Live data from Hacker News

The Trouble with CloudFlare

blog.torproject.org

191–200 of 361 posts

Re: The Trouble with CloudFlare

#191
> Users are either blocked outright with CAPTCHA server failure messages, or prevented from reaching websites with a long (and sometimes endless) loop of CAPTCHAs

Is it really a loop or are users just failing to solve the CAPTCHAs? A loop would be obnoxious: Just tell the user they are blocked; giving them more than 2 or infinite CAPTCHAs is a passive aggressive way to communicate.

Re: The Trouble with CloudFlare

#192

Earlier quoted context omitted.

> What you're doing is called externalizing costs. It's generally recognized as antisocial behavior. So if you're going to claim benefits to yourself at the expense of other people, at least recognize that you're doing it. Remember his preface - cranky old-school network operator. Let's say you have a hundred networks all connected together into some sort of "inter-net" system. If one AS starts sending out malicious…

We're not dealing with 99 ASs blocking another bad actor. We're talking about one service that sits in front of many popular services on the internet deciding to block another for dubious reasons. Cloudflare has near monopoly power here.

I guess I look at it differently - every site using CloudFare made the decision to delegate their web security to them. I don't see it as "one entity blocking another" but "all of those individual sites blocking a single network".

In that context, it's a lot of votes for Tor to find a solution to this problem.

Really, I'm surprised at CloudFare's restraint here. A lot of their customers probably couldn't care less about Tor, but they've been putting a lot of effort into trying to avoid blocking Tor users (actually blocking, not inconveniencing) or compromising their anonymity.

Re: The Trouble with CloudFlare

#193

Earlier quoted context omitted.

> In a system without any real rules or authority, I think "those adversely effected choosing to block the bad actor" is a fairly democratic solution to the problem. That's the part which is adverse to the rest of your argument. You're not voting off the bad actor, you're voting off everyone in the bad actor's country. We know how to deal with this problem. You go to a website, you sign up for an account, it can be p…

> That's the part which is adverse to the rest of your argument. You're not voting off the bad actor, you're voting off everyone in the bad actor's country. The bad actor is the organization or person responsible for administering the network where the abuse is originating. When I'm being attacked by someone's VPS, I report them to their host. After the fourth time I report them only to have their host pass along my…

> The bad actor is the organization or person responsible for administering the network where the abuse is originating.

The bad actor is the individual who acts bad. The Post Office is not a bad actor for delivering letters.

> allow them to externalize the costs of their lack of enforcement

Tor is not an enforcement agency. Neither is CloudFlare. The costs of bad actors are your costs. You have the technical ability to retaliate against common carriers for not allowing you to push those costs onto them, but that doesn't make you right to do it in any sense other than might makes right. And you should realize that in doing it you're knowingly hurting innocent people.

Re: The Trouble with CloudFlare

#194
post #144

Earlier quoted context omitted.

Yes, reputation is a form of tracking. And if you show up to a site with no reputation of your own, from an IP that has a known-bad reputation, it is in the best interest of the site to challenge (not block) you. You are 97% likely to be malicious traffic. Edit: 97% is a real number, not an exaggeration, based on numbers from the report linked in the article.

Even better, treat the website that does so as malicious and stop visiting it.

That's an entirely valid response. Just don't expect anything to change due to your boycott, since only 0.04% of all legitimate traffic comes over Tor. They won't miss you.

Re: The Trouble with CloudFlare

#196
post #130

Earlier quoted context omitted.

Exactly. But I strongly disagree. You don't blame mask manufacturers for malicious people wearing masks. It's like city guards banning everyone with a mask from entering and issuing IDs to them. Then they're using those IDs to determine what they should and shouldn't see in the city, tracking them everywhere "across cities" etc. In the interest of privacy, it is best to instead use the dynamic nature and types of the…

> It's like city guards banning everyone with a mask from entering and issuing IDs to them. The flaw in this analogy is that in this case the mask makes every person completely indistinguishable from every other person wearing the mask. In this case, one ID is issued to every person wearing the mask. When 90%+ of the people with this ID are criminals and vandals, blocking anyone with this ID is a pretty obvious and e…

That's a crazy thing to do. Why would you block everyone? This would completely erode privacy online.

As I said elsewhere, if you see 1000 masked people rush into a bar and block the entrance with their bodies, is the solution to block all masked people from going to all establishments?

Clearly, if this happened IRL, people would just put a limit on the number of masked people entering that bar until there wasn't a group of 1000 of them trying to get in.

Re: The Trouble with CloudFlare

#197
post #60

Maybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those n…

Actually, I think the real problem is the idea that networks are responsible for policing their users, rather than the idea that servers should be responsible for policing their clients. The former is what people want (because it's easy: blame an IP, ban it, be done), but the latter is the reality.

CloudFlare's CAPTCHAs are an attempt to deal with that reality, but they're heavy-handed. Worse, they're at the wrong level: the protected site may have already verified that the user is legitimate, but CloudFlare imposes its block when the user's source IP changes again.

CAPTCHAs belong at the application layer, not the transport layer.

Re: The Trouble with CloudFlare

#198
post #189

Earlier quoted context omitted.

Yes, but Tor flips through IP addresses regularly so you'd get challenged every few minutes. Similarly, if you block cookies/supercookies/etc to avoid being tracked ... you'll be challenged every view.

Yes, you will. But the point is, with no other information to go on, that is the best option for the website. If you don't want to be challenged constantly, you need to give the website operator some incentive to accept your traffic.

Honestly, it probably would be beneficial to my productivity if I dropped all of Cloudflare's IP ranges since it'd keep me from going on HN, Reddit, etc. :P

The need for incentive you mention is silly. The website operator [much like a job searcher with a resume] wants to be in front of as many non-malicious people as possible. And while you might argue .04% of malicious traffic comes over Tor, I've operated sites where 20%+ came over some sort of proxy with poor IP reputation.

You know what?

Fuck it. I'll just build my own site that doesn't use Cloudflare for such a purpose.

Re: The Trouble with CloudFlare

#199

> Users are either blocked outright with CAPTCHA server failure messages, or prevented from reaching websites with a long (and sometimes endless) loop of CAPTCHAs Is it really a loop or are users just failing to solve the CAPTCHAs? A loop would be obnoxious: Just tell the user they are blocked; giving them more than 2 or infinite CAPTCHAs is a passive aggressive way to communicate.

My best guess is that reCAPTCHA doesn't just have two states (pass/fail), but rather something like a confidence factor and a threshold you have to reach to continue to the site (which might depend on your reputation).

Re: The Trouble with CloudFlare

#200

Earlier quoted context omitted.

We're not dealing with 99 ASs blocking another bad actor. We're talking about one service that sits in front of many popular services on the internet deciding to block another for dubious reasons. Cloudflare has near monopoly power here.

I guess I look at it differently - every site using CloudFare made the decision to delegate their web security to them. I don't see it as "one entity blocking another" but "all of those individual sites blocking a single network". In that context, it's a lot of votes for Tor to find a solution to this problem. Really, I'm surprised at CloudFare's restraint here. A lot of their customers probably couldn't care less ab…

Developers care and they are very important to Cloudflare. It is in their best interest to actually do it properly.
Post reply on HN