Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

111–120 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#111
post #91

Earlier quoted context omitted.

Do the same on the login page. You have to stop the bots from trying to brute force user accounts and passwords.

> You have to stop the bots from trying to brute force user accounts and passwords. That shouldn't be an issue if the passwords have enough entropy.

No amount of entropy mitigates a successful credential stuffing attack.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#112
post #59

2018 ... im too lazy to input a captcha dear lord, the how many other things are you too lazy to do

This isn't Reddit. Please follow the guidelines [1] and engage in discussions in good faith. [1]: https://news.ycombinator.com/newsguidelines.html

Why bother slurring another site? There are plenty of good faith discussions happening on Reddit.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#113

Earlier quoted context omitted.

94% of all traffic on the internet is malicious. It all depends on your definitions. A legitimate, human, user makes a handful of connections per minute. Someone running a scanner attempts thousands per second. So if we measure attempted connections then Tor and everything is horrible. But that true for actual bandwidth. The old question: is a simple ping considered an attack? I still here people talking of how their…

Hmmm, this sounds really interesting! Do we have any sources regarding how that 94% number was calculated or are you guessing?

Run a firewall on a server. Count every ping/scan as an attempted hack. Say you have 1000 legitimate users in a give day. You will probably see 1000 pings, scans, and other general junk per hour. (This is hard to do in places like cloudflare that filter much of this junk traffic before it hits their customers.)

Re: Dear customers of Cloudflare: an appeal regarding Tor

#114

Earlier quoted context omitted.

>>> if the passwords have enough entropy. Allow me to optimize your statement. >>> if False

What does it mean? Users always pick low-entropy passwords?

Almost always. It's gotten better with the rise of password managers that generate random passwords, but otherwise, passwords are usually shared across many websites and usually less than 16 characters.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#115

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

The following are questions based on the fact that I am ignorant of Cloudflares services/capabilities: Are you using Cloudflare purely as a CDN? Can you choose to filter access to your content from geographic regions (i.e. block all IPs from [country]) What key services/offerings are you benefiting most from using Cloudflare?

1. You can use it purely as a CDN, turning security to "essentially off" and only having to deal with the website certificate being sni.cloudflaressl.com

2. Only on the enterprise plan. On Pro/Business you can only "challenge" (captcha) or JS/browser Challenge countries, not outright block them.

3. Even with all the other cool and useful features, DDOS mitigation is still one of the most valuable offerings possible.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#116
post #21

Earlier quoted context omitted.

What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.

Why not add a checkmark like this: "[ ] I support dictatorship and want to live under a dictatorship. I don't believe in freedom of speech or expression on any subject, even banal everyday subjects. For all subjects, I oppose freedom of the press, freedom of speech, and the right to read anonymously or express anonymous opinions, regardless of content. If in America, I oppose the fourth amendment ('[t]he right of the…

> I just can't imagine any legitimate Tor user checking that checkbox

Legitimate Tor users will click it for the same reason a large fraction of users in general will click it--it's stopping them from getting where they want to be, and they believe clicking it enable them to move on, and they believe that reading it won't speed up that process.

It's just to them more "stupid stuff the site wants me to agree to that I don't need to bother with because (1) if it is asking me to agree to some rules I don't care because I'm really nice and would never do anything they could object to anyway, and (2) if it is making me give permission to use my data or track me it doesn't matter because (I'm already tracked everywhere else | I've got ad blocking and privacy add-ons installed)".

Re: Dear customers of Cloudflare: an appeal regarding Tor

#117
post #21

Earlier quoted context omitted.

What I do is simply check if CF-IPCountry header == "T1" and block those from being able to register accounts. T1 is Tor.

Why not add a checkmark like this: "[ ] I support dictatorship and want to live under a dictatorship. I don't believe in freedom of speech or expression on any subject, even banal everyday subjects. For all subjects, I oppose freedom of the press, freedom of speech, and the right to read anonymously or express anonymous opinions, regardless of content. If in America, I oppose the fourth amendment ('[t]he right of the…

Wow, you just went way beyond the deep end. The mental gymnastics here is Olympic-level.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#118

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

meanwhile i2p users just fly under the radar

Re: Dear customers of Cloudflare: an appeal regarding Tor

#119
post #116

Earlier quoted context omitted.

Why not add a checkmark like this: "[ ] I support dictatorship and want to live under a dictatorship. I don't believe in freedom of speech or expression on any subject, even banal everyday subjects. For all subjects, I oppose freedom of the press, freedom of speech, and the right to read anonymously or express anonymous opinions, regardless of content. If in America, I oppose the fourth amendment ('[t]he right of the…

> I just can't imagine any legitimate Tor user checking that checkbox Legitimate Tor users will click it for the same reason a large fraction of users in general will click it--it's stopping them from getting where they want to be, and they believe clicking it enable them to move on, and they believe that reading it won't speed up that process. It's just to them more "stupid stuff the site wants me to agree to that I…

Good point! Since my suggestion actually would not stop trolls (abusive users) anyway (they would just click it so they could then abuse the site), how about blocking all Tor traffic with this message:

" Why we are blocking Tor users

You appear not to support dictatorship and or want to live under a dictatorship. As the operator of this site, I don't believe in freedom of speech or expression on any subject, even banal everyday subjects. For all subjects, I oppose freedom of the press, freedom of speech, and the right to read anonymously or express anonymous opinions, regardless of content. If I could, I would repeal the fourth amendment ('[t]he right of the people to be secure in their persons, houses, papers, and effects'). Come back when you are ready to be tracked by your government."

Fair compromise? It sends the message across while blocking all Tor users.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#120
post #9

I've got enough problems on my sites from Tor that I simply block T1 (Cloudflare's "country" code for Tor users) on their settings. Blocking whole countries used to be a Enterprise only feature, but now it's available to Pro users.

Note: Allowing non-enterprise to block countries was a bug, see https://community.cloudflare.com/t/code-10016/28039/13?u=jud...
Post reply on HN