• 18 Posts
  • 100 Comments
Joined 2 年前
cake
Cake day: 2023年7月3日

help-circle




  • That’s because they just terminate TLS at their end. Your DNS record is “poisoned” by the orange cloud and their infrastructure answers for you. They happen to have a trusted root CA so they just present one of their own certificates with a SAN that matches your domain and your browser trusts it. Bingo, TLS termination at CF servers. They have it in cleartext then and just re-encrypt it with your origin server if you enforce TLS, but at that point it’s meaningless.




  • That’s a super valid question, as it seems sometimes that some of these things are configured in a way that begs the question “why?” As far as contributing to documentation, that’s a moot point. This is already in the man pages, and that’s exactly what I referenced in writing this post, in addition to some empirical testing of course. As far as implementation goes, I think that probably lies at a per distribution level, where not one size fits all. Although I don’t know of it off the top of my head, I’m sure there’s a security centric distro out there that implements more of these sandboxing options by default.








  • The primary thing is rather than “dumb” flood routing, you can choose the path your message takes to its destination; as a repeater operator you can also choose the path it takes to repeat out. Its a slight compensation to people carelessly placing infrastructure nodes with poor configurations in poor places. Not perfect, but better. Adoption is much, much lower though, and the licensing is not copyleft.



  • That’s a great question!

    No, blocking a node – router or other – will only block packets originating from that node. All traffic that is forwarded by that node, but originating from others will still be received.

    Ultimately, the only place that blocking nodes strategically makes sense is on high utilization routers. If you’re just blocking nodes on a client, it’s not changing channel or airtime utilization for the rest of the mesh. That said though, if someone is harassing you then a block on a client is still fully worth it. 🙂







  • It’s not about user-led synergy. The personal data market is slurped up by those that already have and are building correlations. Just because a user didn’t report anything to their insurer doesn’t mean an insurer sure as shit isn’t going to want the data if they can link it to the user whatsoever, so long as it will make them more money.

    This is hypothetical, of course, but it’s the way the market of data brokers works.