Hi, I recently encountered this issue when trying to access the instance (both in the browser and Jerboa) while using a VPN. I don’t know if this is just an issue with the one I’m using (Surfshark) but I didn’t have this issue before.
I imagine this security layer was implemented recently, and that’s why it didn’t happen before.
Is this intended, or is it just the filter wrongly taking the VPNs IP as a malicious one?

  • Hey thanks for bringing this to our attention. We’re using CrowdSec as a defense against malicious actors. (Think spammers, password guessing, attempts to access secure configs, software exploit attempts, etc). This should not be affecting regular normal users, but I can see how this would block VPN ips. Could be another user on the shared IP was recently seen trying to run exploits somewhere else, and this their IP was put on the ban list. This then shows up on our ban list. That’s the ‘crowd’ part of CrowdSec.

    Our ban duration is pretty low for an IP, so within an hour our two it should be able to access Beehaw again without issues. Until that IP is detected doing ‘something’ bad again. That is, Crowdsec doesn’t just block a range of IPs. It blocks IPs based on activity of that IP.

    I will need to look into ways to mitigate the affects it’s having on your normal usage. It would help to have the source IPs you’re coming from and I can check the CrowdSec logs to find out specifically why. To anyone else having this issue here, if you feel comfortable doing so, please send me a DM with when you saw this message and from which VPN IP, and I will get you unblocked.