• assaultpotato@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    4
    ·
    16 hours ago

    Let me guess, you’ve never tried to host anything public yourself. If you run fail2ban long enough you end up with a blocklist that heavily skews towards a particular set of countries. Residential proxies are regularly used in criminal activity. I’ve personally and professionally been impacted by TAs using residential proxies to get around firewall rules as part of compromises.

    If authorities in those countries took action against TAs and scammers more aggressively, perhaps blocking their entire country wouldn’t be seen as a valid defensive approach.

    • AwesomeLowlander@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      5
      ·
      16 hours ago

      You do understand that ‘overseas’ means ‘anywhere not in my country’, correct? Not a few specific countries, but literally 90+% of the world, with the exact makeup of that 90% depending on where the company is.

      • assaultpotato@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        13
        arrow-down
        4
        ·
        16 hours ago

        Overseas is generally used for “across an ocean”. As this is an NA based publication, “overseas” would likely be Europe, Africa, Asia, Oceania.

        Malicious traffic frequently originates from at least one place in every one of those continents. We were breached some time ago by a TA using a residential proxy to send traffic from a Ukr AS block that got around our firewall. Blocking all traffic from regions of the world that you have no intention of servicing is a very valid cybersecurity layer. Getting annoyed because someone used the phrase “overseas” to describe areas to be suspicious of I think is rather short sighted from a security point of view.

        Very few cyber attacks come from domestic/near domestic sources, except from botnets and residential proxies. The world will not miss residential proxies.

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          15 hours ago

          Blocking all traffic from regions of the world that you have no intention of servicing is a very valid cybersecurity layer.

          I pretty regularly run into things that block access or make me complete captchas while I’m traveling. I may not be in a region you intend to service, but I’m (possibly) from a region you intend to service. Airplanes are a thing.

          Buying access to a residential proxy to deal with that situation would be an extreme step for most people, but as a cybersecurity practice, it’s problematic.

          • assaultpotato@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            14 hours ago

            Man I’m replying while visiting family in a non-western aligned occupied territory “overseas” to NA. I know. I region block anyways and VPN into Europe/NA when needed, where at least my traffic originates from a VPN’S AS where someone can be made to revoke my access if I abuse it.

            • Zak@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              14 hours ago

              You have experienced the problem and you do it anyway?

              Services that do region blocking also tend to block public VPNs. Breaking the internet like this is bad, and you should feel bad for doing it.

              • assaultpotato@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                3
                ·
                14 hours ago

                Tell that to the guy in Lagos I had to report a few years ago for breaching one of my personal services. Nigerian Police have a dedicated Cybercrime division and they didn’t even reply to my report through their official channels. Sorry, but Nigeria went on the geoblocklist! I have a right to not expose myself to undue risk.

                • Zak@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  arrow-down
                  1
                  ·
                  13 hours ago

                  Sure, you have the right to manage your servers however you like… and I have the right to unfairly use you as a proxy for my rage at everyone who has ever broken the Internet’s global nature to make their server log files a little less noisy.

                  • assaultpotato@sh.itjust.works
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    13 hours ago

                    It’s not just log files - I was running a bad version of some software and suddenly my VPS was cryptomining and they tried to export common config directories. They got nothing and I cleaned it up but I’m not letting my VPS join a botnet and attack others. If the side effect of that is that Nigerians cannot read my person blog or access my self hosted services with 30 users I think this is ok.

                    I’ll happily accept your ire as I also wish the internet was generally safer and more open.

        • AwesomeLowlander@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          14 hours ago

          As this is an NA based publication, “overseas” would likely be Europe, Africa, Asia, Oceania.

          Unless they’re intending that their audience is only from the Americas, then no, overseas is based entirely on where their individual readers are.

          Anyway, I feel like you may have misunderstood me a little. I’m not annoyed from a security perspective, I just found that to be superbly bad writing.

    • Akasazh@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      14 hours ago

      I regularly use an Albanian proxy, because of the add blocking benefits, but it’s unreal how many websites don’t allow you to use it’s functions with an Albanian ip.

      Which is silly because Albanians can use VPNs too, so any aspiring it criminal isn’t really caught in the block.

      • assaultpotato@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        14 hours ago

        The difference is that commercial VPNs are theoretically more beholden to regulatory bodies to shutdown bad traffic/provide subscriber information when so ordered by a court. With a commercial VPN you have a legal recourse against a bad actor. With residential proxies enforcement is much much harder, as traversing beyond the IP hosting the proxy to the TA is often not possible. I also use a VPN to get around content restrictions and have no qualms about their use. Residential proxies are typically bad for everyone except TAs and people who might not have access to traditional VPNs due to their local governments.

    • AwesomeLowlander@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      14 hours ago

      Btw I’m not sure if you’re aware, but this behaviour (blocking based on geographic ip) is literally illegal in the EU. I’m aware it’s not applicable to you since you’re in the states, just an FYI.

        • AwesomeLowlander@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          13 hours ago

          Bad assumption on my part. Anyway yeah. Just an FYI since you were recommending it as a security practice. I have actually contacted European companies and had them remove geoblocks in the past by pointing out they were (probably unknowingly) breaking the law.

      • assaultpotato@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        13 hours ago

        Also I’m not selling anything so that EU law wouldn’t apply to my services even if I did host them in the EU or provide services to the EU.

        • AwesomeLowlander@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          13 hours ago

          Oh yeah I’m not trying to accuse you of anything, don’t worry. Just throwing out some info a lot of people aren’t aware of to contribute to the conversation.