• lemmyvore@feddit.nl
    link
    fedilink
    English
    arrow-up
    7
    ·
    1 hour ago

    crowdsec has always struck me as a really odd approach to security. You give out your logs to strangers and block IPs based on their say-so.

    The cause and effect are so far removed that I can’t wrap my head about how it’s supposed to be efficient. It’s been proven in real-world tests that it lags badly behind the first waves of new vulnerabilities and by the time it starts blocking IPs that were related to those attacks the attackers have moved on and there are also patches available.

    The “thousands of IPs blocked” image reminds me of that WWII airplane bullet-holes image.

  • afk_strats@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    5 hours ago

    That’s really cool. Would you mind posting a few sentences about how you redirected your specific solution and what it’s protecting. That would be super helpful.