Maybe water should not be allowed because rapists can drink it ?
Maybe using IP as identifier is wrong (it does not work since more than 20 years) and doing any kind of IP-based policy in 2024 is a sick behavior that shall be cured in specialized hospitals ?
When I buy something on amazon, what is important is the stuff delivered, not the delivery man.
You would filter packages from entering home based on the delivery man ? Insane ? Yes this is an insane behavior. As if one delivery man were dedicated per home, as it was in 1994. INSANE.
The delivery guy knowingly delivers drugs, it's written on the package, and the authorities told him to stop doing that.
Then what to do ? Remove the license of that most specific delivery guy.
That's what they try to do (though it would be easier if the delivery guy would collaborate of course).
Not saying that blocking internet hosts is a good thing, but I don't see what else they can do, if the counterparty is not compliant :|
(DNS blocking doesn't work anymore as browsers provide circumvention methods by default, and blocking the whole BGP peer has too much side-effects because it blocks all the legitimate delivery guys too)
In theory this would also work for IPs if not for the IP laundering OOP criticised.
Cloudflare chooses to hide thousands of IPs on a single IP - this is a technical choice, not a system necessity. There are of course many reasons for those and many of them legitimate, but it doesn't mean this is the right approach (and with IPv6 certainly other options are possible...)
Cloudflare chooses to hide thousands of IPs on a single IP - this is a technical choice, not a system necessity.
Well, if you want "CDN", then you must break the TCP connection. That is, you must have one TCP connection from client to CDN, and then one from CDN to the backend.Unless you are against CDNs (they do serve a real-world purpose, tho), then it is a system necessity;
So it's a good thing that they're clowns at this.
Also called "URSS", where kind people read your mail and inspect your stuff etc.
Perfect;
https://discuss.privacyguides.net/t/why-did-nobody-do-this-d...
The idea basically is to block all ip's which weren't resolved by the dns server in past specific time period (for example in the last 3 minutes). So all static ip's would be blocked by default. When a domain get's resolved by the dns server, the ip address gets to the whitelist for a specific amount of time.
There is some issues. For example if somebody downloads something, the ip address might only get resolved once but the download happens by directly connecting to the ip address. But I think these issues are definitely solvable.
Would be interested to hear other peoples thoughts on this.
edit: of course this is for home network filtering purposes. If governments did this we are not in a good position.
You joke, but this is a significant part of the justification given for denying water to millions right now (in Gaza).