[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Snapshot behind Fastly; roles and responsibilities



Hi,

On 11/18/24 5:25 PM, Linus Nordberg wrote:
> I think that users connecting to https://snapshot.debian.org/ should
> expect the information about what packages they are interested in to
> stay between them and Debian.

Do they? We are serving deb.debian.org, planet.debian.org,
archive.debian.org, metadata.ftp-master.debian.org,
security-tracker.debian.org, and security.debian.org(!) behind Fastly
already. We are also only collecting at most sampled logs from these
services[1].

I am as sad that it becomes harder and harder to serve things on the
internet without a CDN, given that people no longer obey The Rules. [2]
for another example where some company just put a random host into a
connectivity check.

Kind regards
Philipp Kern

[1] I'd kind of expect Fastly to discard logs otherwise - for compliance
reasons, but I don't actually know if this is true.
[2] https://social.kernel.org/notice/AnylVGygEAY06TT9qS


Reply to: