Domain to remove
insight.rapid7.com
Current blocklist
tracking
Why is this a false positive?
- At least one domain is present in tracking.txt:
insight.rapid7.com, possibly more *.rapid7.com domains.
- This is not arbitrary privacy invasion of unsuspecting victims, this is a genuine international cybersecurity provider to detect and respond to vulnerabilities and malicious activity on endpoints
- The only way a device has any reason to interact with this domain or any of its subdomains, is if their security tooling is purposely and specifically chosen to be installed on that device.
Official website or documentation
https://www.rapid7.com/
Impact description
Devices with security tooling being blocked by this tracking list cannot receive updated vulnerability definitions and scan information, and likewise where a vulnerability has been detected, there is no way for the device to make itself known for remediation through the cloud reporting mechanisms.
Cybersecurity vendors, including Rapid7 through their huge contributions to OSS projects like Metasploit, champion privacy controls and freedoms for the organizations they protect AND the broader worldwide population.
Situations like these cast projects like PiHole as an example of how poorly implemented OSS can lead to dramatically worse privacy and security outcomes for its users, and demonstrates how easily gamed by malicious interference they can be.
Urgency
Critical - Security or business impact
Verification
Domain to remove
insight.rapid7.com
Current blocklist
tracking
Why is this a false positive?
insight.rapid7.com, possibly more *.rapid7.com domains.Official website or documentation
https://www.rapid7.com/
Impact description
Devices with security tooling being blocked by this tracking list cannot receive updated vulnerability definitions and scan information, and likewise where a vulnerability has been detected, there is no way for the device to make itself known for remediation through the cloud reporting mechanisms.
Cybersecurity vendors, including Rapid7 through their huge contributions to OSS projects like Metasploit, champion privacy controls and freedoms for the organizations they protect AND the broader worldwide population.
Situations like these cast projects like PiHole as an example of how poorly implemented OSS can lead to dramatically worse privacy and security outcomes for its users, and demonstrates how easily gamed by malicious interference they can be.
Urgency
Critical - Security or business impact
Verification