• Taasz/Woof@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    16
    ·
    1 day ago

    I don’t believe there are any logs being transferred, just the abusive IPs are shared with the central DB.

    So if an IP starts hitting a ton of rules (like .env access, repeated 403s, 404s, 429s, etc… Or specific AppSec rules) then that IP is blocked and sent to their central DB where it’s pushed out to everyone running crowdsec.

    On my setup crowdsec has been more effective than cloudflare at stopping scanners and bots from overloading things, cloudflare just lets basically everything through so I stopped using it.

    That said I’m curious if you remember the source of the real world tests, because I’d love to see what’s actually better.

    • non_burglar@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      On my setup crowdsec has been more effective than cloudflare at stopping scanners and bots from overloading things

      Cloudflare is in the business of keeping infrastructure up and working. Any security benefits of CF are secondary.

        • non_burglar@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          19 hours ago

          Sure, but that WAF solution is not for us, it’s aimed at clients who can measure their web presence in millions of requests per second.

          Cloudflare is a CDN first and foremost, their success competing with Fastly and Akamai has been good to them, but they don’t care if you get pwned unless you have a ton of money.