mastodon.ie is one of the many independent Mastodon servers you can use to participate in the fediverse.
Irish Mastodon - run from Ireland, we welcome all who respect the community rules and members.

Administered by:

Server stats:

1.7K
active users

#geoblocking

0 posts0 participants0 posts today

When can we declare IP Geo location / country code blocking practically dead as a mitigation strategy?

Sure it is still useful blocking script kiddies from Iran and other low hanging fruit, but do any serious APT crews actually launch attacks from their home country anymore?

With the use of zero trust, distributed attack and delivery networks (looking at you Cloudflare), and VPN usage country blocking feels less useful than in the past.

AppleTV: “Do you want to use your account on this (vacation home) AppleTV? Sign in!”

Me: Sure, and install my previously installed Discovery+ app so I can watch Snooker!

AppleTV: “I’ll switch to the German App Store and install that app for you!“

Me: “Cool! Open it.”

Discovery+ App: “You’re in Denmark, Discovery+ is Max here. Please install the Max app.”

App Store Germany: “There is no Max app here.”

Replied in thread

@landley @jschauma @ryanc @0xabad1dea yeah, the exhaustion problem would've been shoved back with a #64bit or sufficiently delayed by a 40bit number.

Unless we also hate #NAT and expect every device to have a unique static #IP (which is a #privacy nightmare at best that "#PrivacyExtensions" barely fixed.)

  • I mean they could've also gone the #DECnet approach and use the #EUI48 / #MAC-Address (or #EUI64) as static addressing system, but that would've made #vendors and not #ISPs the powerful forces of allocation. (Similar to how technically the #ICCID dictates #GSM / #4G / #5G access and not the #IMEI unless places like Australia ban imported devices.

I guess using a #128bit address space was inspired by #ZFS doing the same before, as the folks who designed both wanted to design a solution that clearly will outlive them (way harder than COBOL has outlived Grace Hopper)...

If I was @BNetzA I would've mandated #DualStack and banned #CGNAT (or at least the use of CGNAT in #RFC1918 address spaces) as well as #DualStackLite!

Replied in thread

@shoppingtonz @alternativeto @torproject also every #Tunneling - regardless if #SSH or #VPN or whatever - will inevitably introduce #latency (unless you happen to be customer of a shitty #ISP with horrible #peering and thus can cut down on hops needed, which is AFAIK only a theoretical scenario)...

In fact I stopped using #HEnet #Tunnelbroker and #IPv6-#GIF-Tunneling because it created more issued than it solved on my #IPv4only #Internet connection…

Replied in thread

@fennix TBH, I think those bs claims should be illegal.

The only valid claims I've seen is that it enables people to circumvent #geoblocking and potentially #InternetCensorship as well as #TrafficDiscrimination due to lack of #NetNeutrality, but those are always to be taken with a truckload of salt!

Most certsinly, there are no "#loglessVPN|s" and no #VPN provider will risk jailtime for any.client

Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”

Ich schaue als #Auslandsdeutsche gerade die Wahlsendung der @tagesschau, aber ich muss mich via VPN ins Netz der Universität Mainz einloggen, um die Sendung online zu sehen. Zum Glück habe ich da noch Zugang! Ansonsten greift leider das #Geoblocking. Liebe #ARD, ich verstehe ja, dass Champions League nicht global frei ausgestrahlt wird, aber eine politische Sendung, die auch im Ausland lebende Deutsche betrifft, die sollte auf jeden Fall für alle zugänglich sein! Das sehe ich als Grundauftrag.

Replied in thread

@kubikpixel @malwaretech @tomscott or to put it into perspective:

I worked at a telco, and whilst clients were above-average in terns of bahaviour, one does get a high single digit or low double-digit amount of LEA requests per day per x million customers.

Now imagine the average #VPN has similar utilization as a #CGNAT, so easily they'll have #LawfulInterception going on 24/7 because logless VPNs are a lie and besides circumventing #Geoblocking they don't do anything else...

  • In fact I'd argue it'll be more privacy friendly to self-host a VPN on-demand with flexible hoster or just having a fixed IP at home, simply because those usually have a higher bar for getting surveillance approved.

TLDR: Just get @torproject @tails_live @tails / #Tails and good.

Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”