this post was submitted on 16 Mar 2025
67 points (97.2% liked)

Buy European

3756 readers
2169 users here now

Overview:

The community to discuss buying European goods and services.


Matrix Chat


Rules:

  • Be kind to each other, and argue in good faith. No direct insults nor disrespectful and condescending comments.

  • Do not use this community to promote Nationalism/Euronationalism. This community is for discussing European products/services and news related to that. For other topics the following might be of interest:

  • Include a disclaimer at the bottom of the post if you're affiliated with the recommendation.

Feddit.uk's instance rules apply:

  • No racism, sexism, homophobia, transphobia or xenophobia
  • No incitement of violence or promotion of violent ideologies
  • No harassment, dogpiling or doxxing of other users
  • Do not share intentionally false or misleading information
  • Do not spam or abuse network features.
  • Alt accounts are permitted, but all accounts must list each other in their bios.

Benefits of Buying Local:

local investment, job creation, innovation, increased competition, more redundancy.


Related Communities:

Buy Local:

!buycanadian@lemmy.ca

!buyafrican@baraza.africa

!buyFromEU@lemm.ee

!buyfromeu@feddit.org

Buying and Selling:!flohmarkt@lemmy.ca

Boycott:!boycottus@lemmy.ca

Stop Publisher Kill Switch in Games Practice:!stopkillinggames@lemm.ee


Banner credits: BYTEAlliance


founded 1 month ago
MODERATORS
 

I know lemm.ee is hosted in the EU, but I can't find that information for lemmy.world.

you are viewing a single comment's thread
view the rest of the comments
[–] notabot@lemm.ee 11 points 1 day ago (1 children)

The US IP address is for Cloudflare, who are acting as a front end for things like DDoS protection. A lot of lemmy servers use them, which is unfortunate, but there don't seem to be any viable European alternatives.

You can check the details with the whois command. The relevant bit when querying for one of their addresses is:

NetRange:       104.16.0.0 - 104.31.255.255
CIDR:           104.16.0.0/12                         
NetName:        CLOUDFLARENET                         
NetHandle:      NET-104-16-0-0-1                      
Parent:         NET104 (NET-104-0-0-0-0)              
NetType:        Direct Allocation                     
OriginAS:       AS13335                               
Organization:   Cloudflare, Inc. (CLOUD14)            
RegDate:        2014-03-28                            
Updated:        2024-09-04                            
Comment:        All Cloudflare abuse reporting can be
done via https://www.cloudflare.com/abuse             
Comment:        Geofeed: https://api.cloudflare.com/local-ip-ranges.csv                                     
Ref:            https://rdap.arin.net/registry/ip/104.16.0.0
[–] Successful_Try543@feddit.org 1 points 1 day ago* (last edited 1 day ago) (1 children)

Thank you. So that's why you 'see' an US IP address while the physical server may be located anywhere, e.g. in Germany.

By looking at their Wikipedia, I've already found out that Cloudflare doesn't do hosting.

[–] notabot@lemm.ee 3 points 1 day ago (2 children)

Cloudflare don't hoat sites, but they do end up being a 'man in the middle' attack on any site they proxy for, regardless of where that site is nominally hosted. That ends up exposing all traffic on those sites to a US corporation, and ultimately the US government. Considering that Cloudflare proxy somewhere between 19% and 40% of all websites, I think that's pretty alarming.

[–] Evotech@lemmy.world 1 points 22 hours ago (1 children)

It's not an attack of you pay for it

[–] notabot@lemm.ee 2 points 20 hours ago

You'll be attacked and pay for the priviledge! I suppose what you're really paying for is knowing who's attacking you. Mind you, I think it's free for small sites, which is probably quite an attractive trade-off for many.

[–] Successful_Try543@feddit.org 1 points 22 hours ago* (last edited 22 hours ago) (1 children)

I don't get the 'man in the middle' part. Is the ssl key for the encrypted https connection not from LW, but from cloudflare?
It's still problematic that they have metadata of the connections.

[–] Evotech@lemmy.world 2 points 22 hours ago (1 children)

For cloudflare to encrypt the traffic they need the key.

[–] Successful_Try543@feddit.org 2 points 21 hours ago* (last edited 21 hours ago) (2 children)

But isn't for https the traffic supposed to be e2e encrypted between the client web browser and the server hosting the web page with the same cert? Does cloudflare decrypt and then re-encrypt the traffic data?

[–] Evotech@lemmy.world 2 points 13 hours ago* (last edited 13 hours ago)

Supposed and supposed... It's easier to manage encryption and certificates on a layer above, you can reencrypt backwards with some whatever cert

You can of course not use cloudflares infra for this but then you lost a lot of insight and features

[–] notabot@lemm.ee 3 points 20 hours ago (1 children)

You see the problem. Yes, cloudflare decrypt the request from the browser, inspect it, then reencrypt it and send it to the host server. Then they take the response, decrypt that, inspect it, reencrypt it and send it to the browser.

Basically there are two TLS flows, one from the browser to cloudflare, and one from clourflare to the host server. Between those, on the cloudflare system, both the traffic and response are in plain text. That includes usernames, passwords (for HTTP basic auth anyway) and any sensitive data you send or receive.

Given that they front sonewhere between 19 and 40% of all websites, d£pending on whose stats you trust, that should be pretty alarming.

[–] Successful_Try543@feddit.org 1 points 18 hours ago

Thank you. I didn't know that.