top | item 39615519

Putting Privacy Focused "Free Speech" VPS Providers to the Test

22 points| fiso64 | 2 years ago |crippled.media

11 comments

order

LinuxBender|2 years ago

These providers are the sources of the strangest and most harmless but interesting traffic I have ever seen. Just the other day I was watching a node at BuyVM send my public DNS server a SYN packet every 10 seconds to port 53. The sequence number and source port stays the same, but the TTL decrements from 64 down to 1 in 64 seconds/packets. Checksums fail. No idea what they are enumerating or what script this is. Both my DNS daemon and the kernel know not to respond to any of it. They stopped before I restarted with debugging enabled. I also get a lot of scans looking for DKIM keys and other poor configurations coming from the providers on this list. I would never block any of it, too much fun to watch.

simmons|2 years ago

Weird! The decrementing TTLs almost sounds like the sender is trying to perform some strange variation on a traceroute. With the long interval, maybe they are sending such packets to many destinations, and trying to build an evolving picture of Internet routing infrastructure?

scrps|2 years ago

Zone transfer shenanigans? Only thing I know that DNS uses TCP for.

combatfrog01|2 years ago

I've never heard of Kyun so I go to their site. It's a very good looking site but the anime girls, minecraft font, and nba youngboy references in their blog posts are just so strange.

KomoD|2 years ago

This honestly just sounds like an ad for "Kyun"?

You have a list of established providers and then some random new provider (who also happens to tick every box for your questionable content)

miloignis|2 years ago

They didn't go with Kyun, they went with Pivex, and they gave 2 other providers the same A+ rating.

It seems pretty evenhanded and not like an ad to me.