Live data from Hacker News

Introducing the Cloudflare Onion Service

blog.cloudflare.com

1–10 of 23 posts

Re: Introducing the Cloudflare Onion Service

#2
> Tor isn’t known for being fast.

Boy, is Tor fast. Try i2p if you would love to see what “not known for being fast” means. Tor is reasonably fast for its use-cases, and those are - for most part - not watching videos.

That said, I very much applaud Cloudflare working on this! The Cloudflare-wall-of-death for Tor users always makes me navigate away from pages immediately.

Re: Introducing the Cloudflare Onion Service

#4

What is the motive behind this? Is it just to harden the stance that Cloudflare puts privacy first? I'm not trying to be at all cynical, just don't understand the energy invested by Cloudflare to launch this?

It enhances privacy by removing the exit nodes and the transit across the Internet. It should make browsing Cloudflare managed sites via Tor fast. It makes it easier for us to deal with abusive requests from the Tor network because we can terminate individual circuits that are abusive and leave legit users alone. It fulfils a promise we made a long time ago. It's cool.

Re: Introducing the Cloudflare Onion Service

#5
So to recap and ensure I understood correctly... Cloudflare will now offer a Tor Service endpoint. All websites running over CF will automatically route traffic over this Tor endpoint if I use Tor Browser 8.

If that is the case, it's quite awesome indeed, I should investigate the alt-svc thingy and add a tor node on my services for that stuff... Very interesting.

Re: Introducing the Cloudflare Onion Service

#6
Thanks to CloudFlare for working with Tor on these issues. The browsing experience for us legit Tor users is much better than it used to be.

I hope that eventually, .onion services can get DV certs so their proxy can serve that cert if the user connects directly, bypassing the need to connect through an exit node for the first connection.

One thing I'm curious about:

> While bad actors can still establish a fresh circuit by repeating the rendezvous protocol, doing so involves a cryptographic key exchange that costs time and computation.

Is there some way for the destination .onion service to scale the difficulty of this rendezvous challenge, so this proof-of-work scheme can continue to work? It would be sad if they get to the point where it's no longer an effective rate limit and have to go back to serving CAPTCHAs for every new circuit.

Re: Introducing the Cloudflare Onion Service

#7
post #6

Thanks to CloudFlare for working with Tor on these issues. The browsing experience for us legit Tor users is much better than it used to be. I hope that eventually, .onion services can get DV certs so their proxy can serve that cert if the user connects directly, bypassing the need to connect through an exit node for the first connection. One thing I'm curious about: > While bad actors can still establish a fresh cir…

I really doubt we'll go back to using CAPTCHA for that. We'd already (ages and ages ago) dropped the use of CAPTCHA for connections from the Tor Browser. Today's announcement is a further refinement of all the work we've been doing to make using Tor smooth with Cloudflare domains.

Re: Introducing the Cloudflare Onion Service

#8
post #7
post #6

Thanks to CloudFlare for working with Tor on these issues. The browsing experience for us legit Tor users is much better than it used to be. I hope that eventually, .onion services can get DV certs so their proxy can serve that cert if the user connects directly, bypassing the need to connect through an exit node for the first connection. One thing I'm curious about: > While bad actors can still establish a fresh cir…

I really doubt we'll go back to using CAPTCHA for that. We'd already (ages and ages ago) dropped the use of CAPTCHA for connections from the Tor Browser. Today's announcement is a further refinement of all the work we've been doing to make using Tor smooth with Cloudflare domains.

Good to hear.

For what it's worth, I haven't seen a CAPTCHA browsing cloudflare sites for a long time (months?), until just today I've gotten two (out of several tens of CF-backed sites visited). Could be related to these changes, not sure.

Re: Introducing the Cloudflare Onion Service

#9

> Tor isn’t known for being fast. Boy, is Tor fast. Try i2p if you would love to see what “not known for being fast” means. Tor is reasonably fast for its use-cases, and those are - for most part - not watching videos. That said, I very much applaud Cloudflare working on this! The Cloudflare-wall-of-death for Tor users always makes me navigate away from pages immediately.

Tor has definitely gotten faster over the past few years. It used to be pretty useless for actual browsing, but now it just feels like slightly slow wifi - even videos load fairly well.
Post reply on HN