The real issue with CF for me isn't the hassle with captchas, but the fact that CloudFlare can track users across all its sites, generate profiles and even read unencrypted traffic. It's a privacy hazard by design that makes Tor particularly attractive. But as long as Tor is used only by a small minority, it will be treated this way.
The Trouble with CloudFlare
41–50 of 361 posts
Re: The Trouble with CloudFlare
#42That's just flawed reasoning all around. I can't even find any e-commerce-specific data in their sources. > A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing comm…
Starting with a blanket blaming statement isn't that great either. Conversion rates and e-commerce sorta go together, so I would say it's fine to entangle them logically. Tor exit nodes entangle users with each other through an IP. If someone's lens is limited, they'll run the risk of blanket blaming the legitimate traffic as well.
Re: The Trouble with CloudFlare
#43Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560
It's Cloudflare, not Cloudflair.
Re: The Trouble with CloudFlare
#44Re: The Trouble with CloudFlare
#45This point seems rather odd. I'm not following the connection between a large percentage of Tor requests being malicious and the fact that Tor users have almost the same conversion rate. Malicious requests are coming from botnets and/or fraudsters. They're, for the most part, not in the subset of Tor users which click ads or do anything else that would be tracked as part of a site's conversion rate. What's funny about this is that the linked report even confirms that requests from exit nodes are far more likely to be malicious:
Tor exit nodes were far more likely to contain malicious requests:
• 1:11,500 non-Tor IPs contained malicious requests
• 1:380 Tor exit nodes contained malicious requests
I'm a huge supporter of Tor and have been running a relay node for years, but it seems their stance on this topic is quite fundamentalist and they chose to ignore any arguments or facts that they don't like while basically grasping at straws in their counterarguments.It's okay to be concerned about CloudFlare having such a huge market share. They're a huge target for nation states and others alike. Global passive¹ adversaries are a problem for things like Tor, and they might very well be forced to become one at some point. It's essential to have more competition in this area, and that's a fair argument to make. However, with regards to how they're handling Tor, I don't think there's anything wrong with what they're doing, and the explanations presented in their blog post seemed sound to me.
¹ Or, rather, possibly an active adversary too?
Re: The Trouble with CloudFlare
#46Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560
Cloudflare does not make the world better for everyone, but it does a great job of making the world better for those who have access to resources, such as dedicated IPs and venture capitalists.
Capitalism has failed, and it's starting to force that fail onto the Internet in a big way. We need to be smarter about how we approach building trusted infrastructure. All that starts with how we approach building infrastructure companies.
If it's an infrastructure service model and it ain't bootstrapped and sustainable, don't use it.
Re: The Trouble with CloudFlare
#47Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560
It's Cloudflare, not Cloudflair.
Re: The Trouble with CloudFlare
#48I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…
How do you classify traffic as from the Tor network? I am interested in how this is done for a real e-commerce site in production.
Re: The Trouble with CloudFlare
#49I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…
How do you classify traffic as from the Tor network? I am interested in how this is done for a real e-commerce site in production.
Re: The Trouble with CloudFlare
#50I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…
> I don't know what the solution is here. Should the ToR network be doing some amount of self policing? (Can it?) I know this might be against some of its principles, but it seems that ToR is there to create privacy, not to be used for criminal activity. And yes, criminal activity differs based on jurisdiction, but I think fraud is generally something everyone agrees should not be allowed.