Skip to content

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone

I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

Uncategorized
6 4 3
  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

    @stefano Disgusting! Today it's a luxury to have a real and untempered internet connection. About 16 years ago I saw Vodafone compressing my images which I uploaded to an FTP server. It's just stupid...

  • @stefano Disgusting! Today it's a luxury to have a real and untempered internet connection. About 16 years ago I saw Vodafone compressing my images which I uploaded to an FTP server. It's just stupid...

    @finn I agree. I don't need Vodafone to sniff my traffic and decide if it's "secure" or not. Years ago that service wasn't Active by default. Then something changed and I started to see, from time to time, those "this site isn't secure" pages. I asked to disable it and they did it. But I remember that I read somewhere they're reenabling it and now it cannot be disabled as "it's for our security".

    All I ask is that they stop messing with my traffic.

  • stefano@mastodon.bsd.cafeundefined stefano@mastodon.bsd.cafe shared this topic
  • @finn I agree. I don't need Vodafone to sniff my traffic and decide if it's "secure" or not. Years ago that service wasn't Active by default. Then something changed and I started to see, from time to time, those "this site isn't secure" pages. I asked to disable it and they did it. But I remember that I read somewhere they're reenabling it and now it cannot be disabled as "it's for our security".

    All I ask is that they stop messing with my traffic.

    @stefano Amen brother! Just give us pure unfiltered internet. If someone wants any "security extras" they can opt-in for that.

  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

    @stefano

    > I even briefly asked an AI (I know, I know...)

    LLMs being used as a search engine "on steroids" is actually a good use case, IMHO.

    You don't have to blindly trust the output, but instead have something to keep searching for an answer.

  • I’ve been losing my mind for almost 4 hours, and I feel like an idiot.

    At first I couldn't understand why the TLS handshake was always taking more than 300 milliseconds. I thought it was a local or server-side issue. Only after about an hour did I test google.com and saw the exact same behavior.

    That's when I realized that with my other WAN connection, the timing drops significantly.

    So I started going crazy over my MikroTik configuration, convinced it had to be something related to multi-WAN. I even briefly asked an AI (I know, I know...), which said the problem was probably my neighbor, who had eaten too much pizza.

    At that point, I kept spiraling.

    Then it hit me that the Vodafone Station has its built-in Wi-Fi disabled, since I manage the network behind it. I could enable it and bypass the MikroTik. I enabled it and ran a direct test.

    Bingo. Same problem.

    So the issue is upstream. I suspect it’s "Vodafone Rete Sicura", some awful thing I never wanted and that probably does some kind of traffic inspection.

    I really can't wait for FTTH to arrive so I can finally get rid of this stuff.

    @stefano residential line ?

    Here in Belgium they filter out the ports 80/443 by default: "security measure".

    > I even briefly asked an AI (I know, I know...),

    to realize that it doesn't help. :)


Gli ultimi otto messaggi ricevuti dalla Federazione
Post suggeriti
  • 0 Votes
    10 Posts
    19 Views
    @stefano bravissimo!!! 👏👏👏👏👏
  • 0 Votes
    6 Posts
    22 Views
    @stefano @christopher I am not sure if I'd say #Linux is becoming like #Windows. I do recall similar statements made on the Debian-User mailing list on a previous release when xorg introduced autoconfiguration. A lot of people were pissed that it was making choices for you instead of manually configuring the xorg.conf file.Honestly, that was a good thing. Painful doesn't begin to describe it but users were unaware they could still hand-configure the file.There has been, however, more stuff added to Linux over the last several years. Call it bloat, call it whatever you want. OSes change. But it has been gradually moving away from simplicity.I miss the simplicity.However, to reply to your original post, coming from COTS solutions, sometimes the vast amount of choice can be overwhelming. For instance, when it comes to #FreeBSD #jails it used to just be jails. Now, it's thin, thick, classic, networking. I understand they have their places but it would be helpful to provide more detailed explanations, tutorials, or best practices for each. The FreeBSD Handbook is good but just scratches the surface but often leaves more questions. It would help with learning and in part...marketing.On a side note: The FreeBSD Handbook is a great resource but there are opportunities to improve it, like tailoring it to new users (better empathy), best practices, architectural examples, and links to additional resources and info.
  • 0 Votes
    1 Posts
    8 Views
    Hot take: pf's built-in connection tracking beats fail2ban/sshguard hands down.One simple ruleset gives you automatic brute-force protection with ZERO userland daemons. No log parsing, no reaction delays, no additional attack surface.table <bruteforce> persistpass in proto tcp to port 22 flags S/SA (max-src-conn 5, max-src-conn-rate 3/30, overload <bruteforce> flush global)Kernel-level enforcement, instant blocking, survives reboots with persist.Why spawn Python processes when your firewall already knows?#bsd #freebsd #runbsd #firewall #pf #sysadmin
  • 0 Votes
    1 Posts
    16 Views
    🧠 Nixers Newsletter #311 is out!Boot processes, reproducible builds, user-mode Linux, FreeBSD sandboxes, and even /dev/null as a database 😄Plus:• Fedora KDE pkg mgmt• Debian vs systemd• raconn — a smart tool for parallel SSH connections to multiple hostnames/IPs in one ProxyCommand. (https://blog.izissise.net/posts/raconn/)• UBIOS (China’s UEFI-alt)Read it 👉 https://newsletter.nixers.net/entries.php#311“There are no life hacks, only trade-offs.” — James Clear#Unix #Linux #FreeBSD #FOSS #SysAdmin #ReproducibleBuilds #SSH #Nixers