Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

181–190 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#181

Earlier quoted context omitted.

GDPR does not regulate “sharing,” it regulates any use of personal data. IP address is considered personal data, so you can’t avoid GDPR compliance if you are running a website at all (since you must process IP addresses in order to serve a website).

I'm using simplified language here, not writing a legal document. The first use was also supposed to be "storing/sharing", but it's processing in practice. But here you go: > GDPR does not regulate “sharing,” 13.1.e requires at least the notification of the recipients of the data. With the requirement about the purpose of use, it effectively regulates sharing. > since you must process IP addresses in order to serve a…

It doesn’t require a consent dialogue but it requires user notifications and data processing agreements with anyone who is helping you serve your site and an agent available to EU jurisdictions to answer inquiries. Granted a lot of people don’t bother or slide by with some vague crappy language they downloaded from somewhere.

The irony here is that the people who think they’re standing up for GDPR are actually the ones not taking it seriously, while the people who take it seriously are the ones who know what a pain it is to comply with.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#182

Earlier quoted context omitted.

I live in Russia and I've never experienced most of the things you're describing. And it's become so much worse after 24/02/2022. We even had Spotify for a year! It was starting to genuinely feel like a first-world country. Now you have to open a bank account in a different country for foreign companies to consider taking your money at all. The internet is utterly broken. The government blocks quite a lot, AND some f…

Do you think the sanctions are having a significant effect in terms of slowing down the war effort?

I'm not an expert and don't have the necessary and verifiable information to asses the consequences in regards to economy/industry, but the sociocultural effects are negative.

1. Sanctions sped up the formation of the class of war beneficiaries. Sanctions created the demand for sanction circumvention. Since their scope is huge, the demand is accordingly very high (from civil consumers to the government). This led to formation of new supply chains that keep being profitable only while the war and sanctions continue. Now thousands of people engaged in these activities have the monetary incentive to support the war and the government course. This one I deem to be the most consequential in the long term.

2. Any noticeable conflict or rights violation happening with Russian citizens abroad is to be blown out of proportion and presented as a confirmation of pervasive anti-Russian sentiment and support the government narrative of existing encircled by enemies.

3. The lack of accessible ways of integration of the emigrants into local societies (especially in Europe) led to thousands of them coming back, some unwillingly, some grudgingly and feeling disillusioned. This is a huge wasted opportunity and I don't get why it happened (I don't buy the "we must secure our countries against possible threat actors and dirty money" explanation).

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#183

Earlier quoted context omitted.

Few of them do have an effect on the military, but hardly a significant one. Some of them forced the government officials to eat their own dog food. Most of them, however, feel like mocking petty revenge. If anything, those sanctions that disproportionately affect regular powerless people only reinforce the official propaganda's view that "we're encircled by enemies". Vladimir Kara-Murza expressed the same ideas much…

> In my own opinion, a good step in the right direction would be if we could travel to European countries as easily as we used to be able to. I don't agree. Russia's regime threatens Europe with invasion and nuclear bombs almost on a daily basis, and vilify everyone who doesn't enthusiastically support their invasion of Ukraine. A few years ago Russia even had a nuclear bomber circling the coast of western Europe. Th…

Russians didn’t start a war. They are not the agressor. The ruling powers of Russia did. You are saying that it’s good to punish those already affected by their governments violence additionally. And with that unfortunate perspective, you will not win the population over, to the contrary.

The anger is justified, but misdirected.

Would every US American be happy to be identified as Trump and Project2025 supporter, in case he wins the elections?

How much is it my responsibility what my government does, if all I have is basically one vote, if even that, and it is life threatening to even voice (and form) my opinion?

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#184

Earlier quoted context omitted.

I'm using simplified language here, not writing a legal document. The first use was also supposed to be "storing/sharing", but it's processing in practice. But here you go: > GDPR does not regulate “sharing,” 13.1.e requires at least the notification of the recipients of the data. With the requirement about the purpose of use, it effectively regulates sharing. > since you must process IP addresses in order to serve a…

It doesn’t require a consent dialogue but it requires user notifications and data processing agreements with anyone who is helping you serve your site and an agent available to EU jurisdictions to answer inquiries. Granted a lot of people don’t bother or slide by with some vague crappy language they downloaded from somewhere. The irony here is that the people who think they’re standing up for GDPR are actually the on…

Have you got some support for this from people experienced with legal matters? Because not only I've never heard of the internet provider notification being required and can't find any act which would apply, I can't even find any European page which does that, including https://op.europa.eu/en/web/about-us/privacy-statement which is responsible for publishing gdpr itself.

That publisher's page lists the third party processors for the documents, (as expected) but not the hosting provider. I'd love to see a counterexample.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#185

Earlier quoted context omitted.

It doesn’t require a consent dialogue but it requires user notifications and data processing agreements with anyone who is helping you serve your site and an agent available to EU jurisdictions to answer inquiries. Granted a lot of people don’t bother or slide by with some vague crappy language they downloaded from somewhere. The irony here is that the people who think they’re standing up for GDPR are actually the on…

Have you got some support for this from people experienced with legal matters? Because not only I've never heard of the internet provider notification being required and can't find any act which would apply, I can't even find any European page which does that, including https://op.europa.eu/en/web/about-us/privacy-statement which is responsible for publishing gdpr itself. That publisher's page lists the third party p…

My experience was the months I spent with a very competent (and no doubt expensive) French law firm to help my employer implement GDPR compliance. None of that is public info that I can link to, however.

I’ll edit to add that the user must be notified that you are collecting and processing personal data, which includes IP address. And the hard part is that you must also have internal paper trails that prove that you have written that notification in full knowledge of all the data processing done on your behalf by all your service providers. Is a data center owner routing traffic to your server? You need paperwork in which they commit not to store the IP addresses of your visitors, for example. That is not public-facing but must be available to regulators upon their request.

That’s the hard part of compliance and what most people skip. They click OK on the standard agreements with service providers and put up a standard privacy template. That is not actually compliant but folks are essentially betting that they are small enough that data regulators won’t ever come call them on it.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#186

Earlier quoted context omitted.

It is extremely hard to stop DDOS attacks without CF; my hoster has DDOS protection, but when there was a very large attack on our site, only CF could remedy it, and did so immediately when we panicked-moved dns and switched on bot fight. Entire attack that my hoster couldn't stop was gone. How do you do this without CF if you are a small company?

There are *so* many options out there. Saying you don't know how to do it without using an evil, monopolistic company is like saying you can't host email without using Google. It's lazy, untechnical and just plain untrue.

Enlighten me please; I have asked many times and everyone keeps sending me to cloudflare, even some hosters. When you search for anything like this, it ends up being very expensive which is not lazy; we cannot afford it. Botfight is free.

Maybe if people knew about alternatives, they would use CF less. I wouldn't use them at all (and don't; I switch when my hoster cannot handle the attack which happened once only).

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#187
post #155

Earlier quoted context omitted.

> you can store it in an encrypted backup which you remove after 90 days (and throw away the key) Sure. But that is much easier said than done. Especially if your previous strategy was to just keep everything, because storage is cheap, development cost is expensive, and then the data will still be there if the customer decides to return in a few years. And in many (most?) cases it's not like you just have a single fi…

I see this and I feel I must ask: why would you EVER engineer ANY application under the idiotic assumption that none of your users will ever want to remove the data that they had stored in it?! Absolutely baffling. Of course, if a business is that short-sighted and careless, it will struggle to implement GDPR.

It might be more nefarious when companies do that, but on the other hand, Hanlon's razor.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#188
post #150
post #76

Earlier quoted context omitted.

It's not a falsehood though. IP address is a reasonably reliable means of geolocation. Lawyers tend to be more comfortable with gray areas than engineers. Intent counts for a lot in assessing legal compliance.

But it isn't a grey area: it simply doesn't work. It doesn't matter if it correctly identifies most people: it has to correctly identity most terrorists, and it simply doesn't do that, because if you are a terrorist you just keep rotating through IP addresses on cloud providers and VPNs until the entire service is burnt. It isn't that it sometimes doesn't work: it's that it doesn't work at all when it actually needs…

Wrong. At this level there is no compliance requirement to specifically identify "terrorists". And the sanctions against Iran, while partly based on state sponsorship of terrorism, aren't limited to just designated terrorist entities.

Most services aren't required to blanket block all traffic from Iran. Only certain specific transactions are prohibited. But a lot of companies choose to block everything identified as coming from Iran (and other sanctioned countries) just to play it safe.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#189

Earlier quoted context omitted.

> I don't see how "they don't work" and "they are inconvenient" are contradictory statements. They would've been if there were feedback mechanisms that we could use to communicate our point of view the government, but there aren't any, so in the end it's just a punishment for having been born in a wrong place at a wrong time. The feedback mechanism you're complaining about is a problem on the side of those being inco…

> If they want to complain, they need to direct their complains to their own regime And get arrested and charged with "discrediting the armed forces", right. Must be nice to write all that from the comfort of your Western home.

> And get arrested and charged with "discrediting the armed forces", right.

If you don't register that as a problem but somehow limiting your tourism options is a concern, that is already telling regarding what your priorities are.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#190

Earlier quoted context omitted.

So in the end it's just a punishment for having been born in a wrong place at a wrong time. That's what war is, unfortunately. Millions of people in Ukraine are currently being "punished" for exactly the same offense, only in ways infinitely worse, as I don't need to tell you. There was absolutely no reason the war had to coming into being at all. But now that we're stuck with it, the only effective questions are --…

[flagged]

> I like how you absolve the Western governments of any agency of their own.

Cut the crap. Russia's regime decided to start a war of invasion. It's an initiative from Russia and Russia alone, and all consequences are derived from Russia's actions. There is no way around it.

Post reply on HN