Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

351–360 of 361 posts

Re: The Trouble with CloudFlare

#351

Tor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of…

The post from the Tor project does not state anywhere that Tor is not used by botnets or that it's used for malicious purposes. They specifically question your specific assertion that 94% of Tor traffic is malicious. I'm not surprised, it's quite a statement and it calls for some supporting evidence. Surely you can see how, given the amount of outreach they do to educate regular people about the positive uses of Tor,…

The calculation must be based on their internal data. How exactly are they supposed to show the supporting evidence without compromising their users privacy?

You seem to be engaged in goalpost shifting. CloudFlare have no incentive to make this figure up. They aren't going to give random people on the internet root access to their servers to recalculate the figure themselves. By claiming they aren't "sticking to the facts" all you do is show a closed mind.

Tor proxies tons of bad stuff. Everyone who has run a big web site knows this. Remember you only need one or two bad guys with fast enough tools to generate a flood of malicious traffic that completely overwhelms thousands of legit web browsing users. It's just so trivial for a minority of bad actors to end up dominating traffic profiles. So, I believe Cloudflare.

Tor guys love to talk about journalists, whistleblowers etc. That must be a really tiny amount of their overall traffic compared to people who just want to torrent, be assholes on forums etc. Just because they love to "educate" anyone who disagrees with them doesn't mean they're right.

Re: The Trouble with CloudFlare

#352

Earlier quoted context omitted.

I agree, but thinking about GET-only requests is one approach to reducing the need for CAPTCHA. For example, maybe CloudFlare could have better Tor defaults for sites that are serving only static content, and default to Captcha for sites that are POST-heavy (just a high level idea). To be honest I'm not interested in solving the CAPTCHA problem just for Tor. That doesn't make a lot of sense. What I am working on is a…

> What I am working on is an overall solution so that the need for CAPTCHAs at all is diminished. I like that idea, but my worry is it will take years to reach that point, and in the meantime Tor/VPN users will just have to suffer. I'd rather see some short-term fixes now and long-term solutions on the horizon. I admit: I have not read the entire Trac thread, so I'm not sure what your current roadmap is.

I like that idea, but my worry is it will take years to reach that point

It won't.

Re: The Trouble with CloudFlare

#353

Earlier quoted context omitted.

But Tor users are complaining about the specific situation where the Tor Browser is used. I don't think that's easy to simulate (or at least I think it's easier for people just to get the Tor Browser).

Tor users are complaining about the captchas. I'm not sure why you think it's so hard to create a sample captcha page to demonstrate the experience. You just need two pages: one with JS-enabled captchas and one with JS-disabled captchas. Do you need me to do this for you? Alternatively, you can create a dummy CloudFlare instance with /0 under Captcha, and put the URL to this in the docs, but this wont let users try t…

Tor users are complaining about the captchas. I'm not sure why you think it's so hard to create a sample captcha page to demonstrate the experience. You just need two pages: one with JS-enabled captchas and one with JS-disabled captchas. Do you need me to do this for you?

It's not that simple.

reCAPTCHA makes an on the fly decision about the strength of the CAPTCHA served depending on the visitor. In the case of Tor there's no visitor information other than IP address (and whatever the browser gives as User-Agent etc.).

So, I can dummy up a CAPTCHA page trivially, what I can't do is dummy up the experience of a Tor Browser user hitting a reCAPTCHA. The way to do that is run the Tor Browser.

Re: The Trouble with CloudFlare

#354
post #348

Earlier quoted context omitted.

Which VPN are you talking about?

It's happened to me with Astrill, ExpressVPN, and vpn.ac so far. Usually I can reconnect to get a new IP to avoid catpchas again, so it seems only certain IPs are being poisoned. And no doubt because they are doing things they shouldn't. Hence the sympathy part. If anything, it's been surprising to me to learn just how many sites are using CloudFlare ;) I don't have a site handy that's triggering it right this moment…

Thanks. I am hopeful that the solution we come up with for Tor will be applicable to situations like this.

Re: The Trouble with CloudFlare

#355

Earlier quoted context omitted.

Tor users are complaining about the captchas. I'm not sure why you think it's so hard to create a sample captcha page to demonstrate the experience. You just need two pages: one with JS-enabled captchas and one with JS-disabled captchas. Do you need me to do this for you? Alternatively, you can create a dummy CloudFlare instance with /0 under Captcha, and put the URL to this in the docs, but this wont let users try t…

Tor users are complaining about the captchas. I'm not sure why you think it's so hard to create a sample captcha page to demonstrate the experience. You just need two pages: one with JS-enabled captchas and one with JS-disabled captchas. Do you need me to do this for you? It's not that simple. reCAPTCHA makes an on the fly decision about the strength of the CAPTCHA served depending on the visitor. In the case of Tor…

Good point. That did not occur to me.

edit: Thanks for the dialogue thus far.

Re: The Trouble with CloudFlare

#356

Earlier quoted context omitted.

The post from the Tor project does not state anywhere that Tor is not used by botnets or that it's used for malicious purposes. They specifically question your specific assertion that 94% of Tor traffic is malicious. I'm not surprised, it's quite a statement and it calls for some supporting evidence. Surely you can see how, given the amount of outreach they do to educate regular people about the positive uses of Tor,…

The calculation must be based on their internal data. How exactly are they supposed to show the supporting evidence without compromising their users privacy? You seem to be engaged in goalpost shifting. CloudFlare have no incentive to make this figure up. They aren't going to give random people on the internet root access to their servers to recalculate the figure themselves. By claiming they aren't "sticking to the…

If the calculation is based on data, they should show it. Since they did not, the Tor project made a best-effort guess as to how they could have come up with this (obviously ridiculous) number of 94% of traffic being malicious.

I have run a Tor exit node, so I have some intuitive idea of the amount of malicious traffic. CloudFlare are full of shit.

The rest of your comment is engaging in the exact same goalpost shifting you accuse me of, suggesting that because there are one or two bad guys it's really no big issue that they block thousands of legitimate users.

Also you completely ignored the most important point of my comment, which is that this problem is not restricted to tor!

If you wish to further the conversation, please actually respond to my points. Thank you.

Re: The Trouble with CloudFlare

#357
post #348

Earlier quoted context omitted.

It's happened to me with Astrill, ExpressVPN, and vpn.ac so far. Usually I can reconnect to get a new IP to avoid catpchas again, so it seems only certain IPs are being poisoned. And no doubt because they are doing things they shouldn't. Hence the sympathy part. If anything, it's been surprising to me to learn just how many sites are using CloudFlare ;) I don't have a site handy that's triggering it right this moment…

Thanks. I am hopeful that the solution we come up with for Tor will be applicable to situations like this.

Awesome news!! Thank you very much for taking the time to respond, and for looking into a solution for Tor/VPNs. It's very much appreciated :D

Re: The Trouble with CloudFlare

#358
post #66

Earlier quoted context omitted.

The main point I took away from the article, that from one exit node many users originate. Some users are spammer. They contaminate the exit node IP. CF blocks an IP for spam, but does not remove the block after some time (when the spammer moved on).

That's definitely a legitimate point, but not the main point IMHO. The main point is that Tor makes zero effort to clean up the problem and uses the legitimate Tor users as helpless, scapegoated victims and a bullying tactic. "But think of the oppressed users!" Sorry, not buying it. The blacklisted IP lifetime problem is real though. It's a problem I've had to raise several times with our product and network teams. P…

Interesting point, what would "Tor cleans up" mean?

Re: The Trouble with CloudFlare

#359
post #261

Earlier quoted context omitted.

The somewhat-faster way to reduce this annoyance (I've been hit by this) is to 'block'/captcha the offending IPs for a time (depends on whatever metrics CloudFlare think is best) then unblock it. At least this will reduce legitimate user's annoyance, instead of being blocked indefinitely My own experience: Tried accessing wikialpha from work LAN, 'blocked' by endless captcha (for a few months already) and opening the…

Given how much of TOR traffic is malicious (94%), what you propose would get all TOR traffic always considered malicious.

Care to share a source for "TOR traffic is malicious (94%)"?

What does malicious percentage of traffic in this case mean? Malicious sessions? IPs used? Packets? Users?

Re: The Trouble with CloudFlare

#360
post #261

Earlier quoted context omitted.

Given how much of TOR traffic is malicious (94%), what you propose would get all TOR traffic always considered malicious.

Care to share a source for "TOR traffic is malicious (94%)"? What does malicious percentage of traffic in this case mean? Malicious sessions? IPs used? Packets? Users?

The number is in the CloudFlare blog post that started this.

> Based on data across the CloudFlare network, 94% of requests that we see across the Tor network are per se malicious. That doesn’t mean they are visiting controversial content, but instead that they are automated requests designed to harm our customers.

Post reply on HN