this post was submitted on 21 Apr 2025
19 points (88.0% liked)

Privacy

40029 readers
341 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

When I connect to a VPN my Ubuntu laptop calls to an ip address BEFORE CONNECTING and the whois is:

inetnum:        185.125.188.0 - 185.125.191.255
netname:        UK-CANONICAL-20151111
country:        GB
...
organisation:   ORG-CGL14-RIPE
org-name:       Canonical Group Limited
country:        GB
org-type:       LIR
address:        5 New Street Square
address:        EC4A 3TW
address:        London
address:        UNITED KINGDOM

What is this and why?? Why does Ubuntu check in to Canonical HQ when I connect to internet??

all 13 comments
sorted by: hot top controversial new old
[–] ShellMonkey@lemmy.socdojo.com 29 points 3 months ago (1 children)

My guess would be an online connectivity check. Most systems try and reach some domain to say if they have network or not. Would be a logical place for them to try.

[–] 0xtero@beehaw.org 1 points 2 months ago

Or NTP sync

[–] Tundra@lemmy.ml 22 points 3 months ago* (last edited 3 months ago)

Canonical is the company that create Ubuntu

https://canonical.com/

[–] Cadende@hexbear.net 7 points 3 months ago* (last edited 3 months ago)

It may be the basic ubuntu telemetry (relatively non-invasive, but still a concern for the privacy-minded) sent by this tool unless you opted out at install:

https://github.com/ubuntu/ubuntu-report

from that page:

So it would not surprise me if it was scheduled to send, failed, and then re-triggered upon activation of a new network connection (the VPN).

Edit: Or even more likely, it is a connection from networkmanager to connectivity-check.ubuntu.com

https://ubuntu.com/core/docs/networkmanager/snap-configuration/connectivity-check

[–] drspod@lemmy.ml 5 points 3 months ago

tcpdump that shit

[–] Dran_Arcana@lemmy.world 5 points 3 months ago* (last edited 3 months ago)

It's almost certainly related to cloud-init, (the canonical tool for handling deployment automation) or Ubuntu pro (extra long support for backporting security packages to older distros, plus some conveniences). They're pre installed as a convenience to paid users of those services, that's the (IMHO, quite reasonable) model they use to fund the distro. I would expect that some or all of that traffic would disappear if you disable/remove those two services.

https://cloud-init.io/

https://ubuntu.com/pro

[–] catloaf@lemm.ee 3 points 3 months ago

What exactly is the connection?

[–] golden_zealot@lemmy.ml 2 points 3 months ago

Sniff the packets and see if you can determine what the data is.

[–] 0xtero@beehaw.org 2 points 3 months ago