Dear customers of Cloudflare: an appeal regarding Tor
51–60 of 172 posts
Re: Dear customers of Cloudflare: an appeal regarding Tor
#52Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place? Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data. Tor users should take those CAPTCHAs as a…
What hosting is acceptable for your privacy wishes? Given that "a contracted party sees plaintext" is apparently the issue, the following clearly are not ok: a) any SaaS b) any of the cloud providers when their load-balancing offerings are used in HTTP mode (e.g. Amazon ELB) c) any traditional "shared" hosting company Are VPSes trustworthy enough, or does it have to be dedicated hardware? Dedicated hardware under dir…
In practice, a rented VPS or dedicated server that terminates its own TLS connections can be considered very private. It's not impossible for the hosting company to acquire the private key but it would require real effort, business risk, and potential liability.
Even if you're not worried about rogue employees, you have to worry about mistakes like the infamous "Cloudbleed" bug that leaked private user traffic.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#53Earlier quoted context omitted.
What problems do you have?
Not GP, but my guess is ban evasion. Someone gets banned from bad behavior, they create a new account. So you IP ban them. Then they switch over to Tor and keep making new accounts from anonymized IPs and start disrupting the forum by spamming it with slurs. The only solution is to ban Tor.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#54Earlier quoted context omitted.
This seems less like a dialogue revolving around the post and more like a promotion of TOR
It's an argument for "why you should care", which is relevant to the post.
I'm not involved in politics enough for it to be something very dangerous for me -- it's just non-sense things I want to see that I cannot because of silly regulators wanting to look important. But at the same time, trying to browse around via Tor to bypass these restrictions make it impossible at times to access information that Роскомнадзор has decided Russians shouldn't be allowed to access.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#55Earlier quoted context omitted.
Eh, I really doubt that it's designed to punish people who aren't tracking. Tracking makes users much more valuable, but the average legitimate user who isn't being tracked is still probably net positive value, so it wouldn't make sense to just block them outright. I think the problem is that a very high percentage of malicious behavior online comes from Tor, certain IP ranges, VPNs, scrapers that don't run Javascrip…
Cranky nerd here. I've tried to use Tor to access websites for legitimate purposes and found much of the web has become unusable recently. But perhaps you need a motivating example, since you don't think there's any value in supporting Tor! I'll give you some. - Security researcher wishes to contact an organization about a security hole in their site or product, but doesn't know if they'll be sued, so they want to pr…
I never said that.
I do think that the onus is on you to explain to whatever company you're railing against here why its in their best interest to welcome Tor traffic, particularly if it will make them more vulnerable. And sorry, to me you're not doing a good job of making that case. These examples seem like edge cases for the vast majority of websites. If I was blocking Tor (I'm not), I wouldn't reconsider my position from these scenarios. The cost is simply too high for too little benefit to too few people, probably none of which are my target audience.
And just to be clear, I truly understand the value of Tor and similar projects, and I hope we get more of them and they're more widely supported. But they come with real downsides too, so it's not surprising to me that many businesses and governments aren't going to out of their way to support them. That's the price you pay.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#56Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place? Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data. Tor users should take those CAPTCHAs as a…
It's a trade-off. If you trust Cloudflare it adds additional protection against bad guys. If you don't trust them don't use them. Same with Amazon or any other place where you can rent server room. Using Cloudflare gives control for control over which part of their site can use shared cache and which is direct link. If you don't trust anyone, run your own servers and don't hire sysadmins.
People you hire can be vetted, fired, sued, and even imprisoned for violating your users' privacy. Blindly handing over your users' data to a third-party includes none of these protections. You're simply abdicating responsibility.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#57Earlier quoted context omitted.
are there any researched measurements to show exactly how much is available? obviously it would vary greatly depending on where the connection is going... but wondering if there is some overarching idea of what it has..
https://metrics.torproject.org/bandwidth.html Currently the network is processing ~125Gbit/s of traffic.
seems like a good amount?
Re: Dear customers of Cloudflare: an appeal regarding Tor
#58Earlier quoted context omitted.
and The Tor Projects response to that: https://blog.torproject.org/trouble-cloudflare They have been in this dispute with each other for a long time.
blog.torproject.org uses an invalid security certificate. This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#592018 ... im too lazy to input a captcha dear lord, the how many other things are you too lazy to do
Re: Dear customers of Cloudflare: an appeal regarding Tor
#60Earlier quoted context omitted.
What hosting is acceptable for your privacy wishes? Given that "a contracted party sees plaintext" is apparently the issue, the following clearly are not ok: a) any SaaS b) any of the cloud providers when their load-balancing offerings are used in HTTP mode (e.g. Amazon ELB) c) any traditional "shared" hosting company Are VPSes trustworthy enough, or does it have to be dedicated hardware? Dedicated hardware under dir…
Yes, options A, B, and C are technologies that shouldn't be used where user privacy is highly valued. They violate the fundamental concept of end-to-end encryption. In practice, a rented VPS or dedicated server that terminates its own TLS connections can be considered very private. It's not impossible for the hosting company to acquire the private key but it would require real effort, business risk, and potential lia…