
anyway unsecure DNS still working for me, will keep using it until the game is over
It seems TM Unifi has finally implemented, transparent DNS proxy
|
|
Sep 2 2024, 06:35 AM
Return to original view | Post
#1
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
|
|
|
Sep 2 2024, 07:10 AM
Return to original view | Post
#2
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
Sep 2 2024, 05:49 PM
Return to original view | Post
#3
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(solarmystic @ Sep 2 2024, 05:35 PM) Everything still seems fine on my end, my Unifi connection is as stated on my sig (300/50). maybe cloudflare doh server down at the time ts did the test kot.Checked Murray Hunter's substack and all the usual suspects too. Nothing has changed since the initial reveal on the 6th of August by sinar project. ![]() ![]() anyway i still waiting for tm to push for the implementation, i guess it will be hard to them since their customers count is in millions.they need to provision alot of servers to cover this, implying that this service can be load balanced in first place. |
|
|
Sep 2 2024, 07:02 PM
Return to original view | Post
#4
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(raynman @ Sep 2 2024, 06:51 PM) I think Unifi is implementing the transparent DNS proxy in stages. while at it can you test out plaintext dns server that i put in my signature want to see how far isp goes.Mine unlucky kena first. I installed Cloudflare's WARP to circumvent the banned websites blocking |
|
|
Sep 2 2024, 07:06 PM
Return to original view | Post
#5
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
Sep 2 2024, 07:50 PM
Return to original view | IPv6 | Post
#6
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(PJng @ Sep 2 2024, 07:13 PM) dns brah.QUOTE Microsoft Windows [Version 10.0.22631.3880] © Microsoft Corporation. All rights reserved. C:\Users\user>nslookup Default Server: OpenWrt.lan Address: fd8f:fd52:ffa3::1 > server 15.235.146.143 Default Server: vps-c690e196.vps.ovh.ca Address: 15.235.146.143 > pornhub.com Server: vps-c690e196.vps.ovh.ca Address: 15.235.146.143 Non-authoritative answer: Name: pornhub.com Address: 66.254.114.41 |
|
|
|
|
|
Sep 2 2024, 07:57 PM
Return to original view | IPv6 | Post
#7
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(PJng @ Sep 2 2024, 07:55 PM) C:\Users\User>nslookup are you affected with the dns transparent proxy implementation?Default Server: dns.tm.net.my Address: 2001:e68::b:68 > server 15.235.146.143 Default Server: vps-c690e196.vps.ovh.ca Address: 15.235.146.143 not yet expert on this, haha router don have those DNS can set, only set on windows 11 use 1.1.1.1 DNS hyperwavedrift liked this post
|
|
|
Sep 2 2024, 07:58 PM
Return to original view | IPv6 | Post
#8
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
Sep 2 2024, 08:08 PM
Return to original view | IPv6 | Post
#9
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(PJng @ Sep 2 2024, 08:06 PM) https://forum.lowyat.net/index.php?showtopi...ost&p=110377412 your default dns is pointing to TM wan la brah. no wonder you cant access.cannot open this site, mean yes right, i no visit those ahem video site i was trying understand on network section, how to test without actually visit those site |
|
|
Sep 2 2024, 08:33 PM
Return to original view | IPv6 | Post
#10
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
Sep 3 2024, 04:33 PM
Return to original view | IPv6 | Post
#11
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
Sep 3 2024, 09:36 PM
Return to original view | IPv6 | Post
#12
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(hyperwavedrift @ Sep 3 2024, 09:02 PM) I have 800mbps plan, the issue is that the slowdown happens at night mostly. What's your data plan? or is this private vpn server? duuhhh, its peak hour (peak hour for SE asia, evening time in europe and USA people start waking up)alot of time its the content provider issue, they choose to downscale the number of CDN capacity because its too darn expensive (not every provider can afford to use cloudlflare CDN), sometime having load balancer limitation. anyway, I still can get 10MB/s single connection download from USA mirror and 15MB/s single connection from EU mirror at this period. do remind that not everything can be cached on CDN end. also it could be ISP problem if you are living in highly dense area. TM GPON max bandwidth is only 2.5gbps and you are sharing those bandwidth with the other 31 houses, dont forget trunk pipe too. anyway, TM is currently upgrading to 10GPON (XGS-PON?), better late than never. ![]() ![]() ![]() anyway, i never like VPN, most of the time direct connection give me better result, i already test multiple singapore VPN already, malaysia VPN wan sure sampah, same goes with thailand wan. This post has been edited by zerorating: Sep 3 2024, 09:52 PM |
|
|
Sep 3 2024, 10:41 PM
Return to original view | IPv6 | Post
#13
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(hyperwavedrift @ Sep 3 2024, 10:30 PM) Whatever the reason is, this didn't used to be a problem before. It only starting to happen after I upgraded my plan around late last year, and I think it's fair to complain and demand better service. So it's good that they are planning to upgrade their service. everytime tm give speed upgrade sure got speed degradation wan. they are not totally ready for speed upgrade in first place, but hey things improve, for example bandwidth to USA, europe or even china is ample now. but why slow, uhmmm, maybe content provider's CDN resource upstream ISP is overloaded? ![]() anyway, internet are heck alot more complex, sometime throw money also wont solve problem. anyway, i have been living in TM 3KB/s to oversea network era, today slowness are not much an issue for me. |
|
|
|
|
|
Sep 3 2024, 10:51 PM
Return to original view | IPv6 | Post
#14
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(mhyug @ Sep 3 2024, 10:31 PM) Proposing mods to move this thread to serious kopitiam. Some good info on how to circumvent since not everyone sangap for porn, some just want to enjoy manga, anime news etc. sometime openly discussing makes the situation even worse. last few months got people so bangga that dns-over-tls(DOT) or dns-over-https(DOH) can overcome this proxy, didnt awared that TM already one step ahead if everything is blocked, looks like its time for me to setup http proxy via VPS, or aws compute resource, with authentication or allowed IP lists of course. sorry, if i setup a proxy, it wont be shared resource, i dont want to be responsible of anyone vile action. This post has been edited by zerorating: Sep 3 2024, 10:59 PM |
|
|
Sep 3 2024, 10:55 PM
Return to original view | IPv6 | Post
#15
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(Thebestscammer @ Sep 3 2024, 10:14 PM) using encryopted dns like next and recently trying adguard, but its so slow thats the limitation of encrypted DNS, there are too much overhead and i dont think DNS service will allow our connection to keep open for long period of time, they have many other clients to serve.i take plaintext DNS anyday.sometimes lowyat news load so slow reddit also load so slow now so fking annoying not even sure if its the night time rush hour crap or what but its so slow to load eveyrthing now |
|
|
Sep 3 2024, 10:57 PM
Return to original view | IPv6 | Post
#16
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(kmrdeva @ Sep 3 2024, 10:25 PM) What connection are you on? TM proxy implementation is by stages.On my Win11 PCs, I've enabled secure DNS (in Edge browser) and adguard (Edge extension) - websites load just fine. they cant have a single server cluster handles the task of hijacking every users dns requests. |
|
|
Sep 3 2024, 11:08 PM
Return to original view | IPv6 | Post
#17
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
|
|
|
Sep 3 2024, 11:13 PM
Return to original view | IPv6 | Post
#18
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(Weisun79 @ Sep 3 2024, 11:12 PM) i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works.... cloudflare and google dont work?or Use Safari... ![]() countingcrows liked this post
|
|
|
Sep 3 2024, 11:29 PM
Return to original view | IPv6 | Post
#19
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(failed.hashcheck @ Sep 3 2024, 11:24 PM) just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil. |
|
|
Sep 3 2024, 11:41 PM
Return to original view | IPv6 | Post
#20
|
![]() ![]() ![]() ![]() ![]()
Senior Member
977 posts Joined: Aug 2007 From: Lokap Polis |
QUOTE(failed.hashcheck @ Sep 3 2024, 11:37 PM) that only for plaintext dns right? IP level la boss, meaning plaintext, dot, doh all redirected.Even with DoT they could only block at most. If they could tamper DoH, like rerouting and return a valid response without hijacking browser certificate, I think we have global IT emergency right now since that means TLS 1.3 has been broken. doh will not work without valid cert. anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net,ans2.Singapore3.Level3.net AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67 alibaba also (47.254.217.105), (may send data to CCP) This post has been edited by zerorating: Sep 3 2024, 11:53 PM |
| Change to: | 0.0505sec
1.14
7 queries
GZIP Disabled
Time is now: 23rd December 2025 - 08:59 PM |