Elektrine lite

← Feed

@Walker@infosec.exchange

Post #3991256

2026-07-21 17:17 UTC

Modern "AI" firewalls are great except when dealing with Cloudflare. Vendor has blocked several legitimate websites at the firewall for their internal users because the sites share the same IP from Cloudflare as identified malicious websites. Tracking down the issue was challenging due to the vendor residing in a different geography than the IT MSP. IP addresses are regional from Cloudflare. #firewalls #cloudflare #ai

Replies (1)

  • @jimz@infosec.exchange 2026-07-21 19:42

    @Walker@infosec.exchange In the 9th Circuit there is case law on what was a default judgment (because even if you serve someone in Pakistan a subpoena they can't get a visa to come to the US anyway)but the judge decided to flesh out what "purposeful availment" means that establishes jurisdiction. Except the lawyers made their case by geolocating Cloudflare IPs in Arizona because... their offices are in Arizona. And there's nobody to rebut any of the assertions. The result? Since you literally can't pick your anycast CDN IP, applying the correct facts, the law is actually working exactly opposite as intended. All sites that use CDNs would be outside3 the court's jurisdiction. The holding has now spread to New York: https://scholar.google.com/scholar_case?case=5281974995515683328&q=purposeful+availment+cloudflare&hl=en&as_sdt=3,29 So much of American law is built on top of tech illiteracy and the assumption of tech illiteracy that the rationale that comes from someone putting a cloudflare ip into ipinfo and is now the law is both sad, and also, feels apt for our times. Meanwhile, I'm sure I can jerry-rig something that lets me run masscan through a rotating bunch of cf workers.

    Open ##3994359