home.social

#proxies — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #proxies, aggregated by home.social.

  1. Ah, nothing screams "cutting-edge tech" like a 3,000-word manifesto on using #proxies to hide secrets from a #chatbot. 🤖🔒 Because clearly, the ultimate #espionage threat is a #language #model with unfulfilled dreams of becoming James Bond. 🕵️‍♂️💻
    joinformal.com/blog/using-prox #cuttingedge #tech #3000wordmanifesto #HackerNews #ngated

  2. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  3. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  4. Apparently, there exists a website called ipv4[.]games, where you can register HTTP web requests from hosts where you have access to. Once accessed, you can "claim" the requesting #IPv4 address with an #HTTP GET request on /claim?name=<NAME>.

    The leaderboard leads the person which claims most addresses of various /8 networks.

    It is wild to see partially 6-digit numbers for various /8s claimed by one and the same user.

    My guess is: Either they leverage residential proxies, or leverage perhaps mass-spamming on having millions of people world-wide clicking links, or alternatively, leveraging modern software design to do the lookup for them (e.g. website previews on social media, or anti-phishing services that do a lookup, before they forward the mail to you).

    No matter what, I am sure that millions of these IP addresses in there can be harvested as #open #proxies

    Other than that, I like the idea, and love how gamification leads to some people developing creative ways on making millions of hosts on the Internet access this website. It probably still invites to unsolicited requests from strangers unknowingly participating in the game of a tech-savvy person.

    #Spamming #spoofing

  5. Our censorship evasion services have processed over 650TB of bandwidth combined in the past 30 days ⚡️

    Help us build more infrastructure, and reach 1PB per month & beyond by making a tax-deductible donation of any amount: unredacted.org/donate/ - we also accept cryptocurrency!

    If you have questions, we're here to answer them 😎

    #Censorship #Tor #Proxies #XMR #ZEC #BTC #Crypto

  6. Commented on FCLTGlobal report, Beyond the Blame Game: Why the Proxy System Needs to Change. (added to prior post corpgov.net/2024/12/pre-disclo ) Reads like DOGE technocrats dismantling government to privatize democracy international transhumanist billionaires who believe they can live forever by merging with machines. Still, the report is the consensus of some of the world’s most important and influential organizations. As such, it is worth reading and discussing. #corpgov #ESG #proxies #proxysystem

  7. We're working on a complete rewrite of github.com/unredacted/freesock into a fully-fledged web application to help anyone with the distribution of Outline & Xray/XTLS access keys.

    Here's a sneak peak of the admin UI.

    #Outline #Xray #XTLS #VPN #Proxies

  8. Excited for #JCON EUROPE 2024? See Abdel Sghiouar at #JCON2024 in Cologne talking about '#Proxies, #Gateways, and Service #Mesh. Why Are Words so Confusing?'

    Can you tell the difference between an #API Gateway, the API Gateway, …

    Get your free #JUG Ticket: jcon.one

  9. If you are interested in the chemical tracers of wildfires, and how those might vary with burn severity, check out our new #preprint authorea.com/doi/full/10.22541

    We leached wildfire ashes and soils from karst areas, so we can better understand the speleothem palaeofire proxy signal. Another team effort, with co-authors from #UNSW (👋 @Andbaker) #ANSTO, #UWA, and #GNSScience

    #palaeofire #paleofire #processUnderstanding #Proxy #proxies #paleoenvironment

  10. Is anyone using #loadbalancers in their #homelab or is it all reverse proxies? Looking for something to do TLS termination and, ideally, make highly available. I tried doing this with #caddy and ehh it's not really working how I want to. I also think I didn't configure it correctly. Documentation is a little sparse.

    #homelab #networking #load #balancers #revers #proxies #minilab