From: Michael Tremer <michael.tremer@ipfire.org>
To: Tim Zakharov <tzakharov@protonmail.com>
Cc: Adam G <ag@ipfire.org>, dbl@lists.ipfire.org
Subject: Re: To block `jumpcloud.com` or not.
Date: Tue, 10 Mar 2026 14:37:26 +0000 [thread overview]
Message-ID: <BEEDF357-B2BE-49D5-91B9-6D6164E286D3@ipfire.org> (raw)
In-Reply-To: <U5FpCGE1_BTrgsRum4WzXT0-L-iQS4et4GnMJK27EteiInR6TOlH03sknQz94YsGfHwAVgUyB6JmIY6ep6-0qut1C1ZW7YuXDQrLK_H6GaM=@protonmail.com>
Hello,
None of this is malware. The upstream list is garbage for our use-case and I have removed it.
-Michael
> On 10 Mar 2026, at 12:15, Tim Zakharov <tzakharov@protonmail.com> wrote:
>
> I just noticed that secure.logmein.com is also categorized as malware. Do we know what others may be on this list? TeamViewer? RustDesk?
>
> On Tuesday, March 10th, 2026 at 7:07 AM, Tim Zakharov <tzakharov@protonmail.com> wrote:
>> Here is my dilemma. First, there is no way to whitelist this specific rule as it is currently set up in IPfire DBL IPS ruleset. Second, the software itself is not coded with malicious intent. It is legitimate commercial software. One could potentially find ways of maliciously using many other legit software packages. Would we then have to categorize each of them as malware? There is a difference between malware and malicious actors that needs to be part of this conversation.
>>
>> On Tuesday, March 10th, 2026 at 6:38 AM, Adam G <ag@ipfire.org> wrote:
>>> Hi all,
>>>
>>> I've moved this discussion about jumpcloud.com from the forum to the correct place.
>>>
>>> This domain was specifically added to the upstream list “mtxadmin - Malware Remote”, which covers remote administration tools. These can potentially be used as Command & Control (C&C) domains by malware and people with bad intentions.
>>>
>>> In Tim’s case it’s blocking devices on his guest network. Most people will never need this domain, so I think it should stay blocked by default and be added to personal whitelists where required.
>>>
>>> If we remove this one, we should remove the entire upstream list too for consistency.
>>>
>>> Thanks,
>>> Adam
>>
>
prev parent reply other threads:[~2026-03-10 14:37 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-10 11:38 Adam G
2026-03-10 12:07 ` Tim Zakharov
2026-03-10 12:15 ` Tim Zakharov
2026-03-10 14:37 ` Michael Tremer [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=BEEDF357-B2BE-49D5-91B9-6D6164E286D3@ipfire.org \
--to=michael.tremer@ipfire.org \
--cc=ag@ipfire.org \
--cc=dbl@lists.ipfire.org \
--cc=tzakharov@protonmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox