Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
8 Pages « < 4 5 6 7 8 >Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
Oltromen Ripot
post Sep 6 2024, 11:05 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(go626201 @ Sep 6 2024, 10:40 PM)
I think this unblock is temporary only.
Next week will redirect again...
*
🎼aku tak percaya lagi akan apa menteri fahmi janji, 🎶
- silap-on-se7en

still going to proceed with my own DNS resolver
Oltromen Ripot
post Sep 7 2024, 12:29 AM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(Khan92 @ Sep 6 2024, 11:10 PM)
This is berbayar right?
*
Berbayar as in i still need VPS somewhere.
Version A1 of completed solution requires root access to install software and related config.

Gonna spend some coding time tonight to come up with version B1, to eliminate need for root access.

I'm avoiding need for VPN and Bind9-or-similar, as I want it to be universal solution that can run without configuring inside router, and on mobile.
Oltromen Ripot
post Sep 7 2024, 02:34 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(Rhetoric @ Sep 7 2024, 12:13 PM)
Seeing some people on twitter defending this dumbass decision irks me. Even more on the replies.

user posted image
*
dia akui diri sendiri bukan pakar IT, tetapi sibuk nak beri komen akan hal yang dia tak ada kelayakan.

dia ingat keperluan DNS tak bertapis ni hanya jika hendak buat jenayah.
Oltromen Ripot
post Sep 8 2024, 03:21 AM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(BladeRider88 @ Sep 7 2024, 09:46 PM)
Maybe some people don't understand this, let me rephrase it

Your lover send you a love letter to your house, but your parents saw it and hide it from you, does it even fair for you especially your privacy! They are invading your privacy and they do not let you see your lover's love letter, heck you might though your lover no longer loves you by stop writing to you

🤣🤣🤣
*
hey, your parents might blacklist your lover, and your parents might intercept your love letters and hid them from even reaching you altogether.

.... but your parents will not write love letters and later claim it to be from your lover.
Oltromen Ripot
post Sep 8 2024, 03:24 AM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(countingcrows @ Sep 7 2024, 09:53 PM)
Jangan fitnah wei. Tindakan kami murni...

user posted image

*
pffffttt.

dey MCMCM, if you are really true to your self-declared pure-hearted intent, start with blocking Facebook.

That alone should take care very very very large percentage of scam advertisements.
Oltromen Ripot
post Sep 8 2024, 10:09 AM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
Either TM don't know what does "transparent proxy" means, OR, MCMC does not know what "hijacking" means.

Potato. Potahto.

Regardless, this heartbreaking state of going-ons is only evident of a serious lack of understanding in the concept of networking and security, which both entities are supposed to grasp.
Oltromen Ripot
post Sep 8 2024, 11:51 AM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(kwss @ Sep 8 2024, 10:39 AM)
I refuse to believe they don't know. Every telco got the memo right. When I first tested Celcom, they did everything to the dot. UDP 53, all addresses, nothing else.

TM network is huge, if people there are this incompetent, I think it would have fallen apart by now. For whatever shit they pulled, ini semua kerja orang gila...
*
transparent proxy means you do it without people noticing.
this is traight up hijacking.

so it means TM went beyond when MCMC say it wants "transparent proxy",
or MCMC bodoh don't know difference between "transparent" and straight -up hijacking.

bboth bodo.
Oltromen Ripot
post Sep 8 2024, 08:02 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(dev/numb @ Sep 8 2024, 06:15 PM)
People saying “we won”. Topkek.
Battle just started.
*
win a battle.

lose the war.
Oltromen Ripot
post Sep 9 2024, 01:21 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
and here i am, signed up VPC for heart bypass.

luckily it's just <$1/mth
Oltromen Ripot
post Sep 9 2024, 01:45 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(kingkingyyk @ Sep 9 2024, 01:23 PM)
Which provider you use?  biggrin.gif
*
hmmmm are you TM staff?

unifi, perhaps? 😂

This post has been edited by Oltromen Ripot: Sep 9 2024, 02:00 PM
Oltromen Ripot
post Sep 9 2024, 02:51 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
urrrghhh.... just realised that Android is using DoT, so it will be vulnerable to TM's hijacking.

iOS is using DoH GET, so it's working.
Oltromen Ripot
post Sep 9 2024, 03:00 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(PRSXFENG @ Sep 9 2024, 02:54 PM)
Actually, Android Private DNS does support DoH

Problem: it only supports well known servers

those well known servers? Cloudflare and Google only
Never heard any more updates after that

https://security.googleblog.com/2022/07/dns...in-android.html

I personally just use a client like Nebulo or RethinkDNS
*
read that earlier. i would imagine it already grown since 2022.
Oltromen Ripot
post Sep 10 2024, 08:19 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(hazairi @ Sep 10 2024, 08:12 PM)
Anybody here who is on 1Gbps package can get 999Mbps download speed on speedtest?
*
each Ethernet frame have protocol header.
each IP frame have protocol header.
each application packet have protocol header.
those will take some space in addition to your actual user data payload.

unless your router AND LAN card are both capable of 2.5Gbps, at most you can get is 940Mbps.
if using Wifi, still have to check whether both sides are capable of communicating at higher capacity.
Oltromen Ripot
post Sep 10 2024, 08:21 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
anyone knows if Unifi Plus Box can be repurposed with mainstream linux distros? don't want those restrictive distros with limited OS packages.

eager to use it for mapping unsecured DNS from dhcp LAN to secure DNS, through IPsec tunnel..

i don't think Play store have app capable of performing the above intent upon every reboot (after power restore).
Oltromen Ripot
post Sep 10 2024, 09:07 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(BenYeeHua @ Sep 10 2024, 08:25 PM)
Normally those device got left the JTAG or dev port for connect ADB, check youtube or yourself la. :thumbsup:
But I think it need bl unlock, which break DRM L1.
*
QUOTE(PRSXFENG @ Sep 10 2024, 08:25 PM)
All I know is the 1st gen Unifi Plus Box is a rebranded Skyworth LEAP S1 with the MicroSD Card Port deleted
powered by an Amlogic S905X2, with 2GB RAM and 8GB of Flash
also rebranded as the MECOOL KM2 and STRONG LEAP S1

There is little info out there beyond like
https://xdaforums.com/t/flashing-strong-leap-s1.4615195/
*
baaah, i don't have capacity or patience if having to pry open and pin here and there.
no time and no conducive working@home enviroment that can support such enthusiastic endeavour.

but it is such a waste that i have 2 more V1 and V2 lying idle in store room.
would have been good if there's app that can do the pony tricks i want, but it will be tricky if needing to relaunch apps again and again, especially when i am away.

(i have a 2nd V2 being used for Android gaming purpose in kids' bedroom.)
Oltromen Ripot
post Sep 10 2024, 09:39 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
is BiliBili tv app working?

No change at all to my router config. But this is 1st time i launched since TM fooled around with DNS.
Oltromen Ripot
post Sep 11 2024, 12:37 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(Moogle Stiltzkin @ Sep 11 2024, 05:19 AM)
is dot or doh better?

i did dot at router, cauz my users r not savvy enough to go browser enable doh (go figure).

You can test here if it's working or not
https://one.one.one.one/help/
*
got too involved as i am working/worked on DNS proxying the past few nights.
an endeavour which itself involved research purposes, with the achieved outcome is obviously meant to facilitate future research purposes.

so far i have DoH working in iphone, ipad, windows, and linux.
android unfortunately requires DoT, which i am avoiding because its default port tcp/853 can be detected and thus subject to blocking - and worst, hijacking.

--

i'm ignoring cost of creating and cost of deciphering DNS wire payload, which is applicable to each below.

DNS
no udp/53 protocol penalty

DNS-over-TLS
tcp/853; cost of establishing TCP session, cost of negotiating secure TLS session, cost of tearing TCP session

DNS-over-HTTP/1, DNS-over-HTTP/1.1, DNS-over-HTTP/2
tcp/443; cost of establishing TCP session, cost of negotiating secure TLS session, cost of parsing HTTP request and response, cost of tearing down TCP session

DNS-over-HTTP/3, which runs over QUIC
udp/443; cost of negotiating QUIC session, cost of parsing HTTP request and response

https://www.f5.com/glossary/quic-http3

user posted image

--

instead of using DoH-proxy reinvented by people out there, i decided to use nginx as my DNS-over-HTTPS forwarder. no need to reinvent the wheel.
immediately can support all HTTP/1 to HTTP/3, tcp and quic protocols.
and specifically choosing nginx; because i can hide my DNS-over-HTTPS entry point behind normal web hosting.
Unless one knows the exact https://what-is-my-exact-name/, you shouldn't be able to identify it nor use it. Hiding in plain sight.

--

(oh, yes. i'm bragging.)

This post has been edited by Oltromen Ripot: Sep 11 2024, 12:48 PM
Oltromen Ripot
post Sep 11 2024, 03:00 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(BladeRider88 @ Sep 11 2024, 02:18 PM)
For Android i know that you can use AdGuard or NexDNS app to get DoH
This 1Gbps package last for 24 months only or permanent?
*
i don't want to use app lah.
just want built-in support.
that's why i am going the extra mile to set up my own.

if use app or vpn, battery will masuk drain faster...

QUOTE(zellleonhart @ Sep 11 2024, 02:48 PM)
I am using nginx to forward DoH queries to my AGH so that I can use https://my-doh-address/somethingelse instead of /dns-query too. But I am still stuck with DoT on android (when it's on mobile data) if I don't use to use third party apps for DNS right?
*
Official document:
only Google and Cloudflare can DoH as secure DNS in Android - for the padt 2 years still no progress!(?)
Oltromen Ripot
post Sep 11 2024, 03:11 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(BladeRider88 @ Sep 11 2024, 03:05 PM)
True also but app can give you protection when you are out from your home network, your 4G/5G network also can be hijacked remember?  whistling.gif

So if you using VPN to connect back to your own server, it still will drain battery too  whistling.gif
*
i have not found solution to this dilemma of wanting to use own DoH in Android.
so still using official adguard-dns.com in my Android.
iOS can already use DoH system-wide; hepi.

i selfishly refuse to accept app-based or vpn-based solution whether in Android or iOS.
not that desperate yet since MCMC is paused at the moment.
Oltromen Ripot
post Sep 11 2024, 03:41 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(BladeRider88 @ Sep 11 2024, 03:21 PM)
EDIT:

I did some research and i come across this

https://www.androidpolice.com/android-dns-o...https-mainline/

Maybe you can give it a try? Since it does not involved any apps and it is bake into the system

EDIT:

I tried on CF and it works~

user posted image
user posted image
*
1. i already read of those 2 as early as yesterday morning

2. ... and somebody pointed it out to me again yesterday afternoon

3. ... which i mentioned again in today afternoon

4. ... which you again invariably mentioned again through another article.

so lets laugh at google for such mediocre effort.

--

those cloudflare and google addresses are capable of both DoT and DoH.
so when we use them as Android's Secure DNS target; how can we be sure whether it's really using DoH? and not DoT?
i know that my own DoH didn't even log any https request.

8 Pages « < 4 5 6 7 8 >Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.1173sec    0.46    7 queries    GZIP Disabled
Time is now: 13th December 2025 - 08:31 PM