Live data from Hacker News

Viewing profile — Philippe_H

Philippe_H

HN member
Joined
Tue, Jul 07, 2020, 3:48 PM UTC
HN karma
40
Public activity
27 items

About Philippe_H

No profile information was provided.

Recent public activity

  1. comment
    Comment #42114133

    CrowdSec scans also firewall logs like PSAD and much more applicative logs types than fail2ban. That being said I use tailscale to ssh to my servers.

  2. comment
    Comment #40703997

    Hi all and @snorremd, (Philippe from the CrowdSec team) The $2.5K / month was for enterprise, but we didn't correctly understand the need and converted it to 2 optional prices: $1K…

  3. story
  4. story
  5. comment
    Comment #24845974

    Well we have a consensus system that's quite advanced to avoid poisoning and false positives. To put it short, all members have a Trust rank, only TR1 can publish an IP without cou…

  6. comment
    Comment #24835809

    CrowdSec is not designed specifically for SSH. It can ingest any type of logs and answer with a bouncer at pretty much any level. IP/Session/User/software stack. Ie, we are working…

  7. comment
    Comment #24835797

    Absolutely. We owe that transparency to our users. The 1.0 should be out in a month from now, and it will include a Local API, an abstraction layer between the core and the bouncer…

  8. comment
    Comment #24835761

    I should maybe have told you also, team members are from pentesting and high security hosting background. We also have created some other OSS components before, like NAXSI (Waf ove…

  9. comment
    Comment #24835739

    no risk here. Tool is MIT, if community doesn't like our approach, you fork it. So we'll be faithful to our commitments and this licensing model is the best insurance for it. Now, …

  10. comment
    Comment #24835718

    Sure, People activate the sharing of what they spot or not. If they do, no money is asked for them benefiting from the global IP rep DB. The one willing to use it without contribut…

  11. comment
    Comment #24835632

    Well actually Spoofing on a private network is trivial, but in TCP over a public network, it's another story entirely and it's not simple at all. UDP can be easily spoofed though, …

  12. comment
    Comment #24835616

    well just whitelist your Public IPs or use a combo of IPset & port knockd. Works fine for me for variable IPs.

  13. comment
    Comment #24831199

    yepn indeed, we call it private sharding or private consensus. Far on the roadmap (4 months), but nevertheless, the team is thinking about it. You could also include or exclude som…

  14. comment
    Comment #24831183

    this is accounted for. By default you have a whitelist containing local lan IP ;)

  15. comment
    Comment #24831168

    We'll (soon) provide a Backoffice, where you can choose which IP you decide to ban (based on their activities, like bot scrapping, bruteforcing, etc.) but also add some 3rd party b…

  16. comment
    Comment #24829980

    Perfwise, we have a user that previously used fail2ban to block some http botnets. He crunches 7000 IPs worth of logs in 50 mins with F2B. under a minute with CrowdSec. Another blo…

  17. comment
    Comment #24829899

    CrowdSec is for all protocoles / system generating logs (can be Cloud trail, syslog, kafka, etc.) and can ban at an applicative, user or IP level.

  18. comment
    Comment #24829775

    Sorry, we should have made it clear, it is totally optional. You just don't get the IP rep DB part of the soft if you don't share, but the behavior is still 100% functional.

  19. comment
    Comment #24829377

    (but I think they already send it through HTTPS)

  20. comment
    Comment #24829369

    Well hashing is (usually) a symmetric function and we are open source... Meaning you could recover the key in the code (or intercept it during transfer). I think Private/Public key…

  21. comment
    Comment #24829304

    Sure. To put it very short, we give every user a trust rank. It varies overtime. If you consistently, and for a long while, reported attacks that could be correlated by others and …

  22. comment
    Comment #24829200

    different approach, but I'm sure at some point we'll get close to one another.

  23. comment
    Comment #24828189

    Hi Guys, thanks for all your feedbacks. (I'm part of the CS team) I'll try to address some few questions. 1/ You don't have to communicate. If you don't, you get a modern, fast, de…

  24. comment
    Comment #24579482

    Thank you, don't hesitate to reach us through gitter or discourse or else.

  25. story