101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

496
active users

#cloudflare

1 post1 participant0 posts today

Вот что ещё нужно сделать, чтобы люди отказались от клаудфлэра??

Они наивно полагают, что флэр действительно защищает от ддос-атак, хотя показал абсолютную бесполезность стандартных правил блокировки много раз, в качестве примера приведу кейс N+1

Они доверяют инфраструктуре, хотя сервера флэра регулярно падают, падает весь централизованный интернет

И почему-то даже люди из ИТ не всегда осознают, что это — классический реверс-прокси, что флэр выполняет MitM-атаку: роутит запросы на свои сервера со своим TLS-сертификатом, расшифровывает трафик и перенаправляет его на настоящий сервер (upstream, origin server)

То есть флэр видит все ваши пароли и токены, отправляемые файлы, а заодно знает айпи-адрес, юзер-агент и все остальные хедеры, спокойно может подменить ответ апстрима (так и делает, кстати, в случае с минификацией css/js), ну и в итоге выполняет функцию глобальной системы трекинга, абсолютной слежки, которую админы добровольно установили на сайт и которую остановить адблоком уже не получится

@rf #cloudflare #privacy

TelegramN + 1Вообще что за дудос или DDoS-атака (это то, что сейчас с нами происходит)? Расшифровывается как Distributed Denial of Service, а переводится — «распределенный отказ в обслуживании». Что это значит: например, наш сайт рассчитан на одновременное подключение 10 000 пользователей, и, чтобы нам насолить (зачем-то, мы пока не понимаем), нехорошие люди направляют на наш сайт большое количество запросов с ip-адресов разных стран (см. скриншот). Собственно, из-за этого и появляются проблемы с загрузкой и отображением материалов. Как раз такой целенаправленной атаке подвергся наш сайт. Первая атака была сегодня ночью, а остальные происходят прямо сейчас.

Good news! We've officially added #Cloudflare #Workers support to the #Fedify roadmap. We've created a detailed issue to track our implementation plan: https://github.com/fedify-dev/fedify/issues/233.

The effort will be tackled in phases, including compatibility assessment, core adaptations for Workers' environment, KV store and message queue implementations, and finally integration with Cloudflare's ecosystem. This will be a substantial project that we'll break down into several sub-issues.

If you're interested in contributing to any specific aspect of Workers support, please comment on the main issue to coordinate efforts.

GitHubCloudflare Workers · Issue #233 · fedify-dev/fedifyBy dahlia

alright, @alexchapman and everyone, you guys should really look at this!
i'm really fuckin mad right now!
so the password leaked feature on cloudflare WAF?
completely!
fuckin!
deceptive!
I don't know about you, but to me, this is a pretty....damn alarming issue!
I want you to come along with me as I show you why
go here
myaccount.blindsoft.net and try these credentials, you will quickly find out they work perfectly, with no roadblocks, even though, in theory, this should not work!
email:
leaked@blindsoft.net
password (without quotes): "admin123"
#cloudflare #cybersecurity @infosec @cybersecurity

myaccount.blindsoft.netmyAuth

torrentfreak.com/dns-piracy-bl

in short, when Government agencies insist a DNS provider block (or worse poison) the resolver for a given pirate site, companies have responded in different ways

OpenDNS = Would rather stop serving an entire country than capitulate

Cloudflare = Blocks the IP but gives an explicit error message stating that it is being forced to do so.

Google DNS = Complete & total submission, DNS won't resolve, leaves customers in the dark.

torrentfreak.comDNS Piracy Blocking Orders: Google, Cloudflare, and OpenDNS Respond Differently * TorrentFreakFacing escalating DNS piracy blocking orders, major providers like OpenDNS, Cloudflare, and Google are adopting notably different responses.

When can we declare IP Geo location / country code blocking practically dead as a mitigation strategy?

Sure it is still useful blocking script kiddies from Iran and other low hanging fruit, but do any serious APT crews actually launch attacks from their home country anymore?

With the use of zero trust, distributed attack and delivery networks (looking at you Cloudflare), and VPN usage country blocking feels less useful than in the past.

Replied in thread
@ins0mniak Torba / #Gab is delusional in thinking his site doen't need it's own users and communities. It's exactly the opposite, we couldn't care less what server it is, we just use these social media sites to chat and talk to people, anyone can operate something like Gab, and him constantly complaining about costs and so on is ludicrous for anyone familiar with the costs nowadays - they're basically giving away these servers, and bandwidth is unlimited and free of charge usually.
Cloudflare is advertised as protecting against hackers and DDOS and such things, but is this worth letting your entire traffic be decrypted by this dubious site? It's extremely suspicious - how can #Cloudflare offer all this for free? (or low cost idk), definitely smells like a honeypot
Replied in thread
@ins0mniak definitely Gab is not to be trusted, trusted with personal data such as real ID and real IP, which is why a VPN or similar measure is not a bad idea there and on many other places on the internet. Gab could be hacked or Torba could give the data way voluntarily, so obviously it shouldn't be given to them in the first place. Them insulting VPN users or stigmatizing them as trolls is outrageous, many dissidents use VPNs even without knowing what they do exactly, probably didn't actually help, but I would never insult them for trying it, which Torba and his "experts" apparently are doing. Some VPN providers were actually advertising on Gab!!! 😆 #Cloudflare is a honeypot in my estimation - it is officially known to decrypt all SSL&TLS traffic, before re-encrypting it and sending it on to the original site, encrypted for this site - how can anyone not be disturbed by this is beyond me.

@cR0w @da_667 nodds in agreement

But the best are those "#AV" Vendors that use #ClownFlare "for #DDoS-Protection" like some #malware distributors from #Russia.

  • Makes them look really trustworthy!

Personally, I just #ban all #proproetary file.formats & -protocols as a matter of principle!

Can you imagine a country where you can't access your server through a cloudflare tunnel because a national sports association has managed to ban its access (and any website that uses it) because pirate sports broadcasting websites also use it? That country is Spain.

By the way, it's midnight around here and the cloudlflare tunnel is working again because the sports day is over.