Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

31–40 of 361 posts

Re: The Trouble with CloudFlare

#31
post #7

This is a tough situation. I don't know about 94% of TOR traffic being fraudulent but I'm sure it's high. But I'm one of the legit users that gets taken out by blacklisting. I use a VPN service pretty regularly and it makes accessing my Cloudflare account and sites using it incredibly annoying.

I assume the actual claim is that 94% of fraudulent traffic comes via tor. Which is quite a different claim. There's a pretty obvious calculus. If you approach the question as 94% of the fraudulent traffic comes from the x% of total traffic that comes via tor... deciding to block tor exit nodes seems rational (particularly if x% is particularly small... say <1%).

> I assume the actual claim is that 94% of fraudulent traffic comes via tor. Which is quite a different claim.

The claim is thus:

> Based on data across the CloudFlare network, 94% of requests that we see across the Tor network are per se malicious. That doesn’t mean they are visiting controversial content, but instead that they are automated requests designed to harm our customers.

Meaning that for any given request coming from Tor, the odds are heavily in favor of it being malicious.

Re: The Trouble with CloudFlare

#32
post #21

Earlier quoted context omitted.

A huge percentage of illegal transactions may be in cash, but a huge percentage of transactions in cash are not illegal.

Which is why large cash transactions are heavily regulated and reported on. In the US, one cannot just withdraw $10k or a series of smaller transactions that add up to $10k or more without the bank reporting on that to the authorities. That's the balance that law makers decided to strike.

That's an interesting point.

Cloudflare is doing something somewhat similar. If you are deemed "possibly a bad person" then you are asked to solve a captcha. If you want to give up some of your anonymity, you can keep the cookie they give you as a token to "prove" you are a good person.

If you don't want that though, there is nothing cloudflare can do to know you aren't a bad person.

It's much less than "heavy regulation", but i can easily see how it could be both a pain and a security issue for some.

This is a shitty problem for all involved with no good solutions...

Re: The Trouble with CloudFlare

#33
post #6

Earlier quoted context omitted.

> The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying with those in itself gives up a good amount of privacy. Prepaid credit cards are essentially anonymous, as far as I know.

>Prepaid credit cards are essentially anonymous, as far as I know. My understanding is that you can only buy prepaid cards after showing ID in many jurisdictions, and many other places require you to register them with ID in order to use the cards.

I am not aware of any places that ID for purchasing prepaid cards, let alone prepaid burner phones.

One of the way scammers get "cash" is to buy Amex gift cards with stolen credit cards. Then use those Amex gift cards to buy more amex gift cards until they feel confident the trail is murky enough. Or they use a combination of store gift cards to buy Amex/Visa gift cards.

Re: The Trouble with CloudFlare

#34
post #4

Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560

The only correspondence you had with the CloudFlare CEO in that thread was:

> eastdakota: I work for CloudFlare. We don't get anything from Google for using reCAPTCHA.

I think you might have gotten a username confused.

Re: The Trouble with CloudFlare

#35
post #4

Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560

Of course CloudFlare's "view" of the situation is "skewed".

So's the Tor project's.

So's the view of the website operators receiving this traffic.

Cloudflare's post acknowledge the fact that there are at least three major points of view on this problem. The Tor project, by contrast, is increasingly striking me as taking on a petulant tone by refusing to acknowledge that and acting (implicitly if nothing else) as if their view is the only one.

To be honest, the core problem here is not Cloudflare. The core problem is that their customers don't really want Tor traffic. Cloudflare is, to my eye, bending over backwards for Tor compared to what I'd expect from a corporation, however it may feel to Tor. I would suggest the Tor project and its users, however annoyed they may be at their day-to-day experience, are ill-advised to take a petulant tone here, lest Cloudflare indeed give their customers the ability to whitelist and blacklist Tor as a whole... because I completely agree with Cloudflare that effectively nobody is going to whitelist it.

Re: The Trouble with CloudFlare

#36
post #4

Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560

It's Cloudflare, not Cloudflair.

Thanks, fixed the typo!

Re: The Trouble with CloudFlare

#38

I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…

How do you classify traffic as from the Tor network? I am interested in how this is done for a real e-commerce site in production.

Re: The Trouble with CloudFlare

#39
post #10

Earlier quoted context omitted.

Tor can't possibly be the only signal of fraudulent activity though? It may be one that has an easy "solution" however, but one that's easily circumvented (one of the many free VPN services out there).

Signal according to Cloudflare isn't "TOR" but the IP's the are used by TOR exit nodes get banned due to them being shared and abused enough to trigger that IP being tagged as a source of trouble. I personally don't buy this, since I know of IPs they don't block again would get enough abussive traffic to merit the same treatment, but don't get the treatment TOR's IPs get.

Since you think CloudFlare is lying, what do you think the truth is?

Re: The Trouble with CloudFlare

#40
I think Cloudflare's blog post was incredibly nuanced, well thoughtout and (dare I say) pro-Tor. They implemented a way for their users to whitelist Tor traffic (bypassing all Captcha's), without allowing their users to blacklist Tor traffic.

This response seems a bit of a childish knee-jerk reaction from the Tor project, which could've been worded more maturely.

Post reply on HN