Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

91–100 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#91

Earlier quoted context omitted.

I'm surprised I don't see it more. You can't impose a regulatory burden more troublesome than your traffic is worth

Sadly the EU doesn't really communicate this very well, and doesn't care to call out outright propaganda from ad tech and surveillance businesses, but the regulation is not actually hard to be compliant with. It literally just asks that you don't spy on people. That's it. Not spying on users? Great, you don't even have to do anything. I would be extremely surprised to see any attempt at enforcement against a website…

It's slightly more involved than this, but not extraordinarily so.

For example seemingly innocuous implementations like loading fonts directly off Google Fonts without consent (i.e. providing Google with information about visitors' browsing habits) would technically be on the wrong side of the GDPR, but I think it's very unlikely that anyone would complain about it, legally speaking.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#92

it's pretty absurd that cloudflare can just effectively cripple a cloud provider by tagging part of their IPv4 range as Iranian and not fixing their issues in over a year (and AFIK have no intention to fix them at all) like I wonder if Hetzner has any way to legally force them to stop misclassifying their IP

What's absurd to me is that Cloudflare gains more and more control over the internet, by people voluntarily submitting to its domination. My favorite is trying to go someone's random blog with like 5 posts (because they have a singular post about the technical topic I'm trying to figure something out about) and I can't access the site because Cloudflare has decided my locked-down Firefox ("resist fingerprinting" + st…

Might have something to do with how that particular website is using Cloudflare.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#93
post #8

Earlier quoted context omitted.

My servers ban huge swaths of IPs from certain places that originates enormous amounts of spam, scanners, and other nefarious traffic. It's very effective

If I followed your strategy I would be blocking all of Google. Back in the days I operated my own mail server >50% of all spam was from Google USA... YMMV.

I do that on several of my hobby nodes. I block entire ASN's for all the major platforms. Real people can still reach them just fine. To your point I do less of that on my self hosted mail servers and instead use a regex methodology called S25R created by a mail admin in Japan a long time ago and it works great.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#94

Earlier quoted context omitted.

I'm surprised I don't see it more. You can't impose a regulatory burden more troublesome than your traffic is worth

The burden of not tracking people is quite small.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes:

"Complying with the GDPR is a huge undertaking"

"GDPR compliance (occupies) a huge amount of IT time and resources"

"Moving your organization into GDPR compliance is a process you ideally started long ago"

The article links to some ICO GDPR data processing checklist, which is a list of 18 different processes you need to have put in place.

"The GDPR is made up of 99 articles that provide a detailed description of the regulation". "[I]t is impossible to provide an exact prescription that will guarantee your organization is in compliance"

"One of the most onerous obligations of the GDPR is to provide “Data Subjects” – the people whose data you are processing – with access to the data that you hold about them (Article 15)",

"They can also request rectification or completion of data if it is inaccurate or incomplete, and they can request that you delete their personal data"

"This is onerous because Data Subjects can make requests in writing or verbally, and you need to be able to comply with the requests “without undue delay"

^-- All that seems to go against your assertion that you just have to "not track them", if you have to build out a system for everyone to access all data you hold about them, rectify it, delete it, verbally or in writing, without delay.

I'm not even half way through the article and I'm skipping over tons of what it's saying needs to be done, with all the security measures that need to put in place, whether or not encrypted data is needed, breach notification, and so on.

It seems like a heck of a lot more than just "not track people", or a trivial amount of work.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#96
post #8

Earlier quoted context omitted.

My servers ban huge swaths of IPs from certain places that originates enormous amounts of spam, scanners, and other nefarious traffic. It's very effective

So, all the cloud, vps, and hosting providers?

I block most of them but something I noticed was that the more affordable a provider is the more garbage that comes from them.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#97
post #39

Earlier quoted context omitted.

It's more that you are on the right side in a unipolar world. When the world shifts to multipolarity in the next few years, the problem will solve itself.

I'm a globalist and all but when people say "multipolar" doesn't that usually mean "the USA shouldn't rule everyone, I want to also rule over some countries "

Not really, it is just used to mean the termination of unipolarity. Though frankly it's looking more like a bipolar West vs. BRICS+ situation.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#98

Earlier quoted context omitted.

I live in a small EU country. There are many, many american sites that just block the whole EU IP ranges becaus they don't want to deal with GDPR.

I’ve been noticing more and more US state and local government websites blocking traffic from outside the US. (And I’m not talking about traffic from North Korea, I’m talking about traffic from ANZUS/AUKUS/FVEY ally Australia.) It seems stupid because just because someone is overseas doesn’t mean they can’t have valid business with a US state or local government. Maybe they are an American who is travelling and has t…

Well, perhaps Australia should stop threatening non-Australian websites that don’t comply with AUS law.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#99

Earlier quoted context omitted.

The burden of not tracking people is quite small.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes: "Complying with the GDPR is a huge undertaking" "GDPR compliance (occupies) a huge amount of IT time and resources" "Moving your organization into GDPR compliance is a process you ideally started long ago" The article links to some ICO GDPR data…

> ^-- All that seems to go against your assertion that you just have to "not track them", if you have to build out a system for everyone to access all data you hold about them, rectify it, delete it, verbally or in writing, without delay.

If you don't track people's data, that "system" becomes an automated email reply with "we don't have any data about you".

But if you deal with individuals, probably you do want to collect at least some data that would be subject to the GDPR protections, and it is definitely easier to forget all about it.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#100
post #44

Earlier quoted context omitted.

but the traffic is _clearly coming from Germany_, the issue is that cloudflare/google have tagged certain ip addresses as Iranian no matter where the traffic actually originates from

> but the traffic is _clearly coming from Germany_ How do you know that if the only thing you see on the receiving side is an IP address, which is marked as Iranian?

Marked where? With the assigning authority of the IP address which has been granted the legal right to manage the IP space (a common good)? Or in the database of some arbitrary company?
Post reply on HN