Tunnel Consent page now requires a password

Author: TheBoroerCreated May 15, 2023Updated Aug 19, 2026
Labelsannouncement

TLDR: a tunnel's password = the tunnel creator's public IP

Hey everyone, It saddens me to be forced to add yet another annoying thing to the public localtunnel server but...

As of 2 minutes ago, all tunnels now require a real user to enter the endpoint IP address (which acts like your tunnel link's password) on the consent page.

Showing and having the users click a continue button in order to access the tunnel content didn't really do too much to fight of people hosting phishing portals via localtunnel. I've also been getting an enormous amount of phishing/abuse notices from various organizations worldwide, forwarded notices from my hosting provider, and even have been put on notice that I will be responsible for costs related to removing IPs from various IP blacklists...

I'm currently building an abuse reporting tool for these orgs to use that'll automate banning users hosting phishing portals but until that's built & tested this new password-protection way of abuse fighting will have to do.

Sorry for any inconvenience...

PS. If localtunnel doesn't work for your use case for whatever reason, feel free to checkout other alternatives like https://ngrok.io


If anyone has any other suggestions on easy ways to fight phishing/malware portals from using this service, i'm all ears!