• 1 Post
  • 1.06K Comments
Joined 2 years ago
cake
Cake day: August 8th, 2023

help-circle






  • fail2ban

    I’m familiar with f2b. I even have several clients licensed with the commercial version but it doesn’t fit this use case as there’s no logon failure for it to work with.

    I automatically ban any IP that comes from outside the US because there’s literally no reason for anyone outside the US to make requests to my infra.

    I have systems setup with geo-blocking but it’s of limited use due to the prevalence of VPNs.

    also, use a WAF on a NAT to expose your apps.

    This isn’t a solution either because a WAF has no way to know what traffic is bad so it doesn’t know what to block.




  • What will happen is that politicians will see this as another reason to push for everyone having their ID associated with their Internet traffic.

    Yes, because like or not that’s the only possible solution. If all traffic was required to be signed and the signatures were tied to an entity then you could refuse unsigned traffic and if signed traffic was causing problems you’d know who it was and have recourse.

    I don’t like this solution but it’s the only way forward that I can see.











  • We actually don’t need an entire Open Source Printer, just an open source controller. So you can buy $printer and then replace it’s control board with an Open Source version. We’re doing this already with things that weigh hundreds of pounds, spin at thousands of RPM, and literally contain explosions!

    Gear heads (car people) are very familiar with this. There’s at least three major, and many minor, Electronic Fuel Injection / Engine Management Systems out there that will allow you to strip the factory “brains” out of a car and replace them with stuff you can control / program yourself.

    A printer is just an assembly of mechanical parts and there’s no reason that an Open Source controller couldn’t command them.