antiX-forum up on Cloudflare

Forum › Forums › News › Announcements › antiX-forum up on Cloudflare

  • This topic has 62 replies, 17 voices, and was last updated Jan 23-5:56 pm by Brian Masinick.
Viewing 15 posts - 16 through 30 (of 63 total)
  • Author
    Posts
  • #192156
    Brian Masinick
    Moderator

      There are several user agent switching tools available for several Web Browsers:
      https://github.com/ray-lothian/UserAgent-Switcher

      about:config is where you alter the string in most browsers I’ve used.
      If you use useragent to search your browser after entering about:config
      you can see the strings available.

      On Firefox, for example, useragent is a boolean variable by default,
      but you can change it to a string and type in whatever value you wish to use.
      I hope that at least provides a high level example; the specifics can and
      will vary somewhat depending on the browser you are actually using.

      --
      Brian Masinick
      Alternate "Search B":
      This search page

      #192160
      Xunzi_23
      Member

        UngoogledChromium and Links2 just took me straight to the forum.

        libreWolf invokes the cloudflare window every time.

        All running on the Beta presently

        #192165
        j0ta
        Member

          Well since cuckflare is here this will be my last post since you should prioritize privacy over surveillance

          “A Cloudflare CDN flaw that can expose some location data to an attacker was patched before being ethically disclosed, but the security researcher that discovered it says that the trick still works with the use of a VPN service and some extra steps.”

          โ€‹๐Ÿ‡ณโ€‹โ€‹๐Ÿ‡ดโ€‹โ€‹๐Ÿ‡ธโ€‹โ€‹๐Ÿ‡พโ€‹โ€‹๐Ÿ‡ธโ€‹โ€‹๐Ÿ‡นโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡ฒโ€‹โ€‹๐Ÿ‡ฉโ€‹ โ€‹๐Ÿ‡บโ€‹โ€‹๐Ÿ‡ธโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡ทโ€‹
          ๐Ÿ‡ฑโ€‹โ€‹๐Ÿ‡ฎโ€‹โ€‹๐Ÿ‡งโ€‹โ€‹๐Ÿ‡ทโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡งโ€‹โ€‹๐Ÿ‡ดโ€‹โ€‹๐Ÿ‡ดโ€‹โ€‹๐Ÿ‡นโ€‹ โ€‹๐Ÿ‡บโ€‹โ€‹๐Ÿ‡ธโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡ทโ€‹
          โ€‹๐Ÿ‡ฆโ€‹โ€‹๐Ÿ‡ณโ€‹โ€‹๐Ÿ‡นโ€‹โ€‹๐Ÿ‡ฎโ€‹โ€‹๐Ÿ‡ฝโ€‹ ๐Ÿ‡บโ€‹โ€‹๐Ÿ‡ธโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡ทโ€‹
          โ€‹๐Ÿ‡ฑโ€‹โ€‹๐Ÿ‡ฎโ€‹โ€‹๐Ÿ‡งโ€‹โ€‹๐Ÿ‡ทโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡ผโ€‹โ€‹๐Ÿ‡ดโ€‹โ€‹๐Ÿ‡ฑโ€‹โ€‹๐Ÿ‡ซโ€‹ โ€‹๐Ÿ‡บโ€‹โ€‹๐Ÿ‡ธโ€‹โ€‹๐Ÿ‡ชโ€‹โ€‹๐Ÿ‡ทโ€‹
          Anti A.I user

          #192168
          CharlesV
          Member

            Well since cuckflare is here this will be my last post since you should prioritize privacy over surveillance
            โ€œA Cloudflare CDN flaw that can expose some location data to an attacker was patched before being ethically disclosed, but the security researcher that discovered it says that the trick still works with the use of a VPN service and some extra steps.โ€

            Sorry to see you go – That article was from January of this year patched in Feb and then patched one more time two days later properly close that issue down.

            First off, surveillance is not the goal, keeping this site up and functional IS! Cloudflare is one of the best methods to keep a site up during heavy attacks and bot infiltration.

            As for privacy, cloudflare was chosen because it is one of the most privacy conscious defense systems out there.

            Unfortunately, many systems suffer leaks once in a while, and there are MANY more issues on the web.

            I am still tweaking working on making things easier for real people and especially logged in users – Like anything, this will take a little time to get it all worked through, but it is being addressed.

            *Linux - This is the way!

            #192171
            Brian Masinick
            Moderator

              Well since cuckflare is here this will be my last post since you should prioritize privacy over surveillance
              โ€œA Cloudflare CDN flaw that can expose some location data to an attacker was patched before being ethically disclosed, but the security researcher that discovered it says that the trick still works with the use of a VPN service and some extra steps.โ€

              Sorry to see you go โ€“ That article was from January of this year patched in Feb and then patched one more time two days later properly close that issue down.

              First off, surveillance is not the goal, keeping this site up and functional IS! Cloudflare is one of the best methods to keep a site up during heavy attacks and bot infiltration.

              As for privacy, cloudflare was chosen because it is one of the most privacy conscious defense systems out there.

              Unfortunately, many systems suffer leaks once in a while, and there are MANY more issues on the web.

              I am still tweaking working on making things easier for real people and especially logged in users โ€“ Like anything, this will take a little time to get it all worked through, but it is being addressed.

              I’m sorry about this too, but I’ve found decidedly improved performance on the site ever since we implemented CloudFlare, and as you’ve said, any logs or other tracking data is only retained for a maximum of fourteen hours, predominantly to have the data present in the event of issues, NOT to watch the activity or usage patterns of users.

              --
              Brian Masinick
              Alternate "Search B":
              This search page

              #192173
              xinomilo
              Member

                (same here.) last post, just for some remarks. (for clarification, i’m anti-bigtech/dystopia).

                – user agent in librewolf shows firefox, not librewolf. so, changing user-agents is not a solution for librewolf users. cloudflare is looking at other browser info.. (who knows what…)
                – cloudflare verification twice (both in login and logout w/ librewolf).
                – cloudflare web analytics/insights (=cloudflare tracker) is enabled on antixforum, so users are or can be tracked. maybe its just tracking user-agents and no personalized data…, but who really knows… (ublock origin blocks it anyway.)
                – asked about the SSL keys earlier… (got no answer). checking current cert issued on 16/12 seems like it’s issued from cloudflare (google trust services), so this bigtech corporation can process all traffic unencrypted. (this wouldn’t change while on CF, even with an own cert). their business model is to be the MiTM anyway….
                – and sorry for saying this, but ~8k bot blocks doesn’t sound like much… what’s the majority of the bots UA? (eg. top 5) ? is it AI-bots? those can be easily blocked at webserver level and never affect forum… anyway i’d suggest to either tweak wordpress/web server/hosting. (or changing hosting providers… )
                – site is slower because of the extra cloudflare verification and 3rd party elements in general (eg. cleantalk js). feeling faster after CF verification because of CDN. used to be slower -before CF- here (southern EU), probably because of USA hosting-lagging…

                CF alternatives :
                – deflect.ca is a much better (+ethical) provider of similar to CF services. even providing free services to non-profits and activists around the world.. (+wordpress hosting)
                – diy self-hosted foss tools like anubis/go-away/some reverse antibot proxy would cut bot traffic. probably entirely.
                – another hosting provider with bot-protection (for free) by default. and for better privacy, maybe a hosting provider not based in 5-eyes countries… eg. an .is one…

                anyway,
                thanks for antiX linux, and thanks for being proudly antifascist in a dystopic fascist world.

                (admins can see my email address should they need to contact. for whatever / still offering my help to antiX, just not on CF hosted platforms. ).

                First they came for the socialists, and I did not speak outโ€”because I was not a socialist.
                Then they came for the trade unionists, and I did not speak outโ€”because I was not a trade unionist.
                Then they came for the Jews, and I did not speak outโ€”because I was not a Jew.
                Then they came for meโ€”and there was no one left to speak for me.

                โ€”Martin Niemรถller

                #192176
                Robin
                Member

                  UngoogledChromium and Links2 just took me straight to the forum.

                  @Xunzi_23 Yes, sure. I also said that this part works. But try logging in. Does that work for you in stable 23 or 25 beta?

                  First off, surveillance is not the goal, keeping this site up and functional IS!

                  No worries, @CharlesV ! People here around in forum know that and are thankful for the effort. Still, surveillance by a capitalist machinerey could be an unwanted side effect. Keep in mind, this OS has an anticapitalist and antifascist stance, so its forum might be easily a worthwhile surveillance target for those in power to do so. Cloudflare actually does know wherever you are active in the web, since more and more sites use their centralised service for site protection, and all data from the checks runs together there, if I’m not mistaken. You have to trust into THEM, so its not at all about questioning trust in the people behind antiX or the antiX forums, when doubting the cloudflare solution from the point of view of privacy.

                  I am still tweaking working on making things easier for real people and especially logged in users โ€“ Like anything, this will take a little time to get it all worked through, but it is being addressed.

                  Many many thanks CharlesV, all your effort is highly recognized.

                  Windows is like a submarine. Open a window and serious problems will start.

                  #192177
                  blur13
                  Member

                    Trying to log in on the forum using Links2 returns:
                    “Enable JavaScript and cookies to continue”

                    So user-agent has nothing to do with it, its lack of JavaScript. (I’ve set the user-agent to firefox, go to setup, network options, http-options, header options).

                    The forum sure is faster with cloudflare.

                    #192180
                    Brian Masinick
                    Moderator

                      The forum sure is faster with cloudflare.

                      That’s what I’ve been saying all along.

                      @xinomilo If there are better alternatives out there and there are those who are experienced in setting them up, contact the development team and explain what you know and what your personal experiences have been. @CharlesV is an active participant with MX Linux and has been helping us out. You can also discuss your findings with him too.

                      --
                      Brian Masinick
                      Alternate "Search B":
                      This search page

                      #192192
                      CharlesV
                      Member

                        And I would love to hear about some of those that are available as well. deflect.ca is only free to non-profits and certain privacy organizations, and under their TOS it does not appear to cover a “public linux support forum”. ( If you have other info.. I would love to hear!)

                        The harsh reality is that in order to inspect IP and traffic to combat bad actors… there *must* be some IP inspection and validation – which means traffic must be scanned under certain conditions. (ie specific pages, non logged in connections, high throughput etc etc. )

                        I have been doing this a VERY long time, and keep current on as much as I can read and take in – and I am *always* open to hear and learn about other methods.

                        To date, I watch over approx 60+- businesses, 260+- computers and approx 26 websites – and I have found nothing better than cloudflare to shut down problems.

                        *Linux - This is the way!

                        #192194
                        Brian Masinick
                        Moderator

                          And I would love to hear about some of those that are available as well. deflect.ca is only free to non-profits and certain privacy organizations, and under their TOS it does not appear to cover a โ€œpublic linux support forumโ€. ( If you have other info.. I would love to hear!)

                          The harsh reality is that in order to inspect IP and traffic to combat bad actorsโ€ฆ there *must* be some IP inspection and validation โ€“ which means traffic must be scanned under certain conditions. (ie specific pages, non logged in connections, high throughput etc etc. )

                          I have been doing this a VERY long time, and keep current on as much as I can read and take in โ€“ and I am *always* open to hear and learn about other methods.

                          To date, I watch over approx 60+- businesses, 260+- computers and approx 26 websites โ€“ and I have found nothing better than cloudflare to shut down problems.

                          Charles, thank you for responding. I trust your opinion and value your expertise. I’m a retired software engineer and I spent the majority of the second half of my career in testing, and the majority of that was for large automotive and financial services firms which needed very strong network security. Given my background, while now out of date, it still validates what you’ve said and what you’re recommending.

                          --
                          Brian Masinick
                          Alternate "Search B":
                          This search page

                          #192217
                          CharlesV
                          Member

                            And Thank you Brian.

                            *Linux - This is the way!

                            #192228
                            Robin
                            Member

                              Seems nasty spambots have learned to circumvent cloudflare:

                              https://www.antixforum.com/forums/topic/qpdfview-window-keeps-growing/#post-192223
                              Footer:

                              fnf[/url]

                              nice try…

                              https://www.antixforum.com/forums/topic/touchpad-issues-and-lid-switch-fails/#post-192226

                              link to game [removed link] [new removed link] domains often used for
                              adding unpleasant extras by scammers so better not visit..

                              Windows is like a submarine. Open a window and serious problems will start.

                              #192234
                              Xunzi_23
                              Member

                                Hi Robin,
                                I had logged in last time but checked now, writing this from UngoogledChromium
                                latest appimage,With UBlock, Localcdn.

                                Links 2 is not working now, I am using the S6-rc as init, unsure if that is related.
                                removing the links2 config in home makes no difference.

                                #192235
                                Xunzi_23
                                Member

                                  Hi Robin,
                                  the nasty, often human spambots are now using AI to try and cloak scams,
                                  it will get worse, antifaschists are a declared enemy of putin and his puppet
                                  trumps gang of goons..

                                Viewing 15 posts - 16 through 30 (of 63 total)
                                • You must be logged in to reply to this topic.