6 ms·
I agree 100%. I went ahead and disabled all logging in Apache just now. Will update the privacy page to reflect this within the hour.
by ybceo 10mo ago
I agree 100%. I went ahead and disabled all logging in Apache just now. Will update the privacy page to reflect this within the hour.
- drink_machine 10mo agoShouldn't you have spent some time to think through basic things like this before trying to write an opinion piece on anonymity? Certainly it shows a lack of depth of understanding.
- ybceo 10mo agoI disagree. Like I said earlier : Web server logs were not tied to user credentials in any way, they were used for debugging purposes and could not have been used to identify users.
- drink_machine 10mo ago[flagged]
- ybceo 10mo agoI went ahead and took action on the criticism as soon as I saw the parent comment. All apache access logs are piped to /dev/null now. I'm not here to debate, the reason I posted here is to hear what people thought and see how I could improve my platform based on the criticism.
- navigate8310 10mo agoI appreciate your opinion on anonymity, but, it's nothing more than, "trust me bro". And being a US company that further tingles the spidy sense.
- joemazerino 10mo agoThe US isn't the sole transgressor against privacy. EU has made that pretty clear in the last month.
- sallveburrpi 10mo agoWhat happened in the last month? Genuine question
- joemazerino 10mo agoLook up Chat Control.
- sallveburrpi 10mo agoChat Control was first proposed in 2022 and is still in parliament. Some try to push it through again and again but it gets blocked. I don’t see why it should be different this time and so far nothing has actually changed for EU citizens.
- basedrum 10mo agoLook into the Apache module called mod-remove-IP, it's old and hasn't had any changes for years, but it works much better than just disabling in the logs because it will also persist those removals throughout any frameworks. Also with Apache you cannot as easily destroy your error logs which sometimes have IPS in them. Consider nginx as an alternative
- reactordev 10mo agoConsider Caddy as an alternative. Nginx is no better. Both Apache httpd and nginx are old and don’t support newer protocols like HTTP/3. Maybe I’m wrong. Another issue is with Apache httpd’s routing. Removing the IP messes up routing sometimes when using mod_rewrite.
- yareally 10mo agoSure they do: https://nginx.org/en/docs/quic.html https://nginx.org/en/docs/quic.html https://apisix.apache.org/docs/apisix/http3/ https://apisix.apache.org/docs/apisix/http3/
- reactordev 10mo agowell damn... old dog new tricks. Maybe it's my distro that's old.
- procaryote 10mo agoFrom your faq: "We maintain zero logs of your activities. We don't track IP addresses, …" Front page says "zero logs" Some logs, including specifically datapoints you have promised not to log, but you mean well (?) is pretty different from zero logs
- ffsm8 10mo agoFwiw, zero logs in that context is usually in the relation to requests through the VPN, whereas this discussion is about requests on their homepage? Or did I misunderstand something here?
- pear01 10mo agoYou disagree and yet you agreed 100% and made the change. I thought the point the preceding parent comment is making is that you should have thought of that beforehand. Yet you seemed to already come to a judgement about it yet then quickly agreed to reverse yourself. Sounds like a clear "lack of a depth of understanding" to me.
- deleted 10mo ago[deleted]
- organsnyder 10mo agoI have a static IP address; and most connections tend to have long-lived leases anyways. It can easily be used to identify me, even if you don't explicitly tie it to my account.
- everdrive 10mo agoThe privacy crowd seems to be incapable of grey areas. Are all these the same thing? Are they all the same severity of problem? - A web site logs traffic in a sort of defacto way, but no one actually reviews the traffic, and it's not sent to 3rd parties. - A government website uses a standard framework and that framework loads a google subdomain. In principle, Google could use this to track you but there's no evidence that this actually happens. - A website tracks user sessions so they can improve UI but don't sell that data to 3rd parties. - A website has many 3rd party domains, many of which are tracking domains. - Facebook knows exactly who you are and sells your information to real-time-bidding ad services. - Your cell phone's 3G connection must in principle triangulate you for the cell phone to function, but the resolution here is fuzzy. - You use Android and even when your GPS is turned "off" Google is still getting extremely high resolution of your location at all times and absolutely using that information to target you. A LOT of the privacy folks would put all those examples in the same category, and it absolutely drives me up a wall. It's purity-seeking at the expense of any meaningful distinction, or any meaningful investigation that actually allows uses to make informed decisions about their privacy.
- Rygian 10mo agoThey belong in the same category: the end user has zero agency over how their privacy is impacted, and is at the whim of the wishes/agency of whoever is serving content to them. Whether the one serving the content is exploiting data at the present moment has very little relevance. Because the end user has no means to assert whether it is happening or not.
- dylan604 10mo ago> - A web site logs traffic in a sort of defacto way, but no one actually reviews the traffic, and it's not sent to 3rd parties. Even if this sounds innocent, these must be turned over if you are provided a warrant or subpoena (which ever would be appropriate, IANAL).
- Brian_K_White 10mo agoBut it's not malicious. It's not ideal, and it should be addressed, but it's not bad faith or intentional spying or even gross negligence or incompetence.
- amarant 10mo agoWe all mess up and miss things, op has shown maturity enough to admit to their mistakes and improve from them. My takeaway from this thread is an increased amount of trust in OP. Not because they made a mistake, but because of how they handled it. Well done OP!
- lisbbb 10mo agoPrivacy was a joke--every time I gave someone my data that data got breached, including the US government.
- ljlolel 10mo agoThe whole thing is behind cloudflare!
- megous 10mo agoAnonymity is responsibility of a visitor in any case. If the visitor's anonymity depends on some website not storing logs, the visitor lost already.
- reactordev 10mo agoYour browser knows more about you than you do. When accessing a website, anonymous or not, it sends a fingerprint so to speak to that site and its ad network. It’s there that your anonymity ceases and you are identified, classified, segmented, and fed more “How to stay safe online” ads. There’s no escaping it. Chromium is not to be trusted.
- bossyTeacher 10mo agoin 2025, can small and medium businesses afford to be exposed to the world wild web? You don't need to be a major site these days to be DDosed on the regular
- V__ 10mo agoWho gets ddosed on the regular? Spam is a regular problem, but I have never encountered a ddos on a business website.
- encom 10mo agoBaseless fear mongering. I've had webservers raw-dogging the Internet for about 25 years. Nothing of any consequence has happened. Hasn't happened to anyone I know, either. Anecdata yes, but people are making it sound like running a webserver is like connecting a Windows XP machine to the internet - instant pwnage. It isn't. I've been DDoS'ed exactly once. In 2003 I got into a pointless internet argument on IRC, and my home connection got hammered, which of course made me lose the argument by default. I activated my backup ISDN, so my Diablo 2 game was barely interrupted.
- mk89 10mo agoAre you allowed to do that in US? I see the company is located in the USA, can companies disable logging just like that? (Asking because I really don't know)
- immibis 10mo agoIn most countries the law doesn't say you have to log everything about your users, but it does say that if you log it and the police ask for it then you have to give the data to them.
- singpolyma3 10mo agoI think you mean if a court asks for it. And they have to ask for something you actually have
- immibis 10mo agoThat's why companies that actually care about privacy (I think there are only two - Mullvad and Signal?) make a point of not ever capturing the data to begin with, and deleting what they do capture as soon as possible.
- singpolyma3 10mo agoInteresting that you mention those two as I'd not trust either with private data. They engage in too much magical thinking in their marketing for my liking...
- reassess_blind 10mo agoWhich privacy-oriented companies do you prefer?
- yencabulator 9mo agoMagical thinking, like Mullvad burning large amounts of engineering effort to make sure their infrastructure never stores anything worth a subpoena. Their VPN servers don't have hard drives. Mullvad is one of the rare examples of doing more than marketing. https://mullvad.net/en/blog/we-have-successfully-completed-our-migration-to-ram-only-vpn-infrastructure https://mullvad.net/en/blog/we-have-successfully-completed-o...
- sdoering 10mo agoDoes it matter, when CF is collecting all that already before people even reach your site?
- zbentley 10mo agoDoes CF matter, when intermediate ISPs are collecting IP address and DNS query activity and can be subpoenaed? The answer to both this and parent is yes: partial privacy improvements are still improvements. There are two big reasons for this and many smaller reasons as well: First, legal actors prioritize who to take action against; some cases are “worth seeing if $law-enforcement-agency can get logs from self-hosted or colo’d servers with minimal legal trouble” but not “worth subpoenaing cloudflare/a vpn provider/ISP for logs that turned out not to be stored on the servers that received the traffic“. Second, illegal actors are a lot more likely to break into your servers and be able to see traffic information than they are to be able to break into cloudflare/vpn/ISP infrastructure. Sure, most attackers aren’t interested in logs. But many of the kind of websites whose logs law enforcement is interested in are also interesting to blackmailers.
- dylan604 10mo agoIf the authorities come to TFA site with demands, they can't do anything about what CF is doing. All they can do is turn over what they have, and/or prove they don't have what is being asked of them. What some 3rd party does is not germane at all.
- godelski 10mo agoJust curious, why not accept cash? Not that I use it, but one of the best privacy features of Mullvad is that you can post them cash with your account number and they will credit it. That makes the transaction virtually, and for all practical purposes, untraceable. It seems like you have the means to do exactly that too.