Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

301–310 of 361 posts

Re: The Trouble with CloudFlare

#301

Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…

More than a hard problem, this is arguably an intractable problem. Tor is already vulnerable, and trading anonymity for convenience (or even appearing to do so) would be unworkable. There are other anonymity systems waiting in the wings, and they would arguably gain support if the Tor Project sold out to CloudFlare. The only viable approach for Tor, as I see it, is to treat CloudFlare as damage, to be routed around.

Re: The Trouble with CloudFlare

#302
post #278

Earlier quoted context omitted.

It's not his job to format his comment to make it convenient for you to rebut. I agree that it's not at all clear how your reply addresses the original comment. Perhaps you could fix that by quoting the portions of the original comment you're replying to, rather than requiring line numbers.

Correct me if I am wrong, but I should format my comment because he refuses to do so, right? He refused to respond to my response to his even in part, though I should spend more time on it, right. My reading of his comment is he didn't read my comment, and he he can't read, there's nothing I am able to do.

Look, I'm just letting you know that from a third party perspective, you come across as the unreasonable one, both in this sub-thread, and throughout most of these comments. It seems like people are bringing up good points and you're refusing to engage, perhaps because you're so invested in your own point of view that you're unable to recognize the legitimacy of others'.

To your specific question, the parent comment's points were well reasoned, and your response read as completely orthogonal. If it wasn't, then yes, the onus is on you to demonstrate the relevance.

Re: The Trouble with CloudFlare

#303
I dislike CloudFare adoption. More and more I come to sites and need to wait 5 seconds, caused by their DDoS protection. Such things make the less more and more aweful.

Re: The Trouble with CloudFlare

#304
post #278

Earlier quoted context omitted.

It's not his job to format his comment to make it convenient for you to rebut. I agree that it's not at all clear how your reply addresses the original comment. Perhaps you could fix that by quoting the portions of the original comment you're replying to, rather than requiring line numbers.

Correct me if I am wrong, but I should format my comment because he refuses to do so, right? He refused to respond to my response to his even in part, though I should spend more time on it, right. My reading of his comment is he didn't read my comment, and he he can't read, there's nothing I am able to do.

Plain English please, no idea beyond your meta ranting about how I comment on a topic, when your not even express a logic response to my comment. More to the point if you have something to express about the topic, if you want to be meta on comments post a link to an "Ask HN:" state a position in Plain English and post a link to it here. Cheers!

Re: The Trouble with CloudFlare

#305
post #196

Earlier quoted context omitted.

> It's like city guards banning everyone with a mask from entering and issuing IDs to them. The flaw in this analogy is that in this case the mask makes every person completely indistinguishable from every other person wearing the mask. In this case, one ID is issued to every person wearing the mask. When 90%+ of the people with this ID are criminals and vandals, blocking anyone with this ID is a pretty obvious and e…

That's a crazy thing to do. Why would you block everyone? This would completely erode privacy online. As I said elsewhere, if you see 1000 masked people rush into a bar and block the entrance with their bodies, is the solution to block all masked people from going to all establishments? Clearly, if this happened IRL, people would just put a limit on the number of masked people entering that bar until there wasn't a g…

> As I said elsewhere, if you see 1000 masked people rush into a bar and block the entrance with their bodies, is the solution to block all masked people from going to all establishments?

Try wearing a mask into a petrol station or convenience store. They've already performed the assessment of 'potential sale vs getting robbed', and decided the risk factor they'd like to accept.

Re: The Trouble with CloudFlare

#306
post #230

Earlier quoted context omitted.

You still purposefully resolve spam domains on at least tim.ns.cloudflare.com and leah.ns.cloudflare.com and refuse do to anything about it. I see a certain hypocrisy in claiming to protect your customers, and at the same time enabling criminal operations through allowing them use of your infrastructure. (For the record and because you tell me this at every point of contact, I know your main business is reverse-proxy…

Yep and on top of that they have for years they have allowed DDoS 'booters' to stay online, with the claim of "we have no way to remove the content, we're just a reverse proxy." If they're not actually hosting it, they think it's OK for whatever it is to pass through their network. http://www.crimeflare.com/damon.html

I've had one incident that was very similar to this (DDoS raiding forum proxied through Cloudflare staging an attack against our servers).

When I reported it, they said they had informed the attackers of my report, which is sortof like having the police tell a gang you snitched on them and could have enabled retaliation.

When I asked them if they had indeed leaked my personal contact information in this report, they responded with this:

As indicated at https://www.cloudflare.com/abuse/form and to which you expressly agreed: "By submitting this report, you consent to the above information potentially being released by CloudFlare to third parties such as the website owner, the responsible hosting provider, law enforcement, and/or entities like Chilling Effects"

And then when I followed up again, they responded with this:

Again, to re-iterate, by submitting a report at https://www.cloudflare.com/abuse/form, you expressly agreed: "By submitting this report, you consent to the above information potentially being released by CloudFlare to third parties such as the website owner, the responsible hosting provider, law enforcement, and/or entities like Chilling Effects"

In this case, it appears that we chose not to forward your report to the website owner. However, we reserve the right to, and you should assume that this should happen when making reports to us.

I don't know what the legal implications of this are, suffice to say, protecting DDoS attackers for free while asking for legitimate sites to pay (in my case, the $6000/mo plan would be needed) feels a hell of a lot like extortion.

As for liability, ISPs aren't liable for hosted content, but there are exceptions (DMCA, CP), and legally, Cloudflare absolutely has legal liability here. They're not just linking to that content like with a BitTorrent tracker, they're literally serving it through their nginx servers.

Re: The Trouble with CloudFlare

#307
post #215

Earlier quoted context omitted.

How do you stop people from scraping your site? Databrokers frequently will mine social sites to build profiles on people. There's legitimate reasons to block TOR for read-only content.

Scrapers visit many unique URLs. Such request patterns should be fairly easily distinguishable from the rest of the visitors. To do it on a large scale in realtime something like loglog[1] counter could be used. [1] https://en.wikipedia.org/wiki/Flajolet%E2%80%93Martin_algori...

How do you id the scraper from request to request? Cookie? Bots can just discard. IP? Now we're back to the same problem. Some sort of super-cookie browser fingerprinting? Sure, maybe possible, but it's super sketchy and sacrifices anonymity which is important.

Re: The Trouble with CloudFlare

#308

Earlier quoted context omitted.

Yep and on top of that they have for years they have allowed DDoS 'booters' to stay online, with the claim of "we have no way to remove the content, we're just a reverse proxy." If they're not actually hosting it, they think it's OK for whatever it is to pass through their network. http://www.crimeflare.com/damon.html

I've had one incident that was very similar to this (DDoS raiding forum proxied through Cloudflare staging an attack against our servers). When I reported it, they said they had informed the attackers of my report, which is sortof like having the police tell a gang you snitched on them and could have enabled retaliation. When I asked them if they had indeed leaked my personal contact information in this report, they…

HN won't let me update this comment for some reason, so I'll just add this here:

The real issue here is that the web is becoming increasingly centralized, which means that we're becoming more dependant on the internal processes of a small handful of venture capital corporations for the web to work. Regardless of Cloudflare's current policy on Tor (they seem to be trying which is good), they could also just arbitrarily change that policy anytime they want, and this is a scary situation for the future of the web. It's a single point of failure for a large chunk of the web, for political manipulation and for advertiser and government spying. Tor (your last chance at a privacy web) users being unable to access major swaths of the web just happens to be the first sign of the implications of this. It's no surprise to me at all that we've seen so much interest in distributed web technologies lately (IPFS, ZeroNet).

Re: The Trouble with CloudFlare

#309

Earlier quoted context omitted.

Scrapers visit many unique URLs. Such request patterns should be fairly easily distinguishable from the rest of the visitors. To do it on a large scale in realtime something like loglog[1] counter could be used. [1] https://en.wikipedia.org/wiki/Flajolet%E2%80%93Martin_algori...

How do you id the scraper from request to request? Cookie? Bots can just discard. IP? Now we're back to the same problem. Some sort of super-cookie browser fingerprinting? Sure, maybe possible, but it's super sketchy and sacrifices anonymity which is important.

I don't think it is necessary to identify the scraper. Something simple should work, like counting how many unique URLs for a particular website got accessed in some period of time and comparing that to similar thing, but counted for known non-bot users (normalized). If one is much bigger than the other one - start requiring CAPTCHAs, but only for those requests, that are not part of known non-bot users set of our probabilistic counter of requests or even a separate bloom filter, depending on what is going to be more efficient and more accurate.

Re: The Trouble with CloudFlare

#310

Earlier quoted context omitted.

As a developer I will direct my clients away from CloudFlare services as long as CloudFlare continues this sort of attack on Tor which is ultimately an attack on privacy.

* facepalm * No room for nuance, huh? Or appreciation for the position CloudFlare is in and their obligation to their clients? How would you solve this? Abuse from Tor IPs is a known and documented problem. If you have a solution, I'll bet CloudFlare has a job opening.

If CloudFlare keeps blocking Tor, the blocks will be circumvented. Unfortunately, it's the assholes who will figure that out first. But so it goes in war.
Post reply on HN