Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
495 Pages « < 299 300 301 302 303 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
blackbox14
post Sep 6 2024, 07:25 PM

Casual
***
Junior Member
349 posts

Joined: Jul 2012
Saw on /k tered that DoH and DoT are not actually blocked and something about TM not having certs?

Does that mean if TM's servers functioned properly, then 8.8.8.8 and other famous DNS would still be usable with DoH, or still blocked?
Epic_winner091
post Sep 6 2024, 07:29 PM

Casual
***
Junior Member
340 posts

Joined: Mar 2010
From: Shah Alam


Not sure whom to trust more, people on this forum/thread of /k lmao.
go626201
post Sep 6 2024, 07:29 PM

Regular
******
Senior Member
1,882 posts

Joined: Sep 2017
QUOTE(blackbox14 @ Sep 6 2024, 07:25 PM)
Saw on /k tered that DoH and DoT are not actually blocked and something about TM not having certs?

Does that mean if TM's servers functioned properly, then 8.8.8.8 and other famous DNS would still be usable with DoH, or still blocked?
*
To be clear,it is never be blocked. JUST REROUTE/REDIRECT.
It is just because the ips has been redirected to TM DNS server,and DOT and DOH need to verify the certificate in order to serve the dns queries.
So when it is redirected,the browser or devices cant verify the domain and certificate to be match with authorities ,so it just out of works to prevent MITM attack.

This post has been edited by go626201: Sep 6 2024, 07:30 PM
PRSXFENG
post Sep 6 2024, 07:30 PM

Look at all my stars!!
*******
Senior Member
2,613 posts

Joined: Nov 2020


QUOTE(blackbox14 @ Sep 6 2024, 07:25 PM)
Saw on /k tered that DoH and DoT are not actually blocked and something about TM not having certs?

Does that mean if TM's servers functioned properly, then 8.8.8.8 and other famous DNS would still be usable with DoH, or still blocked?
*
they didnt block DoH or DoT port 853 directly

however, they are forcibly redirecting your connection for those well known IPs
like, your device asks and says it want's to go to 8.8.8.8
tm says oh it's here
but instead of sending it to the real google, you get sent to tm's trap

but when your device wants to talk with it, it sees that it is dns.tm.net.my, not what it was expecting
and throws an error

if you device doesn't care/verify, then your device thinks its connected to dns.google DoH but is actually TM and the dns exchange happens

their goal is to block stuff and both of these work to block
one just kills the connection as your device knows it's not the correct server
the other just ends up with you asking tm when you think you're asking google


go626201
post Sep 6 2024, 07:34 PM

Regular
******
Senior Member
1,882 posts

Joined: Sep 2017
If they just block/drop it without redirect,confirm atleast 40% of users will suddenly cant use the internet as many people using google dns.
Especially those chrome browser usually equip with google dns.

This post has been edited by go626201: Sep 6 2024, 07:35 PM
AoiB
post Sep 6 2024, 07:35 PM

New Member
*
Junior Member
24 posts

Joined: Mar 2022
Honestly, I think what is most diabolical of it all is that the bastards carried this out in stages, so we're all not sure on the extent/how bad it is.
blackbox14
post Sep 6 2024, 07:36 PM

Casual
***
Junior Member
349 posts

Joined: Jul 2012
QUOTE(go626201 @ Sep 6 2024, 07:29 PM)
To be clear,it is never be blocked. JUST REROUTE/REDIRECT.
It is just because the ips has been redirected to TM DNS server,and DOT and DOH need to verify the certificate in order to serve the dns queries.
So when it is redirected,the browser or devices cant verify the domain and certificate to be match with authorities ,so it just out of works to prevent MITM attack.
*
QUOTE(PRSXFENG @ Sep 6 2024, 07:30 PM)
they didnt block DoH or DoT port 853 directly

however, they are forcibly redirecting your connection for those well known IPs
like, your device asks and says it want's to go to 8.8.8.8
tm says oh it's here
but instead of sending it to the real google, you get sent to tm's trap

but when your device wants to talk with it, it sees that it is dns.tm.net.my, not what it was expecting
and throws an error

if you device doesn't care/verify, then your device thinks its connected to dns.google DoH but is actually TM and the dns exchange happens

their goal is to block stuff and both of these work to block
one just kills the connection as your device knows it's not the correct server
the other just ends up with you asking tm when you think you're asking google
*
Understood. So basically no change for end user since 1am earlier and DoH is still affected. It's just that it isn't actually blocked.

I was just confused by the whole 'they just implemented HTTPS on the TM hijack servers' thing that was mentioned.
penanghomes
post Sep 6 2024, 07:38 PM

Regular
******
Senior Member
1,324 posts

Joined: May 2009


i cant connect
mode light red
georgetown penang

unifi air broadband
PRSXFENG
post Sep 6 2024, 07:38 PM

Look at all my stars!!
*******
Senior Member
2,613 posts

Joined: Nov 2020


QUOTE(AoiB @ Sep 6 2024, 07:35 PM)
Honestly, I think what is most diabolical of it all is that the bastards carried this out in stages, so we're all not sure on the extent/how bad it is.
*
nothing was announced

at first it was some late night 3am tests being noticed in this forum

then Sinar Project sounded the alarm

now this month we are seeing all the ISPs implement it
with TM implementing the most draconian one
cklove96
post Sep 6 2024, 07:40 PM

hehe
*****
Junior Member
707 posts

Joined: Feb 2017

QUOTE(PRSXFENG @ Sep 6 2024, 08:08 PM)
Is bug with their SMS system
Someone asked TM earlier

You are not getting yet another upgrade
*
if upgrade again i pay 89 per month for 1GBps plan ,sad
jiaen0509
post Sep 6 2024, 07:50 PM

Look at all my stars!!
*******
Senior Member
3,307 posts

Joined: Dec 2012
Curious, why I couldn’t access https://dns.google/ but the ponhub (example) can?

I am using iPhone safari to test it out, with Private Relay off

This post has been edited by jiaen0509: Sep 6 2024, 07:52 PM
zz_zizou5
post Sep 6 2024, 07:52 PM

New Member
*
Newbie
3 posts

Joined: Oct 2012


Does anyone have Unifi account for sell?

Prefer Rm 99 for 300Mbps or Rm 119 for 500Mbps Unifi account.

Can accept continue contract or end of contract. Thanks guys.

PRSXFENG
post Sep 6 2024, 07:55 PM

Look at all my stars!!
*******
Senior Member
2,613 posts

Joined: Nov 2020


QUOTE(jiaen0509 @ Sep 6 2024, 07:50 PM)
Curious, why I couldn’t access https://dns.google/ but the ponhub (example) can?

I am using iPhone safari to test it out, with Private Relay off
*
because they have specially blocked those dns provider websites

if you click on view certificate, you will see it says it's dns.tm.net.my
Oltromen Ripot
post Sep 6 2024, 08:00 PM

👍 999999 person Likes this member
*******
Senior Member
4,034 posts

Joined: Dec 2019
QUOTE(blackbox14 @ Sep 6 2024, 06:02 PM)
DNS Shield is just DoH, right?

So you mean they can detect even the presence of DoH now and can DC you immediately regardless of which DNS resolver you connect to?
*
1. maybe, it's not because they detect DoH. After all, DoH is also using tcp/443 like regular HTTPS pages. what might happen is the plain udp/53, plain tcp/53, DoH'a tcp/443, and/or SoT's tcp/853 are all parked on same IP, and thus affected when ISP simply reroute the IP address.

2. maybe, because ISP start using Deep Packet Inspection (DPI), read the initial SNI, and determine this is actually DoH session. plain SNI is precusor to establishing encrypted web HTTPS session. if i am hunting for more DoH, any duly-named "doh.hiding.net" is self-declaring DoH in my opinion.
JohnL77
post Sep 6 2024, 08:03 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(PRSXFENG @ Sep 6 2024, 07:38 PM)
nothing was announced

at first it was some late night 3am tests being noticed in this forum

then Sinar Project sounded the alarm

now this month we are seeing all the ISPs implement it
with TM implementing the most draconian one
*
QUOTE(AoiB @ Sep 6 2024, 07:35 PM)
Honestly, I think what is most diabolical of it all is that the bastards carried this out in stages, so we're all not sure on the extent/how bad it is.
*
Deadline is 30th September.

https://www.business.maxis.com.my/en/faq/da...ns-redirection/
Azusa_San
post Sep 6 2024, 08:06 PM

Casual
***
Junior Member
309 posts

Joined: Mar 2015




This post has been edited by Azusa_San: Sep 6 2024, 08:09 PM
jiaen0509
post Sep 6 2024, 08:14 PM

Look at all my stars!!
*******
Senior Member
3,307 posts

Joined: Dec 2012
QUOTE(Azusa_San @ Sep 6 2024, 08:06 PM)
At least he aware of what MCMC or telco under his ministry do recently. While, he didn’t mention about the times line for appeal would take a year or era to review🤣

“…so they (complainants) can submit appeals, and that body will decide whether to lift the block or not,"


JohnL77
post Sep 6 2024, 08:15 PM

Regular
******
Senior Member
1,887 posts

Joined: Mar 2013


QUOTE(cklove96 @ Sep 6 2024, 01:39 AM)
download vpn also kena blocked ah
user posted image
*
Yo guys, really wanna download VPN oso they blocked?
squall0833
post Sep 6 2024, 08:17 PM

Regular
******
Senior Member
1,473 posts

Joined: Oct 2006
From: Jupiter


is it just me?
becoz I feel open website response is alot slower for the website to load since this called dns hjack thing implemented
JohnLai
post Sep 6 2024, 08:20 PM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
QUOTE(jiaen0509 @ Sep 6 2024, 08:14 PM)
At least he aware of what MCMC or telco under his ministry do recently. While, he didn’t mention about the times line for appeal would take a year or era to review🤣

“…so they (complainants) can submit appeals, and that body will decide whether to lift the block or not,"
*
Does that mean Cloudflare can officially sue them instead?
The company is doing business in Malaysia and he suka suka ask ISP to hijack IP belonging to the company, causing a lot of issue to their customers. dry.gif

495 Pages « < 299 300 301 302 303 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0208sec    0.62    6 queries    GZIP Disabled
Time is now: 18th December 2025 - 04:34 AM