Live data from Hacker News

A public letter to CloudFlare to fix their snoopy vendor

github.com

101–110 of 117 posts

Re: A public letter to CloudFlare to fix their snoopy vendor

#101
post #7

Please Cloudflare, I'm a paying customer and have some IPv6 only users that are very frustrated every time they see a Cloudflare challenge page. Your provider, HCaptcha still do not support IPv6. I have to use workarounds like an alternative domain without CF and this is very frustrating.

Settings » Firewall » Settings » Security Level (Set to "Essentially Off")

Re: A public letter to CloudFlare to fix their snoopy vendor

#102
In the early 2010s for a couple of years all Cloudflare websites would sometimes fail to load on my home connection - 20% or so of page loads would hit a strange error, some sort of tcp or ssl issue

It’s good to see others experience the downside of centralising the internet. Until reading this, it seemed like everyone blindly loves cloudflare.

Re: A public letter to CloudFlare to fix their snoopy vendor

#103
post #19

Earlier quoted context omitted.

This is quite common in countries with lots of people and not enough IPs. ipv6+nat64

Why don't they use IPv4 with CGNAT in addition to IPv6? That's what the US providers do.

You don't need two nats, you don't have to track two types of ip addresses per customer, for most of the traffic, you don't even need nat at all (youtube, facebook, etc, all support native ipv6), and statless nat64 can be simpler and less resource intensive than cgnat

Re: A public letter to CloudFlare to fix their snoopy vendor

#105
post #99
post #93

Earlier quoted context omitted.

You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.

Fortunately, if you can't afford IPv4 then no one else can afford it either, which means the incentive to adopt IPv6 is extremely strong and thus you no longer need IPv4.

Existing large ISPs and cloud providers with remaining IPv4 addresses and no IPv6 support are not going to have a strong incentive until after the damage is already done.

Re: A public letter to CloudFlare to fix their snoopy vendor

#107
post #99
post #93

Earlier quoted context omitted.

You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.

Fortunately, if you can't afford IPv4 then no one else can afford it either, which means the incentive to adopt IPv6 is extremely strong and thus you no longer need IPv4.

Why won’t Google, Cloudflare, AWS, etc. simply own all most IPv4 addresses and leave all end users using NAT (or even CGNAT) to access them? This cements their businesses, since then nobody can reasonably host their own servers except through them.

Re: A public letter to CloudFlare to fix their snoopy vendor

#108
I also tried reporting this issue to Cloudflare in the past through their hackerone page (since I was out of ideas where to get the request though), this is the response I got:

> Enabling SSL/TLS between Cloudflare and the origin site is a customer decision. When this protection is not enabled, as is the case here, an ISP can manipulate the requests before they reach Cloudflare. If this behaviour is not desired, the customer must change the settings for the site in the Cloudflare dashboard.

The request in question gets MITMed after it reaches Cloudflare edge servers, the connection between browser and the edge server happens over SSL

Re: A public letter to CloudFlare to fix their snoopy vendor

#110

Earlier quoted context omitted.

In this case, it is not a random party in the CloudFlare--GitHub connection (say a network operator in UK). The snooping intermediary (Airtel) in this scenario is one that has a commercial relationship with CloudFlare and powers CloudFlare's network. CloudFlare has been aware of this issue for years, but it hasn't done anything to get its vendor to fix their network.

Isn't the censorship applied by Airtel, Jio, etc, because of local laws? https://en.wikipedia.org/wiki/Internet_censorship_in_India I don't see how Cloudflare or any other provider can make Airtel "fix" the snooping when Airtel is forced by law to block those sites. This seems to be a policy/government problem, not a Cloudflare or Airtel problem.

There is no court order to block neovim.io or teachyourselfcs.com.

Airtel isn’t forced to block these sites. It is blocking these because of a mis-configuration somewhere.

Post reply on HN