Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

301–310 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#301

Earlier quoted context omitted.

This is why I'm strongly against spam filtering for email. Spam filters are fundamentally security-through-obscurity. I mean, they don't protect your email from targeted bombing attacks or phishing. If you need spam filters to operate your email on a day-to-day basis, then the security of your email is fundamentally broken. /s, obviously, I hope. Blocking Tor isn't a security measure, it's a nuisance reduction measur…

>This is why I'm strongly against spam filtering for email. Spam filters are fundamentally security-through-obscurity. I mean, they don't protect your email from targeted bombing attacks or phishing. If you need spam filters to operate your email on a day-to-day basis, then the security of your email is fundamentally broken. You kid, but this is completely true Email is simply an incredibly flawed, outdated and broke…

No post body was provided.

Re: You don’t want to be on Cloudflare’s naughty list

#302
post #241

Earlier quoted context omitted.

I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"

The story I've heard is--because their direct customers are websites, not end users--that Cloudflare loves to be ostentatious with these branded blocks and have a vested interest in offering services which punish users because it makes people feel like the product really really does something . Do you constantly hear about people being hosted by Akamai or CDNetworks or whatever going down due to DDoS attacks? No. How…

[deleted]

Re: You don’t want to be on Cloudflare’s naughty list

#303
post #288

Earlier quoted context omitted.

This is why I'm strongly against spam filtering for email. Spam filters are fundamentally security-through-obscurity. I mean, they don't protect your email from targeted bombing attacks or phishing. If you need spam filters to operate your email on a day-to-day basis, then the security of your email is fundamentally broken. /s, obviously, I hope. Blocking Tor isn't a security measure, it's a nuisance reduction measur…

The correct analogy here would be implementing spam filtering by blocking large segments of email addresses. Eg, dropping mail from all non microsoft/gmail domains (as a nuisance reduction measure!), with predictable impact on smaller providers and self hosted email.

You're reframing this to make Tor look a lot better than it is. The signal:noise ratio for Tor is epsilon. It's almost entirely garbage. If a network generated spam at rates analogous to network traffic from Tor, yes, I guarantee that network would be on every single email service's block list.

Tor's advocates in this thread keep trying to argue it from ideology, as though anybody's obligated to deal with Tor traffic on principle alone, and not one of them so far has tried to argue that Tor is not 90+% bots and garbage. Funny, that.

Re: You don’t want to be on Cloudflare’s naughty list

#304
post #152

So this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you ? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a ma…

> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity co…

> Fact-less conspiranoia.

I love how people reflectively answer with cries of "no evidence!" to something that presents the evidence about exactly the thing they are claiming has no evidence. I get a distinct impression that the only person they're trying to convince is themselves, by self-hypnotically denying the reality in public.

There's a fact of CF booting sites, there's a fact of CF having IP blacklist, there's a fact of getting into IP blacklist being a very frustrating experience, there's a fact of various activists itching to make the lives of their political enemies a very unpleasant experience and launching successful pressure campaigns to do exactly that.

Did that happen with CF and IP blocking? No, I explicitly said it didn't, at least - I don't know any cases of it. But there's a lot of facts confirming there's a capability and motivation to do so. You may not believe it would happen, and you have a right to believe so, but when you are denying known facts, I don't think your beliefs are based on anything but wishful thinking. Your argument would be strong if you showed that, despite the known facts, it still couldn't happen. But instead to claim it couldn't happen you have to deny the facts.

> How many times have they done it?

Probably more than I know, but it's too big to bother with me, so I'm not too concerned about it right now. Maybe if I was in the same business as Assange, I'd be worried more.

> very much underweighing the costs of doing something like that.

Like what costs? You mean to say, no major provider would dare to boot the person from the Internet? Like Facebook, Twitter, Paypal, Venmo, Gofundme, Google, Amazon, Microsoft, Mailchimp, Tiktok, etc. would not dare to block people for political dissent and expressing unpopular opinions? Because, you know, opportunity costs, collateral damage, unintended consequences, reputation costs, brand harm. That' just couldn't happen. All that is fact-less conspiranoia.

> Why not make the same complaint about your ISP, your hardware manufacturer, your OS manufacturer

I can buy different hardware. I can install different OS. With some effort, but I can connect to a different ISP. Any of that won't help if Cloundflare would refuse to talk to me.

> Remember that US criminal system attributes 3 elements to a crime

Oh, but that's not a crime. That's the beauty of it - remember, it's a private action of a free enterprise, and you have no rights there. And even if the government would hold weekly meetings with Cloudflare suggesting them who exactly needs to be banned, it's still free enterprise, right? I mean, excluding the fact that the government would never do something like that, because reputation costs, brand harm, etc. That's another instance of fact-less conspiranoia, of course.

> I’m not defending CloudFlare here so much as tired of conspiracy theories and paranoia and social panics.

That's nothing. Imagine how tired you'd be when it turns out everything you thought is "paranoia" is actually happening. Of course, it would never happen to you - you'd never disagree with the government, or any people in power, or voice any unpopular opinions in public, would you now?

Re: You don’t want to be on Cloudflare’s naughty list

#305
post #152

So this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you ? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a ma…

> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity co…

> Who do you know would want to work for a company that did that?

Pretty much anyone who works for Twitter, Facebook, Google, Paypal, Venmo, Amazon, Microsoft, Gofundme, Mailchimp, Tiktok, Reddit, Nextdoor, and many other tech companies routinely engaging in censorship and unpersoning. The idea that people in tech are some kind of high morals freedom lovers that would never work for a company that censors doesn't suffer even minimal scrutiny. If anything, they'd refuse to work for a company that doesn't censor enough - Twitter workers were in utter screaming panic when they thought Musk could but Twitter and relax the censorship a bit. So if anything you just disproven your own argument - maybe what will force CF to censor is not external pressure but the internal one. I don't see why Cloudflare workers would be any better than Twitter ones.

Re: You don’t want to be on Cloudflare’s naughty list

#306
post #62

Earlier quoted context omitted.

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

there are many solid competitors: Amazon, Fastly, Akamai, Imperva to name a few

Fuck Akamai. Have you worked with them? They are the most archaic internet company you can think of. Their UI is stuck in 2000. Just like their procedures.

Re: You don’t want to be on Cloudflare’s naughty list

#307
post #288

Earlier quoted context omitted.

The correct analogy here would be implementing spam filtering by blocking large segments of email addresses. Eg, dropping mail from all non microsoft/gmail domains (as a nuisance reduction measure!), with predictable impact on smaller providers and self hosted email.

You're reframing this to make Tor look a lot better than it is. The signal:noise ratio for Tor is epsilon. It's almost entirely garbage. If a network generated spam at rates analogous to network traffic from Tor, yes, I guarantee that network would be on every single email service's block list. Tor's advocates in this thread keep trying to argue it from ideology, as though anybody's obligated to deal with Tor traffic…

With all the blocks in place, is it ever possible to know whether the 90% is still an innate effect of Tor, or actually an effect of sites blocking Tor?

I have Tor installed, figured it would be worth adding my boring browsing to the mix sometimes, but since most sites I try to load block Tor exits, Tor browser now sits unused.

On the other hand, if I woke up tomorrow deciding to start a bot farm or whatever other malicious thing, or course I'd be interested in hiding through Tor and might try it again (don't worry, I won't wake up that way).

So even if a hypothetical 100% of global internet users really wanted to do all their browsing through Tor, they might all reach the same conclusion as me that too many sites are blocked and therefore leave Tor to mostly bad traffic. Of course it's nowhere near 100%, but hopefully you see my point that the sites blocking Tor IPs (and I absolutely appreciate why) can become a self-fulfilling prophecy - and I'm not sure how you'd get out of that loop?

Re: You don’t want to be on Cloudflare’s naughty list

#308

Earlier quoted context omitted.

An alternative that preserves some privacy also doesn't seem that hard to imagine... though it probably has its own can of worms*. Basically, the core problem is digital identities (accounts, IPs, phone #s etc.) are cheap to create (even considering captchas and all) so fraud is easy. The solution could be just to make it "costly" to create new digital identities. For example, you could get a "verified but anonymous"…

Your idea is comes from a good place, but identity theft is already a thing in the real world. Digital identities would also be very stealable. This malware more harmful in the long term. Imagine if your Twitter gets hacked and your digital identity makes it so your Gmail gets blocked. Similar, the internet is already very difficult for the people with limited means. This would make it even harder.

It's not really my idea (has been proposed multiple times long ago to the point it has even been implemented in many places).

As for identity theft, it's actually not that common/easy except in the US (which has no centralized national ID issuer and largely depends on hacks building on the SSN).

An besides, protecting digital identity is already important even without this bootstrapping.

> Imagine if your Twitter gets hacked and your digital identity makes it so your Gmail gets blocked.

Flip the services around and you have the reality of today.

Re: You don’t want to be on Cloudflare’s naughty list

#309
post #109
post #87

Earlier quoted context omitted.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

It’s absolutely required for most multiplayer games. Many need random ports and some even refuse to work if UPnP is blocked even if you manually open a port for them.

On series X you can set up port forwarding really easily. I had to do it for openwrt

Re: You don’t want to be on Cloudflare’s naughty list

#310

There’s a real lack of education I’ve seen in developers for small projects who go directly to cloudflare for anything and everything. They don’t understand that they are immediately losing a large chunk of their user base who is either from the third world or is privacy literate. Devs working on projects that are targeting those groups need to understand the tradeoffs from using cloudflare.

Obviously they don't. Clourdflare's markets itself as a super easy set-it-and-forget-it solution. The problem is that it isn't. The defaults are broken and it requires careful configuration and monitoring. Of course this isn't good marketing so the only way a user can know is posts like these or to accidently block their users and hear the reports. (Obviously Cloudflare's UI will only tell you how evil bots it blocked were.)
Post reply on HN