Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3
kennedybaird

63 posts

Master Geek

ID Verified

  #3122646 1-Sep-2023 12:23
Send private message

Thanks @cyril7, that's my concern, it seems clear that there is something strange going on with zeronet's infrastructure.




yitz
2074 posts

Uber Geek


  #3122675 1-Sep-2023 13:20
Send private message

Can you check you are definitely using Cloudflare DNS only (and not just adding manually specified Cloudflare resolvers into the round robin pool alongside DNS IPs acquired from the PPP session) - use something like whoami.akamai.net which returns the IP of the recursive resolver as A/AAAA record - do that a few times and note the owner of the IP using whois data. The issue of the Hamilton DNS IP not responding to some DNS queries can be worked around easily - that should at least solve your web page initial loading delay issue.

 

 


kennedybaird

63 posts

Master Geek

ID Verified

  #3122687 1-Sep-2023 13:48
Send private message

I'm assuming you're not making some joke and didn't realise that specific whoami doesn't work anymore 🤣

 

 

 

 

I did some dig'ging in command line, and all my requests seem to be routing through DNS correctly.

I did turn off use-peer-dns in dhcp-client in the router, so the only possible dns options are cloudfares (unless a device bypasses).

And then I found cloudfare's checker: https://1.1.1.1/help

 


yitz:

 

Can you check you are definitely using Cloudflare DNS only (and not just adding manually specified Cloudflare resolvers into the round robin pool alongside DNS IPs acquired from the PPP session) - use something like whoami.akamai.net which returns the IP of the recursive resolver as A/AAAA record - do that a few times and note the owner of the IP using whois data. The issue of the Hamilton DNS IP not responding to some DNS queries can be worked around easily - that should at least solve your web page initial loading delay issue.

 




yitz
2074 posts

Uber Geek


  #3122688 1-Sep-2023 13:57
Send private message

kennedybaird:

 

I'm assuming you're not making some joke and didn't realise that specific whoami doesn't work anymore 🤣 

 

Works for me. 🤷‍♂️ If Cloudflare has it's own checker then that will do too... other than Compass/Zeronet's Hamilton DNS IP quirk which I have bypassed I don't have an issue with them and don't have issues with intermittent delayed page loads or reliability in general. Only on 300/100 here so not going to bother with speed tests.

 

 


kennedybaird

63 posts

Master Geek

ID Verified

  #3122690 1-Sep-2023 14:12
Send private message

yitz:

 

Works for me. 🤷‍♂️ If Cloudflare has it's own checker then that will do too... other than Compass/Zeronet's Hamilton DNS IP quirk which I have bypassed I don't have an issue with them and don't have issues with intermittent delayed page loads or reliability in general. Only on 300/100 here so not going to bother with speed tests.



That's so strange. Not working from any of my devices, or on 2degrees mobile, or if I set a VPN running on my desktop.


kennedybaird

63 posts

Master Geek

ID Verified

  #3122691 1-Sep-2023 14:12
Send private message

yitz:

 

Works for me. 🤷‍♂️ If Cloudflare has it's own checker then that will do too... other than Compass/Zeronet's Hamilton DNS IP quirk which I have bypassed I don't have an issue with them and don't have issues with intermittent delayed page loads or reliability in general. Only on 300/100 here so not going to bother with speed tests.



That's so strange. Not working from any of my devices, or on 2degrees mobile, or if I set a VPN running on my desktop.


yitz
2074 posts

Uber Geek


  #3122694 1-Sep-2023 14:21
Send private message

Just to note - whoami.akamai.net is a host name you can resolve (revealing the IPs of the DNS infrastructure used to perform recursive lookups) - it's not a web site you browse to in your internet brwoser or the name or IP of a DNS resolver so don't try and send DNS queries to it... it's also possible some privacy conscious applications will block it. Akamai is a content delivery network that in the past primarily used geographical load balancing based on recursive DNS.

 

Another thing to note if you send a lot of traffic through Cloudflare is that they don't have peering in Auckland with them and rely on upstream provider Voyager... usually ends in an Australian datacentre, so if you really must have single digit millisecond latency to their services then Zeronet may not be the ISP for you. In saying that they have made upgrades to the network recently so who knows - could be in the pipeline, you could ask them about it?


 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
RunningMan
8953 posts

Uber Geek


  #3122706 1-Sep-2023 15:13
Send private message

https://www.dnsleaktest.com/ will show which DNS servers are in use.


kennedybaird

63 posts

Master Geek

ID Verified

  #3122743 1-Sep-2023 17:48
Send private message

yitz:

 

Just to note - whoami.akamai.net is a host name you can resolve (revealing the IPs of the DNS infrastructure used to perform recursive lookups) - it's not a web site you browse to in your internet brwoser or the name or IP of a DNS resolver so don't try and send DNS queries to it... it's also possible some privacy conscious applications will block it. Akamai is a content delivery network that in the past primarily used geographical load balancing based on recursive DNS.

 

Another thing to note if you send a lot of traffic through Cloudflare is that they don't have peering in Auckland with them and rely on upstream provider Voyager... usually ends in an Australian datacentre, so if you really must have single digit millisecond latency to their services then Zeronet may not be the ISP for you. In saying that they have made upgrades to the network recently so who knows - could be in the pipeline, you could ask them about it?

 



Right, that makes a lot of sense.

After reading all the positives on here about quic I decided to take advantage of the 30 day money back guarantee with ZN, and am going to move to quic


Tinkerisk
4224 posts

Uber Geek


  #3123117 2-Sep-2023 20:35
Send private message

To whom it may concern: https://www.bleepingcomputer.com/news/security/super-admin-elevation-bug-puts-900-000-mikrotik-devices-at-risk/

 

and

 

https://dnscheck.tools/ shows IP adresses, IPv6 DNS resolvers as well, DNSSEC and relevant signatures.

 

 





- NET: FTTH, OPNsense, 10G backbone, GWN APs, ipPBX
- SRV: 12 RU HA server cluster, 0.1 PB storage on premise
- IoT:   thread, zigbee, tasmota, BidCoS, LoRa, WX suite, IR
- 3D:    two 3D printers, 3D scanner, CNC router, laser cutter


kennedybaird

63 posts

Master Geek

ID Verified

  #3124209 6-Sep-2023 15:52
Send private message

For anyone who was curious, these were the final speedtest results up until I was moved over to Quic, added some summary stats at the top. 


nzkc
1571 posts

Uber Geek


  #3124300 6-Sep-2023 23:03
Send private message

Tinkerisk:

 

To whom it may concern: https://www.bleepingcomputer.com/news/security/super-admin-elevation-bug-puts-900-000-mikrotik-devices-at-risk/

 

 

As a Mikrotik user this piqued my interest. CVE report is here: https://nvd.nist.gov/vuln/detail/CVE-2023-30799

 

"MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue." so if you've already upgraded to 7.x I assume you're fine.

 

Also requires an existing admin account to execute the exploit. Its a concern because of the default Admin account being well known and the potential to brute force passwords. Mitigated by not allowing that account access to Winbox or the HTTP portal. I would say especially the portal (insert do not allow internet access to your http portal disclaimer here). Use difficult to guess passwords etc etc.


Tinkerisk
4224 posts

Uber Geek


  #3124360 7-Sep-2023 06:04
Send private message

nzkc:

 

Tinkerisk:

 

To whom it may concern: https://www.bleepingcomputer.com/news/security/super-admin-elevation-bug-puts-900-000-mikrotik-devices-at-risk/

 

 

Also requires an existing admin account to execute the exploit. Its a concern because of the default Admin account being well known and the potential to brute force passwords. Mitigated by not allowing that account access to Winbox or the HTTP portal. I would say especially the portal (insert do not allow internet access to your http portal disclaimer here). Use difficult to guess passwords etc etc.

 

 

I am not using router from Mikrotik. I just came across it and thought someone might be interested.





- NET: FTTH, OPNsense, 10G backbone, GWN APs, ipPBX
- SRV: 12 RU HA server cluster, 0.1 PB storage on premise
- IoT:   thread, zigbee, tasmota, BidCoS, LoRa, WX suite, IR
- 3D:    two 3D printers, 3D scanner, CNC router, laser cutter


RunningMan
8953 posts

Uber Geek


  #3124564 7-Sep-2023 13:42
Send private message

It's also been fixed for nearly a year, so no excuse for not updating to a more recent ROS version.


Tinkerisk
4224 posts

Uber Geek


  #3124627 7-Sep-2023 14:19
Send private message

RunningMan:

 

It's also been fixed for nearly a year, so no excuse for not updating to a more recent ROS version.

 

 

Uh, no? The linked article is from 23 July 2023 and therefore the last fix for the LTS is 19 July 2023.





- NET: FTTH, OPNsense, 10G backbone, GWN APs, ipPBX
- SRV: 12 RU HA server cluster, 0.1 PB storage on premise
- IoT:   thread, zigbee, tasmota, BidCoS, LoRa, WX suite, IR
- 3D:    two 3D printers, 3D scanner, CNC router, laser cutter


1 | 2 | 3
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.