Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

221–230 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#221

Earlier quoted context omitted.

There are *so* many options out there. Saying you don't know how to do it without using an evil, monopolistic company is like saying you can't host email without using Google. It's lazy, untechnical and just plain untrue.

Enlighten me please; I have asked many times and everyone keeps sending me to cloudflare, even some hosters. When you search for anything like this, it ends up being very expensive which is not lazy; we cannot afford it. Botfight is free. Maybe if people knew about alternatives, they would use CF less. I wouldn't use them at all (and don't; I switch when my hoster cannot handle the attack which happened once only).

I don't use them myself, but I only choose colocation providers that have a good handle on their own protections. A quick search, though, shows lots of reviews and options:

https://www.techradar.com/news/best-ddos-protection

https://www.gartner.com/reviews/market/ddos-mitigation-solut...

https://expertinsights.com/insights/top-distributed-denial-o...

No idea about the content of those links, but considering the amount of research I do before selecting a colo provider, it'd be trivial in comparison to research a DDoS protection service.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#222

Yeah, google does it too. I could not use certain Hetzner IPs to download container image on my kubernetes nodes at all. Even the official registry.k8s.io registry is hosted on Google Cloud Services and basic stuff like the pause image cant be pulled.

I can confirm this. All Google container registries, including the official k8s repos are unaccessible via some hetzner ipv4 domains. There is a GitHub issue that also covers the problem and it states you should report thos IPS to their support. I did but support says they can't do anything until the ip region list is updated. IPv6 as a workaround is also difficult because some of the image I need are on GitHub and t…

I noticed some IPv6 addresses were getting blocked too.

We reported a lot IPs to Hetzner, but since we use autoscaling new blocked ones just kept on appearing.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#223

Earlier quoted context omitted.

[flagged]

> I like how you absolve the Western governments of any agency of their own. Cut the crap. Russia's regime decided to start a war of invasion. It's an initiative from Russia and Russia alone, and all consequences are derived from Russia's actions. There is no way around it.

Ah, yes. Just one day Putin woke up and decided to start it. Nothing before.

But you know, the most funny thing here is what you would never say "USA's regime decided to start a war of invasion in Iraq/Afghanistant/Yugoslavia. It's an initiative from US and US alone, and all consequences are derived from US's actions. There is no way around it."

Makes me wonder why.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#224

Earlier quoted context omitted.

Enlighten me please; I have asked many times and everyone keeps sending me to cloudflare, even some hosters. When you search for anything like this, it ends up being very expensive which is not lazy; we cannot afford it. Botfight is free. Maybe if people knew about alternatives, they would use CF less. I wouldn't use them at all (and don't; I switch when my hoster cannot handle the attack which happened once only).

I don't use them myself, but I only choose colocation providers that have a good handle on their own protections. A quick search, though, shows lots of reviews and options: https://www.techradar.com/news/best-ddos-protection https://www.gartner.com/reviews/market/ddos-mitigation-solut... https://expertinsights.com/insights/top-distributed-denial-o... No idea about the content of those links, but considering the amoun…

But you didn't check those sites; they all recommend cloudflare or either very expensive (we all know what it means when there are no prices on the site and sales can call me) solutions, hard to use solutions or solutions you cannot use unless you are a certain type of site (the google one).

So basically the choice is cloudflare if you are not cashed up enough. So nothing to do with lazy; there are no other viable options for most if it's a large attack.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#225

Earlier quoted context omitted.

Have you got some support for this from people experienced with legal matters? Because not only I've never heard of the internet provider notification being required and can't find any act which would apply, I can't even find any European page which does that, including https://op.europa.eu/en/web/about-us/privacy-statement which is responsible for publishing gdpr itself. That publisher's page lists the third party p…

My experience was the months I spent with a very competent (and no doubt expensive) French law firm to help my employer implement GDPR compliance. None of that is public info that I can link to, however. I’ll edit to add that the user must be notified that you are collecting and processing personal data, which includes IP address. And the hard part is that you must also have internal paper trails that prove that you…

There's a known side effect of highly paid legal work... it will produce lots of results. But was it all required or just-in-case-CYA? Is one highly paid lawyer more correct than a sample of European institutions? Maybe...

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#226
post #122

Earlier quoted context omitted.

Falsehoods programmers believe about law: the fact that an identification method isn't 100% accurate means that it has no value

Maybe this is more of a Europe vs. US observation than a programmer vs. lawyer observation, but I have indeed made the observation that US companies are often satisfied with "identity verification" that would absolutely not fly elsewhere. A PDF of a utility bill as "proof of residency", knowing somebody's SSN as "identity verification"... Yes, they might be definitionally best practice and accordingly enough from a l…

If the law says that providing a fake document to a financial institution is considered fraud / money laundering and can be prosecuted, it makes a lot more sense.

This puts criminals in an untenable position. If they provide fake documents to a bank, they save the police a lot of work. If tere's ever any suspicion of criminal activity in their accounts, nobody has to prove anything beyond the fact that they provided fake documents, which isn't that hard. That's enough to send them to prison. They can always provide real documents of course, but there's a reason they were use fake ones in the first place.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#227

Earlier quoted context omitted.

I don't use them myself, but I only choose colocation providers that have a good handle on their own protections. A quick search, though, shows lots of reviews and options: https://www.techradar.com/news/best-ddos-protection https://www.gartner.com/reviews/market/ddos-mitigation-solut... https://expertinsights.com/insights/top-distributed-denial-o... No idea about the content of those links, but considering the amoun…

But you didn't check those sites; they all recommend cloudflare or either very expensive (we all know what it means when there are no prices on the site and sales can call me) solutions, hard to use solutions or solutions you cannot use unless you are a certain type of site (the google one). So basically the choice is cloudflare if you are not cashed up enough. So nothing to do with lazy; there are no other viable op…

You're right that I didn't check them. I said that.

It's like doing research for colo, like my example. If you have the need, then a couple of hours of research is well worthwhile. I don't have the need, so I'm not going to do it now, but that's how one starts.

The colo example is apt - colo providers that don't have pricing are invariably too expensive, so I skip them, but there are plenty of others to check out that aren't Cloudflare. The one article I skimmed even says whether the providers are pricy or affordable.

Nobody needs Cloudflare. If (most) people were aware of how much Cloudflare breaks visibility across the world, they'd likely avoid Cloudflare, too.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#228

Earlier quoted context omitted.

Like what? When I last tried to DIY it, weeks of work resulted in maybe a 20% decrease in spam traffic. Then we tried Cloudflare and overnight it pretty much went to zero. That was like ten years ago though. What are some good alternatives?

You should design your site to be resilient to spam traffic, not try to filter until it's gone. By filtering, you've become unreachable by much of the world, spammers or not.

Well, that sounds easier said than done. Do you have any advice or tutorials on how to do that effectively?

We did try, casually at first over the years, then intensely as a focused effort over several weeks, to little effect. We tried blocklists, fail2ban, firewall rules, heuristics, CDNs, other non-Cloudflare services, etc. It cost us dozens of hours of labor and thousands of dollars of other service provider fees, but the spam didn't abate much. It was causing excessive server load, many credit card authorization attempts (they didn't go through, thankfully), sometimes fake PO orders, screwing up our analytics, etc.

Then out of desperation, we found Cloudflare. It took maybe half an hour to set up, cost $20/mo at the time, and overnight all our spam problems stopped. For a small business, it was a godsend, freeing up our devs to work on actual features instead of fighting bots all the time, and saving us thousands of dollars in hosting fees.

> By filtering, you've become unreachable by much of the world, spammers or not.

But... that's the whole point! We weren't some huge enterprise SaaS trying to advertise to the whole world, just a small US-only business. We had no business in China, Russia, India, etc., where most of the spam was from. We tried in vain to block that traffic on purpose, but couldn't easily do it until Cloudflare.

Then Cloudflare let us flip a toggle... and it all magically worked. Our staff was much happier, our actual customers never noticed (they were all US/Canada based, or rarely Europe), nobody ever complained, and we saved thousands of dollars a year.

It's not just about DDoS (which we did get on occasion, and our host did help us with) but the consistent drive-by bot scraping, pen testing, port scanning, etc.

Cloudflare sometimes gets a lot of hate here, but for small website operators, they are a HUGE lifesaver. I've never actually heard a complaint from a real customer about this, but even if we hypothetically lost a handful, the time and money saved not dealing with spammers is worth it to many businesses.

The internet has long since stopped being the open wonderland where everyone is nice and contributes positively. The overwhelming majority of it is worthless bot traffic, and you could make an entire career out of trying to prevent it... or just give Cloudflare a few dollars and a few minutes. Sorry, I don't see them as evil, just... practical? Useful?

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#229

Earlier quoted context omitted.

For half my life I had an Egyptian passport, and for the other a German passport. Having experienced both sides, that bit of paper is without a doubt the most valuable thing I own. It's hard to quantify the kinds of doors it has opened for me. I was able to get a scholarship to study in the UK that covered home/EU rates (a third of international rates, while I might not have been able to get even a student loan other…

> I see the kind of freedom that I have because of that passport as one of the biggest modern injustices. I think you're confusing a vague and abstract problem of "injustice" with a very concrete and real difference in ways different countries manage their public services and institutions. You only listed personal benefits that a country like Germany provides to their citizens and the higher education institutions bu…

> different countries manage their public services and institutions.

This is the injustice. The decisions made by these institutions are not just. Sometimes they're business decisions (e.g. a university can make more money price gouging international students, when we're getting an identical education).

There can be an overlap with privilege, but at that point you're arguing semantics. For example, I'm privileged if I don't get racially profiled by the police, but it is also unjust for police to racially profile me. To say that it's down to the institutions/countries/individuals making the decisions is the same argument as "well that bakery is a private business, they can decide not to serve you because of your nationality".

Of course there are Germans and Brits that haven't had the same opportunities that I have had, and of course it wasn't handed to me on a silver platter either; I still had to work hard. But my point is that if I were Egyptian _no_ amount of hard work or luck would have gotten me where I am. It would have been quite literally impossible.

I'm not even going to begin to crack open the can of worms that is the colonial history of the same countries (in my case the real and lingering effect that the UK has had on Egypt). The way you compare the institutions "built by the UK" and the ones "provided by Egypt" makes it sound like "well maybe Egypt should just do better m" when the reality is that the prosperity of these very countries is built on centuries of injustice and blood. Call it what you want but it's injustice all the way down.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#230

Earlier quoted context omitted.

Few of them do have an effect on the military, but hardly a significant one. Some of them forced the government officials to eat their own dog food. Most of them, however, feel like mocking petty revenge. If anything, those sanctions that disproportionately affect regular powerless people only reinforce the official propaganda's view that "we're encircled by enemies". Vladimir Kara-Murza expressed the same ideas much…

> In my own opinion, a good step in the right direction would be if we could travel to European countries as easily as we used to be able to. I don't agree. Russia's regime threatens Europe with invasion and nuclear bombs almost on a daily basis, and vilify everyone who doesn't enthusiastically support their invasion of Ukraine. A few years ago Russia even had a nuclear bomber circling the coast of western Europe. Th…

> It's not unheard of having Russian tourists insulting and threatening locals. In Europe or in any corner of the world.

I live in one of the most touristic cities in the world (Rio de Janeiro) and after meeting hundreds of Russians, that's the first time I hear about it.

Post reply on HN