Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

271–280 of 361 posts

Re: The Trouble with CloudFlare

#271

Earlier quoted context omitted.

> The bad actor is the organization or person responsible for administering the network where the abuse is originating. The bad actor is the individual who acts bad. The Post Office is not a bad actor for delivering letters. > allow them to externalize the costs of their lack of enforcement Tor is not an enforcement agency. Neither is CloudFlare. The costs of bad actors are your costs. You have the technical ability…

"The bad actor is the individual who acts bad. The Post Office is not a bad actor for delivering letters." If they actively ignored death threats/didn't send them off to the police when it came to their attention, they become responsible. "The costs of bad actors are your costs." Cloudflare is sick and tired of getting attacked by people from the TOR network. I don't blame them for the ban. It's costing them money..a…

> If they actively ignored death threats/didn't send them off to the police when it came to their attention, they become responsible.

The Post Office reads your mail?

> We used to have a bigger problem with mail spam because server operators constantly would leave anonymous relaying open. How did we stop a great deal of it? By blacklisting the IP until the problem is fixed. It has worked out pretty well.

Only if you're willing to disregard innocent people.

> I guess we have to determine which 'innocent' people are more important: The ones getting their websites attacked and hacked anonymously, the people that can't access those websites because they are down/DOS attacked, or the random people that want to use the TOR network.

The "random people" who use Tor aren't doing it because it's trendy. They're doing it because it's the only way they can access the internet. Or because not using it would get them stoned to death by religious fundamentalists or imprisoned by an oppressive government.

Re: The Trouble with CloudFlare

#272

I [I'm CloudFlare's CTO] have been engaging with the Tor folks through their Trac interface here for about 6 weeks: https://trac.torproject.org/projects/tor/ticket/18361 and been very open about CloudFlare is addressing this. My plan is to continue to do so through that ticket as I've made various commitments there (some of which, like whitelisting, we've already rolled out). It's worth reading the entire ticket to g…

I'm a long-time Tor user that's been affected by CloudFlare captchas for a few years. I appreciate that you (CloudFlare) are trying to tackle the problem, but I feel that both CloudFlare and the Tor community have defeatist attitudes toward this issue.

I have the following suggestions for CloudFlare:

1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisting Tor? For example, when a customer selects to Block or Captcha Tor, a tiny link could show up somewhere that says something like "This affects users who seek privacy, find out more."

2. In addition to better docs, can you setup something that lets site operators view the site as a Tor user? The screenshot on this site does not do the Tor+Captcha experience justice:

https://support.cloudflare.com/hc/en-us/articles/203306930-D...

In particular, the screenshot assumes the Tor browser is running Javascript and that all the user has to do is click that button. In reality, Tor users have to click a bunch of checkmarks, try again once or twice, then copy a code into a textbox then hit submit.

If you provided a "view site as Tor user" demo (JS and non-JS versions), then site operators might be more reluctant to enable Captcha for Tor users.

3. The latest CloudFlare blog post on Tor says "you can do a lot of harm just with GETs." I wish you would give more thought to the idea of a read-only option for non-whitelisted Tor users. If GET requests are harmful (I'm skeptical), reducing the harm of GET requests seems like a much easier problem than the overall problem. Afterall, what good is a CDN that can't handle lots of requests for static content?

I also have the following suggestions for the Tor community:

1. Continue to improve the Tor user experience to gain users! The more people use Tor, the harder it is to ignore (by CloudFlare and others) and the safer it gets. Acquiring more users is one of the best ways to fight back against Captchas. One way to get lots of new users is Firefox integration.

2. Fix hidden services. It's awesome that CloudFlare wants to give the option to setup hidden services for their customers. Make that possible for them!

3. If CloudFlare doesn't want to provide some sort of read-only mode, build that functionality yourselves! For example: when the Tor Browser detects a CloudFlare captcha, it could give the user the option to read a read-only cache from some other CDN.

Re: The Trouble with CloudFlare

#273

Earlier quoted context omitted.

> I don't see this in any practical fashion. You don't? > I can visit a CloudFlare hosted site from the regular internet for hours (even scrape automatically) with no problems Ah but this is not the same. Try doing so from an IP which is also sending malicious traffic, and you will see the same issue.

Technically, no, it's not the same thing. But, for a user, it is the same thing. Ultimately, it's the user's experience that matters, not the technical details. Much like I don't care which bus gets me from point A to point B, or if I'm the only the one on the bus or not... it's the experience of the trip between points that matters.

If you don't care which bus gets you from point A to point B, then stay off of the bus that all of the malicious packets are riding...

Re: The Trouble with CloudFlare

#274

Earlier quoted context omitted.

Yeah, I don't get why CloudFlare are so overaggressive with the captchas. The vast majority of captcha'd pages by CloudFlare on Tor which makes secure web browsing so cumbersome are completely read-only, while some may have a comment system hosted by a third party like Disqus and Facebook (and are therefore protected already). Other sites should have the captchas on a different level than the front page, like the log…

They also protect against ddos, sqli, overuse, bots etc. so comment spam is only one problem and get requests are not always safe. You'd think they could be far more sophisticated about reputation though and adjust it in realtime so that ips are by default trusted and are marked down temporarily for bad behaviour.

When are GET requests unsafe?

Re: The Trouble with CloudFlare

#275
post #230

Earlier quoted context omitted.

You still purposefully resolve spam domains on at least tim.ns.cloudflare.com and leah.ns.cloudflare.com and refuse do to anything about it. I see a certain hypocrisy in claiming to protect your customers, and at the same time enabling criminal operations through allowing them use of your infrastructure. (For the record and because you tell me this at every point of contact, I know your main business is reverse-proxy…

Yep and on top of that they have for years they have allowed DDoS 'booters' to stay online, with the claim of "we have no way to remove the content, we're just a reverse proxy." If they're not actually hosting it, they think it's OK for whatever it is to pass through their network. http://www.crimeflare.com/damon.html

Aye, thanks for the write-up!

I don't really get them either, surely they have enough paying customers to be able to afford some basic data hygiene.

I'd really like to find some ways to make it more costly for them to keep the scum on their networks than to send out stupid "we r a reverse proxy!!!" replies, that clearly have nothing to do with anything.

But yeah, keep complaining about Tor, good job CloudFlare /s

Re: The Trouble with CloudFlare

#276

Earlier quoted context omitted.

> Unfortunately, that then means all we can rely on when a request connects to our network is the reputation of the IP and the contents of the request itself. So, essentially, Cloudflare relies on defense in depth as a security company but as a side effect of this is Tor [and IP anonymity services in general] are affected. Fair enough but you may want to seriously consider just giving the availability to ignore IP re…

Customers can toggle how much they want IP reputation to be taken into account on a site by site basis. Agree that it should be a customer's choice, which is why it has been since the day we launched in 2010. The seeming disconnect is that the vast majority of our customers ask us to provide them a way to block Tor entirely. And we've resisted that because we believe the anonymity Tor provides is a good thing. Same r…

For what it's worth, as somebody who used to manage a site that was under constant attack and who's users were regularly victims of phishing...I appreciate blocking Tor.

We weren't using Cloudflare but our own systems that were using IP threat rating services like MaxMind but eventually we had to totally prevent anything important from being done on the site via anonymous proxies. Bids, Listing Creation, Payments of any kind had to be completely blocked from those sources. People were using Tor to create fake listings on fake users with stolen credit cards that we were then paying charge back fees for. Using Tor to bid up their own auctions. Direct messages soliciting users to take the transactions off site.

Blocking those systems was one of the most effective things that we had to do and our users were vocally happier about it.

Re: The Trouble with CloudFlare

#277
post #189

Earlier quoted context omitted.

Yes, you will. But the point is, with no other information to go on, that is the best option for the website. If you don't want to be challenged constantly, you need to give the website operator some incentive to accept your traffic.

Honestly, it probably would be beneficial to my productivity if I dropped all of Cloudflare's IP ranges since it'd keep me from going on HN, Reddit, etc. :P The need for incentive you mention is silly. The website operator [much like a job searcher with a resume] wants to be in front of as many non-malicious people as possible. And while you might argue .04% of malicious traffic comes over Tor, I've operated sites wh…

Global traffic patterns don't tell the story. I've seen sites where 100% of Tor traffic was malicious, so the fact that 0.04% is typically malicious is meaningless to the people operating that site.

It all depends on what you do. I had a customer a few years ago that was forced to geo-block IP addresses from China, most African nations and Bulgaria. The nature of that customer's business made that an easy solution.

A company like Cloudflare serves everyone without a lot of context. If your site serves a Tor-heavy niche, it's not the right solution.

Re: The Trouble with CloudFlare

#278
post #68

Earlier quoted context omitted.

Please bullet/number your concerns as self-contained statements and I'll explicitly reference them. And yes, my response is to your comment, though do see how it's possible it's ambiguous to how I'm addressing your concerns. Thanks for the comment.

It's not his job to format his comment to make it convenient for you to rebut. I agree that it's not at all clear how your reply addresses the original comment. Perhaps you could fix that by quoting the portions of the original comment you're replying to, rather than requiring line numbers.

Correct me if I am wrong, but I should format my comment because he refuses to do so, right? He refused to respond to my response to his even in part, though I should spend more time on it, right. My reading of his comment is he didn't read my comment, and he he can't read, there's nothing I am able to do.

Re: The Trouble with CloudFlare

#279

Earlier quoted context omitted.

Honestly, it probably would be beneficial to my productivity if I dropped all of Cloudflare's IP ranges since it'd keep me from going on HN, Reddit, etc. :P The need for incentive you mention is silly. The website operator [much like a job searcher with a resume] wants to be in front of as many non-malicious people as possible. And while you might argue .04% of malicious traffic comes over Tor, I've operated sites wh…

Global traffic patterns don't tell the story. I've seen sites where 100% of Tor traffic was malicious, so the fact that 0.04% is typically malicious is meaningless to the people operating that site. It all depends on what you do. I had a customer a few years ago that was forced to geo-block IP addresses from China, most African nations and Bulgaria. The nature of that customer's business made that an easy solution. A…

Privacy oriented niche, but yeah.

Re: The Trouble with CloudFlare

#280

I [I'm CloudFlare's CTO] have been engaging with the Tor folks through their Trac interface here for about 6 weeks: https://trac.torproject.org/projects/tor/ticket/18361 and been very open about CloudFlare is addressing this. My plan is to continue to do so through that ticket as I've made various commitments there (some of which, like whitelisting, we've already rolled out). It's worth reading the entire ticket to g…

What's your timeline for being as open as the Tor folk about abuse of your network and start taking responsibility for all sort of internet scum being protected by your network and allowing them use of your infrastructure?

You seem keen on making locking out malicious use of Tor, when can we expect you to lock out malicious use of CloudFlare?

Post reply on HN