Live data from Hacker News

Cloudflare misidentifies Hetzner IPs as being located in Iran

gitlab.com

101–110 of 245 posts

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#101

Earlier quoted context omitted.

I’ve been noticing more and more US state and local government websites blocking traffic from outside the US. (And I’m not talking about traffic from North Korea, I’m talking about traffic from ANZUS/AUKUS/FVEY ally Australia.) It seems stupid because just because someone is overseas doesn’t mean they can’t have valid business with a US state or local government. Maybe they are an American who is travelling and has t…

Well, perhaps Australia should stop threatening non-Australian websites that don’t comply with AUS law.

I’ve never heard of any Australian authorities making legal demands of US state and local governments.

I don’t necessarily agree with various official Australian attempts to impose Australian law on foreign non-government websites, but I don’t see how that is relevant to whether US governmental websites permit access from Australia

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#102

Earlier quoted context omitted.

I live in a small EU country. There are many, many american sites that just block the whole EU IP ranges becaus they don't want to deal with GDPR.

I’ve been noticing more and more US state and local government websites blocking traffic from outside the US. (And I’m not talking about traffic from North Korea, I’m talking about traffic from ANZUS/AUKUS/FVEY ally Australia.) It seems stupid because just because someone is overseas doesn’t mean they can’t have valid business with a US state or local government. Maybe they are an American who is travelling and has t…

Another annoying one is bank apps being unavailable from other countries. For example Australian bank apps when you're in the UK. Or the Vodafone app the other way around. People travel, it's ok to install an app abroad.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#103

Earlier quoted context omitted.

Sadly the EU doesn't really communicate this very well, and doesn't care to call out outright propaganda from ad tech and surveillance businesses, but the regulation is not actually hard to be compliant with. It literally just asks that you don't spy on people. That's it. Not spying on users? Great, you don't even have to do anything. I would be extremely surprised to see any attempt at enforcement against a website…

It's slightly more involved than this, but not extraordinarily so. For example seemingly innocuous implementations like loading fonts directly off Google Fonts without consent (i.e. providing Google with information about visitors' browsing habits) would technically be on the wrong side of the GDPR, but I think it's very unlikely that anyone would complain about it, legally speaking.

> would technically be on the wrong side of the GDPR, but I think it's very unlikely that anyone would complain about it, legally speaking.

The American in me says that sounds like "someone will definitely complain about it, eventually, if only because they're hoping for a payout".

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#104
I will describe what we do at IPinfo to avoid such a messup. First of all because we do active measurements and our data is usually less prone to errors like this and when it comes to IP location it is as good as it gets.

We have a support team active 247. Then is the issue of update rollout, when things goes wrong (rarely if ever) we can push data updates immediately. We work with our customers and users and try to push immediate fixes.

But the most important thing in my opinion we do is this comment itself. If things go wrong we will address it before you come to our support team.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#105

Earlier quoted context omitted.

The burden of not tracking people is quite small.

As someone that knows next to nothing about it, I was curious and googled how to adhere to the GDPR, and read through the top recommended article. Here's some choice quotes: "Complying with the GDPR is a huge undertaking" "GDPR compliance (occupies) a huge amount of IT time and resources" "Moving your organization into GDPR compliance is a process you ideally started long ago" The article links to some ICO GDPR data…

All of that is about complying with gdpr, assuming you're sharing customer data. If you don't, there's nothing to do. It's like "international shipping of live animals is a massive undertaking and takes lots of time" - cool, it's true - I'm not doing that so I'm done.

Sure, you have to comply with data requests, but if you don't store/share it... that's also trivial.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#106
Is Apple store working in Iran? For example, Apple store is working in Russia.

I genuinely do not understand how logic works between 1.sanctions 2... 3.let's ban some IPs. What is the chain of reasoning happens on step 2? Why this is not applicable to Google/Apple?

There are definitely sanctions against Russia, yet Apple/Play stores work just fine.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#107

Earlier quoted context omitted.

Well, perhaps Australia should stop threatening non-Australian websites that don’t comply with AUS law.

I’ve never heard of any Australian authorities making legal demands of US state and local governments. I don’t necessarily agree with various official Australian attempts to impose Australian law on foreign non-government websites, but I don’t see how that is relevant to whether US governmental websites permit access from Australia

It's much easier to say "I'm going to make it impossible for us to have to worry about the Australian government filing a lawsuit against $my-state-agency, because legal said so" than "Well, if we allow Australian IPs to access this website, there's a 0.x% chance that we get sued by Australia, but it's worth it for the sake of the 0.00x% of American expats in Australia."

Here's a analogously real example from current US-Ukraine policy:

> For example, one current social goal in the U.S., given the geopolitical conflict with Russia, is to avoid facilitating activities that could aid the adversary. As Russia has invaded Ukraine, the U.S. has positioned itself in opposition to Russia but not Ukraine. Banks, therefore, need to align with these geopolitical stances, leading to decisions that might catch some individuals in the crossfire, even if they’re not directly involved.

> Financial institutions often interpret this as: if they're not deeply specialized in doing business in Ukraine, they should avoid it altogether. They fear they won’t be able to consistently ensure compliance with these complex directives from the government [especially because there's a chance those directives might change in a week, or a month, or 3 months].

> This creates a split-brain problem within U.S. decision-making. The government intends to say, "Please cut down on oligarch money laundering that supports Russia’s war effort." However, financial institutions hear this as, "Under no circumstances should you fund anything related to Ukraine," including, for example, scholarships for Ukrainian high schoolers—a slight exaggeration, but not far from the reality in some cases.

(source: https://www.complexsystemspodcast.com/episodes/true-crime-ba...)

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#108

Earlier quoted context omitted.

I'm surprised I don't see it more. You can't impose a regulatory burden more troublesome than your traffic is worth

Sadly the EU doesn't really communicate this very well, and doesn't care to call out outright propaganda from ad tech and surveillance businesses, but the regulation is not actually hard to be compliant with. It literally just asks that you don't spy on people. That's it. Not spying on users? Great, you don't even have to do anything. I would be extremely surprised to see any attempt at enforcement against a website…

It's more than just not spying on people. You have to be able to prove you don't spy on people. And any vendors or contractors you use also don't spy on people, and respond to requests from anyone about all the data you have on them. And delete all of the data you have for anyone who cancels their account. Sure in some cases, that isn't a huge burden, like if you have a website that doesn't handle any customer data. But if you have a non-trivial app where you need to handle a lot of customer data for your app to work, it is a significant burden. And deleting someone's data as soon as they cancel can be really bad if someone accidentally cancels, so you probably want some kind of delayed deletion.

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#109

I'm frequently reminded how thankful I am to live in a country with a strong, positive international reputation. Even ignoring actual quality-of-life stuff associated with where I live - simply not being from a country with a "dodgy" reputation makes many things so much easier. I don't have to think about blocked websites. Companies accept my payments. Couriers ship to me. With my passport, I walk straight to the fro…

I live in Russia and I've never experienced most of the things you're describing. And it's become so much worse after 24/02/2022. We even had Spotify for a year! It was starting to genuinely feel like a first-world country.

Now you have to open a bank account in a different country for foreign companies to consider taking your money at all. The internet is utterly broken. The government blocks quite a lot, AND some foreign services block Russian IPs from their side. I even made a thread about running into Cloudflare's "you're blocked" pages randomly throughout the web: https://mastodon.social/@grishka/111934602844613193

Re: Cloudflare misidentifies Hetzner IPs as being located in Iran

#110

Earlier quoted context omitted.

I’ve never heard of any Australian authorities making legal demands of US state and local governments. I don’t necessarily agree with various official Australian attempts to impose Australian law on foreign non-government websites, but I don’t see how that is relevant to whether US governmental websites permit access from Australia

It's much easier to say "I'm going to make it impossible for us to have to worry about the Australian government filing a lawsuit against $my-state-agency, because legal said so" than "Well, if we allow Australian IPs to access this website, there's a 0.x% chance that we get sued by Australia, but it's worth it for the sake of the 0.00x% of American expats in Australia." Here's a analogously real example from current…

> It's much easier to say "I'm going to make it impossible for us to have to worry about the Australian government filing a lawsuit against $my-state-agency, because legal said so" than "Well, if we allow Australian IPs to access this website, there's a 0.x% chance that we get sued by Australia, but it's worth it for the sake of the 0.00x% of American expats in Australia."

I personally doubt US state and local governments are specifically targeting Australia in the way you suggest.

I actually doubt they are thinking about Australia at all. I also doubt their legal departments are worried about the Australian government, since the Australian government taking legal action against a foreign government (even a local or subnational one) would in most cases be illegal under all three of international, Australian and foreign law due to sovereign state immunity, and diplomatically they wouldn’t do it to the US because it would offend their American allies. If for some strange reason an Australian government agency had a bone to pick with some US state or county, they’d aim to solve it with the US State Department. Private corporations and individuals are not protected by the same legal doctrines or diplomatic protocols.

I think they just see some option in their firewall config (or Cloudflare or whatever) called “limit countries allowed to access”, they turn it on and add only the US, and then they think “see I’ve kept all the foreign hackers out now!”.

Post reply on HN