Welcome Guest ( Log In | Register )

4 Pages  1 2 3 > » Bottom

Outline · [ Standard ] · Linear+

 It seems TM Unifi has finally implemented, transparent DNS proxy

views
     
zerorating
post Sep 2 2024, 06:35 AM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


still working here.
user posted image

anyway unsecure DNS still working for me, will keep using it until the game is over
zerorating
post Sep 2 2024, 07:10 AM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(jonthebaptist @ Sep 2 2024, 06:46 AM)
Didn't have to go through this shit under Bijan
*
site blocking via dns were there since ages. it just step up the game now.
zerorating
post Sep 2 2024, 05:49 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(solarmystic @ Sep 2 2024, 05:35 PM)
Everything still seems fine on my end, my Unifi connection is as stated on my sig (300/50).

Checked Murray Hunter's substack and all the usual suspects too. Nothing has changed since the initial reveal on the 6th of August by sinar project.

user posted image

user posted image
*
maybe cloudflare doh server down at the time ts did the test kot.
anyway i still waiting for tm to push for the implementation, i guess it will be hard to them since their customers count is in millions.they need to provision alot of servers to cover this, implying that this service can be load balanced in first place.
zerorating
post Sep 2 2024, 07:02 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 2 2024, 06:51 PM)
I think Unifi is implementing the transparent DNS proxy in stages.

Mine unlucky kena first.
I installed Cloudflare's WARP to circumvent the banned websites blocking
*
while at it can you test out plaintext dns server that i put in my signature want to see how far isp goes.
zerorating
post Sep 2 2024, 07:06 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(raynman @ Sep 2 2024, 07:05 PM)
I have disabled signature viewing, sorry
*
sure use ip below
15.235.146.143
zerorating
post Sep 2 2024, 07:50 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(PJng @ Sep 2 2024, 07:13 PM)
what that, refuse to connect
*
dns brah.

QUOTE
Microsoft Windows [Version 10.0.22631.3880]
© Microsoft Corporation. All rights reserved.

C:\Users\user>nslookup
Default Server:  OpenWrt.lan
Address:  fd8f:fd52:ffa3::1

> server 15.235.146.143
Default Server:  vps-c690e196.vps.ovh.ca
Address:  15.235.146.143

> pornhub.com
Server:  vps-c690e196.vps.ovh.ca
Address:  15.235.146.143

Non-authoritative answer:
Name:    pornhub.com
Address:  66.254.114.41

zerorating
post Sep 2 2024, 07:57 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(PJng @ Sep 2 2024, 07:55 PM)
C:\Users\User>nslookup
Default Server:  dns.tm.net.my
Address:  2001:e68::b:68

> server 15.235.146.143
Default Server:  vps-c690e196.vps.ovh.ca
Address:  15.235.146.143
not yet expert on this, haha
router don have those DNS can set, only set on windows 11 use 1.1.1.1 DNS
*
are you affected with the dns transparent proxy implementation?
zerorating
post Sep 2 2024, 07:58 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(brkli @ Sep 2 2024, 07:57 PM)
torrent most the time use IP only.. using IP why the heck need DNS.
*
tracker can easily be blocked by ISP.
zerorating
post Sep 2 2024, 08:08 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(PJng @ Sep 2 2024, 08:06 PM)
https://forum.lowyat.net/index.php?showtopi...ost&p=110377412

cannot open this site, mean yes right, i no visit those ahem video site
i was trying understand on network section, how to test without actually visit those site
*
your default dns is pointing to TM wan la brah. no wonder you cant access.
zerorating
post Sep 2 2024, 08:33 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 2 2024, 08:20 PM)
So TM applied this shit but internet slow down still isn't fixed. Get your fucking priorities straight TM
*
actually TM are the one late to implement this dns transparent proxy.
zerorating
post Sep 3 2024, 04:33 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 3 2024, 04:10 PM)
they implement censorship bullshit rather than fixing their service that people pay money for. that's misplaced priority.
*
kesian cant relate to you.
user posted image
user posted image

This post has been edited by zerorating: Sep 3 2024, 04:35 PM
zerorating
post Sep 3 2024, 09:36 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 3 2024, 09:02 PM)
I have 800mbps plan, the issue is that the slowdown happens at night mostly. What's your data plan? or is this private vpn server?
*
duuhhh, its peak hour (peak hour for SE asia, evening time in europe and USA people start waking up)
alot of time its the content provider issue, they choose to downscale the number of CDN capacity because its too darn expensive (not every provider can afford to use cloudlflare CDN), sometime having load balancer limitation. anyway, I still can get 10MB/s single connection download from USA mirror and 15MB/s single connection from EU mirror at this period.

do remind that not everything can be cached on CDN end.

also it could be ISP problem if you are living in highly dense area. TM GPON max bandwidth is only 2.5gbps and you are sharing those bandwidth with the other 31 houses, dont forget trunk pipe too. anyway, TM is currently upgrading to 10GPON (XGS-PON?), better late than never.
user posted image
user posted image
user posted image

anyway, i never like VPN, most of the time direct connection give me better result, i already test multiple singapore VPN already, malaysia VPN wan sure sampah, same goes with thailand wan.

This post has been edited by zerorating: Sep 3 2024, 09:52 PM
zerorating
post Sep 3 2024, 10:41 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(hyperwavedrift @ Sep 3 2024, 10:30 PM)
Whatever the reason is, this didn't used to be a problem before. It only starting to happen after I upgraded my plan around late last year, and I think it's fair to complain and demand better service. So it's good that they are planning to upgrade their service.
user posted image
*
everytime tm give speed upgrade sure got speed degradation wan. they are not totally ready for speed upgrade in first place, but hey things improve, for example bandwidth to USA, europe or even china is ample now. but why slow, uhmmm, maybe content provider's CDN resource upstream ISP is overloaded?
anyway, internet are heck alot more complex, sometime throw money also wont solve problem.

anyway, i have been living in TM 3KB/s to oversea network era, today slowness are not much an issue for me. laugh.gif
zerorating
post Sep 3 2024, 10:51 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(mhyug @ Sep 3 2024, 10:31 PM)
Proposing mods to move this thread to serious kopitiam. Some good info on how to circumvent since not everyone sangap for porn, some just want to enjoy manga, anime news etc.
*
sometime openly discussing makes the situation even worse. last few months got people so bangga that dns-over-tls(DOT) or dns-over-https(DOH) can overcome this proxy, didnt awared that TM already one step ahead sad.gif
if everything is blocked, looks like its time for me to setup http proxy via VPS, or aws compute resource, with authentication or allowed IP lists of course.

sorry, if i setup a proxy, it wont be shared resource, i dont want to be responsible of anyone vile action.

This post has been edited by zerorating: Sep 3 2024, 10:59 PM
zerorating
post Sep 3 2024, 10:55 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(Thebestscammer @ Sep 3 2024, 10:14 PM)
using encryopted dns like next and recently trying adguard, but its so slow
sometimes lowyat news load so slow
reddit also load so slow now
so fking annoying
not even sure if its the night time rush hour crap or what but its so slow to load eveyrthing now
*
thats the limitation of encrypted DNS, there are too much overhead and i dont think DNS service will allow our connection to keep open for long period of time, they have many other clients to serve.i take plaintext DNS anyday.

zerorating
post Sep 3 2024, 10:57 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kmrdeva @ Sep 3 2024, 10:25 PM)
What connection are you on?

On my Win11 PCs, I've enabled secure DNS (in Edge browser) and adguard (Edge extension) - websites load just fine.
*
TM proxy implementation is by stages.
they cant have a single server cluster handles the task of hijacking every users dns requests.
zerorating
post Sep 3 2024, 11:08 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(kmrdeva @ Sep 3 2024, 11:02 PM)
I'm on time fibre though. remember reading that time had implemented this way before tm.
*
but time didnt cover DoH and DoT right?
hopefully SKMM didnt mandate those blocking lel.
zerorating
post Sep 3 2024, 11:13 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(Weisun79 @ Sep 3 2024, 11:12 PM)
i tried.. Firefox... enable Increased Protection.. Chooose NextDNS as provider... it works....

or Use Safari...

user posted image
*
cloudflare and google dont work?

zerorating
post Sep 3 2024, 11:29 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(failed.hashcheck @ Sep 3 2024, 11:24 PM)
or if you use win11, just use OS level DoH at network setting.
*
just read unifi thread, TM just reroute google dns or cloudflare to their TM dns resource. looks like TM use the most efficient method without provisioning tons of servers for transparent proxy. such evil.

zerorating
post Sep 3 2024, 11:41 PM

Miskin Adab
*****
Senior Member
977 posts

Joined: Aug 2007
From: Lokap Polis


QUOTE(failed.hashcheck @ Sep 3 2024, 11:37 PM)
that only for plaintext dns right?
Even with DoT they could only block at most.
If they could tamper DoH, like rerouting and return a valid response without hijacking browser certificate, I think we have global IT emergency right now since that means TLS 1.3 has been broken.
*
IP level la boss, meaning plaintext, dot, doh all redirected.

doh will not work without valid cert.

anyway, i will move to "not widely" known public dns service, koff koff ans1.Singapore3.Level3.net,ans2.Singapore3.Level3.net
AIMS also have DNS server that not filtering ahem site. IP is 110.74.147.67

alibaba also (47.254.217.105), (may send data to CCP)

This post has been edited by zerorating: Sep 3 2024, 11:53 PM

4 Pages  1 2 3 > » Top
 

Change to:
| Lo-Fi Version
0.0505sec    1.14    7 queries    GZIP Disabled
Time is now: 23rd December 2025 - 08:59 PM