Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

71–80 of 361 posts

Re: The Trouble with CloudFlare

#71

Original Cloudflare blog post that this is a response to: https://blog.cloudflare.com/the-trouble-with-tor/

That post also suggests two things that Tor could do to improve the situation for their users:

* Support a stronger hashing algorithm to make it possible for CloudFlare to make .onion versions of all of their customers' sites. * Implement "client-side" CAPTCHAs.

I don't how feasible either of these are, but it seems strange (evasive?) that Tor Project's blog post does not discuss either.

Re: The Trouble with CloudFlare

#72
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

The main point I took away from the article, that from one exit node many users originate. Some users are spammer. They contaminate the exit node IP. CF blocks an IP for spam, but does not remove the block after some time (when the spammer moved on).

What will happen when IPv6 takes off and anyone can just go get a unique, random, throwaway IP address each day? Do "IP reputation" systems work in such a world?

Re: The Trouble with CloudFlare

#73

I think Cloudflare's blog post was incredibly nuanced, well thoughtout and (dare I say) pro-Tor. They implemented a way for their users to whitelist Tor traffic (bypassing all Captcha's), without allowing their users to blacklist Tor traffic. This response seems a bit of a childish knee-jerk reaction from the Tor project, which could've been worded more maturely.

I didn't spot anything worded immaturely. What specifically do you think could be more maturely worded?

Re: The Trouble with CloudFlare

#74
post #69
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

> I know Tor doesn't want to be in the network regulation business, but .... That is exactly why there is a Tor. Tor is for enabling anonymous communication. Now deciding who can do what or why would limit use and that would limit its ability to anonymous communication.

It's not a binary thing. You can regulate out fraud, abuse, and DDoS attacks without harming the legitimate use cases.

It's like selling alcohol (cigarettes, porn, gambling), but not to minors.

You can say "it's OK for this crowd not OK for this crowd". Otherwise you'd probably claim that said regulation would go against the very thing that the merchant is trying to do: make as much money as possible.

Re: The Trouble with CloudFlare

#75
Tor has acknowledged their "botnet problem" since at least 2013:

https://research.torproject.org/techreports/botnet-tr-2013-1...

That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions.

As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of anonymously accessing the Internet. Unfortunately, that means we have to sacrifice some convenience. If you haven't read it, I encourage you to see the post I wrote on the topic:

https://blog.cloudflare.com/the-trouble-with-tor/

The two long-term solutions we proposed — blinded tokens or CloudFlare supporting .onion addresses — we believe could reduce the inconvenience, but they'll require help from the Tor developers. While public posts like this are discouraging in terms of coming up with a better solution, I'm encouraged by private conversations we've had with Tor developers who acknowledge this is a hard problem and want to find solutions.

Re: The Trouble with CloudFlare

#76
post #34
post #4

Exchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560

The only correspondence you had with the CloudFlare CEO in that thread was: > eastdakota: I work for CloudFlare. We don't get anything from Google for using reCAPTCHA. I think you might have gotten a username confused.

Why do you believe I'm mistaken? eastdakota, is the Cloudflare CEO's account.

Re: The Trouble with CloudFlare

#77
post #69
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

> I know Tor doesn't want to be in the network regulation business, but .... That is exactly why there is a Tor. Tor is for enabling anonymous communication. Now deciding who can do what or why would limit use and that would limit its ability to anonymous communication.

Definitely, but they shouldn't complain when the public Internet (Cloudflare) blocks them or views their traffic differently. Anonymity comes at a price, and this is one of them. I think TOR is an important project, but this blog post by them is completely ridiculous and ignores reality.

Why should TOR get a pass on this when network operators need to protect their network from abuse? The choices are either 1) let the abuse continue or 2) try to block the specific attack traffic in question by heuristics which is often difficult or impossible or 3) block abusive IP addresses.

Re: The Trouble with CloudFlare

#78

Earlier quoted context omitted.

This is where 3D Secure truly shines; instead of completely refusing a transaction, you can request the issuing bank (= bank of the card used to pay with) to accept the liability in case of fraud (normally, it's the merchant who has to give the money back). Usually the issuing bank will then request the customer for additional challenge, e.g. a 2FA token, a code in SMS, or just their birthday. Some don't even require…

Why is the choice of using 3DSecure up to the merchant? If 3Dsecure is enabled it shouldn't be possible to make an online purchase without going through 3D secure. Or is this just for cards that don't have 3D secure enabled yet? For example I have 3D secure enabled, and all my online purchases (in my own country) always require to type in the password on the bank's gateway site. If I see a site that allows me to make…

Because the liability is never with the customer in the first place. It's fine that you're worried, but, in reality, you don't really have to be; card gets stolen? See a charge you don't recognize? Not your problem! Call your bank, get your money back.

The one who has to fear fraudsters is not the card owner; it's the merchant! Without 3D Secure, they have to pay the money back! + an extra fine, for good measure. And, of course, the product / service is already gone.

Re: The Trouble with CloudFlare

#79
post #74
post #69

Earlier quoted context omitted.

> I know Tor doesn't want to be in the network regulation business, but .... That is exactly why there is a Tor. Tor is for enabling anonymous communication. Now deciding who can do what or why would limit use and that would limit its ability to anonymous communication.

It's not a binary thing. You can regulate out fraud, abuse, and DDoS attacks without harming the legitimate use cases. It's like selling alcohol (cigarettes, porn, gambling), but not to minors. You can say "it's OK for this crowd not OK for this crowd". Otherwise you'd probably claim that said regulation would go against the very thing that the merchant is trying to do: make as much money as possible.

>You can regulate out fraud, abuse, and DDoS attacks without harming the legitimate use cases.

How? If you think this was possible without completely compromising the Tor protocol, don't you think it would have been done already?

Re: The Trouble with CloudFlare

#80
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

>they need to be if they want their product to thrive. Otherwise, good bye Tor. The ironic thing is actually that by applying any kind of "network regulation" the Tor project would abandon its own primary purpose. The only way it can continue to exist is actually if it doesn't practice any kind of censorship of its users.

This is a very simplistic, binary view of the world. Just because the Internet's view of a product differs from the author's, it doesn't make the Internet wrong. It means the author probably needs to step back and re-evaluate things.

By your logic, gun owners would be able to shoot whatever they want. The primary purpose of a gun is to shoot things. To paraphrase: "To regulate what you can and can't shoot would go against the primary purpose of a gun and the gun manufacturers can't exist that way."

Post reply on HN