From Stealth Blackout to Whitelisting: Inside the Iranian Shutdown

Iran is in the midst of one of the world’s most severe communications blackouts. This post uses Kentik data to detail how this historic event unfolded, where this event lies in the context of previous Iranian shutdowns, and finally discusses what might be in store next for Iran.

Kentik

#Whitelisting the internet in #Iran:

"By keeping IPv4 routes in circulation, Iranian authorities can selectively grant full internet access to specific users while denying it to the broader population."

https://infosec.exchange/@dougmadory/115934628657097462

There are allot of people here who understand the world in my particular way, so I thought I'd throw this out and see if anyone has done this sort of thing before and can save me from wheel reinvention. I have a #Windows machine running #Windows10 which I want to connect to the internet as follows. It has to be #portable. It has to have access only to a very specific and limited number of IP addresses and DNS names which I will identify in advance and which I will edit by hand. It has to block access to everything else including Microsoft's machines, Google's machines, Basically, if it's not on my list, the machine will not connect to it. Whether the machine wants to connect to an IP address, a DNS name, or a device on the local network, I want connections to be promptly blocked. By promptly, I mean that I want the machine not to time out trying to connect to the stuff not on my list, I want the machine to be told no as soon as it tries. I want this because the machine shouldn't be waiting to timeout, it should just be doing what I told it without wasting cycles and time trying to talk to devices I don't want it talking to. The obvious solution is some sort of #whitelisting #firewall or #security system, but I have three problems there. First, I'm #blind and need #a11y with #Jaws and #NVDA. Secondly, as I said, it has to be portable, so I can't carry around a second box with a firewall. Thirdly, the machine has both ireless and ethernet access. I want both ports to have access only to the IPs/names I specify. Whether the machine is connected over ethernet or 802.11, I want those rules to be in effect. I have considered MS' firewall, but am nervous that it will let the machine talk to MS, which I don't want it to. Is any of this even possible? Boosts would be appreciated.
SecPoint Penetrator Vulnerability Scanner V61 Why Whitelisting Matters

YouTube
@HistoPol
I know what #whitelisting is general, but how would I go about this on #Mastodon?

The whitelist, if I don't want to do everything manually (no-go,) would need to be "intelligent" and able to discern the platform s.o. is using for his handle...
I don't use Mastodon, so I don't know for sure. Some people have mentioned that there is a whitelist mode that is called "limited federation mode" or something like that. The admin would have to turn that on since it is for the whole instance.

If you don't want to use whitelist mode, people have been talking about blocklists that can be imported into Mastodon. I am not familiar with how they work. Maybe someone who uses Mastodon could answer this one?
Authorship Studio

@scott

Thanks a lot, Scott.

I am aware of several of these things. A friend of mine, https://stefanbohacek.online/@stefan, created https://jointhefediverse.net to remedy this lack of undesirable for newbies and no-nerds.

I know what #whitelisting is general, but how would I go about this on #Mastodon?

The whitelist, if I don't want to do everything manually (no-go,) would need to be "intelligent" and able to discern the platform s.o. is using for his handle...

I can live with the screenshot issue.

Stefan Bohacek (@[email protected])

19.8K Posts, 1.1K Following, 4.67K Followers · Husband, father, side project enthusiast: https://stefanbohacek.com/projects Big fan of the #fediverse: https://stefanbohacek.com/fediverse Enjoy my work? Here's how you can pay me back: https://stefanbohacek.com/support-my-work/ He/him. 🗺️ Bratislava ➜ NYC ➜ NJ

Stefan's Personal Mastodon Server

Something I want to make clear to #Youtube, #Vice, #Mediate and others...

I am NEVER turning off my #adblocker. EVER.

I followed Youtube's #instructions for #Whitelisting their #website TO THE LETTER, and it didn't work. So no adblocking, #notraffic.

And your precious #Subcriptionservices like #YoutubePremium could cure cancer and it would NOT change the fact I can NOT afford them. If and When I get a job that WON'T be replaced by a #machine or #AI, then MAYBE I'll think about subscribing.

OFC, it's not done with simple #2FA and if #YouTube actually took #ITsec serious they'd do what every halfway good #CDN does and allow #IP #whitelisting for #logins, #uploads and #streams.

Because even #Sony does that shit for their #DevKit|s...

But alas, #Susan is more focussed on whipping out after #ContentCreators.

Also I'd be surprised if #LinusTechTips doesn't have at least equal access to #YouTube #support as #SuzyLu...

If so that would be kinda ashaming...
https://youtu.be/NJduyTTym2w?t=647

Suzy Lu: The Most Problematic YouTuber You've Never Heard Of

YouTube
... wegen Sicherheitsbedenken? Die Bedenken hätte ich, weil es überhaupt erlaubt und möglich ist eine solche App zu installieren. #whitelisting #itsec #kritis
https://www.deutschlandfunk.de/auch-eu-parlament-verbietet-beschaeftigten-tiktok-auf-dienstgeraeten-100.html
Sicherheitsbedenken - Auch EU-Parlament verbietet Beschäftigten Tiktok auf Dienstgeräten

Nach der EU-Kommission verbietet auch das Europäische Parlament seinen Beschäftigten die Nutzung der Social-Media-App Tiktok auf Diensthandys und -tablets.

Die Nachrichten
@heinz @ton @naca7 @yatil @brodnig Es ist zumindest eine absehbare Herausforderung. - Ein #Whitelisting bedeutet dabei letztlich aber nur, dass man sich jeglicher Verantwortung entzieht und nur noch in einer eigenen, kleinen Welt schwimmen will, oder verstehe ich Dich gerade falsch?