5 ms·
I applaud the effort to hate on "smart" middleware proxies! That being said, author gets no points for namedropping random distributed systems algorithms and u
by lkarsten 9y ago
I applaud the effort to hate on "smart" middleware proxies!
That being said, author gets no points for namedropping random distributed systems algorithms and using tcp keepalives (2 hours minimum!) as an argument against TLS terminating proxies.
Is there a reason to (as he says) "fully implement the protocol" in the proxy? I battled with websockets through Pound last week, and it simply doesn't work because the author took a non-postel stand on protocol specifics.
Having a protocol agnostic proxy like hitch (previously stud) fixed that without losing functionality, and I expect it to age better as well.
- jclulow 9y agoIf more software would take an apostel stand, I feel we would have net fewer interoperability problems.
- bringtheaction 9y agoBy that you mean if more software was more strict about what it accepted instead of being liberal about it?
- jclulow 9y agoYes, that.
- zaarn 9y agoSadly the internet isn't as nice. I've been to various hotels where the router would silently drop keep-alive packets (but god forbid informing the packet layer you do this!) and mangled DNS packets ("looking for mail.example.com? Here is the answer for example.com" and "looking for doesnotexist.com? Here is result for internalsearchengine.com which redirects you to a sponsored search page with ads")
- pixl97 9y agoAnd this is why encrypted DNS is a must.
- zaarn 9y agoEven encrypted DNS will suffer because middleboxes with captive portals will attempt to tamper it. Unless you pipe it over TLS or HTTP in which case you run into problems with not knowing why there is no connection in a captive portal (we obviously need to fix captive portals, they're source of 90% of problems)
- geofft 9y agoI learned recently about RFC 7710 which specifies a DHCP (v4/v6) and RA option for "You're on a captive portal, here's the website you should visit before you get access": https://tools.ietf.org/html/rfc7710 https://tools.ietf.org/html/rfc7710 Do any of the major implementations of captive portals support it?
- zaarn 9y agoNot that I know. My pfSense firewall doesn't have it (IIRC), so my guess would be that poorly maintained router boxes in a hotel basement definitely don't have it. I'm not sure if the various DHCP clients communicate this properly to the OS or browser even (I wouldn't know how to query for it on Linux)
- geofft 9y agoIf you're using NetworkManager you can get DHCP options by being mildly angry at the D-Bus API: $ python3 >>> import dbus >>> bus = dbus.SystemBus() >>> nm = bus.get_object("org.freedesktop.NetworkManager", "/org/freedesktop/NetworkManager") >>> conn = bus.get_object("org.freedesktop.NetworkManager", nm.Get("org.freedesktop.NetworkManager", "PrimaryConnection", dbus_interface="org.freedesktop.DBus.Properties")) >>> dhcp = bus.get_object("org.freedesktop.NetworkManager", conn.Get("org.freedesktop.NetworkManager.Connection.Active", "Dhcp4Config", dbus_interface="org.freedesktop.DBus.Properties")) >>> options = dhcp.Get("org.freedesktop.NetworkManager.DHCP4Config", "Options", dbus_interface="org.freedesktop.DBus.Properties") >>> str(options["subnet_mask"]) '255.255.255.240' I guess you can parse /var/lib/dhcp/dhclient.*.leases otherwise?
- gtirloni 9y agoFor reference: https://en.wikipedia.org/wiki/Robustness_principle https://en.wikipedia.org/wiki/Robustness_principle "TCP implementations should follow a general principle of robustness: be conservative in what you do, be liberal in what you accept from others." -- Jon Postel