Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

131–140 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#131
post #98
post #26

Earlier quoted context omitted.

and The Tor Projects response to that: https://blog.torproject.org/trouble-cloudflare They have been in this dispute with each other for a long time.

That's a 2016 post. As discussed in other subthreads, the Tor Project and Cloudflare have reached an accommodation.

Yes, it's from 2016. The above Cloudflare post is from 30 Mar 2016 so I linked The Tor Projects response from 31 Mar 2016.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#132

Earlier quoted context omitted.

blog.torproject.org uses an invalid security certificate. This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox may only connect to it securely. As a result, it is not possible to add an exception for this certificate.

You may be behind a corporate firewall that is blocking access to the site.

You're right. I forgot I was on my work VPN.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#133
post #48

Those Google captchas are horrible. Often they do not let one of through despite giving seemingly correct answers. One is prompted with captcha after captcha after captcha. They not only require cookies, but JavaScript turned on and are a real affront to the whole idea of a usable, open web. On tor, I just give up. There is nothing I want to see on the internet badly enough that I'm willing to spend ten to fifteen mi…

At some point, Google started doing really aggressive increases in their captcha difficulty based on IP trust or even outright refusing to let people try and solve them at all. Since there's going to be a large overlap between IPs that Cloudflare force through the captcha and IPs that Google distrust, this means that anyone trying to access the internet through a network that Cloudflare has put on their evil list will probably find the whole web completely unusable. Of course, any employees testing the captcha feature will go though the easy path and not see the problem...

Re: Dear customers of Cloudflare: an appeal regarding Tor

#134
post #91

Earlier quoted context omitted.

> You have to stop the bots from trying to brute force user accounts and passwords. That shouldn't be an issue if the passwords have enough entropy.

No amount of entropy mitigates a successful credential stuffing attack.

No amount of anything mitigates a successful attack; otherwise it wouldn't be successful.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#135
post #131
post #98

Earlier quoted context omitted.

That's a 2016 post. As discussed in other subthreads, the Tor Project and Cloudflare have reached an accommodation.

Yes, it's from 2016. The above Cloudflare post is from 30 Mar 2016 so I linked The Tor Projects response from 31 Mar 2016.

OK, got it. But do see John Graham-Cumming's comment: https://news.ycombinator.com/item?id=17751464

Re: Dear customers of Cloudflare: an appeal regarding Tor

#136
post #35

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

As a website operator too I don't see spammers, attackers and script kiddies from tor network with valid user agents (tor browser or mainstream up to date browsers). The worst I see in that traffic is very few people trying to post/upload something anonymously, but mostly it's just people trying to access a few pages anonymously. Bots and scrappers for some reason use fake user agents in tor network and just get 403s…

I'm not sure when you last tried Tor, but it's not that slow these days. I first tried Tor several years ago, and it was so slow I couldn't understand how anyone could bear to use it - but I tried it again recently, and (to my surprise) for general browsing at least, it didn't seem to add any noticeable lag.

I wonder if Tor has finally reached critical mass and is ready for more widespread use?

Re: Dear customers of Cloudflare: an appeal regarding Tor

#137

Earlier quoted context omitted.

It's not just Tor. This also affects VPN users. It has affected me. I wouldn't call my use of a VPN for privacy as "illegitimate."

It's not about whether your personal use of VPN is legitimate. It's a numbers game. For any successful site that deals in user generated content, moderation is hard and relentless work. If they observe that a high fraction of visitors from AWS / VPN / Tor exit IPs are attackers, they will add countermeasures.

Then in deploying those countermeasures, they should know they're creating (sometimes significant) friction in the experience those legitimate users, who have legitimate reasons for using those tools, have of their site.

Well-intentioned or not, the UX sucks, and I generally bail and don't come back if I experience a second Captcha in a session. Find a better solution, or accept that you're driving away eyeballs/revenue.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#138

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

It's not just Tor. This also affects VPN users. It has affected me. I wouldn't call my use of a VPN for privacy as "illegitimate."

And proxies, but not Cloudflare - I regularly have to complete captchas from Google when at work.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#139
post #91

Earlier quoted context omitted.

> You have to stop the bots from trying to brute force user accounts and passwords. That shouldn't be an issue if the passwords have enough entropy.

No amount of entropy mitigates a successful credential stuffing attack.

It could be argued that once you use a password more than once its entropy decreases automatically.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#140
post #35

Earlier quoted context omitted.

As a website operator too I don't see spammers, attackers and script kiddies from tor network with valid user agents (tor browser or mainstream up to date browsers). The worst I see in that traffic is very few people trying to post/upload something anonymously, but mostly it's just people trying to access a few pages anonymously. Bots and scrappers for some reason use fake user agents in tor network and just get 403s…

I'm not sure when you last tried Tor, but it's not that slow these days. I first tried Tor several years ago, and it was so slow I couldn't understand how anyone could bear to use it - but I tried it again recently, and (to my surprise) for general browsing at least, it didn't seem to add any noticeable lag. I wonder if Tor has finally reached critical mass and is ready for more widespread use?

The lag is quite noticeable for me - but it's quite similar to a bottom-5th-percentile internet connection. What was your uplink like when using Tor?
Post reply on HN