Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

51–60 of 361 posts

Re: The Trouble with CloudFlare

#51
post #35
post #4

Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560

Of course CloudFlare's "view" of the situation is "skewed". So's the Tor project's. So's the view of the website operators receiving this traffic. Cloudflare's post acknowledge the fact that there are at least three major points of view on this problem. The Tor project, by contrast, is increasingly striking me as taking on a petulant tone by refusing to acknowledge that and acting (implicitly if nothing else) as if t…

Wrong, Google is Cloudflare partner, so it is the opposite, at the very least, one company (Google) loves the fact Cloudflare is doing what they're doing; my estimates peg the value of the data in the hundreds of millions based on what Google already pays to get the same type of data from users.

Second, volume counts do not equal session counts and I find it very hard to believe that a human non-abussive human session looks the same as an abussive session. If true, then it's Cloudflare that's abusing users and exploiting the situation, not TOR.

Also, TOR users are not blocked, but flagged to provided data to Google. Also, Cloudflare's clients like don't even know about the issue since according to Cloudflare they're flagging IPs, not TOR.

Re: The Trouble with CloudFlare

#52
post #7

This is a tough situation. I don't know about 94% of TOR traffic being fraudulent but I'm sure it's high. But I'm one of the legit users that gets taken out by blacklisting. I use a VPN service pretty regularly and it makes accessing my Cloudflare account and sites using it incredibly annoying.

Yeah, 94% seems very high, and although I guess it could be possible, I can't imagine it is quite that high. Cloudflare is zeroed-in on Tor users, but am I crazy for thinking that there are several other ways bad actors could create issues not using Tor? It seems like they are trying to come up with an amicable solution, but for the moment, legitimate Tor and VPN service users suffer. If Cloudflare really refuses to…

A large percentage of malicious traffic is most likely generated by bots, which are quite naturally better at creating a lot of requests.

Re: The Trouble with CloudFlare

#53
post #39
post #10

Earlier quoted context omitted.

Signal according to Cloudflare isn't "TOR" but the IP's the are used by TOR exit nodes get banned due to them being shared and abused enough to trigger that IP being tagged as a source of trouble. I personally don't buy this, since I know of IPs they don't block again would get enough abussive traffic to merit the same treatment, but don't get the treatment TOR's IPs get.

Since you think CloudFlare is lying, what do you think the truth is?

Not sure, though given enough dialog on the topic, I believe that a better solution will be found or it'll become clear that Cloudflare is not responding to the issue.

Simple answer would be that the original analysis is flawed, they've forgotten that the wrote a script to block TOR exit IPs; TOR intentionally provides a list of these IPs to the public.

Might be worth noting that TOR users are often the target of National Security Letters, that Cloudflare based on their own report received National Security Letters, and as such, would be unable to say if those letters impacted code on the topic.

Re: The Trouble with CloudFlare

#54
post #53
post #39

Earlier quoted context omitted.

Since you think CloudFlare is lying, what do you think the truth is?

Not sure, though given enough dialog on the topic, I believe that a better solution will be found or it'll become clear that Cloudflare is not responding to the issue. Simple answer would be that the original analysis is flawed, they've forgotten that the wrote a script to block TOR exit IPs; TOR intentionally provides a list of these IPs to the public. Might be worth noting that TOR users are often the target of Nat…

What kind of "better solution" do you envision? Right now you seem to be insisting that there must be one, which I must say does not make a very compelling case that one actually exists or is possible.

Re: The Trouble with CloudFlare

#55
post #51
post #35

Earlier quoted context omitted.

Of course CloudFlare's "view" of the situation is "skewed". So's the Tor project's. So's the view of the website operators receiving this traffic. Cloudflare's post acknowledge the fact that there are at least three major points of view on this problem. The Tor project, by contrast, is increasingly striking me as taking on a petulant tone by refusing to acknowledge that and acting (implicitly if nothing else) as if t…

Wrong, Google is Cloudflare partner, so it is the opposite, at the very least, one company (Google) loves the fact Cloudflare is doing what they're doing; my estimates peg the value of the data in the hundreds of millions based on what Google already pays to get the same type of data from users. Second, volume counts do not equal session counts and I find it very hard to believe that a human non-abussive human sessio…

Did you intend this as a reply to something else? I can't even connect your comment to what I said. It starts with "wrong" but doesn't seem to address anything I said.

Re: The Trouble with CloudFlare

#56

I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…

You could offer Tor users only the option to pay with Bitcoin. No chargebacks and less loss of privacy.

Re: The Trouble with CloudFlare

#57

I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…

This is where 3D Secure truly shines; instead of completely refusing a transaction, you can request the issuing bank (= bank of the card used to pay with) to accept the liability in case of fraud (normally, it's the merchant who has to give the money back). Usually the issuing bank will then request the customer for additional challenge, e.g. a 2FA token, a code in SMS, or just their birthday. Some don't even require…

Why is the choice of using 3DSecure up to the merchant? If 3Dsecure is enabled it shouldn't be possible to make an online purchase without going through 3D secure. Or is this just for cards that don't have 3D secure enabled yet?

For example I have 3D secure enabled, and all my online purchases (in my own country) always require to type in the password on the bank's gateway site. If I see a site that allows me to make a purchase without going through 3Dsecure I'd be worried and probably call my bank.

Re: The Trouble with CloudFlare

#58

I don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying wit…

This is where 3D Secure truly shines; instead of completely refusing a transaction, you can request the issuing bank (= bank of the card used to pay with) to accept the liability in case of fraud (normally, it's the merchant who has to give the money back). Usually the issuing bank will then request the customer for additional challenge, e.g. a 2FA token, a code in SMS, or just their birthday. Some don't even require…

3D Secure is a complete disaster. It encourages users to put ridiculously sensitive information like social security numbers and bank credentials into an iframe in the merchant site. This trains users to be phished.

Re: The Trouble with CloudFlare

#59
post #4

Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560

Cloudflare's purpose is to make money. If anyone thinks they are here to help make the world better, that's a naive view. Tor's purpose is to help people access data that may be inaccessible to them without it and to help guard against invasion of privacy. While those things can be used for illicit purposes (as shown by the amount of rouge traffic on Tor exit nodes) the return on quality of life for the whole is grea…

That's a sad statement. Cloudflare is one of my role model for publicity and profit tactics. Everyone can use Cloudflare for free. Companies are their only customers.

Re: The Trouble with CloudFlare

#60
Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it.

This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those networks eventually end up on blacklists or Spamhaus lists and their efficacy goes down. Eventually, the network dies out and the criminals move somewhere else. Yes, it's a game of whack-a-mole, but it's proven to work well.

I know Tor doesn't want to be in the network regulation business, but they need to be if they want their product to thrive. Otherwise, good bye Tor.

Post reply on HN