Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

61–70 of 361 posts

Re: The Trouble with CloudFlare

#61

That's just flawed reasoning all around. I can't even find any e-commerce-specific data in their sources. > A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing comm…

[IP addresses of] Tor exit nodes were far more likely to contain malicious requests

However, traffic from Tor exit nodes yielded a conversion rate virtually equal to non-Tor IPs

You just described every busy IP address: if you handle more requests, you are more likely to handle a malicious one. This is the problem with IP based reputation.

Re: The Trouble with CloudFlare

#62
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

The main point I took away from the article, that from one exit node many users originate. Some users are spammer. They contaminate the exit node IP. CF blocks an IP for spam, but does not remove the block after some time (when the spammer moved on).

Re: The Trouble with CloudFlare

#63
post #6

Earlier quoted context omitted.

> The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying with those in itself gives up a good amount of privacy. Prepaid credit cards are essentially anonymous, as far as I know.

>Prepaid credit cards are essentially anonymous, as far as I know. My understanding is that you can only buy prepaid cards after showing ID in many jurisdictions, and many other places require you to register them with ID in order to use the cards.

Bitcoin thieves and malware scammers buy gift cards and prepaid cards on Rakuten with bitcoin to convert their gains to non-Internet-funny-money. Ship to the foreclosed house at the end of block. Done without anyone being the wiser.

Re: The Trouble with CloudFlare

#64

That's just flawed reasoning all around. I can't even find any e-commerce-specific data in their sources. > A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing comm…

> Tor exit nodes were far more likely to contain malicious requests

That's comparing apples to oranges though. A lot of different people send requests from tor exit nodes. That might be comparable to some corporate networks, but many IP addresses are used by only one person (or a family).

Intuition would suggest that tor traffic is more likely to be malicious than average traffic, but suppose there are 500 tor exit nodes in the world, and 1 malicious tor user: then 1 in 500 tor-exit node IPs would have sent a malicious request!

Re: The Trouble with CloudFlare

#65
post #54
post #53

Earlier quoted context omitted.

Not sure, though given enough dialog on the topic, I believe that a better solution will be found or it'll become clear that Cloudflare is not responding to the issue. Simple answer would be that the original analysis is flawed, they've forgotten that the wrote a script to block TOR exit IPs; TOR intentionally provides a list of these IPs to the public. Might be worth noting that TOR users are often the target of Nat…

What kind of "better solution" do you envision? Right now you seem to be insisting that there must be one, which I must say does not make a very compelling case that one actually exists or is possible.

Given Cloudflare appears to have received National Security Letters, it's possible their is no answers.

That said, based on what I know, the answer is to whitelist the TOR IPs, give TOR users a global session that the user has the option to opt into (likely make sense for TOR publish what the impact of this is and Cloudflare to link to it in from that page) and always let users know a global session is set in case the user believe that using TOR they reset the session; resetting it via Cloudflare would be meaningless. General gist though is humans are not bots, don't behave as bots, and Cloudflare treats ever request as the same from an IP, which is a poor way to block bots.

Re: The Trouble with CloudFlare

#66
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

The main point I took away from the article, that from one exit node many users originate. Some users are spammer. They contaminate the exit node IP. CF blocks an IP for spam, but does not remove the block after some time (when the spammer moved on).

That's definitely a legitimate point, but not the main point IMHO. The main point is that Tor makes zero effort to clean up the problem and uses the legitimate Tor users as helpless, scapegoated victims and a bullying tactic. "But think of the oppressed users!" Sorry, not buying it.

The blacklisted IP lifetime problem is real though. It's a problem I've had to raise several times with our product and network teams. People would see an abusive IP and just ban it...without a TTL or lifetime. This really upset me as they seemed to think that was OK not just for the time being, but that it was good enough. When I describe IPv6 to them, their faces just melt as it sinks in that they can't just keep banning IP's and must do something higher up the stack to detect and block fraud.

Re: The Trouble with CloudFlare

#67
post #61

That's just flawed reasoning all around. I can't even find any e-commerce-specific data in their sources. > A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing comm…

[IP addresses of] Tor exit nodes were far more likely to contain malicious requests However, traffic from Tor exit nodes yielded a conversion rate virtually equal to non-Tor IPs You just described every busy IP address: if you handle more requests, you are more likely to handle a malicious one. This is the problem with IP based reputation.

Yes, I think that the more revealing ratio would have been total malicious requests to all requests for each class of IP. If each Tor exit node is sending out 30x as much traffic, with an average of 30 unique users per IP, then the cited ratios are meaningless.

The only thing that can be drawn from that data is that Tor makes IP-based reputation tools ineffective. The thing is, for many people that may be enough to justify what Cloudflare is doing.

Re: The Trouble with CloudFlare

#68
post #55
post #51

Earlier quoted context omitted.

Wrong, Google is Cloudflare partner, so it is the opposite, at the very least, one company (Google) loves the fact Cloudflare is doing what they're doing; my estimates peg the value of the data in the hundreds of millions based on what Google already pays to get the same type of data from users. Second, volume counts do not equal session counts and I find it very hard to believe that a human non-abussive human sessio…

Did you intend this as a reply to something else? I can't even connect your comment to what I said. It starts with "wrong" but doesn't seem to address anything I said.

Please bullet/number your concerns as self-contained statements and I'll explicitly reference them. And yes, my response is to your comment, though do see how it's possible it's ambiguous to how I'm addressing your concerns. Thanks for the comment.

Re: The Trouble with CloudFlare

#69
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

> I know Tor doesn't want to be in the network regulation business, but ....

That is exactly why there is a Tor. Tor is for enabling anonymous communication. Now deciding who can do what or why would limit use and that would limit its ability to anonymous communication.

Re: The Trouble with CloudFlare

#70
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

>they need to be if they want their product to thrive. Otherwise, good bye Tor.

The ironic thing is actually that by applying any kind of "network regulation" the Tor project would abandon its own primary purpose. The only way it can continue to exist is actually if it doesn't practice any kind of censorship of its users.

Post reply on HN