Good god, what if more app developers learn this and implement it?!?!?! Somebody delete my posts!!!!
This technique is not new and Instagram is doing that since ages, the only difference is it doesn't alert the end-user about that but it bombarded the Pixelserv-tls with an insane amount of retry attempts to call home that it even interferes with Pixelserv-tls performance.
I'm sure there are many other apps as well.
Apps. One more way to give away control of your devices, data, and security.
I think that would explain the ungodly amount of “slu” errors I see when the family is instagram-ing away. Knew it was some app or another but this fits.
This is from left field - I got this after the iOS 13.3.1 update yesterday. Below steps cleared the error for me.Update; no dice. Deleted the app, rebooted the phone, reinstalled and still getting the error.
Hmmm... wonder what “checks” this app does.
ep - This manages installed Entware packages.
3 - Manage pixelserv-tls certificates
1 - Purge pixelserv-tls domain certificates
Yep, "graph.instagram.com" is the culpritURLIRL .
For what it’s worth when the brain trust was at its peak during the development of pixelserv 2.2, it was determined through quite a lot of testing that this was the case. What is changing, more recently, is that more and more apps are moving to that model. One of the big reasons everyone is trying to push you to their apps rather than websites and etc. so that they can gather a stunning amount of tracking data that the average user can’t circumvent. The surprising thing to me is that this app was so honest about what was failing.Not exactly. I'm speculating that the expected certificate signature is hard-coded in the app and the pixelserv-generated certificate signature doesn't match that. A way to prevent spoofing of certs, but it's hard to say with any certainty what they're doing inside.
EDIT: what @Asad Ali said.
The surprising thing to me is that this app was so honest about what was failing.
The Entware maintainers have released updated packages. This now brings the official release of pixelserv-tls 2.3.1 to those that were patiently waiting for it.
Use ep in amtm or Diversion to update Entware packages.
Note that for those that updated pixelserv-tls manually or through Diversion to v2.3.1 need to restart pixelserv-tls after the update, in ep, 4.
Since both amtm and Diversion see no version change when it was previously updated to v2.3.1, this step is necessary.
pixelserv-tls 2.3.1 (compiled: Dec 19 2019 11:03:57 flags: tls1_3) options: 192.168.2.3
Mine shows -Thanks!
For the entware pixelserv-tls, what do we expect to see in the banner? This is what I see after updating the entware packages and restarting pixelserv:
Code:pixelserv-tls 2.3.1 (compiled: Dec 19 2019 11:03:57 flags: tls1_3) options: 192.168.2.3
pixelserv-tls 2.3.1 (compiled: Jan 31 2020 13:27:14 flags: tfo tls1_3) options: 192.168.1.2
Mine shows -
Code:pixelserv-tls 2.3.1 (compiled: Jan 31 2020 13:27:14 flags: tfo tls1_3) options: 192.168.1.2
pixelserv-tls 2.3.1 (compiled: Dec 13 2019 20:33:42 flags: tfo tls1_3)
pixelserv-tls 2.3.1 (compiled: Jan 31 2020 13:27:14 flags: tfo tls1_3)
I did as well, when the 2.3.1 update was posted in the pixelserv-tls thread. Just ran the ep update from AMTM (and ep then 4 in Diversion) and this is what I see. (compiled: Jan 31 2020 13:27:14)I did mine manually awhile back.
Code:pixelserv-tls 2.3.1 (compiled: Dec 13 2019 20:33:42 flags: tfo tls1_3)
after you forced the update did you restart the service?
This updates or upgrades pixelserv-tls v2.3.1
1. Update pixelserv-tls, regular Entware version
2. Upgrade pixelserv-tls, regular Entware version
3. Upgrade pixelserv-tls to v2.3.1, Jack Yaz version
Yes- multiple times. There doesn't seem to be a way to force an update, unless I'm missing something. All I see is:
Code:This updates or upgrades pixelserv-tls v2.3.1 1. Update pixelserv-tls, regular Entware version 2. Upgrade pixelserv-tls, regular Entware version 3. Upgrade pixelserv-tls to v2.3.1, Jack Yaz version
This is @Jack Yaz version. Use ep to update to the official release version.pixelserv-tls 2.3.1 (compiled: Dec 19 2019 11:03:57 flags: tls1_3) options: 192.168.2.3
Use ep>6>5 option.
Thread starter | Title | Forum | Replies | Date |
---|---|---|---|---|
C | Diversion Pixelserv replacement | Asuswrt-Merlin AddOns | 2 | |
L | Is Diversion better than NextDNS, PiHole or AdGuard Home? | Asuswrt-Merlin AddOns | 10 |
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!