Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

21–30 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#21

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#22
post #19
post #9

I've got enough problems on my sites from Tor that I simply block T1 (Cloudflare's "country" code for Tor users) on their settings. Blocking whole countries used to be a Enterprise only feature, but now it's available to Pro users.

What problems do you have?

Not GP, but my guess is ban evasion.

Someone gets banned from bad behavior, they create a new account. So you IP ban them. Then they switch over to Tor and keep making new accounts from anonymized IPs and start disrupting the forum by spamming it with slurs. The only solution is to ban Tor.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#23

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

It would be cool if you could set a header to Cloudflare when a user is logged in, perhaps with that user's ID. That could then trigger significantly decreased security.

A kind of "if cookie exists in this format that indicates session then..." ?

That is interesting.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#24
post #18

Criminals will just hire a botnet, as we can see from all incoming spam email and forum bots, etc. For the rest of us who desire to be anonymous online, there is Tor. Whatever people can do over Tor, they can also do without Tor. You're probably never going to find them anyway, even if you would sue in the first place. This whole tor vs clearnet distinction is way overblown. Sure people will do more crap if they're a…

>Criminals will just hire a botnet

... if Tor proves ineffective. If not, then they'll definitely use Tor.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#27
post #21

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.

Source and more info: https://support.cloudflare.com/hc/en-us/articles/200168236-W...

Re: Dear customers of Cloudflare: an appeal regarding Tor

#28
post #19
post #9

I've got enough problems on my sites from Tor that I simply block T1 (Cloudflare's "country" code for Tor users) on their settings. Blocking whole countries used to be a Enterprise only feature, but now it's available to Pro users.

What problems do you have?

Somehow a crazy person decided that I was cheating on Google's SERP using "hacked routers" (?) and started to make random queries to my "/search" endpoint, dozens of "POST newsletter/add" with fake emails per second, and other really lame attempts to get on my nerve and cause downtime.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#30

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

Actually probably not very much traffic is from tor. Tor bandwidth is notoriously bad.
Post reply on HN