24 ms·
One thing I do is I blocklist entire countries' and regional ISP' CIDR blocks. Believe it or not: straight to firewall DROP. China, North Korea, so many africa
by TacticalCoder 2y ago
One thing I do is I blocklist entire countries' and regional ISP' CIDR blocks. Believe it or not: straight to firewall DROP.
China, North Korea, so many african countries who's only traffic is from scammers, tiny islands in the pacific that are used for nothing but scamming...
Straight to DROP.
And I do not care about the whining.
- nequo 2y agoI assume you don’t host anything that could be useful to the 1.5 to 2 billion people that you’re blocking.
- luma 2y agoOr they host a business site that doesn't do business in those countries and so nothing of value is lost to them. For example, it's literally illegal for me to accept payments from .ru, so why bother wasting their time and my bandwidth?
- ajsnigrutin 2y agoI live in EU,and a bunch of american sites just block the whole EU due to GDPR laws. Then someone in US uses my email by accident to subscribe to some newsletter (not the first time, I also get personal emails for that person, since it's just one letter difference, and i'm guessing it's someone old, considering the emails I get), i try to click "unsubscribe", and it just redirects me to "<site> is unavailable in EU, blah blah" page, without unsubscribing. I make sure to report that site to every goddamn spam list possible.
- rapind 2y agoIMO replying unsubscribe should always work for marketing emails and if it doesn’t then I flag the email as spam. Nope, I’m not going to visit that tracked / info gathering unsubscribe link.
- dheera 2y agoI only use unsubscribe links from things I voluntarily and willingly subscribed to. If I was involuntarily subscribed to something, or subscribed because of an inconspicuous "subscribe me" checkbox that I probably didn't notice, including from a legit business that I purchased an item, it's getting reported as spam in Gmail.
- account42 2y agoThis is the right approach. Usually I also avoid any future business with a company that starts spamming me.
- DEADMINCE 2y ago> a bunch of american sites just block the whole EU due to GDPR laws. Which is incredibly reasonable. If the EU didn't try to claim EU law applies globally, those sites might still be up.
- robin_reala 2y agoThe US is just as bad at extraterritorial law, see FATCA for just one example. https://en.wikipedia.org/wiki/Foreign_Account_Tax_Compliance_Act#Criticism https://en.wikipedia.org/wiki/Foreign_Account_Tax_Compliance...
- DEADMINCE 2y agoThat situation is quite different. The US is using its significant power and weight to coerce those non-US banks into compliance with FACTA. Those banks don't have to comply, but they want to do business with the US and US companies, then they don't have much of a choice. It's not like they just made a law and now insisted it applies globally, which is what the EU did.
- echoangle 2y agoIsn’t it actually exactly the same? The website doesn’t have to comply (and many don’t), but if they want to do business in the EU, they have to. How is that different?
- DEADMINCE 2y agoNo, it's not remotely the same. The US is using the fact that people want to do business with them to coerce compliance, and as written the law only applies to US persons. The EU claims the GDPR applies globally, regardless of if people want to do business with the EU, or even if people ever set foot in the EU. It's amusing nonsense.
- mratsim 2y agoWhy is it different? People don't have to comply to GDPR but if they want to serve EU folks then they don't have a choice.
- tiahura 2y agoThe Biden administration needs to explain why they allow ISPs to import data from these countries.
- hahajk 2y agoI'm not sure I understand what you're suggesting. Are you saying that the US govt should make it illegal for people in its borders to communicate with people in those countries?
- gnfedhjmm2 2y ago[dead]
- ajsnigrutin 2y agoPersonal page.. sure. Business? You're a pain to many people and don't care. I live in EU and many US pages just block the whole EU due to GDPR laws... then someone (by mistake) subscribes me to their newsletter, and the "unsubscribe" links leads to "this page is unavalable in EU"? I'll goddamn make sure your domain ends up on every goddamn possible antispam filter I can find.
- cdelsolar 2y agoWhy? Are they spam pages?
- ajsnigrutin 2y agoFor me? Sure. I never subscribed to them. Ans the unsubscribe links doesn't work, probably illegal, although not sure if they can spam an EU citizen from usa, and which/whose/what law are they breaking.
- DEADMINCE 2y ago> I'll goddamn make sure your domain ends up on every goddamn possible antispam filter I can find. Honestly, individuals can't really do much to change the reputation of a domain. Maybe petition your representative to adjust the GDPR so they don't claim it applies globally?
- account42 2y ago> Honestly, individuals can't really do much to change the reputation of a domain. Your hosting provider and ISP will see this differently. So will the FTC. > Maybe petition your representative to adjust the GDPR so they don't claim it applies globally? Your butthurt about the GDPR doesn't absolve you from your obligations under the CAN SPAM act.
- DEADMINCE 2y ago> Your hosting provider and ISP will see this differently. So will the FTC. No. They absolutely won't. Not if I'm not breaking any US laws. The EU bitching would have as much impact as a government official from say Narau doing the same. None. > Your butthurt about the GDPR doesn't absolve you from your obligations under the CAN SPAM act. No. You are misunderstanding and conflating things. My point is I can do whatever I want so long as I am in compliance with US law including CAN-SPAM, and even if I violate GDPR as much as I want (again, as long as it doesn't violate US law).
- ransom1538 2y ago[flagged]
- nativeit 2y agoJust the best.
- DEADMINCE 2y agoThat's very computationally inefficient.
- aforwardslash 2y agoYou can trivially maintain a list of the size of the whole ipv4 space by using bitmaps
- TacticalCoder 2y ago> That's very computationally inefficient. It's O(1) with iptables/nftables ipsets. Moreover as I blocklist entire CIDR blocks, there aren't that many entries in those ipsets.
- mmsc 2y agoHad a travel insurance do this and when I was in hospital in Asia I couldn't start a claim and the hospital nearly kicked me out. I'm sure the sysadmins thought it was a great way to reduce hacking attempts by blocking Asia.
- boredtofears 2y agoThat’s awful but why is the onus on random sys admins around the world to deal with this correctly and not the government hosting the problem entities?
- belk 2y agoThat's like asking why don't we expect burglars to not burgle, they won't, but that doesn't mean walling off a whole neighborhood is the solution either.
- tracker1 2y agoYou haven't seen new construction in many upper end places then... High exterior walls and gated entry. Not that it adds much practically.
- AJayWalker 2y agoI would say because it’s their job to serve their customers, even if they’re abroad? Especially for a travel insurance company.
- kjkjadksj 2y agoGovernment needs lobbying to act
- krsdcbl 2y agoif the government in question is supportive of said problem entities, they won't "deal" with it If the government in question has free reign on regulating said traffic, it's an avenue for repressions and censorship Otherwise it's a legal matter to seek action against such entities, which is already how it works (... but I'm afraid we're actually mostly talking about "scenario 1 entities" here, which makes it futile to seek action from the very offices that already play a role in making it harder to use existing legal means)
- grishka 2y agoAs a Russian, I hate it when people do this. It's extremely annoying when you just click some random interesting-looking link from HN or Reddit or Twitter only to be greeted by a 403 or a connection timeout. Then you turn your VPN on, and magically, it loads just fine.
- mistrial9 2y agopeople here are not thinking in whole systems-- roads have dual purpose.. there is security AND there is trade .. a world without trade is a poor world.. that includes the intellectual arts, civilian institutions cooperating, common issues like Climate. The voices here that say "I block everyone, don't bother me with your whining" .. it is a security practice.. OK. security is not the whole story of civilizations; obstinate thinking leads to ignorance, not evolution. The topic is SSH, an administrative and secured access. Yes security applies. to be on-topic
- grishka 2y agoOf course one can obfuscate and secure their own SSH access as much or as little as they want. Run sshd on a different port, require port knocking, ban IPs after failed login attempts, all that kind of stuff. I'm, however, specifically talking about public-facing services like HTTP(S), which also get blocked with this "I'll just indiscriminately blacklist IPs belonging to countries I don't like" approach.
- phsau 2y agoMalicious traffic is not limited to ssh and comes from the same usual suspects. Automated attacks against web applications is constant. I wouldn't say it's indiscriminate, it's practical.
- tmcdos 2y agoThere are bad people on both side of the border - don't be fooled that they are more on the "other" side of the border because there might be ones that you are not seeing (yet). Blocking the whole "other side" is simply the "path of least resistance" or the "low hanging fruit". Creation and all other good things ALWAYS require more energy than destruction and other bad things. But creation/invention is the only activity that leads to progress and evolution - everything else is stalling, regression, devolution ... Internet was created BY military FOR military - but it evolved into THE only thing in the world that connects people. ALL people. References at the bottom. The most general problem in Internet are not the malicious people - botnets can infect insecure devices ANYWHERE in the world. The main problem is that some (many) of the ISPs at the last mile allow outgoing IP packets with source IP address which is outside of the IP range(s) these ISPs operate/own. Larger ISPs on the upper layer can not prevent this because otherwise IP routing will break. So it all depends on the "last mile" ISPs. And it is quite possible for the "status quo" to live for many years .... https://www.internetsociety.org/resources/2022/impact-of-ukraines-requests-to-block-russias-access-to-the-internet/ https://www.internetsociety.org/resources/2022/impact-of-ukr... https://labs.ripe.net/author/athina/how-sanctions-affect-the-ripe-ncc/ https://labs.ripe.net/author/athina/how-sanctions-affect-the... https://labs.ripe.net/author/farzaneh-badiei/sanctions-and-the-internet-a-report/ https://labs.ripe.net/author/farzaneh-badiei/sanctions-and-t... https://www.sciencedirect.com/science/article/pii/S0308596123001258 https://www.sciencedirect.com/science/article/pii/S030859612... https://labs.ripe.net/author/moritz_muller/internet-sanctions-on-russian-media-diverging-actions-and-mixed-effects/ https://labs.ripe.net/author/moritz_muller/internet-sanction...
- Dah00n 2y agoI'd do this too except by far the most scam traffic I see are US in origin. I'm in the EU.
- michaelcampbell 2y agoSame here. I country-block I think 4 countries and my "not-me" ssh login attempts dropped 90+%. As I run funzies sites, I couldn't care less about the reduced legit traffic.
- normie3000 2y ago> so many african countries who's only traffic is from scammers Which countries specifically? Asking from Africa, and not sure I've encountered this.