assaultpotato

@assaultpotato@sh.itjust.works · Joined ⁨Jul⁩ ⁨2023⁩

Replying to @⁨Zak@lemmy.world⁩

It’s not just log files - I was running a bad version of some software and suddenly my VPS was cryptomining and they tried to export common config directories. They got nothing and I cleaned it up but I’m not letting my VPS join a botnet and attack others. If the side effect of that is that Nigerians cannot read my person blog or access my self hosted services with 30 users I think this is ok.

I’ll happily accept your ire as I also wish the internet was generally safer and more open.

Replying to @⁨Akasazh@lemmy.world⁩

The difference is that commercial VPNs are theoretically more beholden to regulatory bodies to shutdown bad traffic/provide subscriber information when so ordered by a court. With a commercial VPN you have a legal recourse against a bad actor. With residential proxies enforcement is much much harder, as traversing beyond the IP hosting the proxy to the TA is often not possible. I also use a VPN to get around content restrictions and have no qualms about their use. Residential proxies are typically bad for everyone except TAs and people who might not have access to traditional VPNs due to their local governments.

Replying to @⁨AwesomeLowlander@sh.itjust.works⁩

Overseas is generally used for “across an ocean”. As this is an NA based publication, “overseas” would likely be Europe, Africa, Asia, Oceania.

Malicious traffic frequently originates from at least one place in every one of those continents. We were breached some time ago by a TA using a residential proxy to send traffic from a Ukr AS block that got around our firewall. Blocking all traffic from regions of the world that you have no intention of servicing is a very valid cybersecurity layer. Getting annoyed because someone used the phrase “overseas” to describe areas to be suspicious of I think is rather short sighted from a security point of view.

Very few cyber attacks come from domestic/near domestic sources, except from botnets and residential proxies. The world will not miss residential proxies.

Replying to @⁨AwesomeLowlander@sh.itjust.works⁩

Let me guess, you’ve never tried to host anything public yourself. If you run fail2ban long enough you end up with a blocklist that heavily skews towards a particular set of countries. Residential proxies are regularly used in criminal activity. I’ve personally and professionally been impacted by TAs using residential proxies to get around firewall rules as part of compromises.

If authorities in those countries took action against TAs and scammers more aggressively, perhaps blocking their entire country wouldn’t be seen as a valid defensive approach.