Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

NodeBB

  1. Home
  2. General Discussion
  3. if you have ever been curious about running a web application firewall (WAF) in front of Mastodon or other fediverse instance, i've published a repo containing the #openappsec policy we're now using to to maximize privacy.

if you have ever been curious about running a web application firewall (WAF) in front of Mastodon or other fediverse instance, i've published a repo containing the #openappsec policy we're now using to to maximize privacy.

Scheduled Pinned Locked Moved General Discussion
openappsecmastoadminactivitypubmastodon
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • yawnbox@disobey.netY This user is from outside of this forum
    yawnbox@disobey.netY This user is from outside of this forum
    yawnbox@disobey.net
    wrote on last edited by
    #1

    if you have ever been curious about running a web application firewall (WAF) in front of Mastodon or other fediverse instance, i've published a repo containing the #openappsec policy we're now using to to maximize privacy. i've recently turned on prevent mode, blocking critical events

    https://code.disobey.net/dd/ap-waf

    there's a lot of skip exceptions needed in order to not block required ActivityPub transactions. even things like changing a password in Mastodon is seen as a critical (false) positive

    given the number of skip exclusions, there's a lot of attack surface that admins won't be able to action on since so much of ActivityPub looks malicious, and a targeted attack could easily take advantage of these necessary skip policies

    i'm curious if any ActivityPub devs have ever run a WAF in front of their instance, and curious if any improvements can be made to the spec to reduce transactions that look like malicious behavior

    i have to trust that for the ActivityPub exclusions, Mastodon properly sanitizes inputs and so the overall risk is still low

    either way, this is a big win for overall risk reduction for anyone serious about protecting their community

    #MastoAdmin #ActivityPub #Mastodon #OpenAppSec

    julian@activitypub.spaceJ 1 Reply Last reply
    1
    0
    • tag-activitypub@relay.fedi.buzzT tag-activitypub@relay.fedi.buzz shared this topic on
    • yawnbox@disobey.netY yawnbox@disobey.net

      if you have ever been curious about running a web application firewall (WAF) in front of Mastodon or other fediverse instance, i've published a repo containing the #openappsec policy we're now using to to maximize privacy. i've recently turned on prevent mode, blocking critical events

      https://code.disobey.net/dd/ap-waf

      there's a lot of skip exceptions needed in order to not block required ActivityPub transactions. even things like changing a password in Mastodon is seen as a critical (false) positive

      given the number of skip exclusions, there's a lot of attack surface that admins won't be able to action on since so much of ActivityPub looks malicious, and a targeted attack could easily take advantage of these necessary skip policies

      i'm curious if any ActivityPub devs have ever run a WAF in front of their instance, and curious if any improvements can be made to the spec to reduce transactions that look like malicious behavior

      i have to trust that for the ActivityPub exclusions, Mastodon properly sanitizes inputs and so the overall risk is still low

      either way, this is a big win for overall risk reduction for anyone serious about protecting their community

      #MastoAdmin #ActivityPub #Mastodon #OpenAppSec

      julian@activitypub.spaceJ This user is from outside of this forum
      julian@activitypub.spaceJ This user is from outside of this forum
      julian@activitypub.space
      wrote on last edited by
      #2

      @yawnbox@disobey.net some of the NodeBB forums I run sit in front of CloudFlare, although a lot of what they do is opaque to me.

      The instance I am on does not go through CF, but I have deployed Anubis in order to stem bot and AI crawler traffic.

      For the latter there are some adjustments that needed to be made for AP specifically.

      1 Reply Last reply
      1

      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

      With your input, this post could be even better 💗

      Register Login
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups