networkstring
honked back 12 Feb 2025 10:12 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113990141732739818
networkstring rss
Builds anti-surveillance and anti-censorship infrastructure at https://brasshorncommunications.uk and https://ablative.hosting using OpenBSD routers (AS28715, AS209220, AS215833) and servers.
GPG: 0x2AA6E6BC2184073C1779 | Signal: NAMOS.17
https://networksaremadeofstring.com
Presented at EurBSDCon, HOPE, UKNOF and others.
networkstring
honked back 12 Feb 2025 10:12 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113990141732739818
networkstring
honked back 12 Feb 2025 09:21 +0000
in reply to: https://fosstodon.org/users/castaway/statuses/113990164210744328
networkstring
honked back 12 Feb 2025 08:12 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113989867731003090
@neil oh, the MX records have pointed to localhost since the DEA / BBFC / AV stuff got scrapped. Don't want to risk 'retroactive' enforcement by OFCOM. In essence the rough plan is; I've yet to decide whether it'd be done entirely by email or whether the website would display 'safe' thumbnail (GIF?..) with a 'safe' description and an ID. Consumers then email with a subject of the ID ( ~80% of the code is there, just waiting to see what OFCOM says. If it's legal I'll keep writing it to prove a point, if it's not, well it's been fun. I'll update the website with more info later.
mailto:
href to make everyone's lives easier) to retrieve the video/images.
networkstring
honked back 12 Feb 2025 08:01 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113989755529675492
networkstring
honked back 12 Feb 2025 07:15 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113989522441517293
@neil it would seem so. This service is either egregiously in breach or is perfectly legal there isn't a grey area here. If they can't bring themselves to say one way or the other what chance does anyone else have?
networkstring
honked 11 Feb 2025 23:22 +0000
OFCOM have replied to my email as to whether https://pornby.email is compliant with the OSA with;
networkstring
honked back 11 Feb 2025 19:48 +0000
in reply to: https://toots.dgplug.org/users/kushal/statuses/113986884467574511
networkstring
honked back 11 Feb 2025 19:37 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113986736834510288
@neil @aphyr @rachelcoldicutt @jaz so I've been thinking about this in the context of the DSA and the "cloudflare defense". If the content is proxied/mirrored rather than hosted/published then it's a different situation? The OSA sort of understands this which is why CSAM URLs are called out separately to content.
networkstring
honked back 11 Feb 2025 09:13 +0000
in reply to: https://toots.dgplug.org/users/kushal/statuses/113984401543455849
networkstring
honked back 10 Feb 2025 15:58 +0000
in reply to: https://ioc.exchange/users/troed/statuses/113980396244513579
networkstring
honked back 10 Feb 2025 15:51 +0000
in reply to: https://ioc.exchange/users/troed/statuses/113980351247224693
@troed because the UK Government thinks they can fine you or imprison you. Which is wild. And if I weren't in the UK I'd say the same thing to them that I'd say to Roskomnadzor... (and it isn't polite).
networkstring
honked 10 Feb 2025 15:49 +0000
Huh, in an unexpected turn of events Stripe.com seems to have lifted the restriction on https://over18.uk It can now process credit card payments again. Now, how do I check if it is "highly effective"?
networkstring
honked back 10 Feb 2025 15:36 +0000
in reply to: https://en.osm.town/users/InsertUser/statuses/113980266654324019
@InsertUser @russss @neil @steve no, I've emailed the porn supervision team about https://pornby.email and there's an FOI out too ( https://www.whatdotheyknow.com/request/definition_of_email_for_online_s#incoming-2905462 ) so hopefully we'll know soon enough.
networkstring
honked 10 Feb 2025 15:34 +0000
The confirmation from OFCOM that https://geoblockthe.uk is a compliant way to conform with the #OnlineSafetyAct; https://player.vimeo.com/video/1053682977?app_id=122963&autoplay=1#t=1h0m52s
networkstring
honked back 10 Feb 2025 15:18 +0000
in reply to: https://mstdn.social/users/pmdj/statuses/113980112187388939
networkstring
honked back 10 Feb 2025 14:22 +0000
in reply to: https://mas.to/users/plock/statuses/113979965194528879
networkstring
honked back 10 Feb 2025 14:21 +0000
in reply to: https://chaos.social/users/russss/statuses/113979977133684084
networkstring
honked back 10 Feb 2025 14:01 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113979944754051403
@neil @steve @russss I can't tell you the number of times someone has WAF'd their website to the ends of the earth and back again but left the graphql/api that their JS calls totally unprotected... I can easily see e.g. Cloudflare or something launching a "AV WAF" but obvs the server-to-service bit can't be gated in the same way. But this is getting deep into the weeds of hypothetical.
networkstring
honked back 10 Feb 2025 13:55 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113979911188988987
@neil @TheVampireFishQueen @johnmclear AIUI we're still waiting to find out how OFCOM is drawing the line between ASP and "user to user service" given that anything with Internet access is a user-to-user service.
networkstring
honked back 10 Feb 2025 13:49 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113979893912539796
networkstring
honked back 10 Feb 2025 13:26 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113979803691326701
networkstring
honked back 10 Feb 2025 13:07 +0000
in reply to: https://furry.engineer/users/ret/statuses/113979731611293237
@ret that was their starting point for the "Small Providers" session last week and hence why I'm annoyed.
networkstring
honked back 10 Feb 2025 13:06 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113979717343753710
networkstring
honked back 10 Feb 2025 13:01 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113979708486748697
@neil I really wish (for other peoples sake) the information started at; Waaaaaaay before we get to "XYZ Company with it's 500k/monthly users and 8 person strong moderation team..."
networkstring
honked back 09 Feb 2025 22:33 +0000
in reply to: https://socel.net/users/TheVampireFishQueen/statuses/113975936765917238
@TheVampireFishQueen @neil @cyberleagle what's annoying is that the "we campaigned for this" Telegraph are still acting like this only affects "Tech Giants". However it will be amusing if they have to defang it in such a way to be totally useless.
networkstring
honked back 09 Feb 2025 13:05 +0000
in reply to: https://social.vivaldi.net/users/Fonant/statuses/113974046605911375
@Fonant @bazbt3 @Szescstopni @neil exactly. I'm a huge fan of GDPR (even though I'm paying fees to the ICO for all of my companies!)
networkstring
honked back 09 Feb 2025 12:41 +0000
in reply to: https://social.vivaldi.net/users/Fonant/statuses/113973771097713502
@Fonant @bazbt3 @Szescstopni @neil As much as I'd love for the Internet to be entirely open and for blocking / filtering to be opt-in etc at the client side there is a good reason for blocking as many UK users as possible right now. As widely predicted at the time the IPA TCNs are biting (UK Gov ordering backdoor in Apple cloud storage encryption) so the press are latching onto "extra territorial overreach". If everyone starts finding out they suddenly can't reach websites because of another poorly written law with "extra territorial reach" we might get a ground swell to strike out or amend the law. And to be clear; I've less of a problem with multi-billion $ companies with a demonstrated history of causing harm being told "follow our new risk reduction regime or face enforcement action" than I do with folks who can't even get a straight answer of whether they are even in scope or not for their little gardening/knitting/butterfly blog. Sites below a threshold and with no evidence of harm should be simply and obviously carved out to the point where most folks don't have to care about the OSA anymore than they do the DSA, IPA etc etc.
We need to look at The Big Picture, and not rush to block UK users for no reason other than a Bad Law.
networkstring
honked back 08 Feb 2025 20:02 +0000
in reply to: https://infosec.exchange/users/jerry/statuses/113970018696558090
@jerry @pieceofthepie @Marcus @neil absolutely, they've even said that some of the egregious offenders might be single person services with a handful of users but causes a disproportionate amount of harm. Still it sucks for smaller folks who can't understand where they stand or whether they are even covered.
networkstring
honked back 08 Feb 2025 19:10 +0000
in reply to: https://social.n8e.dev/users/pieceofthepie/statuses/113969819177206672
@pieceofthepie @jerry @Marcus @neil indeed. It's just annoying that they refuse to quantify anything and simply say "if you're in scope you must comply".
networkstring
honked back 08 Feb 2025 19:00 +0000
in reply to: https://blimps.xyz/users/cardboard/statuses/113969749088310124
@cardboard at least we'll be 'safe'. With our backdoored encryption. And mass surveillance Internet Connection Records. And trade/freedom crushing Brexit. What joy we have to look forward to.
networkstring
honked back 08 Feb 2025 18:18 +0000
in reply to: https://thx.gg/users/interpipes/statuses/113969572495650623
@interpipes @stephen @neil ah I see what you mean now. It'll also be interesting to see how the (fear of) business disruption measures affect customer take up. As an ASP we have to comply with s100 notices but if the customer is just an email address to us and they ignore OFCOM will there be some naughty sidestepping like we used to see with the Police and CommsData or will they move to use their enforcement powers.
networkstring
honked back 08 Feb 2025 17:44 +0000
in reply to: https://social.treehouse.systems/users/dee/statuses/113968263669720243
networkstring
honked back 08 Feb 2025 17:43 +0000
in reply to: https://furry.engineer/users/ret/statuses/113969035281180379
networkstring
honked back 08 Feb 2025 17:10 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113968866901300800
@neil @steely_glint I did ask OFCOM if literally every ISP on the planet is a user to user service and they refused to "talk about specifics".
networkstring
honked back 08 Feb 2025 17:07 +0000
in reply to: https://infosec.exchange/users/jerry/statuses/113969188248913875
@jerry @Marcus sadly OFCOM refuses to clarify what significant means. If you're interested in looking at the risk assessment / child access assessment stuff might I recommend the excellent resources that @neil has been maintaining over at https://onlinesafetyact.co.UK Or there's https://geoblockthe.uk ;) However as someone following a lot of folks on your instance my preference would be to ignore OFCOM just as you would any other tinpot regulator.
networkstring
honked back 08 Feb 2025 17:03 +0000
in reply to: https://thx.gg/users/interpipes/statuses/113969198387312485
@interpipes @stephen @neil are you thinking of businesses disruption orders as an ASP or something else?
networkstring
honked back 08 Feb 2025 13:55 +0000
in reply to: https://social.treehouse.systems/users/dee/statuses/113968538542900088
@dee @xenogon I think a confusion has arisen over my putting many things on the same page / context. I want sites to block the UK to cause a backlash. I don't want people to not be able to access said sites so suggested Tor to get to sites they can't reach (OFCOM can block sites themselves). I'd love to see more websites running on .onion (and IPv6). At the end of the day if people don't block the UK they might be on the sharp end of OFCOMs enforcement - what they do is a decision for them (and/or their nonexistent legal team)
networkstring
honked back 08 Feb 2025 13:46 +0000
in reply to: https://socel.net/users/TheVampireFishQueen/statuses/113968518671924191
networkstring
honked back 08 Feb 2025 13:35 +0000
in reply to: https://sunny.garden/users/xenogon/statuses/113968392035813088
I recommend Tor as it has a special place in my heart given I run Exits and a .onion hosting company :)
networkstring
honked back 08 Feb 2025 13:32 +0000
in reply to: https://mastodon.neilzone.co.uk/users/neil/statuses/113968490889714121
networkstring
honked back 08 Feb 2025 13:01 +0000
in reply to: https://social.treehouse.systems/users/dee/statuses/113968263669720243
@dee ah, I hadn't even had a coffee yet when I knocked this together! Will double check for the OSS version. As for VPN, I had considered it but there's so many ads/shills and even the one I have by virtue of my email (proton) has become problematic that I didn't want to 'advocate' for a brand.
networkstring
honked back 08 Feb 2025 11:53 +0000
in reply to: https://social.coop/users/smallcircles/statuses/113968070110904741
@smallcircles @aral one day I hope that IPv6 and these multi-Ghz devices everyone carries around will unleash a form of P2P publication and communications the likes of which we've never seen before.
networkstring
honked back 08 Feb 2025 11:16 +0000
in reply to: https://mastodon.scot/users/CGM/statuses/113967946257421844
@CGM beautiful this is one of my big hopes; https://ablative.stream/u/networkstring/h/54w9gWqVm9gcRtdl6M Naturally I'd rather the Act be amended with a carve out for smaller sites but...
networkstring
honked back 08 Feb 2025 11:13 +0000
in reply to: https://kiwi.fuo.fi/notes/a3zmrclvvncj000u
@fuomag9 the act claims 'extra territorial' jurisdiction but how much that matters in reality is unknown to me.
networkstring
honked back 08 Feb 2025 11:20 +0000
in reply to: https://mastodon.ar.al/users/aral/statuses/113967943436411277
@aral indeed thank you. Edit: SmallWeb looks really interesting I'll have a read (now that I actually fully understood your reply!)
networkstring
honked 08 Feb 2025 09:56 +0000
I woke up angry and chose violence; https://geoblockthe.uk/ I'm going for a walk but please send me more guides (preferably the official documentation where possible) and I'll add them.
networkstring
honked back 07 Feb 2025 15:00 +0000
in reply to: https://masto.galooph.com/users/galooph/statuses/113963158030945674
@galooph @neil @cyberleagle @Fonant @aphyr @derickr :) Seeing folks looking to 'fight' to keep their corners of the Internet alive has been quite refreshing. My two biggest worries are about the folks who don't have the will/spoons to fight and what happens next. (Next being massive expansion of ID requirements and/or 'legal but harmful' definitions (see the US' scrubbing of 'DEI/LGBTQI+' content)
networkstring
honked 07 Feb 2025 14:20 +0000
networkstring
honked back 07 Feb 2025 13:33 +0000
in reply to: https://socel.net/users/TheVampireFishQueen/statuses/113962847627866945
@TheVampireFishQueen @neil @hedders what a juicy opportunity for Blair to get his ID cards in at last...
networkstring
honked back 07 Feb 2025 13:08 +0000
in reply to: https://socel.net/users/TheVampireFishQueen/statuses/113962675405529087
@TheVampireFishQueen @neil @hedders too much money to be made by the AV snakeoil crowd. Plus the "think of the children" folks will go nuclear. My feeling from this weeks presentations is that OFCOM thinks AV is perfectly reasonable :/