Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

11–20 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#11
Why would a company that values their users' privacy have Cloudflare man-in-the-middle their traffic in the first place?

Cloudflare decrypts the traffic, which in many cases includes personally identifiable information like names, email addresses, transactions, etc. It's hard to imagine something more anti-privacy than allowing a third-party access to all of your users' data.

Tor users should take those CAPTCHAs as a sign that they're visiting a web site that they can't use while maintaining their privacy.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#12
I get the appeal, and I get it's a PITA. But, if the referenced CloudFlare support document is to be believed, then you'll be putting yourself at additional risk by whitelisting, or otherwise "turning down" the security related settings for Tor users.

Let's pretend for the minute the support article is accurate, and let's pretend CloudFlare's security checks are useful. (I don't have any opinions/knowledge myself if there are true/false, so let's assume they are true - as most CF customers will).

Why should I turn off the security CloudFlare is providing me? The appeal doesn't give me anything I can use to justify turning this off. Given the percentage of tor users vs not-tor users, I can't really call the "it bothers Tor users" statement justification for turning this off.

I know it shouldn't be needed, I know anonymous browsing should be taken for granted, however - reality is - it's not. For an appeal like this to succeed, or even make a measurable dent, you'll need more.

I do hope you find more, anonymous browsing should be the norm, not the exception - but I don't believe this appeal will make a dent.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#13
post #7

The Tor Project is invaluable in countries like Russia, where the gov. can block literally millions of IPs just to get rid of one pesky messaging app. Now that I think about it, people using it should probably donate more to the project. Although this very same gov. can always see it as "supporting the terrorists".

This seems less like a dialogue revolving around the post and more like a promotion of TOR

Re: Dear customers of Cloudflare: an appeal regarding Tor

#14

There is a disconnect here: I've read so many technical articles from cloudflare about neat problems they solve while at the same time they just boldly say fuck you to net neutrality and aggressively try to get people on board with the tracking internet that their corporate partners desire so strongly. I get the sense these aren't the same groups of people at the company itself. I've been browsing anonymously with to…

> they just boldly say fuck you to net neutrality

That's not what "net neutrality" means: Cloudflare is a service the site operators choose to pay for.

An example of actually saying fuck you to net neutrality would be your ISP announcing that access to "premium web sites" will be slowed to 10kb/s unless you pay an additional fee.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#15
post #13
post #7

The Tor Project is invaluable in countries like Russia, where the gov. can block literally millions of IPs just to get rid of one pesky messaging app. Now that I think about it, people using it should probably donate more to the project. Although this very same gov. can always see it as "supporting the terrorists".

This seems less like a dialogue revolving around the post and more like a promotion of TOR

It's an argument for "why you should care", which is relevant to the post.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#17

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

It would be cool if you could set a header to Cloudflare when a user is logged in, perhaps with that user's ID. That could then trigger significantly decreased security.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#18
Criminals will just hire a botnet, as we can see from all incoming spam email and forum bots, etc. For the rest of us who desire to be anonymous online, there is Tor. Whatever people can do over Tor, they can also do without Tor. You're probably never going to find them anyway, even if you would sue in the first place.

This whole tor vs clearnet distinction is way overblown. Sure people will do more crap if they're anonymous, but if you block Tor criminals will just use something else.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#19
post #9

I've got enough problems on my sites from Tor that I simply block T1 (Cloudflare's "country" code for Tor users) on their settings. Blocking whole countries used to be a Enterprise only feature, but now it's available to Pro users.

What problems do you have?

Re: Dear customers of Cloudflare: an appeal regarding Tor

#20
post #5

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

You can do that with pagreules

[deleted]
Post reply on HN