Earlier quoted context omitted.
I didn't spot anything worded immaturely. What specifically do you think could be more maturely worded?
Thanks, agree, I'd like to know exactly what was childish and happy to own up to it if true and attempt to fix the issue.
The Trouble with CloudFlare
91–100 of 361 posts
Re: The Trouble with CloudFlare
#92Earlier quoted context omitted.
But to be fair, in Cloudflare's case they aren't "banning" access, they are putting it behind a captcha. Still far from ideal, but it's not banning.
When every .html resource requested is met with a captcha, access is effectively banned.
If you are blocking that cookie for privacy reasons (which is not a bad thing!), then cloudflare has no way to verify you again (short of doing nefarious things). It's a bit of a self inflicted problem at that point.
That's not to say that the answer is "deal with it", but that we need to find a better way. A a way to verify that someone isn't a bad actor without having them take a pretty significant chunk of their time to answer captchas, or give up some of their privacy.
It's a tough problem, and i think the "proof of work" solution proposed in the original could work, but it would need participation and collaboration from "both sides" of the problem. And of course it won't happen overnight.
Re: The Trouble with CloudFlare
#93Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…
Bitcoin has the same issue: there are lots of legit uses of it, but to make it a good widely used currency, a reputation system is going to emerge, and from there you've already erased half the benefits of using Bitcoin. However, in the mean time Bitcoin is used by a bunch of people purely interested in speculation or as a way of avoiding taxes/money laundering laws/etc. There are people, just like Tor, using it for legit reasons, but my bet it's for mostly reasons nobody in the Bitcoin community likes to admit.
Re: The Trouble with CloudFlare
#94Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…
But that's all utter nonsense! These botnets only access stuff inside the Tor network (i.e the C&C, that the operators want to hide), they don't use Tor to access clearnet content. Even a small botnet will have more nodes than there exists tor exit nodes (966 as of right now), what possible benefit could there be for the botnet operator from doing that?
Re: The Trouble with CloudFlare
#95Earlier quoted context omitted.
>they need to be if they want their product to thrive. Otherwise, good bye Tor. The ironic thing is actually that by applying any kind of "network regulation" the Tor project would abandon its own primary purpose. The only way it can continue to exist is actually if it doesn't practice any kind of censorship of its users.
This is a very simplistic, binary view of the world. Just because the Internet's view of a product differs from the author's, it doesn't make the Internet wrong. It means the author probably needs to step back and re-evaluate things. By your logic, gun owners would be able to shoot whatever they want. The primary purpose of a gun is to shoot things. To paraphrase: "To regulate what you can and can't shoot would go ag…
Re: The Trouble with CloudFlare
#96Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…
Because it sounds like you want to preserve an incorrect system and are pushing this problem on Tor.
Re: The Trouble with CloudFlare
#97The main problem with CloudFlare is how dumb their "protection" is. It doesn't make sense at all to block Tor users from just accessing read-only content, like CloudFlare does today. Forms/login pages/comment boxes etc should be protected of course, and most people wouldn't have anything against solving a captcha for logging in, but preventing people from just reading stuff anonymously/securely is borderline evil fro…
If an IP, or IP range, behaves badly - goodbye. It's a TOR problem to solve it, it's not the problem of web servers and also CloudFlare.
Re: The Trouble with CloudFlare
#98Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…
Re: The Trouble with CloudFlare
#99Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…
The main point I took away from the article, that from one exit node many users originate. Some users are spammer. They contaminate the exit node IP. CF blocks an IP for spam, but does not remove the block after some time (when the spammer moved on).
At least this will reduce legitimate user's annoyance, instead of being blocked indefinitely
My own experience: Tried accessing wikialpha from work LAN, 'blocked' by endless captcha (for a few months already) and opening the said wiki from home network, all is perfectly fine...
well at least now I know why, still does NOT makes it OK from end-users perpective
Re: The Trouble with CloudFlare
#100I think Cloudflare's blog post was incredibly nuanced, well thoughtout and (dare I say) pro-Tor. They implemented a way for their users to whitelist Tor traffic (bypassing all Captcha's), without allowing their users to blacklist Tor traffic. This response seems a bit of a childish knee-jerk reaction from the Tor project, which could've been worded more maturely.
I didn't spot anything worded immaturely. What specifically do you think could be more maturely worded?
Tor exit nodes were far more likely to contain malicious requests
and even:
Risk averse companies may wish to block all Tor traffic
The article then goes on to suggest that it is perfectly reasonable to use the word 'block' to mean showing a captcha - in common usage block means block - deny requests, not attempt to determine if a user is human with a captcha or some other method - that's not blocking, it's annoying and potentially pointless, but it's certainly not simply blocking users and it's disingenuous to describe it as such.
All of that adds up to a response which seems to be more interested in scoring points than finding a solution for legitimate Tor users. I'm not sure I'd describe it as immature, but it's not a very constructive response, to an article which went out of its way to be Tor friendly and propose solutions. It would be much easier for cloudflare to really block Tor traffic, they would probably suffer very little from doing so.