Earlier quoted context omitted.
Thanks. Can I whitelist the whole internet (by using /0 perhaps?) using this method? I've seen people complaining about this issue on VPNs and such too.
You can whitelist CIDR ranges of /16 and /24 currently. So yes, you can to some extent whitelist everyone.
The Trouble with CloudFlare
241–250 of 361 posts
Re: The Trouble with CloudFlare
#242Earlier quoted context omitted.
What jurisdictions are those? You don't need ID to purchase or register Visa, MasterCard or American Express prepaid/gift cards in the US. I've bought all of those with cash, and registered them all with nothing more than the card number and CVV code.
In Canada, the prepaid cards I got once required me to submit a government ID. These are the ones from Canada Post in case anyone is curious.
However, in order to make certain purchases online, it's often been the case that you need to "Register" the card with the provider, and supply details that would match billing information for the selling party. I can't see any reason why you couldn't fudge that, although shipping information for real goods would leak information.
Re: The Trouble with CloudFlare
#243Earlier quoted context omitted.
Since they use HSTS, I literally can't click "ignore" or I would have. I, and (I assume) anyone else who uses the latest version of Chrome cannot access this content right now. Or it might just be me, but I don't know what the solution is. You also missed the point if you think what I said included the words "all the time" in the other thread we were talking in.
I'm on Tor and able to see the file, no idea why you're getting that error, or I'd try to help. Assume you know this, but Google has a cached version as text if you Google... [cache:http...] ^^ where you remove the open/close brackets and insert the full URL after "cache:"
Re: The Trouble with CloudFlare
#244Earlier quoted context omitted.
That argument only holds true if the person operating the site has no idea at all about the HTTP standards. * GET requests have to be idempotent. * Security by Obscurity is not Security. * Content Scraping is nothing you have to protect against, or should protect against – DRM just does not work .
Right, but this is about abuse and solutions for that. Obviously, blocking Tor is not going to prevent a determined attacker from scraping your site or trying some SQLi vectors. It might, however, prevent a large number of bots from scraping your site for emails, scanning for vulnerabilities, or doing click fraud. It's not a perfect solution, but those rarely exist. CloudFlare sees a lot of malicious traffic, so they…
I don’t block them either.
Instead, I use fail2ban with a 30min ban for the IP for all my servers, and have the rest of the system hardened. Also, I add an additional delay that’s just below the timeout that browsers have for each request from an IP of that block for the next 30min.
Reduced my logs of "123.456.789.012 tried to authenticate as "root" with invalid password" from several gigabytes a day to a few kilobytes.
________________________
Sure, I don’t host a large site, or get much traffic, but saying "Tor is the only issue" or even "Tor is the largest issue" isn’t true.
And there are solutions for these cases. Solutions which allow legitimate users to continue using the services.
Re: The Trouble with CloudFlare
#245Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…
Why don't you just drop IP-based reputation system for Tor IPs completely and develop something else for these IPs, something based on data from actual requests and responses? Because it sounds like you want to preserve an incorrect system and are pushing this problem on Tor.
Couple that with most clients passing all the same fingerprintable data (browser brand and version, OS version, etc), and you can't uniquely identify different clients coming from the same IP with any level of accuracy.
There is no solution where everyone wins. Simple as that.
Re: The Trouble with CloudFlare
#246I [I'm CloudFlare's CTO] have been engaging with the Tor folks through their Trac interface here for about 6 weeks: https://trac.torproject.org/projects/tor/ticket/18361 and been very open about CloudFlare is addressing this. My plan is to continue to do so through that ticket as I've made various commitments there (some of which, like whitelisting, we've already rolled out). It's worth reading the entire ticket to g…
Re: The Trouble with CloudFlare
#247Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…
> Tor needs to clean up and police its network I think you don't understand what Tor is or how it works. Tor is a way to anonymize its users. You have no way to analyze a packet until it reaches an exit node, and you have no way to analyze that packet if it's done over https, and you have no way to block an ip from that exit node because it comes from another node where plenty of other ips are coming from. If you sta…
> what you are saying goes against Tor's principals
That's why it will probably never be cleaned up. That's also why more and more people will probably block access from Tor. CloudFlare says they get a 95% attack rate from it. A blog post the other day said FotoForensics gets about 91% attacks from Tor.
No one is going to put up with 91% attacks for long. And if that means Tor becomes it's own walled garden that doesn't 'interact' with the public internet, so be it.
Re: The Trouble with CloudFlare
#248> 5) A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing commercial activity was "virtually equal" to that of non-Tor IP addresses). This point seems rather odd. I'…
> Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing commercial activity was "virtually equal" to that of non-Tor IP addresses
So when seeing actual web traffic things are identical. That only measures real web traffic. It doesn't measure all the SSH attacks, SPAM being sent, possibly checking for vulnerabilities and unpatched software/etc.
Re: The Trouble with CloudFlare
#249Earlier quoted context omitted.
> Unfortunately, that then means all we can rely on when a request connects to our network is the reputation of the IP and the contents of the request itself. So, essentially, Cloudflare relies on defense in depth as a security company but as a side effect of this is Tor [and IP anonymity services in general] are affected. Fair enough but you may want to seriously consider just giving the availability to ignore IP re…
Customers can toggle how much they want IP reputation to be taken into account on a site by site basis. Agree that it should be a customer's choice, which is why it has been since the day we launched in 2010. The seeming disconnect is that the vast majority of our customers ask us to provide them a way to block Tor entirely. And we've resisted that because we believe the anonymity Tor provides is a good thing. Same r…
https://www.cloudflare.com/features-security/
> In addition to CloudFlare’s automatic detection, you can easily add an IP address, IP ranges or entire countries to your Trust and Block list.
Umm, vast majority is non-paying I take it since I believe its available on every paid plain?
https://support.cloudflare.com/hc/en-us/articles/200170056-W...
> A low security setting will challenge only the most threatening visitors. A high security setting will challenge all visitors that have exhibited threatening behavior within the last 14 days.
I'm guessing you mean the "Essentially Off" option which implies Cloudflare basically stops providing security?
Re: The Trouble with CloudFlare
#250Earlier quoted context omitted.
> But, if we've seen your browser behave elsewhere on the Internet acting like a regular web surfer and not a hacker, then we can use your browser’s good reputation to override the bad reputation of the hacker coffee shop's IP. Look, please correct me if I'm misunderstanding or taking your words out of context. But what I hear you saying is that CloudFlare is fundamentally opposed to user privacy at a business and an…
Can you conceive of an alternate way to score traffic on the Internet? What might that be?