GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Troy Hunt (troyhunt@infosec.exchange)'s status on Wednesday, 19-Mar-2025 06:17:31 JSTTroy HuntTroy Hunt
    in reply to
    • Viss
    • Matthew Green
    • Dan Goodin
    • benjojo
    • sp00ky cR0w 🏴

    @benjojo @dangoodin @cR0w @Viss @matthew_d_green I suggest the term “snooping” is the problem here. A huge part of the value proposition of any reverse proxy with WAF features (not just Cloudflare) is the ability to inspect traffic. By design, a service like this sits in a position where they can inspect traffic, and that’s a decision the site operator makes. Inspecting traffic then also provides the ability to report on it; I can pull back traffic stats based on the UA string, for example. There’s no explicit “consent” involved in people sending that data, just like there’s no explicit consent in them submitting a form with PII in it; it’s implied. It’s also up to the site owner to enable leaked credential check, who already has the ability to decide what happens to passwords submitted to their service whether CF exists or not: https://developers.cloudflare.com/waf/detections/leaked-credentials/

    In conversationabout 7 months ago from gnusocial.jppermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: developers.cloudflare.com
      Leaked credentials detection · Cloudflare Web Application Firewall (WAF) docs
      The leaked credentials traffic detection scans incoming requests for credentials (usernames and passwords) previously leaked from data breaches.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.