Hacker News new | past | comments | ask | show | jobs | submit login

But what about GP's point regarding mirrors? Your IP will be transmitted to potentially a wide range of effectively 3rd party hosts. Looking at my /var/log/dnf.librepo.log I can see requests from a number of hosts, including:

  http://fedora.mirror.constant.com
  http://mirror.arizona.edu
  http://mirror.atl.genesisadaptive.com
  http://mirror.genesisadaptive.com
  http://mirror.lax.genesisadaptive.com
  http://mirror.math.princeton.edu
  http://mirror.siena.edu
  http://mirrors.syringanetworks.net
  http://mirror.us.leaseweb.net
  http://mirror.web-ster.com
  http://repo.radeon.com
  https://codecs.fedoraproject.org
  https://d2lzkl7pfhq30w.cloudfront.net
  https://download.docker.com
  https://ewr.edge.kernel.org
I never explicitly agreed to connect to all of these hosts (some are from repos I did manually enable), and it wasn't made abundantly clear to me during install they would be used. As far as trying to keep GDPR hygiene up, I don't see why this is better than configuring a default DNS server if you're worried about IP address transmission.



There's a huge difference between disclosing your IP and disclosing all the various websites you visit. Moreover, those websites are being disclosed to entities whose commercial business is to track you--for marketing, for performance, w'ever.

Relatedly, your IP is also disclosed via NTP. NTP hosts can be advertised over DHCP, similar to DNS resolvers. And systemd also has built-in fallbacks for NTP, which has actually caused major headaches working on security compliance for U.S. government services because the instances should never use any NTP server other than time.nist.gov. But if time.nist.gov is unavailable for w'ever reason, systemd by default falls back to non-compliant NTP hosts. Disabling this is tricky if you rely on DHCP-advertised NTP servers (which is preferable to minimize the diff between govcloud and non-govcloud deployment images).




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: