Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

111–120 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#111
post #106

Is Apple store working in Iran? For example, Apple store is working in Russia. I genuinely do not understand how logic works between 1.sanctions 2... 3.let's ban some IPs. What is the chain of reasoning happens on step 2? Why this is not applicable to Google/Apple? There are definitely sanctions against Russia, yet Apple/Play stores work just fine.

> For example, Apple store is working in Russia.

Apple hasn't officially sold any hardware in Russia in the last 2+ years. Any Apple devices you can buy come from "parallel import" and are priced 1.5x compared to other countries.

As far as I know, the only way you can pay on the app store is from your prepaid balance at some carriers. Play store doesn't accept payments at all, it pops up a modal saying "payments in Russia are paused".

I can't understand what these sanctions are intended to achieve either. They just make us angrier because there's nothing we can do besides wait it out.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#112

Earlier quoted context omitted.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes: "Complying with the GDPR is a huge undertaking" "GDPR compliance (occupies) a huge amount of IT time and resources" "Moving your organization into GDPR compliance is a process you ideally started long ago" The article links to some ICO GDPR data…

All of that is about complying with gdpr, assuming you're sharing customer data. If you don't, there's nothing to do. It's like "international shipping of live animals is a massive undertaking and takes lots of time" - cool, it's true - I'm not doing that so I'm done. Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.

> assuming you're sharing customer data. If you don't, there's nothing to do.

This is 100% not true and would be a violation under the GDPR. You need not share any data and if you do nothing, you'd be violating the GDPR.

> Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.

Nope, this is also not true. At least, it's not just "data requests."

You are in violation of the GDPR.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#113
post #99

Earlier quoted context omitted.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes: "Complying with the GDPR is a huge undertaking" "GDPR compliance (occupies) a huge amount of IT time and resources" "Moving your organization into GDPR compliance is a process you ideally started long ago" The article links to some ICO GDPR data…

> ^-- All that seems to go against your assertion that you just have to "not track them", if you have to build out a system for everyone to access all data you hold about them, rectify it, delete it, verbally or in writing, without delay. If you don't track people's data, that "system" becomes an automated email reply with "we don't have any data about you". But if you deal with individuals, probably you do want to c…

Given that most things are personal data under the GDPR (e.g., IP addresses have been considered personal data, and things like usernames are clearly personal data), I don't think most companies can get off quite that trivially, short of being completely stateless and never logging anything.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#114

Earlier quoted context omitted.

How is it stupid? You de-risk your enterprise significantly by cutting Iran out completely, and you only lose the handful of dollars this would’ve translated into down the road. Some customers aren’t worth having.

Banning an entire country and punishing its innocent citizens feels extreme. It doesn't seem right that, for example, an Iranian student can't use cloud services. Ban commercial and government entities, not the individuals.

This is a political argument, not a business one. Now that Uncle Sam has swung the banhammer on a particular country, pity the exec who exposes their company to doing business with the enemy.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#115

I'm frequently reminded how thankful I am to live in a country with a strong, positive international reputation. Even ignoring actual quality-of-life stuff associated with where I live - simply not being from a country with a "dodgy" reputation makes many things so much easier. I don't have to think about blocked websites. Companies accept my payments. Couriers ship to me. With my passport, I walk straight to the fro…

I live in Russia and I've never experienced most of the things you're describing. And it's become so much worse after 24/02/2022. We even had Spotify for a year! It was starting to genuinely feel like a first-world country. Now you have to open a bank account in a different country for foreign companies to consider taking your money at all. The internet is utterly broken. The government blocks quite a lot, AND some f…

Do you think the sanctions are having a significant effect in terms of slowing down the war effort?

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#116
post #76
post #61

Falsehoods lawyers believe about the Internet: You can identify a person (and their jurisdiction) from “their” IP address.

It's not a falsehood though. IP address is a reasonably reliable means of geolocation. Lawyers tend to be more comfortable with gray areas than engineers. Intent counts for a lot in assessing legal compliance.

From a "best practice"/CYA perspective, sure.

But I'm not a lawyer, and looking purely at the outcome of IP blocks (which is usually that regular people are inconvenienced, but the people such policies are actually designed to keep out just shrug and use a $5/month VPN), I can still say that it looks a bit silly.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#117
post #61

Falsehoods lawyers believe about the Internet: You can identify a person (and their jurisdiction) from “their” IP address.

Ah. So I can log IP addresses that connect to my service and store them forever?

IP addresses are great for identifying traffic patterns, figuring out where your audience is roughly located etc. as long as you don't use them to selectively block users – since then nobody has a real incentive to "cloak" theirs.

Once you start doing that, you've completely destroyed the measurement, and at the same time you're still not keeping out unintended users – because these will just use a VPN.

To go with an analogy: Imagine a bank enforcing embargo/sanction policies by just asking everyone at the entrance for their name but not checking their ID! You'd get a lot of personal data (since most people won't lie), yet you won't keep any sanction evaders out.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#118

Earlier quoted context omitted.

It's slightly more involved than this, but not extraordinarily so. For example seemingly innocuous implementations like loading fonts directly off Google Fonts without consent (i.e. providing Google with information about visitors' browsing habits) would technically be on the wrong side of the GDPR, but I think it's very unlikely that anyone would complain about it, legally speaking.

> would technically be on the wrong side of the GDPR, but I think it's very unlikely that anyone would complain about it, legally speaking. The American in me says that sounds like "someone will definitely complain about it, eventually, if only because they're hoping for a payout".

Maybe that's the problem, I thought the (mostly local media) companies that were blocking EU citizens were doing it out of spite or to make a point, because it doesn't make sense (for one, they're not subject to gdpr if they don't explicitly do business with EU citizens).

But maybe it's just because the US environment is so hostile that they assume it's the same in the EU.

But national regulators in the EU don't waste their time with foreign companies that might by oversight not be totally compliant since they're not even under their jurisdiction (worst is they could be fined and have to pay it if ever they incorporate in that country in the near future? Nobody's going to waste time in that).

And nobody can sue a company on gdpr grounds and get a payout. They're only fines, they benefit to central states and are a negligible amount in regard to national budgets.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#119

Earlier quoted context omitted.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes: "Complying with the GDPR is a huge undertaking" "GDPR compliance (occupies) a huge amount of IT time and resources" "Moving your organization into GDPR compliance is a process you ideally started long ago" The article links to some ICO GDPR data…

All of that is about complying with gdpr, assuming you're sharing customer data. If you don't, there's nothing to do. It's like "international shipping of live animals is a massive undertaking and takes lots of time" - cool, it's true - I'm not doing that so I'm done. Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.

GDPR does not regulate “sharing,” it regulates any use of personal data. IP address is considered personal data, so you can’t avoid GDPR compliance if you are running a website at all (since you must process IP addresses in order to serve a website).

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#120

Earlier quoted context omitted.

If I followed your strategy I would be blocking all of Google. Back in the days I operated my own mail server >50% of all spam was from Google USA... YMMV.

I do that on several of my hobby nodes. I block entire ASN's for all the major platforms. Real people can still reach them just fine. To your point I do less of that on my self hosted mail servers and instead use a regex methodology called S25R created by a mail admin in Japan a long time ago and it works great.

Tricky thing about Google is quite a lot of my contacts are on Gmail or some domain hosted by Gmail so blocking Google's ASN is a no go for me. I'm now with Fastmail -- they use Spamassassin (plus I suspect their own custom rules) which uses a range of different metrics to determine whether an email is spam. That is is far more effective than straight up blocking ASNs and the like.
Post reply on HN