Live data from Hacker News

Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

news.ycombinator.com

51–60 of 61 posts

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#51
post #6

Earlier quoted context omitted.

A valid use case for wanting to know the “real” IP of a site hiding behind CloudFlare is being able to access the website from a Tor IP address (which they categorically block). For users in a country with censored internet, such a service would be essential.

> which they categorically block Everytime I check this statement with Cloudflare-enabled sites... it was either always accessible (a nagging screen might be shown momentarily, but that's it), or the block is usually due to that site being a bank or something else that will block Tor users regardless of their firewall solutions. I've just tested it again just in case something has changed, but that statement holds up…

They stopped blocking them now but used to in the past.

Additionally, there are privacy reasons a person may wish to access a service directly and not be tracked by Cloudflare.

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#52

> CloudFlare had it taken down. I'm not sure where the idea that we took this down came from, but I checked with legal and we didn't. Such tools, services, etc. have existed forever. Just one reason why we encourage people to protect their public IP ( https://developers.cloudflare.com/fundamentals/get-started/s... ) and have Cloudflare Tunnel ( https://developers.cloudflare.com/cloudflare-one/connections... ).

Thanks for clarifying that it had to be Github. The post you replied to says Gitbub or Cloudflare take it down. Either way, this issue should be brought to customers attention more clearly. Most people probably don’t know that the entire internet can be scanned in a matter of hours or days which might uncover their site. I’m curious how many customers are paying for your anti-ddos service yet their sites are easily findable using such a tool effectively rendering the service useless. Do you scan the internet yourself and proactively warn customers when their real IP is findable in this way?

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#53

> CloudFlare had it taken down. I'm not sure where the idea that we took this down came from, but I checked with legal and we didn't. Such tools, services, etc. have existed forever. Just one reason why we encourage people to protect their public IP ( https://developers.cloudflare.com/fundamentals/get-started/s... ) and have Cloudflare Tunnel ( https://developers.cloudflare.com/cloudflare-one/connections... ).

Say that, despite your linked recommendations for hiding the public IP, thousands of customers were under the impression that as long as no one leaked the IP, no one would be able to discover the site. They’re paying you a lot of money for security, yet that security can be completely undermined by a teen with a scanner tool. If there’s thousands of clients paying for anti-DDOS services yet their IP is easily findable, then it’s like…what are they even paying for? On a scale of thousands this probably adds up to a large sum of money…Money paid for pointless services rendered.

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#54
If you are going to use someone else to front your service, take care to make sure that that (1) it cant even be accessed except via that front, and (2) that you dont leak your origin IP address or network, even if traffic to that origin is dropped from sources other than the service fronting it.

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#55
post #48

Earlier quoted context omitted.

It’s a story in itself that a simple script which locates a site’s real IP was taken down for TOS violations. Cloudflare doesn’t own the real IPs or something so it’s really unclear why they (or GitHub) were entitled to take down this repository. Just because it threatens their million dollar buisness model they think they can take it down? That’s wrong my friend. And people need to know. Cloudflare or GitHub overste…

Apparently you will not believe anything, but the CEO responded here: https://news.ycombinator.com/item?id=31097086

    ^E^T

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#56
post #53

> CloudFlare had it taken down. I'm not sure where the idea that we took this down came from, but I checked with legal and we didn't. Such tools, services, etc. have existed forever. Just one reason why we encourage people to protect their public IP ( https://developers.cloudflare.com/fundamentals/get-started/s... ) and have Cloudflare Tunnel ( https://developers.cloudflare.com/cloudflare-one/connections... ).

Say that, despite your linked recommendations for hiding the public IP, thousands of customers were under the impression that as long as no one leaked the IP, no one would be able to discover the site. They’re paying you a lot of money for security, yet that security can be completely undermined by a teen with a scanner tool. If there’s thousands of clients paying for anti-DDOS services yet their IP is easily findabl…

As someone on the “buy side” of Cloudflare-like services, that’s not how it works. How could a third party like Cloudflare protect my unprotected IP address? A very basic part of using a CDN/DDOS protection product is not allowing raw traffic to your origin server.

RE “as long as no one leaked their IP” - the IPv4 space is quite small. It’s trivial to scan it and discuss unadvertised, but ultimately very public, servers.

If customers don’t already have an understanding of both of these points, then they need to increase their competence in areas that are, frankly, pretty basic.

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#57
post #53

> CloudFlare had it taken down. I'm not sure where the idea that we took this down came from, but I checked with legal and we didn't. Such tools, services, etc. have existed forever. Just one reason why we encourage people to protect their public IP ( https://developers.cloudflare.com/fundamentals/get-started/s... ) and have Cloudflare Tunnel ( https://developers.cloudflare.com/cloudflare-one/connections... ).

Say that, despite your linked recommendations for hiding the public IP, thousands of customers were under the impression that as long as no one leaked the IP, no one would be able to discover the site. They’re paying you a lot of money for security, yet that security can be completely undermined by a teen with a scanner tool. If there’s thousands of clients paying for anti-DDOS services yet their IP is easily findabl…

Security tools, when misused or misunderstood, may have security weaknesses.

My house has a lock on the front door. Yet that security can be completely undermined if a teen throws a brick at my window. That isn't the fault of the manufacturer of the lock on my front door.

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#58
post #56
post #53

Earlier quoted context omitted.

Say that, despite your linked recommendations for hiding the public IP, thousands of customers were under the impression that as long as no one leaked the IP, no one would be able to discover the site. They’re paying you a lot of money for security, yet that security can be completely undermined by a teen with a scanner tool. If there’s thousands of clients paying for anti-DDOS services yet their IP is easily findabl…

As someone on the “buy side” of Cloudflare-like services, that’s not how it works. How could a third party like Cloudflare protect my unprotected IP address? A very basic part of using a CDN/DDOS protection product is not allowing raw traffic to your origin server. RE “as long as no one leaked their IP” - the IPv4 space is quite small. It’s trivial to scan it and discuss unadvertised, but ultimately very public, serv…

> How could a third party like Cloudflare protect my unprotected IP address?

Simple, they could scan the internet like I explained and notify their customers who’s site IP is findable this way with a big scary warning message. They could do this easily and cheaply, but for some reason they don’t.

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#59
post #8

Why on earth would you try to help DDOS'ers? I think you should really take a step back here and reevaluate what drives you here and what impact you have on other people.

There is a website currently publishing my (outdated) informations without my consent (old home address, current email, old phone number) and it is hiding behind cloudflare. I wrote to cloudflare months ago, and silence... So there can be many sides to that story here...

edit : oh and what the hell, name and shame https://www.reversecanada.com/ (and they have variants for other countries)

Re: Ask HN: What gives Cloudflare the right to takedown apps revealing site real IP?

#60
post #52

> CloudFlare had it taken down. I'm not sure where the idea that we took this down came from, but I checked with legal and we didn't. Such tools, services, etc. have existed forever. Just one reason why we encourage people to protect their public IP ( https://developers.cloudflare.com/fundamentals/get-started/s... ) and have Cloudflare Tunnel ( https://developers.cloudflare.com/cloudflare-one/connections... ).

Thanks for clarifying that it had to be Github. The post you replied to says Gitbub or Cloudflare take it down. Either way, this issue should be brought to customers attention more clearly. Most people probably don’t know that the entire internet can be scanned in a matter of hours or days which might uncover their site. I’m curious how many customers are paying for your anti-ddos service yet their sites are easily f…

> Do you scan the internet yourself and proactively warn customers when their real IP is findable in this way?

There is no reason for them to scan the internet. They could simply probe the configured origin server from an IP outside the whitelisted cloudflare IP range, and display a warning if it's accessible.

Post reply on HN