I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
It would be cool if you could set a header to Cloudflare when a user is logged in, perhaps with that user's ID. That could then trigger significantly decreased security.
Dear customers of Cloudflare: an appeal regarding Tor
61–70 of 172 posts
Re: Dear customers of Cloudflare: an appeal regarding Tor
#62This shouldn’t be necessary. We changed our handling of Tor so long ago that I’ve forgotten how long go it was. If you are using the Tor Browser Bundle you should not see a CAPTCHA. If you do please report it to us.
What's special about Tor Browser Bundle? What would I need to configure to use it with another browser?
Re: Dear customers of Cloudflare: an appeal regarding Tor
#63Re: Dear customers of Cloudflare: an appeal regarding Tor
#64Earlier quoted context omitted.
It's a trade-off. If you trust Cloudflare it adds additional protection against bad guys. If you don't trust them don't use them. Same with Amazon or any other place where you can rent server room. Using Cloudflare gives control for control over which part of their site can use shared cache and which is direct link. If you don't trust anyone, run your own servers and don't hire sysadmins.
> ... and don't hire sysadmins. People you hire can be vetted, fired, sued, and even imprisoned for violating your users' privacy. Blindly handing over your users' data to a third-party includes none of these protections. You're simply abdicating responsibility.
But you must have them on site 24/7 to be able to respond as fast as Couldfare to any new security issues. You must pay them a lots of money because they must be expert level. You also need to have 24/7 security around your servers and all the backups and redundancy.
Very few businesses have customer information that is wroth the paranoia and investment to doing everything inhouse.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#65Criminals will just hire a botnet, as we can see from all incoming spam email and forum bots, etc. For the rest of us who desire to be anonymous online, there is Tor. Whatever people can do over Tor, they can also do without Tor. You're probably never going to find them anyway, even if you would sue in the first place. This whole tor vs clearnet distinction is way overblown. Sure people will do more crap if they're a…
>Criminals will just hire a botnet ... if Tor proves ineffective. If not, then they'll definitely use Tor.
Tor is a common CnC and exfiltration vector. Nothing good will ever originate from a pseudoanonymous network developed for spycraft. We have enough problems with it that we shoot it on sight.
The bigger problem is becoming abuse of cheap VPS and seedbox services (and anon VPNs) to launch attacks. $5 gets you a non-attributable box managed by an overseas entity with a gigabit link and an IP strategically located near your target to thwart geoip-based blocking. With that price point and features, why fuck around with botnets or Tor?
Re: Dear customers of Cloudflare: an appeal regarding Tor
#66I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#67Those Google captchas are horrible. Often they do not let one of through despite giving seemingly correct answers. One is prompted with captcha after captcha after captcha. They not only require cookies, but JavaScript turned on and are a real affront to the whole idea of a usable, open web. On tor, I just give up. There is nothing I want to see on the internet badly enough that I'm willing to spend ten to fifteen mi…
seems like google could alleviate this if they checked value of certain cookies before making people repeatedly solve captchas.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#68I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
Re: Dear customers of Cloudflare: an appeal regarding Tor
#69I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
It would be cool if you could set a header to Cloudflare when a user is logged in, perhaps with that user's ID. That could then trigger significantly decreased security.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#70Earlier quoted context omitted.
Actually probably not very much traffic is from tor. Tor bandwidth is notoriously bad.
are there any researched measurements to show exactly how much is available? obviously it would vary greatly depending on where the connection is going... but wondering if there is some overarching idea of what it has..