Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

121–130 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#121
post #76
post #61

Falsehoods lawyers believe about the Internet: You can identify a person (and their jurisdiction) from “their” IP address.

It's not a falsehood though. IP address is a reasonably reliable means of geolocation. Lawyers tend to be more comfortable with gray areas than engineers. Intent counts for a lot in assessing legal compliance.

No need for anticipatory obedience though. If whois says it's not Iran - who cares.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#122
post #61

Falsehoods lawyers believe about the Internet: You can identify a person (and their jurisdiction) from “their” IP address.

Falsehoods programmers believe about law: the fact that an identification method isn't 100% accurate means that it has no value

Maybe this is more of a Europe vs. US observation than a programmer vs. lawyer observation, but I have indeed made the observation that US companies are often satisfied with "identity verification" that would absolutely not fly elsewhere. A PDF of a utility bill as "proof of residency", knowing somebody's SSN as "identity verification"...

Yes, they might be definitionally best practice and accordingly enough from a legal perspective, but I don't see them having any value in actually keeping out bad actors. A fence that surrounds 99% of your pasture indeed has no value if the wolves know where the 1% gap is.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#123

Earlier quoted context omitted.

I live in a small EU country. There are many, many american sites that just block the whole EU IP ranges becaus they don't want to deal with GDPR.

I'm surprised I don't see it more. You can't impose a regulatory burden more troublesome than your traffic is worth

But why do these companies care? The EU cannot impose this on US companies in the US, so why block? Just do nothing?

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#124
post #40

Earlier quoted context omitted.

Multipolarity is a more dangerous world, as we have seen Russia asserts itself at the expense of Ukraine.

Yes, but "safety" or "peace" is not always desirable. MLK himself said it best: https://kinginstitute.stanford.edu/king-papers/documents/whe... A short snippet: > The next day after Autherine was dismissed the paper came out with this headline: 'Things are quiet in Tuscaloosa today. There is peace on the campus of the university of Alabama.' Yes things were quiet in Tuscaloosa. yes there was peace on the campus, but…

I do not want to find out that hegemonic stability theory is false, that would definitely make the rest of my lifespan worse, even if the odds are remote

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#125
post #121
post #76

Earlier quoted context omitted.

It's not a falsehood though. IP address is a reasonably reliable means of geolocation. Lawyers tend to be more comfortable with gray areas than engineers. Intent counts for a lot in assessing legal compliance.

No need for anticipatory obedience though. If whois says it's not Iran - who cares.

This makes me wonder, though: Who started the IP checks? I think there's a high chance this by itself was anticipatory obedience, since it's fairly easy and cost-effective to do and it gives companies at least something to point at in case of a lawsuit.

But my point is that all of this compliance theater does add up; every once in a while mistakes (as outlined in TFA) do happen.

Even if they don't, almost free isn't the same thing as free – and some company will inevitably go even further, it'll set a precedent, and the cost to everybody will increase, with questionable benefit.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#126
post #99

Earlier quoted context omitted.

> ^-- All that seems to go against your assertion that you just have to "not track them", if you have to build out a system for everyone to access all data you hold about them, rectify it, delete it, verbally or in writing, without delay. If you don't track people's data, that "system" becomes an automated email reply with "we don't have any data about you". But if you deal with individuals, probably you do want to c…

Given that most things are personal data under the GDPR (e.g., IP addresses have been considered personal data, and things like usernames are clearly personal data), I don't think most companies can get off quite that trivially, short of being completely stateless and never logging anything.

You can log with log if you have good reason; you just have to delete them after a reasonable time. Nothing about this is hard or costly if you think about from the start. Your 'forever data' basically should never contain PII as some users might have terminated their accounts etc so then their info cannot be in some cold store tape archive. Again, not complex; delete backups after a reasonable time and throw away the encryption key.

The intent of the gdpr is that you think about all of this and not simply store everything to mine, have stolen, leak or sell later on. The problem is that many companies or the software they use is literally build to abuse that data so then it is indeed 'hard' and expensive to comply.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#127

Earlier quoted context omitted.

All of that is about complying with gdpr, assuming you're sharing customer data. If you don't, there's nothing to do. It's like "international shipping of live animals is a massive undertaking and takes lots of time" - cool, it's true - I'm not doing that so I'm done. Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.

> assuming you're sharing customer data. If you don't, there's nothing to do. This is 100% not true and would be a violation under the GDPR. You need not share any data and if you do nothing, you'd be violating the GDPR. > Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial. Nope, this is also not true. At least, it's not just "data requests." You are in violation of th…

If you don't have the data, it is trivial; you send an automated mail you don't store anything (of course if you really don't).

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#128

Earlier quoted context omitted.

I'm surprised I don't see it more. You can't impose a regulatory burden more troublesome than your traffic is worth

But why do these companies care? The EU cannot impose this on US companies in the US, so why block? Just do nothing?

[deleted]

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#129
post #108

Earlier quoted context omitted.

Sadly the EU doesn't really communicate this very well, and doesn't care to call out outright propaganda from ad tech and surveillance businesses, but the regulation is not actually hard to be compliant with. It literally just asks that you don't spy on people. That's it. Not spying on users? Great, you don't even have to do anything. I would be extremely surprised to see any attempt at enforcement against a website…

It's more than just not spying on people. You have to be able to prove you don't spy on people. And any vendors or contractors you use also don't spy on people, and respond to requests from anyone about all the data you have on them. And delete all of the data you have for anyone who cancels their account. Sure in some cases, that isn't a huge burden, like if you have a website that doesn't handle any customer data.…

You don't have to delete as soon as they cancel; you can store it in an encrypted backup which you remove after 90 days (and throw away the key). There are a lot of 'for a reasonable period' things; meaning, you cannot store PII (including IPs) forever and you cannot store it at all in case you do not need it in the first place for your app to function (example; SaaS asking for my home address which they don't ship anything).

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#130

Earlier quoted context omitted.

Isn't intent of sanctions to weaken the adversary? Providing services, even free-tier (or, may be, especially so), to sanctioned countries is exactly the opposite of that.

The adversary is the government and businesses associated with the government, not all of the 90 million people living in Iran.

As long as government controls the country, it's the country as a whole. Because that's where the government gets its resources.
Post reply on HN