mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

8.1K
active users

#geoblocking

0 posts0 participants0 posts today

Here's a #security #tip for you...

If you host your own services (either at home or in the cloud) -- especially if you also use
#CloudFlare -- one of the easiest, simples, fastest, and effective things you can do is to enable #GeoBlocking for your domain.

What is geoblocking? It's where you only allow traffic to your service from locations that need it.

I'm not talking about a self-hosted fedi instance. I'm talking about things like
#NextCloud, #VaultWarden, self-hosted photo galleries, Plex servers, etc.

If you're in the UK, do you really want someone in Belarus or Myanmar being able to access your own private web service?

By enabling geo blocking for your domain you can restrict your services to only be accessible from those geographic regions that you authorize.

Say you're in the UK but you frequently vacation in Spain or Cyprus or Greece. Only enable traffic to your services from the UK, Spain, Cyprus, and Greece.

What you're doing is reducing your exposure to network-based threats and attacks.

Best of all it takes two seconds to setup.

Replied in thread

@landley @pmevzek @jschauma @ryanc @0xabad1dea And that is espechally baffling considering that #APNIC as #RIR ran out of #IPv4|s first.

Cuz people telling me "Oh, just use HEnet's Tunnelbroker"" never experienced the shitshow that is #Geoblocking and #GDPR-#Noncompliance with #Malvertising to slap their faces!

  • Cuz believe me, I tried, but since some idiots decided to #GeoIP entire #ASN|s and not #IP - #Allocations the PoP in FRA (FFM actually) will get me mislocated to the #USA!
Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)@pmevzek@framapiaf.org @landley@mstdn.jp @jschauma@mstdn.social @ryanc@infosec.exchange @0xabad1dea@infosec.exchange no, it's just absurd to skip #64bit... I'd not be pissed if #IPv6 was widely available. - I can't even get a /64 but my ISP is happy to give me /28 subnets of IPv4...
#GeoIP#asn#ip
Replied in thread

@neu3no @halva yes and no.

  • I can see the benefit of a miniaturized retro gaming system (I think legacy systems need to be served with properly maintained software & hardware).

youtube.com/watch?v=2P1E2vjpcRo
youtube.com/watch?v=B8WfiRRvQXo

As with #IPv4 the problem is that there is no mandate to provide users with static prefixes and I'm stuck on a /28 of IPv4's and can't even get a singoe /64.

  • And before you ask: No, #Tunnelbroker is not a valid solution as HE.net's tunnel will get #USA #GeoIP'd even eith the PoP in FRA so it bricks a shitload of things due to #Geoblocking and bad #peering. Believe me, I tried that already!
Replied in thread

@jwildeboer I do #GeoBlocking on the login side of my server (submission, imap). Only login from an European country is allowed. This is possible, because I usually know the whereabouts of my users. If we travel outside Europe, I can temporarily allow that counrty. :-)

Do you do anything of that kind?

AppleTV: “Do you want to use your account on this (vacation home) AppleTV? Sign in!”

Me: Sure, and install my previously installed Discovery+ app so I can watch Snooker!

AppleTV: “I’ll switch to the German App Store and install that app for you!“

Me: “Cool! Open it.”

Discovery+ App: “You’re in Denmark, Discovery+ is Max here. Please install the Max app.”

App Store Germany: “There is no Max app here.”

Replied in thread

@landley @jschauma @ryanc @0xabad1dea yeah, the exhaustion problem would've been shoved back with a #64bit or sufficiently delayed by a 40bit number.

Unless we also hate #NAT and expect every device to have a unique static #IP (which is a #privacy nightmare at best that "#PrivacyExtensions" barely fixed.)

  • I mean they could've also gone the #DECnet approach and use the #EUI48 / #MAC-Address (or #EUI64) as static addressing system, but that would've made #vendors and not #ISPs the powerful forces of allocation. (Similar to how technically the #ICCID dictates #GSM / #4G / #5G access and not the #IMEI unless places like Australia ban imported devices.

I guess using a #128bit address space was inspired by #ZFS doing the same before, as the folks who designed both wanted to design a solution that clearly will outlive them (way harder than COBOL has outlived Grace Hopper)...

If I was @BNetzA I would've mandated #DualStack and banned #CGNAT (or at least the use of CGNAT in #RFC1918 address spaces) as well as #DualStackLite!

Replied in thread

@shoppingtonz @alternativeto @torproject also every #Tunneling - regardless if #SSH or #VPN or whatever - will inevitably introduce #latency (unless you happen to be customer of a shitty #ISP with horrible #peering and thus can cut down on hops needed, which is AFAIK only a theoretical scenario)...

In fact I stopped using #HEnet #Tunnelbroker and #IPv6-#GIF-Tunneling because it created more issued than it solved on my #IPv4only #Internet connection…

Apple-Geräte aus China: Harte Blockade von Apple Intelligence

Wer Mac, iPhone & iPad in China kauft, kann darauf Apple Intelligence nicht starten, auch nicht mit passendem Account. Apple nutzt offenbar hartes Geoblocking.

heise.de/news/Apple-Geraete-au

heise online · Apple-Geräte aus China: Harte Blockade von Apple IntelligenceBy Ben Schwan