7 ms·
Before going to a long 3 month trip to Asia last year, I installed WireGuard on my Raspberry Pi 1 (original model B from 2012) which was running at home in US.
by otterpro 3y ago
Before going to a long 3 month trip to Asia last year, I installed WireGuard on my Raspberry Pi 1 (original model B from 2012) which was running at home in US. I found PiVPN to be the easiest way to install Wireguard. I didn't know if I even needed a VPN but I was glad, and I was able to use internet as if I were at home. It was weird, but a lot of sites are blocked oversea, even though it shouldn't. For example, I couldn't access Homedepot.com. I also couldn't make payment to my Target card as the website refused connection. Apparently a lot of US business sites refuse to connect from oversea IP because of too many hacking attempts, or they just don't want to deal with it. Anyway, I was glad I had set up a VPN before I left for the trip.
Also, the original Pi (2012) was able to run Wireguard well enough for light VPN, although I didn't push it too much since I didn't use it for anything heavy like video streaming.
- eddieroger 3y agoI don't know first hand, nor am I speaking for my employer (who happens to be one of the two companies you mentioned), but if it was me, I would assume that if my company doesn't do business outside of the United States, then may as well deny traffic for services that wouldn't be available outside of the United States, since it is more often than not problematic traffic. This means sometimes legit traffic would be inconvenienced, as you were, and sorry about that, but it is a realistic scenario that the small amount of legit pain is worth the incredibly reduced risk footprint. Of course, baddies could get VPNs, too, but that's all part of the game.
- LVDOVICVS 3y agoMy Canadian stepfather died. Family is not close and I’m in the US. The Canadian newspaper where his obit would be doesn’t allow connections from the US. More than a “small amount of legit pain” was the result.
- couchand 3y agoI'm sorry for your loss. Do they have a phone?
- vlovich123 3y agoWas the site unavailable through archive.is? Also, plenty of people live far away from family and have to deal with death (I’m in the same boat). It sucks but I’m also curious why the obit was particularly important to you because as far as I understand that’s topically just a small blurb in the newspaper? My family doesn’t do obits so I’m curious. Not to minimize what you went through at all, but it’s interesting in today’s times how we expect so much immediacy. My immediate family escaped the USSR just before it collapsed but my dad’s was family was stuck in Russia and couldn’t leave even after it fell. My father had to deal with his brother, father, and mother dying within 5 years or so with no visits in between that time (a combination of finances + probably fear about traveling back). Comparatively I personally have a much easier time in that I at least get to see my family once a year or so. Again, in no way a comparison as dealing with loss and living far away from family is always hard. Just a reflection of how much technology has changed and made maintaining more closeness easier (eg video calling).
- eddieroger 3y agoI am sorry for your loss, and I'm not trying to minimize your pain. This is the problem with data, it's unfeeling and cold. You and I are two customers of something companies with lots more than us, and a spreadsheet doesn't capture our pains when we feel them.
- ivanhoe 3y ago> it is a realistic scenario that the small amount of legit pain is worth the incredibly reduced risk footprint. Well, I guess it depends on the type of attacks one experiences, but hackers and spammers who target US-based businesses are not idiots, they know how to use vpns and tor and proxies. So on a technical level you get close to nothing security-wise. You reduce a number of bots and worms randomly accessing your servers, can stop some script kiddies who don't know better and make life a bit harder to web scrapers (but not much) - and that's it.
- lxgr 3y ago> I would assume that if my company doesn't do business outside of the United States You forgot to consider "any of my company's existing US-resident customers temporarily traveling outside of the US".
- kybernetyk 3y agoCan’t access homedepot from Germany either. I guess it’s HD blocking pesky foreigners
- tssva 3y agoIf you don't do business in the EU why accept traffic from there and possibly have to deal with GDPR issues.
- oh_sigh 3y agoThat's not how GDPR works but it is a common misconception and I can't really blame non-EU businesses for not taking the time to understand a foreign law when blocking is so easy.
- doix 3y agoWhat do you mean? That's pretty much how it works. You load up Homedepot website and they along with a bunch of 3rd parties that they partner with will start collecting data about you and storing it. You can't do that to someone from the EU without getting permission along with other restrictions. For Homedepot to comply with GPDR, they would have to treat EU and non-EU users differently, or they could just block EU. Since you're not trying to sell anything to EU users, blocking them makes things easier.
- indeyets 3y agoGDPR doesn't care about where people are located right now. From the GDPR point of view you still have to treat EU-residents in a special way, even if they're located in US right now. But EU has less of the leverage if company refuses to do business in EU — that's true. on the other hand, CCPA is still a thing
- lxgr 3y ago> treat EU-residents in a special way, even if they're located in US right now. This part of GDPR has always seemed completely unpracticable/unenforceable to me. How would a non-EU company even know that one of their customers is an EU resident and only temporarily visiting? Most services in the US aren't asking for my passport, at least. Practically, I'd assume that this will be interpreted by courts to only apply to companies "intentionally doing business with/commercially targeting EU residents", which is already the case for similar scenarios (e.g. that's how, to my understanding, German law requiring all sites to provide an imprint has been interpreted by courts). In any case, I suppose we'll have to wait for precedent; I'm not aware of any at the moment.
- FredPret 3y agoI have a US-and-Canada based business and I ban customers from elsewhere in my T’s and C’s. Simply because I don’t know their laws. I don’t outright block them because I myself travel, and some foreign laws apply to their citizens wherever they are. I can completely see why you might want to ban overseas IP connections though, and I’ll probably do it soon.
- lxgr 3y agoBanning new signups/sales from overseas IPs can make sense for legal, tax, and shipping reasons – but please do provide some way for existing customers to access their subscriptions/orders/accounts from abroad. International travel is a thing.
- FredPret 3y agoI know! This is why I have it enabled - for me. I'm still worried about breaking some EU law without ever knowing it though.
- bitlax 3y agoDid you do anything to handle the event where, say, you lose connectivity and the system needs a reboot? Just curious about what would be the best way to handle that scenario.
- otterpro 3y agoWhile I didn't do this last time, in the future, I would plug the Raspberry pi to one of my smart power outlet (ie Kasa wifi power outlet) connected via HomeAssistant, so I can remotely restart it if Raspberry Pi becomes unresponsive. I also have another Raspberry Pi (again, the original 2012), so I could add redundancy by running second WireVPN on it, too.
- megous 3y agoYou can have local watchdog process and reboot to failsafe configuration on next boot. You can also set a timer to do this unconditionally when trying a new network configuration.
- darkwater 3y agoI also did something similar, plus all my home automation which is 98% local-first|only. My trip was just 3 weeks but on the first day leaving, between one plane and another, my power company had a 4hours extraordinary maintenance cut, my UPS didn't last enough and with that blackout the RPi SD card died, and I was locked out my LAN for all the trip. Lesson learned: configure the UPS to communicate with the servers and shut them down in a controlled manner when batteries are dying.
- momirlan 3y agorun linux from SSD, can get a cheapo one for less than $25 these days. the SATA to USB adapter will probably cost as much. no more SD issues
- kijiki 3y agoMay or may not work for your usecase, but I have some scripts to prepare read-only raspbian images here: https://github.com/nolanl/ropi https://github.com/nolanl/ropi There are commands to enable/disable read-write mode, so you can still make changes and do upgrades. I've had 0 problems with SDcard death after I started using it.
- BrandoElFollito 3y ago> Apparently a lot of US business sites refuse to connect from oversea IP because (...) they just don't want to deal with it I am French. What I find fascinating is that there are local US newspapers (that server a tiny community) that went through the effort to do a geoblock from the EU and put a page along the lines "we cannot be compliant to Privacy laws in the EU so we must block you". Why do they care at all? How is the EU law relevant to their small, local business? Large companies are different - there could be some litigation against their footprint in the EU etc. - but for thosewho just live in the US (or anywhere outside the EU) going the extra mile to block because of non compliance is really weird.
- wkearney99 3y agoThey care because no matter how small with travel and such these days there are potential risks if they're 'found' to be non-compliant. Simpler to say "no, we can't comply" than spend time/money/risk fighting about it later. Not that I disagree with you on the 'it seems stupid' front. But that doesn't change the risk profile for the company.
- mattsan 3y agoI'm sure there are still some people willing to report the websites to EU commission, it's a guaranteed fine (less so a paycheque, I have no clue if the company has to comply with paying it (unless later on they want to expand to the EU))
- BrandoElFollito 3y agoThis is a fine that the EU can issue but why would the local business care? If I was issued a fine by the US, China, India or Japan it would directly go to the trashbin. It is their law, and their problem, not mine. Of course this means that I will not be able to do business there, if I travel I may be in trouble etc. But again - we are talking about small local newspapers (and similar businesses).
- mattsan 3y ago
- lxgr 3y ago> Apparently a lot of US business sites refuse to connect from oversea IP because of too many hacking attempts, or they just don't want to deal with it. Yes, and it's infuriating. For example, it was (and probably still is) impossible to access the NY MTA's OMNY portal from many, but curiously not all, European countries. The OMNY system itself works using foreign cards, but this makes it very annoying to download receipts for expense reports. Another fun one was not being able to cancel some streaming service from outside of the US due to the service geoblocking their account management site as well. I actually had to use a VPN to cancel! There are countless other examples.