Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

141–150 of 361 posts

Re: The Trouble with CloudFlare

#141
post #65
post #54

Earlier quoted context omitted.

What kind of "better solution" do you envision? Right now you seem to be insisting that there must be one, which I must say does not make a very compelling case that one actually exists or is possible.

Given Cloudflare appears to have received National Security Letters, it's possible their is no answers. That said, based on what I know, the answer is to whitelist the TOR IPs, give TOR users a global session that the user has the option to opt into (likely make sense for TOR publish what the impact of this is and Cloudflare to link to it in from that page) and always let users know a global session is set in case th…

> That said, based on what I know, the answer is to whitelist the TOR IPs

That's an option CloudFlare is offering to their customers now.

> give TOR users a global session that the user has the option to opt into (likely make sense for TOR publish what the impact of this is and Cloudflare to link to it in from that page) and always let users know a global session is set in case the user believe that using TOR they reset the session

Has this been researched or suggested by the Tor project at all? I think it's fairly dangerous to suggest CloudFlare starts offering something like this before it has been vetted.

Re: The Trouble with CloudFlare

#142
post #130

Earlier quoted context omitted.

This is exactly what is wrong with this form of idealism. People create these things which remove accountability/reputation, it works great for awhile and is lots of fun (just like a mask party), and then the leeches move in and use it for spam/trolling/illegal stuff. It's usually the leeches who are the real long-term beneficiaries of these kinds of networks. However, the idealistic people who originally created it…

Exactly. But I strongly disagree. You don't blame mask manufacturers for malicious people wearing masks. It's like city guards banning everyone with a mask from entering and issuing IDs to them. Then they're using those IDs to determine what they should and shouldn't see in the city, tracking them everywhere "across cities" etc. In the interest of privacy, it is best to instead use the dynamic nature and types of the…

> Going with the mask analogy, they should instead check if a person is brute forcing lock combinations. Maybe even condition on the fact that they're wearing a mask.

That's what they're doing. They are seeing brute forcing come from a bunch of IPs and they're blocking those. What do you expect them to block on? The people using the anonymous service voluntarily identifying themselves on every request (cookies, browser fingerprinting, or pretty much anything else coming from the client side that can be faked)?

Re: The Trouble with CloudFlare

#143
post #71

Original Cloudflare blog post that this is a response to: https://blog.cloudflare.com/the-trouble-with-tor/

That post also suggests two things that Tor could do to improve the situation for their users: * Support a stronger hashing algorithm to make it possible for CloudFlare to make .onion versions of all of their customers' sites. * Implement "client-side" CAPTCHAs. I don't how feasible either of these are, but it seems strange (evasive?) that Tor Project's blog post does not discuss either.

I believe Tor is working on a new version of hidden services which would address the first concern.

Re: The Trouble with CloudFlare

#144

Earlier quoted context omitted.

Quoting from our post ( https://blog.cloudflare.com/the-trouble-with-tor/ ): At CloudFlare we've not explicitly treated traffic from Tor any differently, however users of the Tor browser have been more likely to have their browsing experience interrupted by CAPTCHAs or other restrictions. This is because, like all IP addresses that connect to our network, we check the requests that they make and assign a threat score…

> But, if we've seen your browser behave elsewhere on the Internet acting like a regular web surfer and not a hacker, then we can use your browser’s good reputation to override the bad reputation of the hacker coffee shop's IP. Look, please correct me if I'm misunderstanding or taking your words out of context. But what I hear you saying is that CloudFlare is fundamentally opposed to user privacy at a business and an…

Yes, reputation is a form of tracking. And if you show up to a site with no reputation of your own, from an IP that has a known-bad reputation, it is in the best interest of the site to challenge (not block) you. You are 97% likely to be malicious traffic.

Edit: 97% is a real number, not an exaggeration, based on numbers from the report linked in the article.

Re: The Trouble with CloudFlare

#145

The main problem with CloudFlare is how dumb their "protection" is. It doesn't make sense at all to block Tor users from just accessing read-only content, like CloudFlare does today. Forms/login pages/comment boxes etc should be protected of course, and most people wouldn't have anything against solving a captcha for logging in, but preventing people from just reading stuff anonymously/securely is borderline evil fro…

This was addressed in CloudFlare's blog post:

> One suggestion has been that we treat GET requests for static content differently than we do more risky requests like POSTs. We actually already do treat more dangerous requests differently than less risky requests. The problem is Tor exit nodes often have very bad reputations due to all the malicious requests they send, and you can do a lot of harm just with GETs. Content scraping, ad click fraud, and vulnerability scanning are all threats our customers ask us to protect them from and all only take GET requests.

Re: The Trouble with CloudFlare

#146

Earlier quoted context omitted.

Quoting from our post ( https://blog.cloudflare.com/the-trouble-with-tor/ ): At CloudFlare we've not explicitly treated traffic from Tor any differently, however users of the Tor browser have been more likely to have their browsing experience interrupted by CAPTCHAs or other restrictions. This is because, like all IP addresses that connect to our network, we check the requests that they make and assign a threat score…

> But, if we've seen your browser behave elsewhere on the Internet acting like a regular web surfer and not a hacker, then we can use your browser’s good reputation to override the bad reputation of the hacker coffee shop's IP. Look, please correct me if I'm misunderstanding or taking your words out of context. But what I hear you saying is that CloudFlare is fundamentally opposed to user privacy at a business and an…

Can you conceive of an alternate way to score traffic on the Internet? What might that be?

Re: The Trouble with CloudFlare

#147
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

At a point in the recent past, around 90% of all E-mail traffic was spam. Now it's down to around 50% or so [1]. What happened? It could have been due to thousands of ISPs simultaneously cleaning up and policing their networks. But it also could be due to blocking tools getting better. Maybe the spammers moved away from E-mail to more profitable spam channels. Or is there just more legit traffic now, and the percenta…

It's definitely because of the major botnets being taken down. I remember the McColo bust specifically, spam volumes never recovered to their previous levels after that bust. (PDF) https://www.rsaconference.com/writable/presentations/file_up...

Re: The Trouble with CloudFlare

#148

Earlier quoted context omitted.

* facepalm * No room for nuance, huh? Or appreciation for the position CloudFlare is in and their obligation to their clients? How would you solve this? Abuse from Tor IPs is a known and documented problem. If you have a solution, I'll bet CloudFlare has a job opening.

Absolutely not. I believe in privacy and have zero tolerance for big businesses who throw their weight around at the expense of minority communities (Tor users in this case). I understand CloudFlare's need to make a profit. That is why we need to turn treating Tor traffic like normal traffic into a good business decision.

Why so much hate against CloudFlare? What's the big deal about being a "company" if you can see the CEO replying to you right here, right now?

On top of that CloudFlare as a free service helped lots of small controversial, hated-by-some-government websites to stay alive. They protect >ANYONEIf keeping freedom of speech ( as in "being online" ) for all those users they protect, for you is "at the expense of minority", I think you are totally biased.

Re: The Trouble with CloudFlare

#149

Earlier quoted context omitted.

The main point of Tor is that nobody knows where the traffic comes from. Realize you're asking them to break their own service. Your premise seems to be that you can't be bothered to protect your networks so you want to put that responsibility on someone else. It's called intermediary liability and it's terrible because the intermediary has all the wrong incentives. You demand that the intermediary eliminate maliciou…

> What you're doing is called externalizing costs. It's generally recognized as antisocial behavior. So if you're going to claim benefits to yourself at the expense of other people, at least recognize that you're doing it. Remember his preface - cranky old-school network operator. Let's say you have a hundred networks all connected together into some sort of "inter-net" system. If one AS starts sending out malicious…

> In a system without any real rules or authority, I think "those adversely effected choosing to block the bad actor" is a fairly democratic solution to the problem.

That's the part which is adverse to the rest of your argument. You're not voting off the bad actor, you're voting off everyone in the bad actor's country.

We know how to deal with this problem. You go to a website, you sign up for an account, it can be pseudonymous but to get it you have to put up some collateral. Money/Bitcoin, proof of work, vouching by an existing member, whatever you like. Then if your account misbehaves you forfeit your collateral.

But this isn't a CloudFlare-level problem. They're trying to solve it at the wrong layer of abstraction. Identity isn't a global invariant, it's a relationship between individuals. Endpoints identify each other with persistent pseudonyms. The middle of the network should have nothing to do with it.

Re: The Trouble with CloudFlare

#150
I think CloudFlare's security measures are insane. I use a VPN and I can tell which sites use CloudFlare because I consistently get a Error 520, where it claims the browser and CloudFlare are working, but the website is not responding. Yet I turn of the VPN and magically it works fine. That's dishonest. At least own that you are the one blocking my visit.

I'm also developing with Dwolla's API, and CloudFlare blocks all HTTP requests from my local IP, so I can't develop locally. Thanks CloudFlare.

Post reply on HN