Live data from Hacker News

Dear customers of Cloudflare: an appeal regarding Tor

gitlab.com

141–150 of 172 posts

Re: Dear customers of Cloudflare: an appeal regarding Tor

#141
post #35

Earlier quoted context omitted.

As a website operator too I don't see spammers, attackers and script kiddies from tor network with valid user agents (tor browser or mainstream up to date browsers). The worst I see in that traffic is very few people trying to post/upload something anonymously, but mostly it's just people trying to access a few pages anonymously. Bots and scrappers for some reason use fake user agents in tor network and just get 403s…

I'm not sure when you last tried Tor, but it's not that slow these days. I first tried Tor several years ago, and it was so slow I couldn't understand how anyone could bear to use it - but I tried it again recently, and (to my surprise) for general browsing at least, it didn't seem to add any noticeable lag. I wonder if Tor has finally reached critical mass and is ready for more widespread use?

Not only do I use Tor a lot and find it mostly OK, but I use OrBot to encrypt traffic from other apps on my phone and most of the time I don't notice any overhead.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#144
post #90

Earlier quoted context omitted.

That makes a lot more sense, regarding in-Tor bandwidth. I've also had quite a few projects in which I'm trying to normalize Tor usage. My biggest one thus to date is a Tor-ified IoT network that uses your own resources instead of nebulous "cloud" providers. https://hackaday.io/project/12985-multisite-homeofficehacker... Long story short, there's a lot of promise to a .onion address, given it acts like a telephone nu…

Yes, Tor hidden services are neat technology, using them for IoT is a clever idea. Authenticated, not really scannable and you avoid the typical issue of going out to someone pre-determined to get connectivity from the outside.

This only works for HSv3 though. HSv2 addresses are enumerable without too too much work.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#145

Earlier quoted context omitted.

You need to provide fiscal value or convince the operations team of legitimate companies to not treat Tor as a bad apple. It may not be right but money is the only motivating example that matters to companies.

The plea also goes out to people who have their blogs running through Cloudflare. (For some reason.)

A zero-configuration free CDN is a pretty good reason in my opinion.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#146
post #22

Earlier quoted context omitted.

Not GP, but my guess is ban evasion. Someone gets banned from bad behavior, they create a new account. So you IP ban them. Then they switch over to Tor and keep making new accounts from anonymized IPs and start disrupting the forum by spamming it with slurs. The only solution is to ban Tor.

Or, you know, limit the ability of newly created user to spam forums. Or put them on "must be reviewed" lists. Or... The easiest solution is to ban Tor, but it's far from the only solution.

All of those may entail much, much more work than banning Tor.

I can think of plenty of cool, robust systems I can build as well, but I do not have unlimited resources.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#147
post #32

Earlier quoted context omitted.

Actually probably not very much traffic is from tor. Tor bandwidth is notoriously bad.

are there any researched measurements to show exactly how much is available? obviously it would vary greatly depending on where the connection is going... but wondering if there is some overarching idea of what it has..

You can see that for a 5MiB file average download time is around 12 seconds [0], which is around 425KiB/s, the main problem with Tor is latency, downloading a 50KiB file takes around 1 to 2 seconds.

[0] https://metrics.torproject.org/torperf.html?start=2018-05-15...

Re: Dear customers of Cloudflare: an appeal regarding Tor

#148
post #18

Criminals will just hire a botnet, as we can see from all incoming spam email and forum bots, etc. For the rest of us who desire to be anonymous online, there is Tor. Whatever people can do over Tor, they can also do without Tor. You're probably never going to find them anyway, even if you would sue in the first place. This whole tor vs clearnet distinction is way overblown. Sure people will do more crap if they're a…

Almost all of the attacks on my website have used Tor (trying to get bitcoin from other users).

Sure, attackers can find an alternative. It just won’t be Tor. :)

Re: Dear customers of Cloudflare: an appeal regarding Tor

#149
post #84

Earlier quoted context omitted.

I use it to control my 3d printers at our local hackerspace. I have octoprint set up with a IP behind a NAT, and a hidden service. When I'm not at the 'space, I use Orbot on my android and OctoRemote. I get reasonably good speeds and latency. I can also view my webcam on the printer. It's not 4HD by any means, but is definitely usable.

It wouldn't be surprising if hidden services had a lot better performance. Running a guard node is a lot less risky than an exit, so there's probably a lot more capacity available for traffic staying inside the network.

They perform quite worse:

https://metrics.torproject.org/torperf.html?start=2018-05-15... https://metrics.torproject.org/torperf.html?start=2018-05-15...

You can see that for a 5MiB file, hidden services perform 2-3 times slower, I would put most of the blame on data having to travel through more hops when using hidden services.

Re: Dear customers of Cloudflare: an appeal regarding Tor

#150

I fully get the pain of a "bothersome captcha" but as a website operator (who's sites are behind cloudflare), there is a balancing operation. How much of the traffic out of Tor is legitimate, and how much is spammers, attackers and other script kiddies? For me, the answer is "very little legitimate". A better request for Cloudflare websites would be to put the CAPTCHA's just on actions that need protection. Reading a…

Definitely in line with your statement, I ran a forum for years. At one point I found an iptables script that blocked all known Tor endpoints. What happened was, trolls posting gore and porn to a child oriented forum (which had persisted for 2-3 years) immediately and totally stopped. People in these threads point out that "criminals can use a VPN", but in practice it never happened to us. I never once heard from anyone that a legitimate user was impacted.
Post reply on HN