Earlier quoted context omitted.
Cranky nerd here. I've tried to use Tor to access websites for legitimate purposes and found much of the web has become unusable recently. But perhaps you need a motivating example, since you don't think there's any value in supporting Tor! I'll give you some. - Security researcher wishes to contact an organization about a security hole in their site or product, but doesn't know if they'll be sued, so they want to pr…
You need to provide fiscal value or convince the operations team of legitimate companies to not treat Tor as a bad apple. It may not be right but money is the only motivating example that matters to companies.
Dear customers of Cloudflare: an appeal regarding Tor
101–110 of 172 posts
Re: Dear customers of Cloudflare: an appeal regarding Tor
#102this pisses me off even more than writing captcha
Re: Dear customers of Cloudflare: an appeal regarding Tor
#103This shouldn’t be necessary. We changed our handling of Tor so long ago that I’ve forgotten how long go it was. If you are using the Tor Browser Bundle you should not see a CAPTCHA. If you do please report it to us.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#104Earlier quoted context omitted.
and The Tor Projects response to that: https://blog.torproject.org/trouble-cloudflare They have been in this dispute with each other for a long time.
blog.torproject.org uses an invalid security certificate. This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#105I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
It would be cool if you could set a header to Cloudflare when a user is logged in, perhaps with that user's ID. That could then trigger significantly decreased security.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#106Criminals will just hire a botnet, as we can see from all incoming spam email and forum bots, etc. For the rest of us who desire to be anonymous online, there is Tor. Whatever people can do over Tor, they can also do without Tor. You're probably never going to find them anyway, even if you would sue in the first place. This whole tor vs clearnet distinction is way overblown. Sure people will do more crap if they're a…
>Criminals will just hire a botnet ... if Tor proves ineffective. If not, then they'll definitely use Tor.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#107Earlier quoted context omitted.
Furthermore, as an expat living in Russia at the moment, it is quite surprising to one day be in an EU country and able to access any wide variety of sites, and the next day get a friendly message from Роскомнадзор telling me this website has been blocked for my protection or some other non-sense. I'm not involved in politics enough for it to be something very dangerous for me -- it's just non-sense things I want to…
For those wondering, "Роскомнадзор" is Russia's "Censorship Agency", Roskomnadzor[1]. If you are wondering, why is there a Censorship Agency in a country whose Constitution explicitly bans censorship[2], well... Let's just say it's not the first time in our history. Probably not the last. [1] https://en.wikipedia.org/wiki/Federal_Service_for_Supervisio... . [2] https://en.wikisource.org/wiki/Constitution_of_Russia#Ar…
Re: Dear customers of Cloudflare: an appeal regarding Tor
#108All the author had to do with this "appeal" was present the text to be read. Instead they put it on gitlab behind javascript. Literally nothing renders without JS enabled, and even with it enabled in browsers more than a year or two old it's just spins forever: no text. Text is easy guys. Here's my appeal: stop hiding all content behind javascript. It's not required and because if it I am unable to read the author's…
That's also not a trick you need to memorize or something - if you load a markdown page on Gitlab without Javascript, it won't render, but you can still click on the button to view it raw, and that button is clearly labeled with semantic HTML that will be accessible to any web browser that can handle a link tag. You do need to be able to handle HTTPS encryption, but that's another debate - most raw text documents are also going to be served over HTTPS anyway.
And of course, from the Javascript side of things, the vast majority of Gitlab's front-end is open source and all of their Javascript is served from their own servers without any third-party trackers or ads. So no worries on that front.
I get that people get annoyed about aggressive and unnecessary useage of Javascript and some choose for ethical reasons not to run proprietary code. I am all for accommodating you. But Gitlab does accommodate you. There has to be at least a little bit of effort put in on both sides here. Otherwise sites are just going to throw up their hands and say, "well nothing pleases these people, why should we bother?"
Gitlab does a great job of accommodating people who want access to raw text while also accommodating people who want to be able to do basic layout. And the approach of sites like this have significantly encouraged devs to use markdown more - if this was a static site, or something exported out from Org-mode, or even just a rendered Markdown file, you wouldn't have access to the original raw text version.
The only reason you have access to the raw text is because the uploader chose to serve the raw text and then handle rendering clientside instead of serverside. If you want to be able to read more content in Markdown form, Gitlab is your friend, not your enemy.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#109I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.
"[ ] I support dictatorship and want to live under a dictatorship. I don't believe in freedom of speech or expression on any subject, even banal everyday subjects. For all subjects, I oppose freedom of the press, freedom of speech, and the right to read anonymously or express anonymous opinions, regardless of content. If in America, I oppose the fourth amendment ('[t]he right of the people to be secure in their persons, houses, papers, and effects') and promise to vote to repeal it."
Then only allow people who check it with an x to register. This should remove any legitimate Tor users from your demographics.
---
EDIT: I got downvoted but I promise it will remove legitimate Tor users from your demographics. I just can't imagine any legitimate Tor user checking that checkbox. (By legitimate, I mean ones who are not abusive trolls etc. Of course abusive trolls won't mind checking that checkbox, before attempting to disrupt your site. My advice was on how to remove legitimate Tor users.)
Re: Dear customers of Cloudflare: an appeal regarding Tor
#110Earlier quoted context omitted.
> You have to stop the bots from trying to brute force user accounts and passwords. That shouldn't be an issue if the passwords have enough entropy.
>>> if the passwords have enough entropy. Allow me to optimize your statement. >>> if False