Viewing profile — Philippe_H
Philippe_H
HN member- Joined
- Tue, Jul 07, 2020, 3:48 PM UTC
- HN karma
- 40
- Public activity
- 27 items
- HN profile
- View on Hacker News ↗
About Philippe_H
No profile information was provided.
Recent public activity
-
comment
Comment #42114133
CrowdSec scans also firewall logs like PSAD and much more applicative logs types than fail2ban. That being said I use tailscale to ssh to my servers.
-
comment
Comment #40703997
Hi all and @snorremd, (Philippe from the CrowdSec team) The $2.5K / month was for enterprise, but we didn't correctly understand the need and converted it to 2 optional prices: $1K…
- story
- story
-
comment
Comment #24845974
Well we have a consensus system that's quite advanced to avoid poisoning and false positives. To put it short, all members have a Trust rank, only TR1 can publish an IP without cou…
-
comment
Comment #24835809
CrowdSec is not designed specifically for SSH. It can ingest any type of logs and answer with a bouncer at pretty much any level. IP/Session/User/software stack. Ie, we are working…
-
comment
Comment #24835797
Absolutely. We owe that transparency to our users. The 1.0 should be out in a month from now, and it will include a Local API, an abstraction layer between the core and the bouncer…
-
comment
Comment #24835761
I should maybe have told you also, team members are from pentesting and high security hosting background. We also have created some other OSS components before, like NAXSI (Waf ove…
-
comment
Comment #24835739
no risk here. Tool is MIT, if community doesn't like our approach, you fork it. So we'll be faithful to our commitments and this licensing model is the best insurance for it. Now, …
-
comment
Comment #24835718
Sure, People activate the sharing of what they spot or not. If they do, no money is asked for them benefiting from the global IP rep DB. The one willing to use it without contribut…
-
comment
Comment #24835632
Well actually Spoofing on a private network is trivial, but in TCP over a public network, it's another story entirely and it's not simple at all. UDP can be easily spoofed though, …
-
comment
Comment #24835616
well just whitelist your Public IPs or use a combo of IPset & port knockd. Works fine for me for variable IPs.
-
comment
Comment #24831199
yepn indeed, we call it private sharding or private consensus. Far on the roadmap (4 months), but nevertheless, the team is thinking about it. You could also include or exclude som…
-
comment
Comment #24831183
this is accounted for. By default you have a whitelist containing local lan IP ;)
-
comment
Comment #24831168
We'll (soon) provide a Backoffice, where you can choose which IP you decide to ban (based on their activities, like bot scrapping, bruteforcing, etc.) but also add some 3rd party b…
-
comment
Comment #24829980
Perfwise, we have a user that previously used fail2ban to block some http botnets. He crunches 7000 IPs worth of logs in 50 mins with F2B. under a minute with CrowdSec. Another blo…
-
comment
Comment #24829899
CrowdSec is for all protocoles / system generating logs (can be Cloud trail, syslog, kafka, etc.) and can ban at an applicative, user or IP level.
-
comment
Comment #24829775
Sorry, we should have made it clear, it is totally optional. You just don't get the IP rep DB part of the soft if you don't share, but the behavior is still 100% functional.
-
comment
Comment #24829377
(but I think they already send it through HTTPS)
-
comment
Comment #24829369
Well hashing is (usually) a symmetric function and we are open source... Meaning you could recover the key in the code (or intercept it during transfer). I think Private/Public key…
-
comment
Comment #24829304
Sure. To put it very short, we give every user a trust rank. It varies overtime. If you consistently, and for a long while, reported attacks that could be correlated by others and …
-
comment
Comment #24829200
different approach, but I'm sure at some point we'll get close to one another.
-
comment
Comment #24828189
Hi Guys, thanks for all your feedbacks. (I'm part of the CS team) I'll try to address some few questions. 1/ You don't have to communicate. If you don't, you get a modern, fast, de…
-
comment
Comment #24579482
Thank you, don't hesitate to reach us through gitter or discourse or else.
- story