Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

51–60 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#52
post #39
post #11

Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place? Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data. Tor users should take those CAPTCHAs as a…

What hosting is acceptable for your privacy wishes? Given that "a contracted party sees plaintext" is apparently the issue, the following clearly are not ok: a) any SaaS b) any of the cloud providers when their load-balancing offerings are used in HTTP mode (e.g. Amazon ELB) c) any traditional "shared" hosting company Are VPSes trustworthy enough, or does it have to be dedicated hardware? Dedicated hardware under dir…

Yes, options A, B, and C are technologies that shouldn't be used where user privacy is highly valued. They violate the fundamental concept of end-to-end encryption.

In practice, a rented VPS or dedicated server that terminates its own TLS connections can be considered very private. It's not impossible for the hosting company to acquire the private key but it would require real effort, business risk, and potential liability.

Even if you're not worried about rogue employees, you have to worry about mistakes like the infamous "Cloudbleed" bug that leaked private user traffic.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#53
post #22
post #19

Earlier quoted context omitted.

What problems do you have?

Not GP, but my guess is ban evasion. Someone gets banned from bad behavior, they create a new account. So you IP ban them. Then they switch over to Tor and keep making new accounts from anonymized IPs and start disrupting the forum by spamming it with slurs. The only solution is to ban Tor.

Then they go an get a list of countless http or socks proxies and the solution is to...?

Re: Dear customers of Cloudflare: an appeal regarding Tor

#54
post #15
post #13

Earlier quoted context omitted.

This seems less like a dialogue revolving around the post and more like a promotion of TOR

It's an argument for "why you should care", which is relevant to the post.

Furthermore, as an expat living in Russia at the moment, it is quite surprising to one day be in an EU country and able to access any wide variety of sites, and the next day get a friendly message from Роскомнадзор telling me this website has been blocked for my protection or some other non-sense.

I'm not involved in politics enough for it to be something very dangerous for me -- it's just non-sense things I want to see that I cannot because of silly regulators wanting to look important. But at the same time, trying to browse around via Tor to bypass these restrictions make it impossible at times to access information that Роскомнадзор has decided Russians shouldn't be allowed to access.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#55
post #34

Earlier quoted context omitted.

Eh, I really doubt that it's designed to punish people who aren't tracking. Tracking makes users much more valuable, but the average legitimate user who isn't being tracked is still probably net positive value, so it wouldn't make sense to just block them outright. I think the problem is that a very high percentage of malicious behavior online comes from Tor, certain IP ranges, VPNs, scrapers that don't run Javascrip…

Cranky nerd here. I've tried to use Tor to access websites for legitimate purposes and found much of the web has become unusable recently. But perhaps you need a motivating example, since you don't think there's any value in supporting Tor! I'll give you some. - Security researcher wishes to contact an organization about a security hole in their site or product, but doesn't know if they'll be sued, so they want to pr…

But perhaps you need a motivating example, since you don't think there's any value in supporting Tor!

I never said that.

I do think that the onus is on you to explain to whatever company you're railing against here why its in their best interest to welcome Tor traffic, particularly if it will make them more vulnerable. And sorry, to me you're not doing a good job of making that case. These examples seem like edge cases for the vast majority of websites. If I was blocking Tor (I'm not), I wouldn't reconsider my position from these scenarios. The cost is simply too high for too little benefit to too few people, probably none of which are my target audience.

And just to be clear, I truly understand the value of Tor and similar projects, and I hope we get more of them and they're more widely supported. But they come with real downsides too, so it's not surprising to me that many businesses and governments aren't going to out of their way to support them. That's the price you pay.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#56
post #11

Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place? Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data. Tor users should take those CAPTCHAs as a…

It's a trade-off. If you trust Cloudflare it adds additional protection against bad guys. If you don't trust them don't use them. Same with Amazon or any other place where you can rent server room. Using Cloudflare gives control for control over which part of their site can use shared cache and which is direct link. If you don't trust anyone, run your own servers and don't hire sysadmins.

> ... and don't hire sysadmins.

People you hire can be vetted, fired, sued, and even imprisoned for violating your users' privacy. Blindly handing over your users' data to a third-party includes none of these protections. You're simply abdicating responsibility.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#57
post #36
post #32

Earlier quoted context omitted.

are there any researched measurements to show exactly how much is available? obviously it would vary greatly depending on where the connection is going... but wondering if there is some overarching idea of what it has..

https://metrics.torproject.org/bandwidth.html Currently the network is processing ~125Gbit/s of traffic.

is there a way to see the average bandwidth a tor end user would get?

seems like a good amount?

Re: Dear customers of Cloudflare: an appeal regarding Tor

#58
post #26

Earlier quoted context omitted.

and The Tor Projects response to that: https://blog.torproject.org/trouble-cloudflare They have been in this dispute with each other for a long time.

blog.torproject.org uses an invalid security certificate. This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.

Works fine for me, using Firefox 61.0.2.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#59

2018 ... im too lazy to input a captcha dear lord, the how many other things are you too lazy to do

This isn't Reddit. Please follow the guidelines [1] and engage in discussions in good faith.

[1]: https://news.ycombinator.com/newsguidelines.html

Re: Dear customers of Cloudflare: an appeal regarding Tor

#60
post #52
post #39

Earlier quoted context omitted.

What hosting is acceptable for your privacy wishes? Given that "a contracted party sees plaintext" is apparently the issue, the following clearly are not ok: a) any SaaS b) any of the cloud providers when their load-balancing offerings are used in HTTP mode (e.g. Amazon ELB) c) any traditional "shared" hosting company Are VPSes trustworthy enough, or does it have to be dedicated hardware? Dedicated hardware under dir…

Yes, options A, B, and C are technologies that shouldn't be used where user privacy is highly valued. They violate the fundamental concept of end-to-end encryption. In practice, a rented VPS or dedicated server that terminates its own TLS connections can be considered very private. It's not impossible for the hosting company to acquire the private key but it would require real effort, business risk, and potential lia…

So avoid using more than 75% of the web? You may be right in that these websites value your privacy less than other things but it certainly doesn't seem like a viable solution for most users. What's the day to day usage look like when you take your privacy this seriously? I'm not well versed with what tools you would use currently to achieve privacy.
Post reply on HN