<div dir="ltr"><div>I see a lot of naivety in your messages. Or maybe you don't understand the true nature of the problem. The various checks of the authenticity of the spots (i.e whitelist), cannot be based on the information contained in it (for example the source node, ip address, and so on), because all this information can be forged at will by the attacker.</div><div><br></div><div>We have to go to the source of the issue.</div><div><br></div><div>73s</div><div><br></div><div>Andrea</div><div><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature">--></div></div><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Fri, Mar 7, 2025 at 5:33 PM Tony K1AX via Dxspider-support <<a href="mailto:dxspider-support@tobit.co.uk">dxspider-support@tobit.co.uk</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg-3381599753342716448">
<div dir="ltr">
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Hi Tobias,</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Thank you for sharing your perspective. I understand the concerns of some web cluster operators regarding the impact of $DXProt::sendverify = 2, though my experience has been quite different.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I recently launched my own web cluster, DX Data (<a href="https://dxdata.io" target="_blank">https://dxdata.io</a>), and while I recognize the challenges you’ve outlined, not all web clusters appear to be affected in the same way. My web cluster continues to function as expected, and spots from my users
are still being picked up by DXSpider, CC Cluster, and most web clusters, including yours. I’d be happy to compare notes at some point to better understand why some web clusters are experiencing issues while others, like mine, remain unaffected.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
73,</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Tony K1AX</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<hr style="display:inline-block;width:98%">
<div dir="ltr" id="m_-1513459800710903261divRplyFwdMsg" style="color:inherit"><span style="font-family:Calibri,sans-serif;font-size:11pt;color:rgb(0,0,0)"><b>From:</b> Dxspider-support <<a href="mailto:dxspider-support-bounces@tobit.co.uk" target="_blank">dxspider-support-bounces@tobit.co.uk</a>> on behalf of Tobias Wellnitz via Dxspider-support
<<a href="mailto:dxspider-support@tobit.co.uk" target="_blank">dxspider-support@tobit.co.uk</a>><br>
<b>Sent:</b> Thursday, March 6, 2025 7:21 PM<br>
<b>To:</b> The DXSpider Support list <<a href="mailto:dxspider-support@tobit.co.uk" target="_blank">dxspider-support@tobit.co.uk</a>><br>
<b>Cc:</b> Tobias Wellnitz <<a href="mailto:tobias.wellnitz@gmail.com" target="_blank">tobias.wellnitz@gmail.com</a>><br>
<b>Subject:</b> [Dxspider-support] You are killing all Webclusters!</span>
<div> </div>
</div>
<div style="direction:ltr">Hi all,</div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">my apologies for the slightly provocative email subject, but in the name of all Web Cluster operators I would like to express our strong concerns and disagreement about the recently rolled out "source" verification of DX Spots!
This setting does more harm than good. Literally all spots submitted through web clusters are been dropped since the roleout of $DXProt::sendverify = 2.</div>
<div style="direction:ltr">Why? Because web clusters manage their users and their accounts in the web stack and not in dxspider. </div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">Just to give you an idea about the magnitude: Only my web cluster (<a href="http://dxheat.com" id="m_-1513459800710903261OWA42047361-eaf2-f35d-09be-02f6b19a6b03" target="_blank">dxheat.com</a>) has >30.000 registered users
and has at any time 800 - 1500 connected users. I know that Dxfun and Dxwatch are serving even larger user bases!</div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">Look at Andrea's table of dropped spots within a day:</div>
<div style="direction:ltr"> </div>
<div style="direction:ltr;font-family:monospace">+-------+----------+<br>
| SPOTS | NODE |<br>
+-------+----------+<br>
| 502 | EA4RCH-5 |<br>
| 411 | VE7CC-1 |<br>
| 273 | DH1TW-2 |<br>
| 208 | AE5E |<br>
| 138 | PY1NB-4 |<br>
| 104 | EA6VQ-2 |<br>
| 103 | DO5SSB-2 |</div>
<div style="direction:ltr;font-family:monospace">[...]</div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">Here is the mapping:</div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">EA4RCH-5 -> <a href="http://dxfun.com" id="m_-1513459800710903261OWA1124a304-b88e-3251-6200-a47c2322ed30" target="_blank">
dxfun.com</a></div>
<div style="direction:ltr">DH1TW-2 -> <a href="http://dxheat.com" id="m_-1513459800710903261OWAa60df4a0-808a-0709-f20a-353ca6efe0ec" target="_blank">
dxheat.com</a></div>
<div style="direction:ltr">PY1NB-4 -> <a href="http://dxwatch.com" id="m_-1513459800710903261OWAee4f13d4-db6b-ac14-89e1-5d4bd893343f" target="_blank">
dxwatch.com</a></div>
<div style="direction:ltr">EA6VQ-2 -> <a href="http://dxmaps.com" id="m_-1513459800710903261OWA7b2ddd9d-bea2-81e2-9cc1-fcf845c8b075" target="_blank">
dxmaps.com</a></div>
<div style="direction:ltr">DO5SSB-2 -> <a href="http://qrzcq.com/dxtron" id="m_-1513459800710903261OWAc5144fff-3a8b-3dc3-8b3d-b92565417752" target="_blank">
qrzcq.com/dxtron</a></div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">As you can imagine, we have put a lot of effort into building and operating these web clusters. The total number of affected users, which participate in the dx cluster network through our web services is larger than the overall
users connected via telnet!</div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">We therefore kindly ask you to reconsider and undo the recent changes! </div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">Let jointly keep on discussing other possibilities on how to further harden together our DX Cluster network!</div>
<div style="direction:ltr"><br>
</div>
<div style="direction:ltr">Thanks & 73,</div>
<div style="direction:ltr">Tobias, DH1TW</div>
</div>
_______________________________________________<br>
Dxspider-support mailing list<br>
<a href="mailto:Dxspider-support@tobit.co.uk" target="_blank">Dxspider-support@tobit.co.uk</a><br>
<a href="https://mailman.tobit.co.uk/mailman/listinfo/dxspider-support" rel="noreferrer" target="_blank">https://mailman.tobit.co.uk/mailman/listinfo/dxspider-support</a><br>
</div></blockquote></div>