Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

211–220 of 361 posts

Re: The Trouble with CloudFlare

#211
The really questionable thing CloudFlare seems to be doing is that they captcha traffic depending on the overall reputation of only the source IP rather than whether the source IP is attacking that specific site or even whether the site is under attack.

What they should do instead is this:

1. If the server is not overloaded, do not captcha any traffic at all

2. If the server starts being overloaded, only captcha traffic from IPs that have been detected as attacking THAT specific site

3. If the server is still overwhelmed, only then switch to captchaing all IPs with "bad reputation"

Most websites are probably almost never under attack, so this would make encountering CloudFlare captcha extremely rare in the wild while still providing DDOS protection.

They could even only do this for Tor exit nodes and other IPs that are known to be used by lots of people.

If a site is being DDOSsed a lot and the slower start up of this technique is a problem, then they can revert for those sites to the current behavior of using reputation.

Re: The Trouble with CloudFlare

#212
post #189

Earlier quoted context omitted.

Yes, but Tor flips through IP addresses regularly so you'd get challenged every few minutes. Similarly, if you block cookies/supercookies/etc to avoid being tracked ... you'll be challenged every view.

Yes, you will. But the point is, with no other information to go on, that is the best option for the website. If you don't want to be challenged constantly, you need to give the website operator some incentive to accept your traffic.

There is plenty of information to go off of. They just don't want to put in the engineering effort required to utilize it.

Is there really a constant DDoS attack on all of these sites from users with no cookies?

Re: The Trouble with CloudFlare

#213

I think CloudFlare's security measures are insane. I use a VPN and I can tell which sites use CloudFlare because I consistently get a Error 520, where it claims the browser and CloudFlare are working, but the website is not responding. Yet I turn of the VPN and magically it works fine. That's dishonest. At least own that you are the one blocking my visit. I'm also developing with Dwolla's API, and CloudFlare blocks a…

Yeah, this is beyond just Tor - they're breaking VPN and carrier-grade NAT traffic too. Even if Tor bowed to their demands those would stay broken, and scammers would still fill out the captchas manually. But they seem very set on their chosen solution!

Re: The Trouble with CloudFlare

#214
Services like CloudFlare are responsible for more and more of the DNS. When they are poor net citizens, they are poor net citizens at a massive scale. Heuristics that end up being equivalent to "Tor users are guilty until proven innocent" can't become the default mode of the Internet. As customers, Tor users, and just people who have a stake in the Internet as a shared resource, we need to demand that they try harder than that.

Re: The Trouble with CloudFlare

#215

The main problem with CloudFlare is how dumb their "protection" is. It doesn't make sense at all to block Tor users from just accessing read-only content, like CloudFlare does today. Forms/login pages/comment boxes etc should be protected of course, and most people wouldn't have anything against solving a captcha for logging in, but preventing people from just reading stuff anonymously/securely is borderline evil fro…

How do you stop people from scraping your site? Databrokers frequently will mine social sites to build profiles on people. There's legitimate reasons to block TOR for read-only content.

Re: The Trouble with CloudFlare

#216

Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…

The post from the Tor project does not state anywhere that Tor is not used by botnets or that it's used for malicious purposes. They specifically question your specific assertion that 94% of Tor traffic is malicious. I'm not surprised, it's quite a statement and it calls for some supporting evidence.

Surely you can see how, given the amount of outreach they do to educate regular people about the positive uses of Tor, putting forth unfounded statements like that might be perceived negatively.

I am glad that CloudFlare has put effort into this problem and as a Tor user I appreciate it (though obviously, this problem goes far beyond Tor, as mentioned in the article - your systems will have the exact same problems with large-scale IPv4 NAT, so really it's not optional for a CDN provider).

But please, stick to facts when presenting the case.

Re: The Trouble with CloudFlare

#217

Payments originating from TOR IP addresses absolutely are more likely to be fraudulent. Anyone running an online business could tell you that.

Hassling Tor users shouldn't become the Internet's default. If you're having trouble, consider informing Tor users checking out that you won't process the payment without their providing additional information. This raises the cost to carders a lot more than needing to rent a SOCKS proxy in a residential area.

Re: The Trouble with CloudFlare

#218
post #154

Earlier quoted context omitted.

Yeah, I don't get why CloudFlare are so overaggressive with the captchas. The vast majority of captcha'd pages by CloudFlare on Tor which makes secure web browsing so cumbersome are completely read-only, while some may have a comment system hosted by a third party like Disqus and Facebook (and are therefore protected already). Other sites should have the captchas on a different level than the front page, like the log…

"Read-only" pages are still fertile ground for layer 7 DDOS.

The Tor egress bandwidth is sufficiently small and sparsely located that this wouldn't be an issue for a CDN.

Re: The Trouble with CloudFlare

#219
post #21

Earlier quoted context omitted.

A huge percentage of illegal transactions may be in cash, but a huge percentage of transactions in cash are not illegal.

Which is why large cash transactions are heavily regulated and reported on. In the US, one cannot just withdraw $10k or a series of smaller transactions that add up to $10k or more without the bank reporting on that to the authorities. That's the balance that law makers decided to strike.

an interesting aspect is that the bank secrecy act was passed in 1970, but has not been adjusted for inflation, so when the law was passed it was more like a $60k limit that has been encroaching on us ever since...

Re: The Trouble with CloudFlare

#220
post #186

I'm getting "Attackers might be trying to steal your information from blog.torproject.org (for example, passwords, messages, or credit cards). NET::ERR_CERT_AUTHORITY_INVALID" When trying to visit this blog post.

>> Laaw: "But I don't want end to end encryption"

Sorry, but I thought you didn't want encryption. Bit puzzled, just click ignore error to fix the issue.

Clearly this advice is based on you not wanting end-to-end encryption; heads up, NSA flags users that visit Tor's website, though clearly, you've done nothing wrong.

(Yes, I'm making a point, hope it's clear.)

Post reply on HN