tag yourself
@ShadowJonathan I'm gonna be honest i have no idea what any of these are besides the excavator

@ShadowJonathan anything but funcion and form radical is wrong.

“In the beginning the ARPANET was created.
This had made many people very angry and has been widely regarded as a bad move."

@ShadowJonathan eBPF + XDP with a little VETH sprinkled in is a firewall.
@ShadowJonathan can't see 99% WAN packet drop here, is that covered by the excavator?
@ShadowJonathan
just a few weeks ago our excavator firewall saved us from a hacker (i think, i don't know for sure since the internet was gone). Thank you city administration, that you enabled the excavator firewall

@ShadowJonathan (3,2) ofc

Anything is a firewall if you try hard enough

@ShadowJonathan I always make sure I know where my own trusty firewall is.
@ShadowJonathan I don't know... they all seem valid...
@ShadowJonathan I needed this last week when I was explaining firewalls to my class
@miles @ShadowJonathan just rawdog the internet like berners-lee intended!
@ShadowJonathan Also, big respect for excavators for making network paths and restricting network traffic in the process.
Georgian woman cuts off web access to whole of Armenia

Entire country loses internet for five hours after woman, 75, slices through cable while scavenging for copper

The Guardian

@ShadowJonathan the chart is wrong but anyway:

iptables -t raw -A PREROUTING -j EXCAVATOR

@ShadowJonathan “NAT is a security feature”
@ShadowJonathan where does "NAT is my firewall" land me on that chart?

@ShadowJonathan

in my reality I am WRT but in my mind I am excavator

@ShadowJonathan This is on my cubicle wall. I've been tempted to add this to my evidence for Firewalls that is submitted to the auditor.
@ShadowJonathan the firewall for my industrial network is the whole thing bursting into flames if you scan it
@ShadowJonathan Excavator is best firewall. Hands down.
@ShadowJonathan I wrote my first firewall in iptables. I am not ashamed. It was the 90s. We all did weird shit in the 90s.
@sbisson ufw implements its rules in iptables, so don't worry :)
@ShadowJonathan no virtual machine firewall?
@ShadowJonathan i barfed in my mouth reading palo alto, then did it again typing this comment 🤮
@ShadowJonathan I'm so chaotic good it hurts, but also I appreciate lawful neutral and true neutral.
@ShadowJonathan form purist, function radical
@ShadowJonathan well, after reading a bit, I think the table is badly organized?

Like, my definition if firewall implies several types:
* feature based: as part of routing like Network ACLs
* software based: software spifiv got thr use like IPtables
* hardware based: either software or directly hardware implemented but in device specific for that purpose
@ShadowJonathan I can see how the radical/radical position is interpretable as a "firewall" in the same sense as "Any machine is a smoke machine if it is used wrong enough."
@ShadowJonathan spaghetti fork the cables in the ground is a firewall
@ShadowJonathan avid iptables fan (i hate myself)

@ShadowJonathan

One of the cases where I prefer German:

English: "Excavator": Pompous, pretentous (why not call it "digger?")

German: "Bagger": Cute, friendly, lewd.