4 ms·
> We blocked these IPs from accessing any of our services. > ... we’re tightening up our Access implementation to prevent any logins from unknown VPNs This re
by fjni 4y ago
> We blocked these IPs from accessing any of our services.
> ... we’re tightening up our Access implementation to prevent any logins from unknown VPNs
This requires clarification. I think this means cloudflare is completely blocking some of mullvad's ip addresses for their internal tools (or third-party services they use?) But "all services" could also mean if I run my service on cloudflare, this will affect some of my customers who happen to be using these mullvad nodes.
If it's the latter, I understand the immediate concern is the phishing attack, but on a larger level this is concerning since I can't see how this response would mirror to cloudflare's own vpn offering. If an actor were to use cloudflare's vpn offering for nefarious purposes (directed at cloudflare or someone else,) I don't see cloudflare implementing this policy aimed at their own offering.
- kurupt213 4y agoif it was cloudflare's own VPN, wouldn't they know the IP address of the system connecting to the VPN?
- eastdakota 4y agoWe’re tightening up controls and not letting any non-whitelisted/approved VPNs access any of our internal tools. This has been a feature of Cloudflare Access. We just hadn’t enabled it ourselves.