Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

281–290 of 361 posts

Re: The Trouble with CloudFlare

#281
post #275

Earlier quoted context omitted.

Yep and on top of that they have for years they have allowed DDoS 'booters' to stay online, with the claim of "we have no way to remove the content, we're just a reverse proxy." If they're not actually hosting it, they think it's OK for whatever it is to pass through their network. http://www.crimeflare.com/damon.html

Aye, thanks for the write-up! I don't really get them either, surely they have enough paying customers to be able to afford some basic data hygiene. I'd really like to find some ways to make it more costly for them to keep the scum on their networks than to send out stupid "we r a reverse proxy!!!" replies, that clearly have nothing to do with anything. But yeah, keep complaining about Tor, good job CloudFlare /s

Let me get this straight.

People are criticizing CloudFlare for inconveniencing Tor users - a tool which, among other things, can be used to fight censorship.

At the same time, people are calling them out on their abuse policy which essentially boils down to "We won't take down sites based on content unless we receive a court order telling us to."

That's interesting, to say the least.

Re: The Trouble with CloudFlare

#282
post #162

Earlier quoted context omitted.

With signature detection, you're referring to browser fingerprinting? Because that's not going to work for Tor users (or, more specifically, TBB users).

I'm talking about, people who commit credit card fraud have a credit card whose billing address is in New York City but try to get the product shipped to Nigeria.

Thats only one type of credit card fraud. There's fraud against digital goods and gift cards. There's even carders who test credit cards online with real information before coding them to magnetic strip or selling them off. Heuristic based detection is very limited if there is no ip reputation or Javascript to do fingerprinting and other tricks to umask the user.

Ecommerce knows full well the cost of not supporting TOR. Just like we know the full cost when they deprecate browsers like IE9. Opportunity cost of building out more advanced systems to detect fraud compared to just blank banning open relays and TOR. I didn't even factor in the cost towards hardware when ecommerce site get hit with a bot running through a TOR endpoint or Open Relay.

Tor is not the only IPs get blocked. Ecommerce site frequently blacklist Azure, AWS and other hosting providers. They have the data they crunch and know full well who they will affect and what the cost is. There is always collateral damage.

You don't have the right to use any ecommerce site while using TOR much like you don't have the right to walk into a bank with a ski mask on and get service.

Re: The Trouble with CloudFlare

#283
post #18

I find Cloudflare's argument analogous to that of cash - i'm sure some huge percentage of all illegal transactions are with cash, but that does not mean the solution is to ban cash...though some would probably disagree

It's different in that I can accept a cash payment from you without having to worry that your cash will somehow harm me. Not so with a request coming from an IP address from which malicious requests are known to originate. So with cash, people can disagree on its benefits and drawbacks to society as a whole, but as long as it's legal, there's little reason for me, individually, to not use it, regardless of my opinion…

> without having to worry that your cash will somehow harm me.

Really? What if it is counterfeit? What if it has some kind of poison, germ, or disease on it?

I get your general point I think, but cash can definitely harm you.

Re: The Trouble with CloudFlare

#284
post #281
post #275

Earlier quoted context omitted.

Aye, thanks for the write-up! I don't really get them either, surely they have enough paying customers to be able to afford some basic data hygiene. I'd really like to find some ways to make it more costly for them to keep the scum on their networks than to send out stupid "we r a reverse proxy!!!" replies, that clearly have nothing to do with anything. But yeah, keep complaining about Tor, good job CloudFlare /s

Let me get this straight. People are criticizing CloudFlare for inconveniencing Tor users - a tool which, among other things, can be used to fight censorship. At the same time, people are calling them out on their abuse policy which essentially boils down to "We won't take down sites based on content unless we receive a court order telling us to." That's interesting, to say the least.

One is a tool that can be (and is being) used for all sorts of good purposes; run by mostly volunteers and whose entire reason for existence is not policing their network, because that would defeat the entire purpose of the endeavor.

The other one is a for-profit organization who's CEO's rationalization for taking money from internet scum is that if he doesn't take it, someone else will [0].

And to be clear, you are not quoting their abuse policy correctly. They say they will MITM phishing and malware sites to insert warning banners and take down childporn.

They will however not tell a scammer "Hi, please take your business elsewhere" based on some misguided "CloudFlare will save the internet"-fantasy.

[0] https://blog.cloudflare.com/thoughts-on-abuse/

Re: The Trouble with CloudFlare

#285
post #166

Earlier quoted context omitted.

So a single IP address can DDoS each page of a website for a little while before CloudFlare blocks them? That makes the whole protection pretty useless. I guess it would stop someone from brute-forcing password attempts, but that's not the only thing they're trying to protect against here.

A single IP can't "DDoS" anything.

Ha! Seriously though if some set of IPs is DoSing then they have to take action against at least some of the IPs in the set.

Re: The Trouble with CloudFlare

#286
post #196

Earlier quoted context omitted.

> It's like city guards banning everyone with a mask from entering and issuing IDs to them. The flaw in this analogy is that in this case the mask makes every person completely indistinguishable from every other person wearing the mask. In this case, one ID is issued to every person wearing the mask. When 90%+ of the people with this ID are criminals and vandals, blocking anyone with this ID is a pretty obvious and e…

That's a crazy thing to do. Why would you block everyone? This would completely erode privacy online. As I said elsewhere, if you see 1000 masked people rush into a bar and block the entrance with their bodies, is the solution to block all masked people from going to all establishments? Clearly, if this happened IRL, people would just put a limit on the number of masked people entering that bar until there wasn't a g…

>Clearly, if this happened IRL, people would just put a limit on the number of masked people entering that bar until there wasn't a group of 1000 of them trying to get in.

IRL, the bar would call the police and anti-riot forces would move in with crowd control equipment. Tear gass would be launced at the masked people and a lot of the masked people would be hauled to the police station where their identity would be recorded and a background check would be performed. It's not pretty but it's reasonable.

I have used Tor out of a legitimate wish for privacy. I have cursed Cloudflare and Google in passing to myself for their captchas presented to me when I've browsed through Tor.

Captchas in general are a royal pain in the butt, but they are among the most effective at protecting sites from abuse, so even though they annoy me at times, I hold the view that they are a net positive.

If you want to help preserve anonymity, I think the best course of action is not to focus on Clouflare, but instead to help maintain one or more communities on onion sites. The change must come from within. Once it has been shown that an onion site is able to provide useful services over time with privacy but with the same level of protection from abuse and bad people, then, in my view, it is time to reach out and educate the wider 'net on how this can be done.

Re: The Trouble with CloudFlare

#287

Earlier quoted context omitted.

Definitely, but they shouldn't complain when the public Internet (Cloudflare) blocks them or views their traffic differently. Anonymity comes at a price, and this is one of them. I think TOR is an important project, but this blog post by them is completely ridiculous and ignores reality. Why should TOR get a pass on this when network operators need to protect their network from abuse? The choices are either 1) let th…

Complain is exactly what they should do. People should care about privacy even when it's other people's privacy.

Haha if CF get this kind of response to their gentle observations I'd hate to see what a frank honest complaint would get...

Re: The Trouble with CloudFlare

#288

I [I'm CloudFlare's CTO] have been engaging with the Tor folks through their Trac interface here for about 6 weeks: https://trac.torproject.org/projects/tor/ticket/18361 and been very open about CloudFlare is addressing this. My plan is to continue to do so through that ticket as I've made various commitments there (some of which, like whitelisting, we've already rolled out). It's worth reading the entire ticket to g…

I'm a long-time Tor user that's been affected by CloudFlare captchas for a few years. I appreciate that you (CloudFlare) are trying to tackle the problem, but I feel that both CloudFlare and the Tor community have defeatist attitudes toward this issue. I have the following suggestions for CloudFlare: 1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisti…

1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisting Tor? For example, when a customer selects to Block or Captcha Tor, a tiny link could show up somewhere that says something like "This affects users who seek privacy, find out more."

I'll make sure the product team sees that suggestion.

2. In addition to better docs, can you setup something that lets site operators view the site as a Tor user?

That seems like an enormous amount of work when anyone can just get the Tor Browser and test it out.

3. The latest CloudFlare blog post on Tor says "you can do a lot of harm just with GETs." I wish you would give more thought to the idea of a read-only option for non-whitelisted Tor users. If GET requests are harmful (I'm skeptical), reducing the harm of GET requests seems like a much easier problem than the overall problem.

If you read the Trac thread you'll see that I've answered that. In short, I don't want to do it because that diverts engineering resource away from the right thing to work on (which is reduce the need for CAPTCHA).

Re: The Trouble with CloudFlare

#289

Earlier quoted context omitted.

They also protect against ddos, sqli, overuse, bots etc. so comment spam is only one problem and get requests are not always safe. You'd think they could be far more sophisticated about reputation though and adjust it in realtime so that ips are by default trusted and are marked down temporarily for bad behaviour.

When are GET requests unsafe?

ddos or sqli, see the cf article

Re: The Trouble with CloudFlare

#290
post #282

Earlier quoted context omitted.

I'm talking about, people who commit credit card fraud have a credit card whose billing address is in New York City but try to get the product shipped to Nigeria.

Thats only one type of credit card fraud. There's fraud against digital goods and gift cards. There's even carders who test credit cards online with real information before coding them to magnetic strip or selling them off. Heuristic based detection is very limited if there is no ip reputation or Javascript to do fingerprinting and other tricks to umask the user. Ecommerce knows full well the cost of not supporting T…

> Thats only one type of credit card fraud.

It's also only one type of bad act. Yet no others exist for which IP blacklisting is the only possible solution.

> There's fraud against digital goods and gift cards.

So treat gift cards as passthrough. Don't ship something to Nigeria if it was paid for with a gift card purchased with a credit card with a billing address in NYC.

And the idea that any meaningful number of people are going to use stolen credit cards to buy digital goods instead of just torrenting them is ridiculous.

> You don't have the right to use any ecommerce site while using TOR much like you don't have the right to walk into a bank with a ski mask on and get service.

Yet I can use an ATM or online banking while wearing a ski mask or using coffee house wifi with no trouble at all for either me or the bank, because we know how to solve that problem and it doesn't require IP blacklisting.

Post reply on HN