Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

31–40 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#31
post #22
post #19

Earlier quoted context omitted.

What problems do you have?

Not GP, but my guess is ban evasion. Someone gets banned from bad behavior, they create a new account. So you IP ban them. Then they switch over to Tor and keep making new accounts from anonymized IPs and start disrupting the forum by spamming it with slurs. The only solution is to ban Tor.

Or, you know, limit the ability of newly created user to spam forums. Or put them on "must be reviewed" lists. Or...

The easiest solution is to ban Tor, but it's far from the only solution.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#32

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

Actually probably not very much traffic is from tor. Tor bandwidth is notoriously bad.

are there any researched measurements to show exactly how much is available?

obviously it would vary greatly depending on where the connection is going... but wondering if there is some overarching idea of what it has..

Re: Dear customers of Cloudflare: an appeal regarding Tor

#33
post #11

Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place? Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data. Tor users should take those CAPTCHAs as a…

It's a trade-off. If you trust Cloudflare it adds additional protection against bad guys. If you don't trust them don't use them. Same with Amazon or any other place where you can rent server room.

Using Cloudflare gives control for control over which part of their site can use shared cache and which is direct link.

If you don't trust anyone, run your own servers and don't hire sysadmins.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#34

There is a disconnect here: I've read so many technical articles from cloudflare about neat problems they solve while at the same time they just boldly say fuck you to net neutrality and aggressively try to get people on board with the tracking internet that their corporate partners desire so strongly. I get the sense these aren't the same groups of people at the company itself. I've been browsing anonymously with to…

Eh, I really doubt that it's designed to punish people who aren't tracking. Tracking makes users much more valuable, but the average legitimate user who isn't being tracked is still probably net positive value, so it wouldn't make sense to just block them outright. I think the problem is that a very high percentage of malicious behavior online comes from Tor, certain IP ranges, VPNs, scrapers that don't run Javascrip…

Cranky nerd here. I've tried to use Tor to access websites for legitimate purposes and found much of the web has become unusable recently.

But perhaps you need a motivating example, since you don't think there's any value in supporting Tor! I'll give you some.

- Security researcher wishes to contact an organization about a security hole in their site or product, but doesn't know if they'll be sued, so they want to protect their identity. (source: this is me; have met other people doing this)

- Pedophile (who doesn't want to be one) seeking therapy options that don't involve a high risk of being incarcerated or killed. (source: read an article about this)

- Teenager in a repressive environment trying to access LGBTQ resources; parents have a netfilter on, or maybe have snoopware on the router. (source: several acquaintances)

- Chinese citizen trying to find a different view of history (source: pretty freaking common, although Great Firewall makes it tricky)

These are people who don't have other, good options. And you'll need to be able to withstand the sizeable quantities of malicious traffic that don't come through Tor, so it's not like you really win anything. It's worth not blocking Tor.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#35

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

As a website operator too I don't see spammers, attackers and script kiddies from tor network with valid user agents (tor browser or mainstream up to date browsers). The worst I see in that traffic is very few people trying to post/upload something anonymously, but mostly it's just people trying to access a few pages anonymously. Bots and scrappers for some reason use fake user agents in tor network and just get 403s, but the amount of that is so tiny compared to the rest of the bots, that's it's not even worth mentioning. Tor network is sort of self-limiting in this regard, because it's too slow and too obvious for such use, it's only viable for casual browsing.

Cloudflare proved that it's both unwilling and unable to solve the problem.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#36
post #32

Earlier quoted context omitted.

Actually probably not very much traffic is from tor. Tor bandwidth is notoriously bad.

are there any researched measurements to show exactly how much is available? obviously it would vary greatly depending on where the connection is going... but wondering if there is some overarching idea of what it has..

https://metrics.torproject.org/bandwidth.html

Currently the network is processing ~125Gbit/s of traffic.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#37
post #26

Background on tor problems: https://blog.cloudflare.com/the-trouble-with-tor/

and The Tor Projects response to that: https://blog.torproject.org/trouble-cloudflare They have been in this dispute with each other for a long time.

blog.torproject.org uses an invalid security certificate.

This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#38

This shouldn’t be necessary. We changed our handling of Tor so long ago that I’ve forgotten how long go it was. If you are using the Tor Browser Bundle you should not see a CAPTCHA. If you do please report it to us.

I'm seeing the CAPTCHA a lot with the Brave Browser Tor Tab. You might want to reach out to the developers to make their Tor Tab be treated the same as the Tor Browser Bundle.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#39
post #11

Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place? Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data. Tor users should take those CAPTCHAs as a…

What hosting is acceptable for your privacy wishes? Given that "a contracted party sees plaintext" is apparently the issue, the following clearly are not ok:

a) any SaaS

b) any of the cloud providers when their load-balancing offerings are used in HTTP mode (e.g. Amazon ELB)

c) any traditional "shared" hosting company

Are VPSes trustworthy enough, or does it have to be dedicated hardware? Dedicated hardware under direct control of the company only? And how many companies run those, vs setups falling under a-c) above?

I see people make comments like this all the time when it is about Cloudflare, but somehow very seldom if it's about Amazon AWS, Shopify, ..., despite the same caveats applying to those, and it being widely accepted that third-party processing is fine if for a clear purpose and under proper contracts.

Post reply on HN