Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

131–140 of 361 posts

Re: The Trouble with CloudFlare

#131

Earlier quoted context omitted.

The main point of Tor is that nobody knows where the traffic comes from. Realize you're asking them to break their own service. Your premise seems to be that you can't be bothered to protect your networks so you want to put that responsibility on someone else. It's called intermediary liability and it's terrible because the intermediary has all the wrong incentives. You demand that the intermediary eliminate maliciou…

"...you can't be bothered to protect your network..." Huh? Isn't this exactly what CF is attempting to do? And Tor traffic tends to be abusive so the good is caught up with the bad, but it's all in the name of protection.

> Isn't this exactly what CF is attempting to do?

No. The real bad people have botnets and can cycle through a million random IP addresses every time you block one. A real solution needs to be secure against someone you don't yet know is bad.

This is going to get a lot worse as we've run out of IPv4 addresses. ISPs are going to start to NAT many users behind one IP address. Some already have. Then you have the same issue as Tor where one user is malicious but shares the same IP address as a thousand innocent users. IP blocking isn't going to work anymore so you might as well find an alternative solution now.

Re: The Trouble with CloudFlare

#132
post #61

Earlier quoted context omitted.

[IP addresses of] Tor exit nodes were far more likely to contain malicious requests However, traffic from Tor exit nodes yielded a conversion rate virtually equal to non-Tor IPs You just described every busy IP address: if you handle more requests, you are more likely to handle a malicious one. This is the problem with IP based reputation.

Yes, I think that the more revealing ratio would have been total malicious requests to all requests for each class of IP. If each Tor exit node is sending out 30x as much traffic, with an average of 30 unique users per IP, then the cited ratios are meaningless. The only thing that can be drawn from that data is that Tor makes IP-based reputation tools ineffective. The thing is, for many people that may be enough to j…

That's what CloudFlare did in their blog post:

> Based on data across the CloudFlare network, 94% of requests that we see across the Tor network are per se malicious.

Re: The Trouble with CloudFlare

#133
post #96

Earlier quoted context omitted.

Why don't you just drop IP-based reputation system for Tor IPs completely and develop something else for these IPs, something based on data from actual requests and responses? Because it sounds like you want to preserve an incorrect system and are pushing this problem on Tor.

Quoting from our post ( https://blog.cloudflare.com/the-trouble-with-tor/ ): At CloudFlare we've not explicitly treated traffic from Tor any differently, however users of the Tor browser have been more likely to have their browsing experience interrupted by CAPTCHAs or other restrictions. This is because, like all IP addresses that connect to our network, we check the requests that they make and assign a threat score…

> But, if we've seen your browser behave elsewhere on the Internet acting like a regular web surfer and not a hacker, then we can use your browser’s good reputation to override the bad reputation of the hacker coffee shop's IP.

Look, please correct me if I'm misunderstanding or taking your words out of context.

But what I hear you saying is that CloudFlare is fundamentally opposed to user privacy at a business and an architectural level.

I.e., if you don't agree to let CloudFlare track you around the web (perhaps by simply declining cookies) CloudFlare is likely to degrade your user experience to the point of being borderline unusable and then point the blame at you for coming from a bad network neighborhood.

Re: The Trouble with CloudFlare

#134
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

As is cloudfare. I have lost count of sites that pirate our software that are using cloudfare. Cloudfare know of the problem and refuse to do anything about it.

Thankfully. They're already the "Wifi Captive Portal" of the internet, be glad that they're not also the police of the internet.

Re: The Trouble with CloudFlare

#135

Earlier quoted context omitted.

The main point of Tor is that nobody knows where the traffic comes from. Realize you're asking them to break their own service. Your premise seems to be that you can't be bothered to protect your networks so you want to put that responsibility on someone else. It's called intermediary liability and it's terrible because the intermediary has all the wrong incentives. You demand that the intermediary eliminate maliciou…

> What you're doing is called externalizing costs. It's generally recognized as antisocial behavior. So if you're going to claim benefits to yourself at the expense of other people, at least recognize that you're doing it. Remember his preface - cranky old-school network operator. Let's say you have a hundred networks all connected together into some sort of "inter-net" system. If one AS starts sending out malicious…

[deleted]

Re: The Trouble with CloudFlare

#136

Earlier quoted context omitted.

* facepalm * No room for nuance, huh? Or appreciation for the position CloudFlare is in and their obligation to their clients? How would you solve this? Abuse from Tor IPs is a known and documented problem. If you have a solution, I'll bet CloudFlare has a job opening.

Absolutely not. I believe in privacy and have zero tolerance for big businesses who throw their weight around at the expense of minority communities (Tor users in this case). I understand CloudFlare's need to make a profit. That is why we need to turn treating Tor traffic like normal traffic into a good business decision.

I think you underestimate how much of the traffic from Tor that is malicious.

I have barely ever seen any legitimate Tor traffic, it has all been spam bots or other kinds of traffic I would rather avoid.

Re: The Trouble with CloudFlare

#137
post #96

Earlier quoted context omitted.

Why don't you just drop IP-based reputation system for Tor IPs completely and develop something else for these IPs, something based on data from actual requests and responses? Because it sounds like you want to preserve an incorrect system and are pushing this problem on Tor.

Quoting from our post ( https://blog.cloudflare.com/the-trouble-with-tor/ ): At CloudFlare we've not explicitly treated traffic from Tor any differently, however users of the Tor browser have been more likely to have their browsing experience interrupted by CAPTCHAs or other restrictions. This is because, like all IP addresses that connect to our network, we check the requests that they make and assign a threat score…

Since traffic from Tor is so low (0.4%) why do even care to do IP-based blocking? Won't all your other threat detection models kick in when necessary anyway?

Re: The Trouble with CloudFlare

#139

Earlier quoted context omitted.

>Prepaid credit cards are essentially anonymous, as far as I know. My understanding is that you can only buy prepaid cards after showing ID in many jurisdictions, and many other places require you to register them with ID in order to use the cards.

What jurisdictions are those? You don't need ID to purchase or register Visa, MasterCard or American Express prepaid/gift cards in the US. I've bought all of those with cash, and registered them all with nothing more than the card number and CVV code.

In Canada, the prepaid cards I got once required me to submit a government ID. These are the ones from Canada Post in case anyone is curious.

Re: The Trouble with CloudFlare

#140

Earlier quoted context omitted.

The main point of Tor is that nobody knows where the traffic comes from. Realize you're asking them to break their own service. Your premise seems to be that you can't be bothered to protect your networks so you want to put that responsibility on someone else. It's called intermediary liability and it's terrible because the intermediary has all the wrong incentives. You demand that the intermediary eliminate maliciou…

> What you're doing is called externalizing costs. It's generally recognized as antisocial behavior. So if you're going to claim benefits to yourself at the expense of other people, at least recognize that you're doing it. Remember his preface - cranky old-school network operator. Let's say you have a hundred networks all connected together into some sort of "inter-net" system. If one AS starts sending out malicious…

We're not dealing with 99 ASs blocking another bad actor. We're talking about one service that sits in front of many popular services on the internet deciding to block another for dubious reasons. Cloudflare has near monopoly power here.
Post reply on HN