Skip to content
This repository has been archived by the owner on Jun 6, 2021. It is now read-only.

Policy page does not discuss anti-botnet/proxy measures #404

Open
fndax opened this issue May 26, 2019 · 2 comments
Open

Policy page does not discuss anti-botnet/proxy measures #404

fndax opened this issue May 26, 2019 · 2 comments

Comments

@fndax
Copy link
Contributor

fndax commented May 26, 2019

https://freenode.net/policies does not discuss technical measures used by freenode to prevent botnets, open proxies, and other undesirable activity. I suggest that we add wording covering, at a minimum:

  • Open proxy scanning
  • SSH banner detection (are we even still doing this?)
  • CTCP VERSION and CTCP WEBSITE by freenode-connect
  • Usage of DNSBLs

As far as I know, none of the above is currently discussed anywhere on freenode's website, and some of them (e.g. sending IPs to DNSBLs, and any data retention of any of the above if applicable) may have GDPR consequences. It'd also be nice to have somewhere to point #freenode users when they ask about it, instead of re-iterating everything each time.

All of the above has been discussed publicly in #freenode in the past, so I figure it should all be fine to discuss on the website?

@Mikaela
Copy link
Contributor

Mikaela commented Sep 8, 2019

I was asking how do the DNSBLs work out of curiosity and @tomaw told me that they aren't aware of the queries doing anything more complicated than going to DNS server of the server sponsor and I understand this to mean that they go in plaintext.

IP address is considered as personal data by GDPR and judging by What information should I receive when I provide my personal data? I think the privacy policy should name the DNSBLs and DNS servers and possibly say that they are contacted over insecure connection.

I am not sure if GDPR would accept the insecure connection part though as encrypting DNS isn't that difficult to setup nowadays (thanks to dnscrypt-proxy and Unbound), but someone observing the network around freenode servers would already see the incoming connections without reading the DNS queries.

I thought stats A and stats n could also be used by normal users, but that doesn't seem to be the case.

@jesopo
Copy link
Contributor

jesopo commented Sep 18, 2020

I'd add usage of MX RBLs on to this list

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

4 participants