Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

331–340 of 361 posts

Re: The Trouble with CloudFlare

#331
To me personally all of this just seems like fluff. I can't be the only one that feels this way.

I don't want to 'prove I'm a human' to view your crappy site. I'll go and look at the other bits of the Internet instead.

As an individual browsing, the only contact I have with CloudFlare is a bouncer telling me 'no shoes no entry'.

Your entire company to me feels like a pointless gatekeeper because of these shenanigans (on and off of Tor).

To be perfectly clear - CloudFlare, as a brand, is tainted to me, and I expect to many others.

Fundamentally I don't think CloudFlare cares because their customers are not the viewers of websites - and if the viewers of websites come to think of CloudFlare as toxic - it still doesn't matter to them directly.

Re: The Trouble with CloudFlare

#332

Earlier quoted context omitted.

1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisting Tor? For example, when a customer selects to Block or Captcha Tor, a tiny link could show up somewhere that says something like "This affects users who seek privacy, find out more." I'll make sure the product team sees that suggestion. 2. In addition to better docs, can you setup something that let…

>> 2. In addition to better docs, can you setup something that lets site operators view the site as a Tor user? > > That seems like an enormous amount of work when anyone can just get the Tor Browser and test it out. Sure, but most site operators aren't going to get the Tor browser to test it out -- especially if they don't realize that that is something they should do. By "view site as Tor user" I simply meant havin…

But Tor users are complaining about the specific situation where the Tor Browser is used. I don't think that's easy to simulate (or at least I think it's easier for people just to get the Tor Browser).

Re: The Trouble with CloudFlare

#333

Earlier quoted context omitted.

1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisting Tor? For example, when a customer selects to Block or Captcha Tor, a tiny link could show up somewhere that says something like "This affects users who seek privacy, find out more." I'll make sure the product team sees that suggestion. 2. In addition to better docs, can you setup something that let…

> If you read the Trac thread you'll see that I've answered that. In short, I don't want to do it because that diverts engineering resource away from the right thing to work on (which is reduce the need for CAPTCHA). I agree, but thinking about GET-only requests is one approach to reducing the need for CAPTCHA. For example, maybe CloudFlare could have better Tor defaults for sites that are serving only static content…

I agree, but thinking about GET-only requests is one approach to reducing the need for CAPTCHA. For example, maybe CloudFlare could have better Tor defaults for sites that are serving only static content, and default to Captcha for sites that are POST-heavy (just a high level idea).

To be honest I'm not interested in solving the CAPTCHA problem just for Tor. That doesn't make a lot of sense. What I am working on is an overall solution so that the need for CAPTCHAs at all is diminished.

Re: The Trouble with CloudFlare

#334

Earlier quoted context omitted.

1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisting Tor? For example, when a customer selects to Block or Captcha Tor, a tiny link could show up somewhere that says something like "This affects users who seek privacy, find out more." I'll make sure the product team sees that suggestion. 2. In addition to better docs, can you setup something that let…

> If you read the Trac thread you'll see that I've answered that. In short, I don't want to do it because that diverts engineering resource away from the right thing to work on (which is reduce the need for CAPTCHA). I agree, but thinking about GET-only requests is one approach to reducing the need for CAPTCHA. For example, maybe CloudFlare could have better Tor defaults for sites that are serving only static content…

I agree, but thinking about GET-only requests is one approach to reducing the need for CAPTCHA. For example, maybe CloudFlare could have better Tor defaults for sites that are serving only static content, and default to Captcha for sites that are POST-heavy (just a high level idea).

To be honest I'm not interested in solving the CAPTCHA problem just for Tor. That doesn't make a lot of sense. What I am working on is an overall solution so that the need for CAPTCHAs at all is diminished.

Re: The Trouble with CloudFlare

#335

Earlier quoted context omitted.

This is where 3D Secure truly shines; instead of completely refusing a transaction, you can request the issuing bank (= bank of the card used to pay with) to accept the liability in case of fraud (normally, it's the merchant who has to give the money back). Usually the issuing bank will then request the customer for additional challenge, e.g. a 2FA token, a code in SMS, or just their birthday. Some don't even require…

3D Secure is a complete disaster. It encourages users to put ridiculously sensitive information like social security numbers and bank credentials into an iframe in the merchant site. This trains users to be phished.

Eh. 3D Secure is a protocol which can be implemented in reasonable ways. My bank has a 2FA in there.

Re: The Trouble with CloudFlare

#336

Earlier quoted context omitted.

Social security numbers?! Who the hell implemented it like THAT? 3D Secure redirects to the bank's site (not in an iframe! a real window with a visible address bar) where you enter a one-time code from SMS!

I have worked with systems implementing 3D Secure and have multiple credit cards that trigger it. I can assure you that the standard deployment for US-based banks and merchants uses iframes and in the majority of cases will ask for enough personal information to steal your identity or drain your bank account.

I assume this is a US problem because in the US card fees are high enough that banks don't need to worry too much about fraud yet. Look at European banks if you want to see reasonable 3D Secure.

Re: The Trouble with CloudFlare

#337

Earlier quoted context omitted.

I see a lot of fraud on my site as well, and I can say that there are some ISPs in Eastern Europe and Asia that are just as likely as Tor as being the origin for a malicious attack. I don’t block them either. Instead, I use fail2ban with a 30min ban for the IP for all my servers, and have the rest of the system hardened. Also, I add an additional delay that’s just below the timeout that browsers have for each request…

But Tor is not specifically treated differently... their exit IPs cross a threshold and CAPTCHA's are applied, just like with your fail2ban solution.

There is a difference: They ban each IP from all their services. And eternally, not just for 30min.

Re: The Trouble with CloudFlare

#338

I [I'm CloudFlare's CTO] have been engaging with the Tor folks through their Trac interface here for about 6 weeks: https://trac.torproject.org/projects/tor/ticket/18361 and been very open about CloudFlare is addressing this. My plan is to continue to do so through that ticket as I've made various commitments there (some of which, like whitelisting, we've already rolled out). It's worth reading the entire ticket to g…

Hello, please also consider VPN usage. Unlike Tor, we even pay for this service, because we take it so seriously.

Despite using the most reputable VPN provider I could find with a serious privacy policy; I've seen a steady increase in Captcha requests from CloudFlare to simply view read-only pages. And all I can think is that the Captcha page often requires the same amount of bandwidth as the page I was requesting in the first place.

The net effect is that it's not saving you any CPU usage or bandwidth (if anything, it's costing you more as we still request the actual page after the Captcha system runs), it's making customers like me abandon your customer's sites out of frustration, and it's eroding the last line of defense we have against invasive tracking.

I'm sympathetic to the problem you're trying to solve, but surely there must be a better way for simple GET requests.

This doesn't just affect people like me as a user. Having experienced this, I would be averse to deploying or recommending CloudFlare in its current state.

Re: The Trouble with CloudFlare

#339
post #7

This is a tough situation. I don't know about 94% of TOR traffic being fraudulent but I'm sure it's high. But I'm one of the legit users that gets taken out by blacklisting. I use a VPN service pretty regularly and it makes accessing my Cloudflare account and sites using it incredibly annoying.

> I don't know about 94% of TOR traffic being fraudulent but I'm sure it's high. I was curious and ran a quick check on my servers. 5 servers, about 300 domains, checked my logs going back 1 week. I could find just ONE legitimate session. Everything else was something trying to break WordPress or PHPMyAdmin or something else. I'd love to support Tor but I feel like I can't fight this fight.

While still higher than regular ISP addresses, VPN abuse should be significantly lower than Tor abuse on account of these services costing real money. And nearly all of them not accepting anonymous forms of payment.

I expect my VPN use to keep me hidden amongst a crowd from various internet companies trying to track and profile me; but I don't expect for a minute that it offers protection against criminal activities (and I have no intention of engaging in such things.) Any intelligent criminal would likely feel the same way and not use a service with their real billing information to commit crimes. Especially with Tor available.

Yet despite this, I am constantly hit by CloudFlare captchas on sites that are very clearly not being hit by DoS traffic. Further, it seems site operators don't even realize this is happening. When I reported the captcha issue to Zotac's Twitter account, they had no idea CloudFlare was doing this.

Google is also a huge offender with the captchas. I'm this close to switching to Duck Duck Go. Facebook is too, but I'm fine with not ever going there.

Re: The Trouble with CloudFlare

#340
I have a question that I'm hoping will spur some discussion and maybe I can learn some stuff.

"Is anonymity in Tor incompatible with low-latency?"

I ask this having read this: http://freehaven.net/anonbib/cache/pets13-flow-fingerprints....

I suspect that countermeasures to defeat deanonimization all have a negative impact on latency(e.g. inserting extra packets, pausing between sends).

If the answer to my question is yes, then maybe the best thing the Tor project can do is abandon its push for low latency, and instead focus on anonymity. If Tor we're a much higher latency network attackers would probably find it less interesting.

Post reply on HN