Skip to content
Snippets Groups Projects
  1. Jan 11, 2024
  2. Jan 07, 2024
  3. Dec 31, 2023
  4. Dec 20, 2023
  5. Dec 16, 2023
  6. Dec 13, 2023
  7. Oct 31, 2023
  8. Oct 30, 2023
  9. Oct 22, 2023
  10. Oct 21, 2023
  11. Oct 13, 2023
  12. Sep 29, 2023
    • Sheogorath's avatar
      removal(crowdsec): Dropping crowdsec · cf0bef90
      Sheogorath authored
      After some testing and fiddling around, I don't think it's worth the
      hassle. Not only was ingress-nginx much less stable since integrating
      the crowdsec bouncer plugin, but also just providing some questionable
      log parsers etc, mainly focusing on bruteforce attacks for passwords,
      which is useless when everything goes to SSO anyway.
      
      Finally there were some other technical faux pas, like hardcoded
      passwords on the integrated dashboard (which is also mostly useless),
      expired GPG keys on the Fedora repository and finally a lack of bouncer
      modules on current Fedora releases, depsite the docs claiming otherwise.
      And given the issues date back to march, it doesn't seem to be a
      something that will be resolved any time soon.
      
      I guess my biggest critique is that the whole "fail2ban of the modern
      area" limits itself to IP addresses only. No additional metadata to
      block or mitigate attacks or identify attackers. Relying on IP addresses
      only in 2023 is not on time. The whole being distributed with the lapi
      server, is nice, but not enough to make this acceptable.
      Verified
      cf0bef90
  13. Sep 28, 2023
  14. Sep 27, 2023
  15. Sep 26, 2023
  16. Sep 25, 2023
  17. Sep 20, 2023
  18. Sep 15, 2023
  19. Sep 09, 2023
  20. Sep 06, 2023
  21. Sep 04, 2023
  22. Sep 03, 2023
Loading