Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

141–150 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#141
post #43
post #18

Earlier quoted context omitted.

Google's IP to location mapping is so bad it has to be intentional. I was in Japan and using my home network as a VPN quite a bit, after a while Google decided my home comcast IP had to be located in Japan. Even though others in the household were still there, they started getting default-Japanese pages on google/maps/youtube/... It didn't fix itself back until a couple weeks after I got home, even filled out https:/…

They finger print your browser. You need to vpn to your home and serve from your US browser not tunnel traffic back to your Japan machine.

I'd be more willing to bet that it's because my GPS location is in Japan, which is the strongest signal of my physical location. Nevertheless, my home IP is used by multiple people, they probably know who they are and that they're not in Japan. My own signals are a mix of VPN'd/non-VPN'd apps on my phone and laptop (not strict about the VPN, some Japan sites require a Japanese IP), and I do often NoMachine back to my home machine and access google services just like I do at home.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#142

Earlier quoted context omitted.

You can log with log if you have good reason; you just have to delete them after a reasonable time. Nothing about this is hard or costly if you think about from the start. Your 'forever data' basically should never contain PII as some users might have terminated their accounts etc so then their info cannot be in some cold store tape archive. Again, not complex; delete backups after a reasonable time and throw away th…

Sure, but regardless of your data-retention period, you still have to know where to find everything derived from anything user-generated, if you want to accurately respond to requests. You're free to argue that the GDPR is making companies do things that they already ought to have been doing, but my point is that "just don't be one of those evil user-tracking companies" is not a viable compliance policy in itself.

If your data retention period is less than your response time (which has to be less than a month), can you not say "everything we had at the time of request is deleted" and be done with it?

A reminder that we're talking about passing visitors without accounts here, and for logging and analytics there shouldn't be a need to store anything longer than a couple days.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#143
post #117

Earlier quoted context omitted.

Ah. So I can log IP addresses that connect to my service and store them forever?

IP addresses are great for identifying traffic patterns, figuring out where your audience is roughly located etc. as long as you don't use them to selectively block users – since then nobody has a real incentive to "cloak" theirs. Once you start doing that, you've completely destroyed the measurement, and at the same time you're still not keeping out unintended users – because these will just use a VPN. To go with an…

I think we have the same perspective on this. I should have been more specific about my snark - what I was really calling out was the GDPR considering IP address as PII, which is widely lauded on this forum.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#144

Earlier quoted context omitted.

The burden of not tracking people is quite small.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes: "Complying with the GDPR is a huge undertaking" "GDPR compliance (occupies) a huge amount of IT time and resources" "Moving your organization into GDPR compliance is a process you ideally started long ago" The article links to some ICO GDPR data…

You listed just one slightly onerous requirement: allowing people access and agency over their data. If you don't store their data, you don't have to do that.

It's a bit hyperbolic to say that you're, "not even half way through the article and I'm skipping over tons of what it's saying needs to be done", when you've literally only listed one thing.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#145

Earlier quoted context omitted.

All of that is about complying with gdpr, assuming you're sharing customer data. If you don't, there's nothing to do. It's like "international shipping of live animals is a massive undertaking and takes lots of time" - cool, it's true - I'm not doing that so I'm done. Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.

GDPR does not regulate “sharing,” it regulates any use of personal data. IP address is considered personal data, so you can’t avoid GDPR compliance if you are running a website at all (since you must process IP addresses in order to serve a website).

"since you must process IP addresses in order to serve a website"

That's complete nonsense.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#146

Earlier quoted context omitted.

What's absurd to me is that Cloudflare gains more and more control over the internet, by people voluntarily submitting to its domination. My favorite is trying to go someone's random blog with like 5 posts (because they have a singular post about the technical topic I'm trying to figure something out about) and I can't access the site because Cloudflare has decided my locked-down Firefox ("resist fingerprinting" + st…

It is extremely hard to stop DDOS attacks without CF; my hoster has DDOS protection, but when there was a very large attack on our site, only CF could remedy it, and did so immediately when we panicked-moved dns and switched on bot fight. Entire attack that my hoster couldn't stop was gone. How do you do this without CF if you are a small company?

There are *so* many options out there. Saying you don't know how to do it without using an evil, monopolistic company is like saying you can't host email without using Google. It's lazy, untechnical and just plain untrue.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#147

Earlier quoted context omitted.

Do you think the sanctions are having a significant effect in terms of slowing down the war effort?

Few of them do have an effect on the military, but hardly a significant one. Some of them forced the government officials to eat their own dog food. Most of them, however, feel like mocking petty revenge. If anything, those sanctions that disproportionately affect regular powerless people only reinforce the official propaganda's view that "we're encircled by enemies". Vladimir Kara-Murza expressed the same ideas much…

Thanks -- those are some useful data points.

What about the freezing (and probable eventual seizure) of $300b of CBRF assets (apparently 60 percent its total foreign currency reserves)? That's got to be causing some significant pain, somewhere.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#148

Earlier quoted context omitted.

Few of them do have an effect on the military, but hardly a significant one. Some of them forced the government officials to eat their own dog food. Most of them, however, feel like mocking petty revenge. If anything, those sanctions that disproportionately affect regular powerless people only reinforce the official propaganda's view that "we're encircled by enemies". Vladimir Kara-Murza expressed the same ideas much…

Thanks -- those are some useful data points. What about the freezing (and probable eventual seizure) of $300b of CBRF assets (apparently 60 percent its total foreign currency reserves)? That's got to be causing some significant pain, somewhere.

Not sure if it's caused by this or the sanctions related to USD and EUR currencies themselves, but CBRF has introduced limitations on foreign currency transactions in March 2022. They were supposed to last 6 months but every time they're about to expire they get extended for 6 more months.

You can't withdraw more than $10k of USD or EUR cash combined from all foreign currency accounts in each bank, and you can only withdraw the money that was there before March 2022. Past that limit and for any money you received after March, you can only withdraw it as rubles at the CBRF exchange rate, iirc. Most banks also treat dollars and euros like they're radioactive and will hit you with monthly fees if you have too much. So in the end we have three different exchange rates for these currencies: the CBRF one, the one for online operations with those "virtual" dollars and euros in currency accounts, and the "real" one for cash.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#149

Earlier quoted context omitted.

Do you think the sanctions are having a significant effect in terms of slowing down the war effort?

Few of them do have an effect on the military, but hardly a significant one. Some of them forced the government officials to eat their own dog food. Most of them, however, feel like mocking petty revenge. If anything, those sanctions that disproportionately affect regular powerless people only reinforce the official propaganda's view that "we're encircled by enemies". Vladimir Kara-Murza expressed the same ideas much…

> In my own opinion, a good step in the right direction would be if we could travel to European countries as easily as we used to be able to.

I don't agree. Russia's regime threatens Europe with invasion and nuclear bombs almost on a daily basis, and vilify everyone who doesn't enthusiastically support their invasion of Ukraine. A few years ago Russia even had a nuclear bomber circling the coast of western Europe.

This behavior is not limited to government. It's not unheard of having Russian tourists insulting and threatening locals. In Europe or in any corner of the world. There are also Russian citizens attacking refugees and asylum seekers in foreign soil, even Russia's own war dodgers.

You cannot expect to systematically threat neighbors and still demand or even expect them to continue to cater to the whims of the agressor. It is a voluntary relationship that cuts both ways.

When you start a war, you should expect to experience war.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#150
post #76
post #61

Falsehoods lawyers believe about the Internet: You can identify a person (and their jurisdiction) from “their” IP address.

It's not a falsehood though. IP address is a reasonably reliable means of geolocation. Lawyers tend to be more comfortable with gray areas than engineers. Intent counts for a lot in assessing legal compliance.

But it isn't a grey area: it simply doesn't work. It doesn't matter if it correctly identifies most people: it has to correctly identity most terrorists, and it simply doesn't do that, because if you are a terrorist you just keep rotating through IP addresses on cloud providers and VPNs until the entire service is burnt. It isn't that it sometimes doesn't work: it's that it doesn't work at all when it actually needs to work. We could argue that the services shouldn't let you do that in the first place, but the reality is that services currently do work like that, no one is trying to change that, and if they did try to change it we would all be even less happy with the resulting even-more-powerful surveillance state.
Post reply on HN