tricks i want, but it will be tricky if needing to relaunch apps again and again, especially when i am away. (i have a 2nd V2 being used for Android gaming purpose in kids' bedroom.) |
|
|
Sep 10 2024, 09:39 PM
Return to original view | IPv6 | Post
#116
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
is BiliBili tv app working?
No change at all to my router config. But this is 1st time i launched since TM fooled around with DNS. |
|
|
Sep 11 2024, 12:37 PM
Return to original view | IPv6 | Post
#117
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(Moogle Stiltzkin @ Sep 11 2024, 05:19 AM) is dot or doh better? got too involved as i am working/worked on DNS proxying the past few nights. i did dot at router, cauz my users r not savvy enough to go browser enable doh (go figure). You can test here if it's working or not https://one.one.one.one/help/ an endeavour which itself involved research purposes, with the achieved outcome is obviously meant to facilitate future research purposes. so far i have DoH working in iphone, ipad, windows, and linux. android unfortunately requires DoT, which i am avoiding because its default port tcp/853 can be detected and thus subject to blocking - and worst, hijacking. -- i'm ignoring cost of creating and cost of deciphering DNS wire payload, which is applicable to each below. DNS no udp/53 protocol penalty DNS-over-TLS tcp/853; cost of establishing TCP session, cost of negotiating secure TLS session, cost of tearing TCP session DNS-over-HTTP/1, DNS-over-HTTP/1.1, DNS-over-HTTP/2 tcp/443; cost of establishing TCP session, cost of negotiating secure TLS session, cost of parsing HTTP request and response, cost of tearing down TCP session DNS-over-HTTP/3, which runs over QUIC udp/443; cost of negotiating QUIC session, cost of parsing HTTP request and response https://www.f5.com/glossary/quic-http3 ![]() -- instead of using DoH-proxy reinvented by people out there, i decided to use nginx as my DNS-over-HTTPS forwarder. no need to reinvent the wheel. immediately can support all HTTP/1 to HTTP/3, tcp and quic protocols. and specifically choosing nginx; because i can hide my DNS-over-HTTPS entry point behind normal web hosting. Unless one knows the exact https://what-is-my-exact-name/, you shouldn't be able to identify it nor use it. Hiding in plain sight. -- (oh, yes. i'm bragging.) This post has been edited by Oltromen Ripot: Sep 11 2024, 12:48 PM zellleonhart, BladeRider88, and 2 others liked this post
|
|
|
Sep 11 2024, 03:00 PM
Return to original view | IPv6 | Post
#118
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(BladeRider88 @ Sep 11 2024, 02:18 PM) For Android i know that you can use AdGuard or NexDNS app to get DoH i don't want to use app lah.This 1Gbps package last for 24 months only or permanent? just want built-in support. that's why i am going the extra mile to set up my own. if use app or vpn, battery will masuk drain faster... QUOTE(zellleonhart @ Sep 11 2024, 02:48 PM) I am using nginx to forward DoH queries to my AGH so that I can use https://my-doh-address/somethingelse instead of /dns-query too. But I am still stuck with DoT on android (when it's on mobile data) if I don't use to use third party apps for DNS right? Official document:only Google and Cloudflare can DoH as secure DNS in Android - for the padt 2 years still no progress!(?) |
|
|
Sep 11 2024, 03:11 PM
Return to original view | IPv6 | Post
#119
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(BladeRider88 @ Sep 11 2024, 03:05 PM) True also but app can give you protection when you are out from your home network, your 4G/5G network also can be hijacked remember? i have not found solution to this dilemma of wanting to use own DoH in Android.So if you using VPN to connect back to your own server, it still will drain battery too so still using official adguard-dns.com in my Android. iOS can already use DoH system-wide; hepi. i selfishly refuse to accept app-based or vpn-based solution whether in Android or iOS. not that desperate yet since MCMC is paused at the moment. |
|
|
Sep 11 2024, 03:41 PM
Return to original view | IPv6 | Post
#120
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,034 posts Joined: Dec 2019 |
QUOTE(BladeRider88 @ Sep 11 2024, 03:21 PM) EDIT: 1. i already read of those 2 as early as yesterday morningI did some research and i come across this https://www.androidpolice.com/android-dns-o...https-mainline/ Maybe you can give it a try? Since it does not involved any apps and it is bake into the system EDIT: I tried on CF and it works~ ![]() ![]() 2. ... and somebody pointed it out to me again yesterday afternoon 3. ... which i mentioned again in today afternoon 4. ... which you again invariably mentioned again through another article. so lets laugh at google for such mediocre effort. -- those cloudflare and google addresses are capable of both DoT and DoH. so when we use them as Android's Secure DNS target; how can we be sure whether it's really using DoH? and not DoT? i know that my own DoH didn't even log any https request. |
|
Topic ClosedOptions
|
| Change to: | 0.1173sec
0.46
7 queries
GZIP Disabled
Time is now: 13th December 2025 - 08:31 PM |