Local dns rewrite problems on android
I have some services set up which i make available with tailscale and a domain name outside my lan. Inside my home network i set up adguard dns rewrites to use the same domain for devices which are not on my tailnet. I disabled dns rebind protection in my fritzbox for these domains.
Now my problem: I don't leave my phone connected to tailscale all of the time because of high battery drain. Inside of my wifi the phone should still be able to access my services using the domain, but it is only able some of the time. My work laptop (not on my tailnet) is able to access the services.
Is the dns cached somehow in android? Is the private dns setting of android overwriting the dns i configured in my router? Where else could the problem lie?
Any hints are appreciated 😀
Israel’s PM Netanyahu orders ‘powerful, immediate’ attacks on Gaza
Israeli Prime Minister Benjamin Netanyahu has ordered the military to carry out “powerful” attacks in Gaza, his office says.
It comes after Netanyahu alleged Hamas committed a “clear violation” of the ceasefire deal. For its part, Gaza’s Government Media Office accused Israel of committing 125 violations of the ceasefire since it came into effect on October 10, including killing 94 Palestinians.
Updates: Israel PM Netanyahu orders ‘powerful, immediate’ attacks on Gaza
Netanyahu’s decision to attack Gaza comes despite US-brokered ceasefire that came into effect on October 10.Stephen Quillen (Al Jazeera)
like this
Israeli side is still a prevalent voice in covering the conflict with no voice leveraged to the same stage from palestinians, so whatever happens the mainstream news would be in their hands. It is an unequal exchange by design. It is hard to even start a dialog about peace if one side is a state recognized by everyone and the other is not.
One way is to start to recognize Palestine internationally, the other is to undo recognition of Israel. These tho can happily coexist.
I have no firm belief about this whole situation, but at the very least I don't find any reason for israelis to scale up their territory. If they are to have their 50s borders in the end, no israeli settler or IDF fighter has any right to cross that line, that they do as we speak. These are terrorist acts, and a genocide, and if Israeli dream can't be achieved without that, it is to be dismantled.
RSF fighters film themselves massacring Sudanese fleeing el-Fasher
The moment the paramilitary Rapid Support Forces (RSF) announced it had stormed the city of el-Fasher on Sunday morning, it was clear that 260,000 Sudanese trapped in the city were in serious and immediate danger.
Middle East Eye has reviewed dozens of video clips and images allegedly taken in el-Fasher since the RSF assault began.
Some were published by the RSF itself; others emerged on social media, particularly Sudanese Telegram groups.
RSF members filmed themselves with people they have captured fleeing. In one clip, scores of men are seen sat on the ground surrounded by fighters, who repeatedly call them “slaves”.
In another, fighters tell six detained men, who are in civilian clothes but identify themselves as soldiers, that they can flee. Once the men begin running, the gunmen open fire on them, downing at least three.
like this
This is one of the few reasons I wish there were gods. Humans are monsters and we need intervention. So easily and callously is human life destroyed.
How I wish the Sudanese, and so many other people in similar plights, mattered to the rest of the world.
😖
Gadgetbridge data dashboard
Hey all. Unemployed and looking for something fun/interesting to work on lol
I use gadgetbridge to connect to a smart ring to track some basic health data, and while having everything on the phone is OK, I much prefer doing/viewing things from my PC. I thought maybe having some kind of self hosted dashboard/site displaying data gathered by gadgetbridge could be cool, but what do you guys think? Anything more interesting that could be done with the database that it can export on a schedule? I've also considered having gadgetbridge as one of several sources, but I'm not sure how many other privacy conscious options are out there.
I'm thinking of just leaving the transferring of the database to other programs, would that be acceptable? I already have gadgetbridge export every 2hrs and use syncthing to get it onto the NAS.
Would appreciate any thoughts, or if you think it's unnecessary even.
SEIA Says Solar Still Cheapest Source Of Electricity, Australia Unveils Free Solar Plan
The Solar Energy Industries Association (SEIA) is obviously concerned by the full frontal assault on renewable energy being conducted by the Moron of Mar-A-Loco and his henchmen. In a blog post this week, it argued that solar will blow away all other forms of electricity generation — if they all compete on a level playing field.
SEIA Says Solar Still Cheapest Source Of Electricity, Australia Unveils Free Solar Plan - CleanTechnica
The SEIA says solar will win out over all forms of fossil fuels in a straight fight with no subsidies going to either side.Steve Hanley (CleanTechnica)
like this
[Technology Connections] I was right about dishwasher pods, and now I can prove it [41:26]
- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
Internet Archive’s legal fights are over, but its founder mourns what was lost - Ars Technica
Last month, the Internet Archive’s Wayback Machine archived its trillionth webpage, and the nonprofit invited its more than 1,200 library partners and 800,000 daily users to join a celebration of the moment. To honor “three decades of safeguarding the world’s online heritage,” the city of San Francisco declared October 22 to be “Internet Archive Day.” The Archive was also recently designated a federal depository library by Sen. Alex Padilla (D-Calif.), who proclaimed the organization a “perfect fit” to expand “access to federal government publications amid an increasingly digital landscape.”The Internet Archive might sound like a thriving organization, but it only recently emerged from years of bruising copyright battles that threatened to bankrupt the beloved library project. In the end, the fight led to more than 500,000 books being removed from the Archive’s “Open Library.”
“We survived,” Internet Archive founder Brewster Kahle told Ars. “But it wiped out the Library.”
An Internet Archive spokesperson confirmed to Ars that the archive currently faces no major lawsuits and no active threats to its collections. Kahle thinks “the world became stupider” when the Open Library was gutted—but he’s moving forward with new ideas.
Internet Archive’s legal fights are over, but its founder mourns what was lost
“We survived, but it wiped out the library,” Internet Archive’s founder says.Ashley Belanger (Ars Technica)
Internet Archive’s legal fights are over, but its founder mourns what was lost - Ars Technica
Last month, the Internet Archive’s Wayback Machine archived its trillionth webpage, and the nonprofit invited its more than 1,200 library partners and 800,000 daily users to join a celebration of the moment. To honor “three decades of safeguarding the world’s online heritage,” the city of San Francisco declared October 22 to be “Internet Archive Day.” The Archive was also recently designated a federal depository library by Sen. Alex Padilla (D-Calif.), who proclaimed the organization a “perfect fit” to expand “access to federal government publications amid an increasingly digital landscape.”The Internet Archive might sound like a thriving organization, but it only recently emerged from years of bruising copyright battles that threatened to bankrupt the beloved library project. In the end, the fight led to more than 500,000 books being removed from the Archive’s “Open Library.”
“We survived,” Internet Archive founder Brewster Kahle told Ars. “But it wiped out the Library.”
An Internet Archive spokesperson confirmed to Ars that the archive currently faces no major lawsuits and no active threats to its collections. Kahle thinks “the world became stupider” when the Open Library was gutted—but he’s moving forward with new ideas.
Internet Archive’s legal fights are over, but its founder mourns what was lost
“We survived, but it wiped out the library,” Internet Archive’s founder says.Ashley Belanger (Ars Technica)
adhocfungus likes this.
momenti tosti con la mancanza della distruzione, quindi l’octaggio diventa strategico (sto cercando un’alternativa decente al tagliarmi)
Come avevo vagamente accennato, in questi ultimi giorni, il vuoto oscuro sta ritornando, non so perché. Questo è un problema, sì, ma il vero problema è che, di conseguenza, stanno tornando anche le urge. Le distrazioni ovviamente non funzionano granché, sia perché l’oscurità rende di suo più difficile immergermi bene in esse… ma anche perché, […]
Why Trump hijacked the .gov domain
Why Trump hijacked the .gov domain
By using federal agency websites to blame Democrats for the government shutdown, MAGA and Trump have found a new online billboard to blast their enemies.Tina Nguyen (The Verge)
Genova, i cassonetti saranno intelligenti, ma il progetto si ferma
Genova, si ferma il progetto dei 'cassonetti intelligenti': costi alti, risultati modesti
Dal 2022 Amiu ha installato solo 5.400 contenitori sui 26 mila previsti, spendendo complessivamente 30 milioni di euro
telenord.it/genova-si-ferma-il…
Genova, si ferma il progetto dei 'cassonetti intelligenti': costi alti, risultati modesti
Dal 2022 Amiu ha installato solo 5.400 contenitori sui 26 mila previsti, spendendo complessivamente 30 milioni di euro tra bidoni e mezzi compatibiliRedazione (Telenord)
US Senate rejects funding package for 14th time with shutdown in 35th day
But talks between factions are under way as Democrats and Republicans try to bring standoff to a close
copymyjalopy likes this.
Belgian airspace lockdown: Brussels, Charleroi and Liège airports temporarily closed after multiple drone sightings
Belgian authorities temporarily closed the airspace above Brussels Airport (EBBR), Charleroi Airport (EBCI) and Liège Airport (EBLG) on Tuesday evening following multiple reports of drones flying near several strategic aviation sites, including civilian airports and military bases.
Security Breach Leaks Far-right Minister Ben-Gvir's Private Notes on Major Israeli Journalists, Politicians
Ben-Gvir's Professional Diary Details His Exchanges With Haaretz Opponent Amit Segal as Well as Israeli Rapper Yoav Eliasi, Also Known as The Shadow, Who Is Known for His Far-right Political Views
Archived version: archive.is/20251104211410/haar…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Security breach leaks far-right minister Ben-Gvir's private notes on major Israeli journalists, politicians
Ben-Gvir's professional diary details his exchanges with Haaretz opponent Amit Segal as well as Israeli rapper Yoav Eliasi, also known as The Shadow, who is known for his far-right political viewsJosh Breiner (Haaretz)
Iran releases two French nationals from detention
Cécile Kohler and Jacques Paris are thought to have been the last French people held in Iran.
Archived version: archive.is/newest/bbc.com/news…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
We’re not really close to the point where any prosthetic is an upgrade on any human limb. Prosthetics you can control with your mind do exist, but are severely limited compared to human limbs. I’ve yet to see any prosthetic that’s stronger than a human limb.
There are two big limitations to consider:
1. Even if you could attach a more powerful machine to a person, the attachment point is always going to be the weak point.
2. How do you power it? Battery technology just isn’t there yet. You’d be lucky if you got 2hrs of super arm followed by several hours of charging.
I’m no expert, but I do have an interest in prosthetics and have been following the news and have seen lots of conversations that have no solutions for those two problems.
Sheinbaum: Mexico close to reaching new flight route agreement with US
President Sheinbaum says Mexico can soon reach an accord with the U.S. regarding a dispute over the bilateral air transport agreement.
‘Civil war in the Democratic Party’: Andrew Cuomo votes in NYC election
‘Civil war in the Democratic Party’: Andrew Cuomo votes in NYC election
NYC mayoral candidate Andrew Cuomo said Trump would cut through rival Zohran Mamdani “like a hot knife through butter."Al Jazeera
copymyjalopy likes this.
Ex-candidato a vice-prefeito de Niterói é preso acusado de furto milionário
cross-posted from: lemmy.eco.br/post/18000443
É um esforço danado pra omitir quando é de direita.
Ex-candidato (do NOVO) a vice-prefeito (na chapa do PSL) de Niterói é preso acusado de furto milionário
Ex-candidato a vice-prefeito de Niterói é preso acusado de furto milionário
Apontado pela Polícia Civil como autor de um furto cinematográfico em Niterói, o empresário Alexandre Ceotto André, de 50 anos, foi preso na segunda-feira (3) após se entregar na Delegacia dMauro Touguinhó (atribunarj.com.br)
Jessie Gender: Liberalism Can't Save You [2h23m]
To celebrate election day, I made a video about the part of liberalism that keeps going “we can fix fascism with a well-crafted podcast episode.”
- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
What does Oracle actually do? | Good Work [11:47]
- YouTube
Profitez des vidéos et de la musique que vous aimez, mettez en ligne des contenus originaux, et partagez-les avec vos amis, vos proches et le monde entier.www.youtube.com
adhocfungus likes this.
A hospital in Xiamen, Fujian province, facilitated the world's first successful cross-border remote robot-assisted heart surgery with experts from France, marking a historic milestone
Hospital pioneers remote robotic surgery - People's Daily Online
A hospital in Xiamen, Fujian province, facilitated the world's first successful cross-border remoteen.people.cn
Jeffrey Epstein had accounts with Goldman Sachs and HSBC, documents show
Jeffrey Epstein, the disgraced late financier and sex offender, had accounts at Goldman Sachs (GS.N, HSBC (HSBA.L), and other banks, new court filings show.
The revelations came in previously sealed documents made public by JPMorgan Chase (JPM.N), once Epstein's main bank, in a now-settled lawsuit brought by the U.S. Virgin Islands, where Epstein had a private island residence.
Released to the public on Friday, the report did not provide dollar amounts or details about Epstein's relationships with other banks, but alerted authorities to money transfers he made.
A U.S. judge ordered the documents unsealed in response to requests from The New York Times and The Wall Street Journal. Bloomberg earlier reported the banks' names.
In an emailed statement, Goldman said: "We terminated our client relationship with Mr. Epstein, and his assets were transferred out of the firm in 2010."
HSBC declined to comment.
copymyjalopy likes this.
Shutdown may force US to close some air space next week, official sees 'mass chaos'
New Mexico becomes first state to offer free child care for all families
“New Mexico is creating the conditions for better outcomes in health, learning, and well-being,” said Neal Halfon, professor of pediatrics, public health and public policy at the University of California, Los Angeles.
In addition to offering free child care, the state has launched initiatives to expand access, including a campaign to recruit more licensed and registered home providers. It also established a $12.7 million low-interest loan fund to help construct, expand and renovate child care facilities.
New Mexico becomes first state to offer free child care for all families
New Mexico is now the first state in the nation to guarantee free child care for all families, regardless of income.Scripps News Group (News Channel 5 Nashville (WTVF))
Anticipazioni Belve 4 novembre 2025: Iva Zanicchi, Irene Pivetti e Adriano Pappalardo ospiti da Francesca Fagnani
Torna stasera, martedì 4 novembre 2025, alle 21:20 su Rai 2, un nuovo appuntamento con Belve, il programma ideato e condotto da Francesca Fagnani.
Il talk-show più irriverente della televisione italiana conferma anche questa settimana la sua formula vincente: interviste dirette, ironiche e profondamente umane, capaci di svelare lati inediti dei protagonisti dello spettacolo e della politica.
LEGGI LE ANTICIPAZIONI: Anticipazioni Belve 4 novembre 2025: Iva Zanicchi, Irene Pivetti e Adriano Pappalardo ospiti da Francesca Fagnani
Belve anticipazioni 4 novembre 2025: ospiti Iva Zanicchi, Pivetti e Pappalardo
Anticipazioni Belve del 4 novembre 2025: Francesca Fagnani intervista Iva Zanicchi, Irene Pivetti e Adriano Pappalardo. Tutti i dettagli e la sorpresa della serata.Redazione (Atom Heart Magazine)
Pentagon confirms ‘decapitation strikes’ for Venezuela as armada builds
Pentagon confirms ‘decapitation strikes’ for Venezuela as armada builds - MR Online
What Washington is building is not merely a show of force; it is a forward posture aimed at breaking the Bolivarian Republic’s resistance and installing a pliant, pro-U.S. order in Caracas.Editor (MR Online)
copymyjalopy likes this.
Jacobin Has Charted Zohran Mamdani’s Rise From the Beginning
Jacobin Has Charted Zohran Mamdani’s Rise From the Beginning
From our first interview immediately after he won his state assembly election in 2020 through profiles, op-eds, interviews, and speeches, Jacobin has closely covered Zohran Mamdani’s political career rooted in the socialist movement since its start.jacobin.com
Stratospheric Aerosol Injection may not be enough to save coffee, chocolate and wine, new study finds
Climate intervention may not be enough to save coffee, chocolate and wine, new study finds - IOP Publishing
A new study published in Environmental Research Letters reveals that even advanced climate intervention strategies may not be enough to secure the future of wine grapes, coffee and cacao.Kate Giles (IOP Publishing)
SAI is not a viable solution in general. I've studied this specifically, and it should be like a break-glass solution, if it all. It should be a "5 billion people will absolutely die unless we don't do it" type of thing.
Once started, it will have to be continued due to threat of termination shock, which could essentially compress all of the climate effects in the next 5 decades into 1 year or so, which will cause many millions of deaths. Also it will negatively affect some areas, and positively affect some areas, but it's very hard to precisely determine those areas, which can lead to geopolitical tensions and even war.
Tommy Robinson is a wasteman, but he shouldn’t have been arrested using terror laws
A court has found Tommy Robinson to be innocent of a terror-related offence. It follows a border stop in which Robinson refused to hand his phone over to the police. Unfortunately, it’s far from the first time authorities have used terror legislation as a blanket excuse to do whatever they like.
Robinson detained under Terrorism Act
As reported by the BBC, Tommy Robinson was stopped by the police at the entrance to the Channel Tunnel. It was there that he was asked to give his phone pin over, and it was there that he refused because he claimed to have “journalist material” on his device. As he was detained under Schedule 7 of the Terrorism Act, police had the right to demand that he unlock his phone, but Robinson refused.
This is what we wrote during the trial:
Now, we here at the Canary don’t consider Robinson to be a journalist because he isn’t one; he’s a political activist who uses the veneer or journalism to push a far-right agenda. At the same time, we are very much opposed to the Terrorism Act and the inevitable overreach which results from it.Anyone can be arrested at any time for refusing the police access to their electronic devices when ordered to do so under Schedule 7 of the Terrorism Act. No suspicion is required.
No one should support the prosecution of Tommy Robinson under this legislation.
— Gyll King Post Skip Diplomacy (@GyllKing) October 13, 2025
Highlighting how terror legislation is frequently used to abuse civil liberties, Emily Apple wrote the following for the Canary back in 2016:
The police have shown repeatedly that they regard fracking protesters as an extremist threat. Fracking protesters have been included in Prevent training about extremism, and campaigners questioned under anti-terrorism legislation at airports.
The government’s proscription of Palestine Action is the most significant misuse of terror legislation to happen recently:
The Met Police in effect confirms that the govt’s decision to ban Palestine Action as a terrorist group is “drawing resources away” from defending the public from actual terrorism. Who would have thought? pic.twitter.com/K1gvb1MCRJ— Mark Curtis (@markcurtis30) October 4, 2025
EXCLUSIVE: A Scottish counter-terrorism board found that Palestine Action’s activities fell below the threshold to be considered terrorism before the group were banned by Labour, The National can reveal pic.twitter.com/FJ85pTlqpQ
— The National (@ScotNational) October 14, 2025
If people have broken the law, that needs to be resolved in some fashion. The problem is successive governments and police services have decided that opposing them is an offence in itself – even when said opposition does not cross the threshold of illegality.
This state overreach needs to stop.
This extraordinary decision means we can no longer question who is labelled as a terrorist - Canary
This chilling decision has implications for all of us.Emily Apple (The Canary)
When SNAP benefits will arrive is still in flux. Here's what communities are doing to fill the gap
The Trump administration says it will restart the national food aid program known as SNAP using money from a Department of Agriculture contingency fund but will only pay out half the amount participants would normally receive.
In a court filing, officials said depleting that fund means "no funds will remain for new SNAP applicants certified in November, disaster assistance, or as a cushion against the potential catastrophic consequences of shutting down SNAP entirely."
Starting Nov. 1, SNAP benefits did not hit accounts as expected after the USDA, which administers SNAP, froze funding, citing the federal government shutdown. The shutdown is now in its 35th day.
It is unclear when low-income families who depend on SNAP will receive these partial funds. The Trump administration said it anticipates long delays — "anywhere from a few weeks to up to several months" — before benefits arrive in the hands of registered SNAP recipients.
Deranged Zionist senator Lindsey Graham says the quiet part out loud again
Deranged Zionist US senator Lindsey Graham is, once again, saying the quiet part out loud.
In a speech to the ‘Republican Jewish Coalition’ – a lobby group that claims to represent Jewish people but makes its real agenda clear by attacking those they consider to “possess strong anti-Israel biases” – Graham wasn’t shy about telling his audience, to frequent cheers, that the US is “killing all the right people” and that if anyone wants to object to US support for Israel they’d better argue with God, exulting that “we’ve run out of bombs” and adding that he feels “good about where we’re going as a nation”:
thecanary.co/wp-content/upload…
This is far from a one-off for the rancid Graham, who has previously threatened to invade the International Criminal Court for daring to issue an arrest warrant for war criminal Benjamin Netanyahu. He’s called for Gaza to be nuked, called for Israel to sink humanitarian boats trying to deliver aid to Gaza, demanded the US bomb Iran just in case it ever posed a danger to Israel and accused the United Nations relief agency, UNRWA, of teaching Palestinians in Gaza to “kill all the Jews”.
Zionist senator Lindsey Graham mouths off again
Bloodthirsty bigot Lindsey Graham told lobby group the Republican Jewish Coalition that the US is "killing all the right people"Skwawkbox (The Canary)
reshared this
Judge says allegations of conditions at Chicago-area immigration site are 'disgusting'
The government is accused of denying detainees proper access to food, water and medical care and coercing them to sign documents they don’t understand. Without that knowledge, and without private communication with lawyers, they have unknowingly relinquished their rights and faced deportation, the lawsuit alleges.
“This is not an issue of not getting a toilet or a Fiji water bottle,” attorney Alexa Van Brunt of the MacArthur Justice Center told the judge. “These are a set of dire conditions that when taken together paint a harrowing picture.”
U.S. District Judge Robert Gettleman presided at the hearing just days after Van Brunt’s group and the American Civil Liberties Union of Illinois filed the lawsuit and sought a temporary restraining order. The judge said the allegations are “disgusting.”
Tech companies don’t care that students use their AI agents to cheat
Tech companies don’t care that students use their AI agents to cheat
AI agents are unstoppable cheating machines, and AI companies like OpenAI and Perplexity don’t seem to mind.Elissa Welle (The Verge)
Proposal: Host reddit→lemmy crossposting bot (Lemmit)
Norway’s mega wealth fund to reject Elon Musk’s $1 trillion Tesla pay package
Norway's mega wealth fund to reject Elon Musk's $1 trillion Tesla pay package
Managers of the world’s largest sovereign wealth fund said they are “concerned” about the proposed deal.Chloe Taylor (CNBC)
adhocfungus likes this.
China Is Building the Future
What the U.S. Can Learn From China’s Technological Success
The United States can learn from its technological success.Eric Schmidt (The Atlantic)
November 2025 ForumWG Meeting
November 2025 ForumWG Meeting
Monthly meetings are held on the first Thursday of each month, at 13h00 to 14h00 Eastern Time (currently 18h00 to 19h00 UTC). You can find them listed in the SocialCG Calendar. The next meeting will be held (today) on 2 October 2025.
Please note the time difference if applicable, ForumWG meeting times follow Eastern (± Daylight) Time Zone.
Meeting link: meet.jit.si/ap-forum-wg
Discussions will continue re:
- Context (topic/thread) deletion and moving between audiences (communities/categories)
Re: November 2025 ForumWG Meeting
The Authoritarian Stack
The Authoritarian Stack
How Tech Billionaires Are Building a Post-Democratic America — And Why Europe Is Nextwww.authoritarian-stack.info
~~Probably an odd bug in WG Tunnel - either upload or download slow based on MTU~~ Edit: And it was an IPv6 leak (for the most part)
Edit: Yay, with MTU < 1280 the client seems to just disable IPv6, including the ::/0 in AllowedIPs.
Disabling IPv6 also fixed the low upload speed (probably getting a better route over Wireguard).
That also explains why the differences didn't present themselves with iperf3, as that absolutely had to use Wireguard.
What remains now is why TCP download takes such a huge hit, while it doesn't on laptop.
Not asking for support (anymore). I tried the official Wireguard client, and the issue doesn't present itself there.
So likely a bug, but a bit interesting.
Welp, few hours of playing around and searching wasted.
~~At least you might not waste time with it too, like I did, and I already wrote this...~~
App used: github.com/wgtunnel/wgtunnel
So, this seems like a bit of a magic.
"Server" has MTU of 1420, its connection is 1500. The now-limited ifconfig in Termux shows 1500 for data interface.
I've seen a few people mention the 80 bytes is overhead of WG.
I've had issues with far slower download speed (half expected), so I switched MTU to 1280 (minimum for IPv6) which worked for me in the past for Mullvad. No luck.
I've got an idea, that perhaps if my data interface is 1280, then I should try 1200. That worked... for download. Now upload got significantly slower. I also tried matching MTU on "server" but that made no difference. I also tried some fairly low values like 500, which worked for download, but further killed upload. So far that testing was done using speedtest.net and fast.com.
Through trial and error I've found:
if MTU >= 1280 then upload speed is normal, but download slower
if MTU <= 1279 then download speed is normal, but upload slower
Tailscale is using 1280, and is fine in both directions. Moving to iperf3 (seemingly unaffected by MTU changes):
Plain wireguard
Download (TCP)
```<>
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-20.12 sec 33.2 MBytes 13.9 Mbits/sec 117 sender
[ 5] 0.00-20.00 sec 32.2 MBytes 13.5 Mbits/sec receiver
Upload (TCP)
```<>
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-20.00 sec 101 MBytes 42.4 Mbits/sec 401 sender
[ 5] 0.00-20.17 sec 100 MBytes 41.6 Mbits/sec receiverDownload (UDP)
```<>
[ ID] Interval Transfer Bitrate Jitter Lost/Total Datagrams
[ 5] 0.00-20.13 sec 480 MBytes 200 Mbits/sec 0.000 ms 0/410100 (0%) sender
[ 5] 0.00-20.00 sec 267 MBytes 112 Mbits/sec 0.047 ms 174331/402352 (43%) receiver
Upload (UDP)
```<>
[ ID] Interval Transfer Bitrate Jitter Lost/Total Datagrams
[ 5] 0.00-20.00 sec 477 MBytes 200 Mbits/sec 0.000 ms 0/407504 (0%) sender
[ 5] 0.00-20.54 sec 119 MBytes 48.5 Mbits/sec 0.201 ms 305999/407495 (75%) receiverConclusion: TCP download significantly slower.
Tailscale
Download (TCP)
```<>
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-20.12 sec 236 MBytes 98.6 Mbits/sec 2 sender
[ 5] 0.00-20.00 sec 233 MBytes 97.7 Mbits/sec receiver
Upload (TCP)
```<>
[ ID] Interval Transfer Bitrate Retr
[ 5] 0.00-20.00 sec 120 MBytes 50.2 Mbits/sec 625 sender
[ 5] 0.00-20.15 sec 119 MBytes 49.6 Mbits/sec receiverDownload (UDP)
```<>
[ ID] Interval Transfer Bitrate Jitter Lost/Total Datagrams
[ 5] 0.00-20.12 sec 480 MBytes 200 Mbits/sec 0.000 ms 0/409543 (0%) sender
[ 5] 0.00-20.00 sec 254 MBytes 107 Mbits/sec 0.039 ms 176388/393285 (45%) receiver
Upload (UDP)
```<>
[ ID] Interval Transfer Bitrate Jitter Lost/Total Datagrams
[ 5] 0.00-20.00 sec 477 MBytes 200 Mbits/sec 0.000 ms 0/407167 (0%) sender
[ 5] 0.00-20.29 sec 138 MBytes 57.2 Mbits/sec 0.196 ms 289036/407167 (71%) receiverConclusion: No significant difference between UDP vs TCP.
Note: 200 Mbits/sec in UDP tests refers to my pre-set limit, as higher speeds wouldn't be achieved anyway. Otherwise it keeps spraying out at full speed if no limit is set.
And now for the biggest oddity: My laptop speeds are fine even with default 1420 MTU, even though it runs over hostpot.
What magic is going on in here?
Also, the VPS doesn't have IPv6, so it's probably not that being routed slower in one direction (as IPv6 requires 1280).
GitHub - wgtunnel/wgtunnel: A FOSS Android client for WireGuard and AmneziaWG with auto-tunneling.
A FOSS Android client for WireGuard and AmneziaWG with auto-tunneling. - wgtunnel/wgtunnelGitHub
like this
Fixing an old hack - why we are bumping the IPv6 MTU
Back in 2015 we deployed ECMP routing - Equal Cost Multi Path - within our datacenters. This technology allowed us to spread traffic heading to a single IP address across multiple physical servers.The Cloudflare Blog
Welp, turns out I am just an idiot. 1279 and below disabled IPv6, and thus the ::/0 route didn't get applied either, causing a leak. What's still odd is the lower download speed that doesn't happen in another client.
As for the upload, it probably gets a better route through the VPS, giving me a faster speed, and giving me some confusion.
So my first idea with IPv6 was close, but on the other side of the connection.
Anyway, your reply helped me find this issue, as my outtake was to try fully disabling IPv6 (not the first time I tried such "solution").
rtxn
in reply to marci • • •Probably. If that setting is enabled, Android (including Graphene) defaults to 8.8.8.8 if the higher-priority DNS servers (manual or received from DHCP) don't support DNS-over-TLS or DNS-over-HTTPS.
marci
in reply to rtxn • • •Any other ideas on how to pin down the issue?
rtxn
in reply to marci • • •digornslookupcommand to query the DNS name, and check which DNS server is queried. If it's the private server's address, you might be having connectivity issues. If it's100.100.100.100, the resolver is still trying to query Tailscale's MagicDNS.hexagonwin
in reply to rtxn • • •doesn't termux always default to 1.1.1.1?
edit: old.reddit.com/r/pihole/commen… maybe its 8.8.8.8, don't have my phone so can't check rn
marci
in reply to hexagonwin • • •kossa
in reply to marci • • •I kinda had a similar problem. Never found the root cause, but what did the trick for me was to put an OpenWRT Router between the default ISP router and my home network.
As I said, I never figured out, why Android did not respect the DHCP settings of the default router, but here we are. Maybe it was some DNS shenanigans by the ISP's config, maybe it was a wrong DNS/DHCP configs from my side, maybe it was IPv6 shenanigans. Those are the culprits I would investigate from your side.
marci
in reply to kossa • • •Thanks!