49 points goldenmember 2 hours ago 21 comments
After a quick check, I found that our IP address is listed on UCEPROTECT Level 3. The listing is based on the reputation of the entire ASN 14061 (DigitalOcean, US) [1]. In other words, even if your IP did nothing wrong, it will still be listed because of its ASN.
If your site is innocent and listed only because it's hosted on DigitalOcean, UCEPROTECT offers to whitelist it for about $30/month or $108/year [2].
I checked the ASNs of several other popular hosting providers, and they're all listed too. So if your site is hosted on DigitalOcean or any other major provider, it's probably blacklisted as well. That can cut you off from customers on mobile networks like Orange, whose "cybersecurity protection" uses blacklists like UCEPROTECT to filter traffic.
Honestly, in my 20-year career, this is the first time I've seen a blacklist misbehave this badly and ask for money when there's clearly been no wrongdoing.
[1] http://www.uceprotect.net/en/rblcheck.php?asn=14061
[2] https://www.whitelisted.org/
someonebaggy 1 hour ago | parent
At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone cared about that list.
But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
goldenmember 1 hour ago | parent
As I explained, Orange's security filter seems to automatically block requests at the DNS level if your website's domain resolves to an IP listed on UCEPROTECT Level 3. In this case, that appears to be the entire DigitalOcean ASN.
someonebaggy 52 minutes ago | parent
I am not a lawyer, so consult one.
john_strinlai 29 minutes ago | parent
it was only 2 /23's (only 1024 IPs, ASN14061 is 3,140,680 IPs), and was resolved without a monthly subscription in ~24 hours after being posted to the NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/...
JohnMakin 1 hour ago | parent
mmh0000 1 hour ago | parent
Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.
I think this is a great policy decision by uceprotect.
goldenmember 1 hour ago | parent
ozim 1 hour ago | parent
goldenmember 1 hour ago | parent
ButlerianJihad 1 hour ago | parent
However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.
I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.
rithdmc 1 hour ago | parent
I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.
Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
goldenmember 52 minutes ago | parent
pelagicAustral 1 hour ago | parent
mrmattyboy 55 minutes ago | parent
So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).
So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
garaetjjte 34 minutes ago | parent