Admin on the slrpnk.net Lemmy instance.

He/Him or what ever you feel like.

XMPP: povoq@slrpnk.net

Avatar is an image of a baby octopus.

  • 528 Posts
  • 2.61K Comments
Joined 3 years ago
cake
Cake day: September 19th, 2022

help-circle



  • If someone is offering a public wifi, there is a reasonable expectation that other people sitting in the same cafe for example can’t listen in on what you are doing on your device. As older wifi encyption standards are easily compromised, this requires enforcing a semi-recent wifi-standard. You can of course make your own judgement in your own home, but in a public space it is different.

    As for SSL certificates… this isn’t only a captive portal issue. If your device has such outdated root certificates that you run into issues already at the captive portal, you will have also issues with each and every website that uses https. Root certificates are only cycled out of use for good reasons, such as them becoming compromised, so by using an super old root certificate on your device you are wide open to MITM attacks on supposedly secure connections.













  • poVoq@slrpnk.netMtoSelf-hosting@slrpnk.netConntrack question
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    11 days ago

    You could enable Suricata on OPNsense, which will allow you to subscribe to some known attacker lists and so one. But the problem these days are mostly AI scrapers that usually don’t show up on these lists as they are not attackers per se, but just cause a lot of database load by repeatably probing every part of your web-applications.






  • No one is disputing that in theory (!) Anubis offers very little protection against an adversary that specifically tries to circumvent it, but we are dealing with an elephant in the porcelain shop kind of situation. The AI companies simply don’t care if they kill off small independently hosted web-applications with their scraping and Anubis is the mouse that is currently sufficient to make them back off.

    And no, forced site reloads are extremely disruptive for web-applications and often force a lot of extra load for re-authentication etc. It is not as easy as you make it sound.