Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

71–80 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#71

There is a disconnect here: I've read so many technical articles from cloudflare about neat problems they solve while at the same time they just boldly say fuck you to net neutrality and aggressively try to get people on board with the tracking internet that their corporate partners desire so strongly. I get the sense these aren't the same groups of people at the company itself. I've been browsing anonymously with to…

Cloudflare spent a lot of energy and effort trying to fix this problem for visitors like you: https://blog.cloudflare.com/cloudflare-supports-privacy-pass...

Re: Dear customers of Cloudflare: an appeal regarding Tor

#72
I've been trying to use the Tor browser lately and so far it's been a mostly futile endeavor. Between these captchas (which take 1-2 minutes to solve) and other automated "bot" detection, most of the web is unusable. You might be able view it, but good luck interacting with it in any way. That's when you run into the "Sorry, something about your activity seems fishy" messages.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#73
post #21

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.

I run dedicated onion addresses for my sites and check the CF-IPCountry headers and just redirect Tor users to the Onion site.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#74
post #22

Earlier quoted context omitted.

Not GP, but my guess is ban evasion. Someone gets banned from bad behavior, they create a new account. So you IP ban them. Then they switch over to Tor and keep making new accounts from anonymized IPs and start disrupting the forum by spamming it with slurs. The only solution is to ban Tor.

Or, you know, limit the ability of newly created user to spam forums. Or put them on "must be reviewed" lists. Or... The easiest solution is to ban Tor, but it's far from the only solution.

It's the most effective solution, not just the easiest.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#75
post #48

Those Google captchas are horrible. Often they do not let one of through despite giving seemingly correct answers. One is prompted with captcha after captcha after captcha. They not only require cookies, but JavaScript turned on and are a real affront to the whole idea of a usable, open web. On tor, I just give up. There is nothing I want to see on the internet badly enough that I'm willing to spend ten to fifteen mi…

Captcha's are very overused. I cancelled my PlayStation Vue service because the website kept bugging me with the worst of the worst Google captchas every couple days or so (not using Tor). Unreal that anyone thinks those are a good idea just to log into a service someone is paying for.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#76

This shouldn’t be necessary. We changed our handling of Tor so long ago that I’ve forgotten how long go it was. If you are using the Tor Browser Bundle you should not see a CAPTCHA. If you do please report it to us.

As someone who sees it constantly on sites using Cloudflare.... Tails doesn't work for this. Tor Browser Bundle does. Correct?

Yeah tails was so broken with CloudFare I had to give up on it. Many sites showed the annoying captcha and, if you got past that, still refused to show content because it was presumably served from a separate domain. If you looked at source and copied the urls to the images and tried to open them directly you got another CloudFare captcha.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#77

Earlier quoted context omitted.

>Criminals will just hire a botnet ... if Tor proves ineffective. If not, then they'll definitely use Tor.

Botnets are too unreliable. They're only any good for coordinating DoS attacks and spamming, the sorts of attacks that don't require persistence of infrastructure. Tor is a common CnC and exfiltration vector. Nothing good will ever originate from a pseudoanonymous network developed for spycraft. We have enough problems with it that we shoot it on sight. The bigger problem is becoming abuse of cheap VPS and seedbox se…

>>> The bigger problem is becoming abuse of cheap VPS and seedbox services (and anon VPNs)

Cloudflare have the solution for that. You can ban by AS number and by country code.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#78
All the author had to do with this "appeal" was present the text to be read. Instead they put it on gitlab behind javascript. Literally nothing renders without JS enabled, and even with it enabled in browsers more than a year or two old it's just spins forever: no text.

Text is easy guys. Here's my appeal: stop hiding all content behind javascript. It's not required and because if it I am unable to read the author's appeal.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#79
post #48

Those Google captchas are horrible. Often they do not let one of through despite giving seemingly correct answers. One is prompted with captcha after captcha after captcha. They not only require cookies, but JavaScript turned on and are a real affront to the whole idea of a usable, open web. On tor, I just give up. There is nothing I want to see on the internet badly enough that I'm willing to spend ten to fifteen mi…

I think the number of times a captcha is presented is directly correlated with the risk associated with the IP address. But you're right, very annoying indeed.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#80
post #54
post #15

Earlier quoted context omitted.

It's an argument for "why you should care", which is relevant to the post.

Furthermore, as an expat living in Russia at the moment, it is quite surprising to one day be in an EU country and able to access any wide variety of sites, and the next day get a friendly message from Роскомнадзор telling me this website has been blocked for my protection or some other non-sense. I'm not involved in politics enough for it to be something very dangerous for me -- it's just non-sense things I want to…

For those wondering, "Роскомнадзор" is Russia's "Censorship Agency", Roskomnadzor[1]. If you are wondering, why is there a Censorship Agency in a country whose Constitution explicitly bans censorship[2], well... Let's just say it's not the first time in our history. Probably not the last.

[1] https://en.wikipedia.org/wiki/Federal_Service_for_Supervisio....

[2] https://en.wikisource.org/wiki/Constitution_of_Russia#Articl....

Post reply on HN