Earlier quoted context omitted.
and The Tor Projects response to that: https://blog.torproject.org/trouble-cloudflare They have been in this dispute with each other for a long time.
That's a 2016 post. As discussed in other subthreads, the Tor Project and Cloudflare have reached an accommodation.
Dear customers of Cloudflare: an appeal regarding Tor
131–140 of 172 posts
Re: Dear customers of Cloudflare: an appeal regarding Tor
#132Earlier quoted context omitted.
blog.torproject.org uses an invalid security certificate. This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.
You may be behind a corporate firewall that is blocking access to the site.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#133Those Google captchas are horrible. Often they do not let one of through despite giving seemingly correct answers. One is prompted with captcha after captcha after captcha. They not only require cookies, but JavaScript turned on and are a real affront to the whole idea of a usable, open web. On tor, I just give up. There is nothing I want to see on the internet badly enough that I'm willing to spend ten to fifteen mi…
Re: Dear customers of Cloudflare: an appeal regarding Tor
#134Earlier quoted context omitted.
> You have to stop the bots from trying to brute force user accounts and passwords. That shouldn't be an issue if the passwords have enough entropy.
No amount of entropy mitigates a successful credential stuffing attack.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#135Earlier quoted context omitted.
That's a 2016 post. As discussed in other subthreads, the Tor Project and Cloudflare have reached an accommodation.
Yes, it's from 2016. The above Cloudflare post is from 30 Mar 2016 so I linked The Tor Projects response from 31 Mar 2016.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#136I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
As a website operator too I don't see spammers, attackers and script kiddies from tor network with valid user agents (tor browser or mainstream up to date browsers). The worst I see in that traffic is very few people trying to post/upload something anonymously, but mostly it's just people trying to access a few pages anonymously. Bots and scrappers for some reason use fake user agents in tor network and just get 403s…
I wonder if Tor has finally reached critical mass and is ready for more widespread use?
Re: Dear customers of Cloudflare: an appeal regarding Tor
#137Earlier quoted context omitted.
It's not just Tor. This also affects VPN users. It has affected me. I wouldn't call my use of a VPN for privacy as "illegitimate."
It's not about whether your personal use of VPN is legitimate. It's a numbers game. For any successful site that deals in user generated content, moderation is hard and relentless work. If they observe that a high fraction of visitors from AWS / VPN / Tor exit IPs are attackers, they will add countermeasures.
Well-intentioned or not, the UX sucks, and I generally bail and don't come back if I experience a second Captcha in a session. Find a better solution, or accept that you're driving away eyeballs/revenue.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#138I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…
It's not just Tor. This also affects VPN users. It has affected me. I wouldn't call my use of a VPN for privacy as "illegitimate."
Re: Dear customers of Cloudflare: an appeal regarding Tor
#139Earlier quoted context omitted.
> You have to stop the bots from trying to brute force user accounts and passwords. That shouldn't be an issue if the passwords have enough entropy.
No amount of entropy mitigates a successful credential stuffing attack.
Re: Dear customers of Cloudflare: an appeal regarding Tor
#140Earlier quoted context omitted.
As a website operator too I don't see spammers, attackers and script kiddies from tor network with valid user agents (tor browser or mainstream up to date browsers). The worst I see in that traffic is very few people trying to post/upload something anonymously, but mostly it's just people trying to access a few pages anonymously. Bots and scrappers for some reason use fake user agents in tor network and just get 403s…
I'm not sure when you last tried Tor, but it's not that slow these days. I first tried Tor several years ago, and it was so slow I couldn't understand how anyone could bear to use it - but I tried it again recently, and (to my surprise) for general browsing at least, it didn't seem to add any noticeable lag. I wonder if Tor has finally reached critical mass and is ready for more widespread use?