Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

171–180 of 361 posts

Re: The Trouble with CloudFlare

#171

Earlier quoted context omitted.

If CloudFlare would at least let their client decide by themselves, that would be an awesome start. Even if it's enabled by default.

They do this already. See their blog post. You can explicitly whitelist Tor IPs, I thought it was plan limited to only enterprise, but it seems it's available to all actually.

It's a fundamental problem with IP-based reputation. Same goes for VPNs where there isn't a specific list of hosts you can whitelist.

Re: The Trouble with CloudFlare

#173
post #162

Earlier quoted context omitted.

The point of the argument is that preventing fraud using IP blocking is costing you money that you could have in your pocket if you would instead prevent fraud using signature detection or some other method.

With signature detection, you're referring to browser fingerprinting? Because that's not going to work for Tor users (or, more specifically, TBB users).

I'm talking about, people who commit credit card fraud have a credit card whose billing address is in New York City but try to get the product shipped to Nigeria.

Re: The Trouble with CloudFlare

#174
Someone with more knowledge of these thing, let me know:

Why does Tor not "charge" per request? i.e. Using some decentralized currency, to pay for requests.

1. Make it cheep enough such that users don't care, however, financially disincentives spammers/malicious users.

2. It would continue to be anonymous. - cycle through wallets - all transactions would also be proxied.

3. It would incentivize proxying and exit nodes (exit nodes would effectively collect a bunch of virtual money to be resold to clients for USD).

Re: The Trouble with CloudFlare

#175
post #166
post #152

Earlier quoted context omitted.

Instead of having IP-based reputation system, that persists for quite a while, they could have a time limit per IP for specific kinds of requests. Like if you fail to log in to a site, 2^(attempts) timeout from that IP for that page only. Can also integrate a combination of request headers. Sure, it's still IP-based reputation, but it doesn't persist and is much less intrusive. Most sites require specific cookies on…

So a single IP address can DDoS each page of a website for a little while before CloudFlare blocks them? That makes the whole protection pretty useless. I guess it would stop someone from brute-forcing password attempts, but that's not the only thing they're trying to protect against here.

Not necessarily. These work in combination.

If they're requesting specific type of content like images or some weird request that queries DB, these would be grouped together.

What I'm saying is gather more information for each request and use it more wisely to expire IP reputation quicker - within minutes as opposed to months.

The DDoS problem is actually easier than the rest because you need a large volume of requests to do anything. Usually these requests are very similar, come in rapid succession and come from the same bunch of IPs.

Edit:

Going with the mask analogy again, it's like you see 1000 masked people rush into a bar and block the entrance with their bodies.

Is the solution really to ban wearing masks everywhere?

Re: The Trouble with CloudFlare

#176

Earlier quoted context omitted.

> What you're doing is called externalizing costs. It's generally recognized as antisocial behavior. So if you're going to claim benefits to yourself at the expense of other people, at least recognize that you're doing it. Remember his preface - cranky old-school network operator. Let's say you have a hundred networks all connected together into some sort of "inter-net" system. If one AS starts sending out malicious…

> In a system without any real rules or authority, I think "those adversely effected choosing to block the bad actor" is a fairly democratic solution to the problem. That's the part which is adverse to the rest of your argument. You're not voting off the bad actor, you're voting off everyone in the bad actor's country. We know how to deal with this problem. You go to a website, you sign up for an account, it can be p…

> That's the part which is adverse to the rest of your argument. You're not voting off the bad actor, you're voting off everyone in the bad actor's country.

The bad actor is the organization or person responsible for administering the network where the abuse is originating.

When I'm being attacked by someone's VPS, I report them to their host. After the fourth time I report them only to have their host pass along my report but take no further action, the host becomes, maybe not a bad actor but, a "bad citizen".

My choices are to allow them to externalize the costs of their lack of enforcement (or decision not to enforce) and attempt to find a way to block the specific actor under their purview, or just to block that host and accept whatever collateral damage that occurs. (And yes, sometimes that "bad citizen" may end up being most of a country - it doesn't change the equation for me.)

It's the only method I have to exert any pressure on the host to act responsibly. If enough people agree with me, then it quickly becomes "their problem" rather than "my problem" as they get blackholed from everywhere on the internet.

Re: The Trouble with CloudFlare

#177
post #130

Earlier quoted context omitted.

This is exactly what is wrong with this form of idealism. People create these things which remove accountability/reputation, it works great for awhile and is lots of fun (just like a mask party), and then the leeches move in and use it for spam/trolling/illegal stuff. It's usually the leeches who are the real long-term beneficiaries of these kinds of networks. However, the idealistic people who originally created it…

Exactly. But I strongly disagree. You don't blame mask manufacturers for malicious people wearing masks. It's like city guards banning everyone with a mask from entering and issuing IDs to them. Then they're using those IDs to determine what they should and shouldn't see in the city, tracking them everywhere "across cities" etc. In the interest of privacy, it is best to instead use the dynamic nature and types of the…

> It's like city guards banning everyone with a mask from entering and issuing IDs to them.

The flaw in this analogy is that in this case the mask makes every person completely indistinguishable from every other person wearing the mask. In this case, one ID is issued to every person wearing the mask.

When 90%+ of the people with this ID are criminals and vandals, blocking anyone with this ID is a pretty obvious and effective way to prevent crime and vandalism. It's seems pretty reasonable to me when presented this way.

Re: The Trouble with CloudFlare

#178
post #144

Earlier quoted context omitted.

> But, if we've seen your browser behave elsewhere on the Internet acting like a regular web surfer and not a hacker, then we can use your browser’s good reputation to override the bad reputation of the hacker coffee shop's IP. Look, please correct me if I'm misunderstanding or taking your words out of context. But what I hear you saying is that CloudFlare is fundamentally opposed to user privacy at a business and an…

Yes, reputation is a form of tracking. And if you show up to a site with no reputation of your own, from an IP that has a known-bad reputation, it is in the best interest of the site to challenge (not block) you. You are 97% likely to be malicious traffic. Edit: 97% is a real number, not an exaggeration, based on numbers from the report linked in the article.

Even better, treat the website that does so as malicious and stop visiting it.

Re: The Trouble with CloudFlare

#179

Earlier quoted context omitted.

Quoting from our post ( https://blog.cloudflare.com/the-trouble-with-tor/ ): At CloudFlare we've not explicitly treated traffic from Tor any differently, however users of the Tor browser have been more likely to have their browsing experience interrupted by CAPTCHAs or other restrictions. This is because, like all IP addresses that connect to our network, we check the requests that they make and assign a threat score…

> But, if we've seen your browser behave elsewhere on the Internet acting like a regular web surfer and not a hacker, then we can use your browser’s good reputation to override the bad reputation of the hacker coffee shop's IP. Look, please correct me if I'm misunderstanding or taking your words out of context. But what I hear you saying is that CloudFlare is fundamentally opposed to user privacy at a business and an…

> I.e., if you don't agree to let CloudFlare track you around the web (perhaps by simply declining cookies) CloudFlare is likely to degrade your user experience to the point of being borderline unusable and then point the blame at you for coming from a bad network neighborhood.

It seems like CloudFlare is not absolutely committed to this position because they're willing to explore things like the blinded tokens approach.

Re: The Trouble with CloudFlare

#180
post #96

Earlier quoted context omitted.

Why don't you just drop IP-based reputation system for Tor IPs completely and develop something else for these IPs, something based on data from actual requests and responses? Because it sounds like you want to preserve an incorrect system and are pushing this problem on Tor.

Quoting from our post ( https://blog.cloudflare.com/the-trouble-with-tor/ ): At CloudFlare we've not explicitly treated traffic from Tor any differently, however users of the Tor browser have been more likely to have their browsing experience interrupted by CAPTCHAs or other restrictions. This is because, like all IP addresses that connect to our network, we check the requests that they make and assign a threat score…

> Unfortunately, that then means all we can rely on when a request connects to our network is the reputation of the IP and the contents of the request itself.

So, essentially, Cloudflare relies on defense in depth as a security company but as a side effect of this is Tor [and IP anonymity services in general] are affected.

Fair enough but you may want to seriously consider just giving the availability to ignore IP reputation altogether [except during a DDoS] to your customers since it isn't just Tor but also VPNs, etc. that are impacted by this sort of strategy.

Post reply on HN