Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

81–90 of 361 posts

Re: The Trouble with CloudFlare

#81
The trouble with Clouflare is that they receive disproportionate amount of attention on Hackernews. Sometimes HN feels like an extension of their marketing machine. I'm not so sure they every single blog post of their needs to be an item on HN. Anyway that's my .02 cents.

Re: The Trouble with CloudFlare

#82
post #74
post #69

Earlier quoted context omitted.

> I know Tor doesn't want to be in the network regulation business, but .... That is exactly why there is a Tor. Tor is for enabling anonymous communication. Now deciding who can do what or why would limit use and that would limit its ability to anonymous communication.

It's not a binary thing. You can regulate out fraud, abuse, and DDoS attacks without harming the legitimate use cases. It's like selling alcohol (cigarettes, porn, gambling), but not to minors. You can say "it's OK for this crowd not OK for this crowd". Otherwise you'd probably claim that said regulation would go against the very thing that the merchant is trying to do: make as much money as possible.

It's very easy to say that one can filter out certain things, but in practice I think it's far more difficult. Especially in Tor's case where the goal is to provide truly anonymous access.

Do you have a proposal for filtering out that kind of traffic while allowing other traffic? I can't think of a way off the top of my head and I'm sure the people behind Tor would at least consider a logical solution.

Edit: This sounds kind of confrontational, but I don't mean it like that. I honestly would like to hear of a potential solution to this because I really can't think of one.

Re: The Trouble with CloudFlare

#83
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

The main point of Tor is that nobody knows where the traffic comes from. Realize you're asking them to break their own service.

Your premise seems to be that you can't be bothered to protect your networks so you want to put that responsibility on someone else. It's called intermediary liability and it's terrible because the intermediary has all the wrong incentives.

You demand that the intermediary eliminate malicious traffic but they suffer much less than individual users if they also eliminate non-malicious traffic, so they set up a system with a high rate of false positives and harm many honest people. YouTube does this with Content ID. Spam registries do this with innocent small mail servers. CloudFlare does this with Tor.

What you're doing is called externalizing costs. It's generally recognized as antisocial behavior. So if you're going to claim benefits to yourself at the expense of other people, at least recognize that you're doing it.

Re: The Trouble with CloudFlare

#84
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

At a point in the recent past, around 90% of all E-mail traffic was spam. Now it's down to around 50% or so [1]. What happened? It could have been due to thousands of ISPs simultaneously cleaning up and policing their networks. But it also could be due to blocking tools getting better. Maybe the spammers moved away from E-mail to more profitable spam channels. Or is there just more legit traffic now, and the percentage is down because the denominator is larger?

1. http://www.bbc.com/news/technology-33564016

Re: The Trouble with CloudFlare

#85

I find Cloudflare's argument analogous to that of cash - i'm sure some huge percentage of all illegal transactions are with cash, but that does not mean the solution is to ban cash...though some would probably disagree

But to be fair, in Cloudflare's case they aren't "banning" access, they are putting it behind a captcha. Still far from ideal, but it's not banning.

When every .html resource requested is met with a captcha, access is effectively banned.

Re: The Trouble with CloudFlare

#86

Earlier quoted context omitted.

Cloudflare's purpose is to make money. If anyone thinks they are here to help make the world better, that's a naive view. Tor's purpose is to help people access data that may be inaccessible to them without it and to help guard against invasion of privacy. While those things can be used for illicit purposes (as shown by the amount of rouge traffic on Tor exit nodes) the return on quality of life for the whole is grea…

That's a sad statement. Cloudflare is one of my role model for publicity and profit tactics. Everyone can use Cloudflare for free. Companies are their only customers.

Cloudflare literally and knowingly sucks the life out of people by consuming their time and forcing them to perform labor for free to the benefit of their business partners to the tune of hundreds of millions of dollars.

Unless they attempt to change, sorry, but they are a bad company, potiental evil if the data is being used to dox TOR users via a NSL.

Re: The Trouble with CloudFlare

#87

I find Cloudflare's argument analogous to that of cash - i'm sure some huge percentage of all illegal transactions are with cash, but that does not mean the solution is to ban cash...though some would probably disagree

But to be fair, in Cloudflare's case they aren't "banning" access, they are putting it behind a captcha. Still far from ideal, but it's not banning.

In fact, paying with cash sometimes requires a sort of captcha equivalent: the pens[1] that are used to detect counterfeit bills.

Depending on the area you're in, when you pay with a $20 bill (the most commonly counterfeited), the cashier will mark the note with a pen before accepting it.

The business is simply profiling the transaction - a $20 cash bill brings with it a higher risk of fraud - and behaving accordingly. I can't think of a way to argue that it's unfair to the customer that the business does this.

An astute observer will point out that the captcha presented by CloudFlare is an order of magnitude (or two) less convenient than the counterfeit detection pens, but I would argue that this doesn't support a position that CloudFlare is wrong to do what they do.

1: https://en.wikipedia.org/wiki/Counterfeit_banknote_detection...

Re: The Trouble with CloudFlare

#88
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

[deleted]

Re: The Trouble with CloudFlare

#89

I think Cloudflare's blog post was incredibly nuanced, well thoughtout and (dare I say) pro-Tor. They implemented a way for their users to whitelist Tor traffic (bypassing all Captcha's), without allowing their users to blacklist Tor traffic. This response seems a bit of a childish knee-jerk reaction from the Tor project, which could've been worded more maturely.

I didn't spot anything worded immaturely. What specifically do you think could be more maturely worded?

Thanks, agree, I'd like to know exactly what was childish and happy to own up to it if true and attempt to fix the issue.

Re: The Trouble with CloudFlare

#90
The main problem with CloudFlare is how dumb their "protection" is.

It doesn't make sense at all to block Tor users from just accessing read-only content, like CloudFlare does today. Forms/login pages/comment boxes etc should be protected of course, and most people wouldn't have anything against solving a captcha for logging in, but preventing people from just reading stuff anonymously/securely is borderline evil from a user experience point of view.

However it's obviously much easier from an engineering standpoint though to just block people outright.

Post reply on HN