Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

311–320 of 361 posts

Re: The Trouble with CloudFlare

#311

Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…

The post from the Tor project does not state anywhere that Tor is not used by botnets or that it's used for malicious purposes. They specifically question your specific assertion that 94% of Tor traffic is malicious. I'm not surprised, it's quite a statement and it calls for some supporting evidence. Surely you can see how, given the amount of outreach they do to educate regular people about the positive uses of Tor,…

Yes, that botnet dig is bullshit. Some botnets use Tor for C&C. But jerks don't need botnets to have lots of Tor exits. That's what VMs are for. Botnets give you lots of residential IPs.

Re: The Trouble with CloudFlare

#312
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

At a point in the recent past, around 90% of all E-mail traffic was spam. Now it's down to around 50% or so [1]. What happened? It could have been due to thousands of ISPs simultaneously cleaning up and policing their networks. But it also could be due to blocking tools getting better. Maybe the spammers moved away from E-mail to more profitable spam channels. Or is there just more legit traffic now, and the percenta…

Email didn't outrun the bear. It outran the other hiker.

The honeypot space for spam is now systems other than email. Social media. Blogspam. Web advertising. Dating services. SMS.

(I'm not sure precisely which, but pick from among there and you'll likely turn up the issues.)

Email is fairly well defended at this point, though not without considerable collateral damage (small / self-hosted email is quite difficult, most of us rely on a small number of high-volume providers who may present a considerable privacy risk).

Re: The Trouble with CloudFlare

#313
post #196

Earlier quoted context omitted.

That's a crazy thing to do. Why would you block everyone? This would completely erode privacy online. As I said elsewhere, if you see 1000 masked people rush into a bar and block the entrance with their bodies, is the solution to block all masked people from going to all establishments? Clearly, if this happened IRL, people would just put a limit on the number of masked people entering that bar until there wasn't a g…

> As I said elsewhere, if you see 1000 masked people rush into a bar and block the entrance with their bodies, is the solution to block all masked people from going to all establishments? Try wearing a mask into a petrol station or convenience store. They've already performed the assessment of 'potential sale vs getting robbed', and decided the risk factor they'd like to accept.

That's because IRL you're already pseudo anonymous.

Now imagine a convenience store that demands you to tell them where you've been this month and doesn't let you in otherwise.

Re: The Trouble with CloudFlare

#314
post #260
post #247

Earlier quoted context omitted.

I think it's clear he understands how it works. > what you are saying goes against Tor's principals That's why it will probably never be cleaned up. That's also why more and more people will probably block access from Tor. CloudFlare says they get a 95% attack rate from it. A blog post the other day said FotoForensics gets about 91% attacks from Tor. No one is going to put up with 91% attacks for long. And if that me…

> I think it's clear he understands how it works. Agree to disagree :) > if that means Tor becomes it's own walled garden that doesn't 'interact' with the public internet, so be it Most websites are not using Cloudflare and have no idea how to block a range of ips. So no Tor is not going to become its own walled garden.

>> I think it's clear he understands how it works. > Agree to disagree :)

I know very well how it works thank you very much. It doesn't mean I have to like it.

Since you're apt to throwing around unfounded accusations, I'll join the party. I have more experience than you do at running large networks, dealing with fraud, dealing with abuse, dealing with malware, and dealing with law enforcement/government agents. The Internet has enough problems with the well-run networks that actually care. We could care less about Tor users that might be blocked.

Re: The Trouble with CloudFlare

#315
post #212

Earlier quoted context omitted.

There is plenty of information to go off of. They just don't want to put in the engineering effort required to utilize it. Is there really a constant DDoS attack on all of these sites from users with no cookies?

On a given site, not necessarily, but on some sites that cloudflare is protecting, pretty much always would be my guess... cloudflare doesn't know you're not the spammer/bot/malicious actor using the same exit node... it only knows that you don't have any cookies, and that means you look a lot like the bad guys coming from the same IP. One could setup an IDENT-like service that delivers a hash for the source's route,…

There are a number of other ways to identify abuse.

Listed those in other responses.

Re: The Trouble with CloudFlare

#317

Earlier quoted context omitted.

The post from the Tor project does not state anywhere that Tor is not used by botnets or that it's used for malicious purposes. They specifically question your specific assertion that 94% of Tor traffic is malicious. I'm not surprised, it's quite a statement and it calls for some supporting evidence. Surely you can see how, given the amount of outreach they do to educate regular people about the positive uses of Tor,…

Yes, that botnet dig is bullshit. Some botnets use Tor for C&C. But jerks don't need botnets to have lots of Tor exits. That's what VMs are for. Botnets give you lots of residential IPs.

C&C? VMs? What?

Re: The Trouble with CloudFlare

#318
post #284
post #281

Earlier quoted context omitted.

Let me get this straight. People are criticizing CloudFlare for inconveniencing Tor users - a tool which, among other things, can be used to fight censorship. At the same time, people are calling them out on their abuse policy which essentially boils down to "We won't take down sites based on content unless we receive a court order telling us to." That's interesting, to say the least.

One is a tool that can be (and is being) used for all sorts of good purposes; run by mostly volunteers and whose entire reason for existence is not policing their network, because that would defeat the entire purpose of the endeavor. The other one is a for-profit organization who's CEO's rationalization for taking money from internet scum is that if he doesn't take it, someone else will [0]. And to be clear, you are…

Both are services which are used by a variety of people for both good and nefarious reasons. To paint TOR as the white knights of the internet is at best incredibly naive. There is a good reason that most mature security operations groups maintain blocklists of TOR exit nodes (in case it's not clear, that reason is the amount of alerts triggered by traffic from those nodes, relative to any other set of addresses).

Below is a direct quote from the article you have cited. It refutes your underlying premise, namely that cloudflare is in it for the money and doesn't care. The knee-jerk reaction that corporations take money for services, therefore they're evil, needs to die in fire.

""" LulzSec and other problematic customers tend to sign up for our free service and we don't make a dime off of them. When they upgrade they usually pay with stolen credit cards."""

Re: The Trouble with CloudFlare

#319
post #317

Earlier quoted context omitted.

Yes, that botnet dig is bullshit. Some botnets use Tor for C&C. But jerks don't need botnets to have lots of Tor exits. That's what VMs are for. Botnets give you lots of residential IPs.

C&C? VMs? What?

C&C = command and control [0]

VM = virtual machine (local or remote VPS) [1]

Let's say that I have a box with a couple quad-core Xeons and 64GB RAM, and a 100Mbps uplink. I can easily run 150-200 Debian VMs, each running one or more tor processes.

[0] https://security.radware.com/ddos-knowledge-center/ddospedia...

[1] VPS = virtual private server

Re: The Trouble with CloudFlare

#320
post #317

Earlier quoted context omitted.

C&C? VMs? What?

C&C = command and control [0] VM = virtual machine (local or remote VPS) [1] Let's say that I have a box with a couple quad-core Xeons and 64GB RAM, and a 100Mbps uplink. I can easily run 150-200 Debian VMs, each running one or more tor processes. [0] https://security.radware.com/ddos-knowledge-center/ddospedia... [1] VPS = virtual private server

Ah right, didn't think about running several Tor instances in VMs. I'm sure there are better ways to run Tor from VMs though, if you know how the protocol works just run instances of some program that runs it instead of running the whole thing in a VM.
Post reply on HN