deCloudflare/subfiles/people/2022.mastodon.md
2022-04-21 01:00:57 +00:00

6 lines
915 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

## Mastodon
- Fdroid is getting dicey for privacy now that are allowing a tech giant to snoop on who fetches which app. Many users choose @fdroidorg for security, but security is compromized when Cloudflare is given reconnaisance data on the apps and versions various users are running. This info opens up Fdroid users to attacks that exploit known bugs. ([bojkotiMalbona@infosec.exchange](https://infosec.exchange/@bojkotiMalbona/108165961277908385))
- @fdroidorg I suggest not trusting the Fdroid app itself anymore. By default it enables ~6 mirrors, any of which can become Cloudflared w/out notice. There is no toggle to automatically block or disable Cloudflare hosts. Its thus more secure to fetch f-droid apps from the web over Tor, after checking whether a host is CFd. ([bojkotiMalbona@infosec.exchange](https://infosec.exchange/@bojkotiMalbona/108166039629460241))
- ↳ [Back to list](../people/)