26 ms·
The Trouble with CloudFlare
- travjones 11y agoOriginal Cloudflare blog post that this is a response to: https://blog.cloudflare.com/the-trouble-with-tor/ https://blog.cloudflare.com/the-trouble-with-tor/
- deleted 11y ago[deleted]
- mjs 11y agoThat post also suggests two things that Tor could do to improve the situation for their users: * Support a stronger hashing algorithm to make it possible for CloudFlare to make .onion versions of all of their customers' sites. * Implement "client-side" CAPTCHAs. I don't how feasible either of these are, but it seems strange (evasive?) that Tor Project's blog post does not discuss either.
- pfg 11y agoI believe Tor is working on a new version of hidden services which would address the first concern.
- mootothemax 11y agoI don't know what the solution is here. One of my sites enjoys a ridiculous number of fraudsters trying to make purchases, many - but very much not all - from the tor network. The easy solution is to punish everyone and ban tor exit nodes from access, and woo, a significant reduction in my fraud rate. The way I justify this to myself is that the site only accepts payment via PayPal and/or credit cards, and paying with those in itself gives up a good amount of privacy. For sites that don't make a profit and have to use unpaid time to clean up the mess from some tor nodes, I really don't know what the solution is. It definitely sucks for legitimate users. Edit: one more difficulty is that I don't know if I was targeted by one or two lazy-yet-determined fraudsters who only use tor, and so make tor look worse than it is with their repeated attempts. No idea even where to begin with that one.
- jimktrains2 11y agoTor can't possibly be the only signal of fraudulent activity though? It may be one that has an easy "solution" however, but one that's easily circumvented (one of the many free VPN services out there).
- mootothemax 11y ago>Tor can't possibly be the only signal of fraudulent activity though? Yes and no. Yes: many fraudsters are ridiculously lazy, and fraud rates go down when the tor block is in place. No: plenty of fraudsters access from elsewhere (and I put them through a separate fraud-detection-SaaS)
- nxzero 11y agoSignal according to Cloudflare isn't "TOR" but the IP's the are used by TOR exit nodes get banned due to them being shared and abused enough to trigger that IP being tagged as a source of trouble. I personally don't buy this, since I know of IPs they don't block again would get enough abussive traffic to merit the same treatment, but don't get the treatment TOR's IPs get.
- Kalium 11y agoSince you think CloudFlare is lying, what do you think the truth is?
- nxzero 11y agoNot sure, though given enough dialog on the topic, I believe that a better solution will be found or it'll become clear that Cloudflare is not responding to the issue. Simple answer would be that the original analysis is flawed, they've forgotten that the wrote a script to block TOR exit IPs; TOR intentionally provides a list of these IPs to the public. Might be worth noting that TOR users are often the target of National Security Letters, that Cloudflare based on their own report received National Security Letters, and as such, would be unable to say if those letters impacted code on the topic.
- nxzero 11y agoExchanged comments with Cloudflare's CEO on the topic and in my opinion it appears that they simply don't understand that their view of the situation is skewed. Here's hoping that given they truly do appear to care about TOR users that they'll revisit the situation and find a better solution. Here's a link to Cloudflare's blog post an the related comments on HN: https://news.ycombinator.com/item?id=11388560 https://news.ycombinator.com/item?id=11388560
- d_theorist 11y agoIt's Cloudflare, not Cloudflair.
- nxzero 11y agoThanks, fixed the typo!
- d_theorist 11y ago:) Actually, I got it wrong as well, because it's really CloudFlare.
- Reedx 11y agoCloudflair is how their employees express themselves.
- chatmasta 11y agoAlso Tor, not TOR...
- nxzero 11y agoIt was TOR, now it's Tor. I like TOR better, since it makes it clear the letters have a meaning.
- ejcx 11y agoThe only correspondence you had with the CloudFlare CEO in that thread was: > eastdakota: I work for CloudFlare. We don't get anything from Google for using reCAPTCHA. I think you might have gotten a username confused.
- kjsthree 11y agoThis is a tough situation. I don't know about 94% of TOR traffic being fraudulent but I'm sure it's high. But I'm one of the legit users that gets taken out by blacklisting. I use a VPN service pretty regularly and it makes accessing my Cloudflare account and sites using it incredibly annoying.
- altotrees 11y agoYeah, 94% seems very high, and although I guess it could be possible, I can't imagine it is quite that high. Cloudflare is zeroed-in on Tor users, but am I crazy for thinking that there are several other ways bad actors could create issues not using Tor? It seems like they are trying to come up with an amicable solution, but for the moment, legitimate Tor and VPN service users suffer. If Cloudflare really refuses to acknowledge that their view may be a tad skewed, I don't see how this is readily or easily remedied.
- pfg 11y agoA large percentage of malicious traffic is most likely generated by bots, which are quite naturally better at creating a lot of requests.
- fluidcruft 11y agoI assume the actual claim is that 94% of fraudulent traffic comes via tor. Which is quite a different claim. There's a pretty obvious calculus. If you approach the question as 94% of the fraudulent traffic comes from the x% of total traffic that comes via tor... deciding to block tor exit nodes seems rational (particularly if x% is particularly small... say <1%).
- Kalium 11y ago> I assume the actual claim is that 94% of fraudulent traffic comes via tor. Which is quite a different claim. The claim is thus: > Based on data across the CloudFlare network, 94% of requests that we see across the Tor network are per se malicious. That doesn’t mean they are visiting controversial content, but instead that they are automated requests designed to harm our customers. Meaning that for any given request coming from Tor, the odds are heavily in favor of it being malicious.
- rbcgerard 11y agoI find Cloudflare's argument analogous to that of cash - i'm sure some huge percentage of all illegal transactions are with cash, but that does not mean the solution is to ban cash...though some would probably disagree
- nxzero 11y agoThis is an interesting point, one which would apply to a number of topics. Nice.
- d_theorist 11y agoA huge percentage of illegal transactions may be in cash, but a huge percentage of transactions in cash are not illegal.
- rietta 11y agoWhich is why large cash transactions are heavily regulated and reported on. In the US, one cannot just withdraw $10k or a series of smaller transactions that add up to $10k or more without the bank reporting on that to the authorities. That's the balance that law makers decided to strike.
- Klathmon 11y agoThat's an interesting point. Cloudflare is doing something somewhat similar. If you are deemed "possibly a bad person" then you are asked to solve a captcha. If you want to give up some of your anonymity, you can keep the cookie they give you as a token to "prove" you are a good person. If you don't want that though, there is nothing cloudflare can do to know you aren't a bad person. It's much less than "heavy regulation", but i can easily see how it could be both a pain and a security issue for some. This is a shitty problem for all involved with no good solutions...
- rbcgerard 11y agoan interesting aspect is that the bank secrecy act was passed in 1970, but has not been adjusted for inflation, so when the law was passed it was more like a $60k limit that has been encroaching on us ever since...
- Artemis2 11y agoThat's just flawed reasoning all around. I can't even find any e-commerce-specific data in their sources. > A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing commercial activity was "virtually equal" to that of non-Tor IP addresses). Actual data from the report: • Comparison of Tor and non-Tor Traffic: Of legitimate requests, non-Tor IPs accounted for 99.96 percent of requests, while Tor exit nodes accounted for 0.04 percent Of malicious requests, non-Tor IPs accounted for 98.74 percent of requests, while Tor exit nodes accounted for 1.26 percent • Tor exit nodes were far more likely to contain malicious requests: 1:11,500 non-Tor IPs contained malicious requests 1:380 Tor exit nodes contained malicious requests • However, traffic from Tor exit nodes yielded a conversion rate virtually equal to non-Tor IPs: Conversion rate for non-Tor IPs was 1:834 Conversion rate for Tor exit nodes was 1:895 Source: slide 7 of the report they link in the article – https://i.imgur.com/TcstnWD.jpg https://i.imgur.com/TcstnWD.jpg
- deleted 11y ago[deleted]
- kordless 11y ago> That's just flawed reasoning all around. Starting with a blanket blaming statement isn't that great either. Conversion rates and e-commerce sorta go together, so I would say it's fine to entangle them logically. Tor exit nodes entangle users with each other through an IP. If someone's lens is limited, they'll run the risk of blanket blaming the legitimate traffic as well.
- ynniv 11y ago[IP addresses of] Tor exit nodes were far more likely to contain malicious requests However, traffic from Tor exit nodes yielded a conversion rate virtually equal to non-Tor IPs You just described every busy IP address: if you handle more requests, you are more likely to handle a malicious one. This is the problem with IP based reputation.
- jamespo 11y agoThat post doesn't really offer any solutions. It would be interesting to find out how CF came to the 94% figure but a lot of the other claims made are not countered and presumably valid. I doubt CF's (paying) customers are particularly saddened by Tor users being inconvenienced.
- das-boot 11y ago>the site only accepts payment via PayPal >and/or credit cards, and paying with those in >itself gives up a good amount of privacy. i think both methods have proven not to be private at all.
- das-boot 11y ago>the site only accepts payment via PayPal >and/or credit cards, and paying with those in >itself gives up a good amount of privacy. I think both methods areactually not private and have proven not te be private at all
- tlrobinson 11y agoI feel like Tor is burying their head in the sand here. I think Tor is great, but I don't find it at all surprising or unlikely that 94% of traffic (not users) is malicious (spam, vulnerability scanning, scraping, etc) because it's likely that malicious traffic is automated while legitimate traffic is not. That said, I'd also like to hear more about CloudFlare's methodology.
- thinkMOAR 11y agoThe trouble with cloudflare, the lawyers of the internet. Making money on other peoples problems but not really solving anything.
- breakingcups 11y agoI think Cloudflare's blog post was incredibly nuanced, well thoughtout and (dare I say) pro-Tor. They implemented a way for their users to whitelist Tor traffic (bypassing all Captcha's), without allowing their users to blacklist Tor traffic. This response seems a bit of a childish knee-jerk reaction from the Tor project, which could've been worded more maturely.
- aeorgnoieang 11y agoI didn't spot anything worded immaturely. What specifically do you think could be more maturely worded?
- nxzero 11y agoThanks, agree, I'd like to know exactly what was childish and happy to own up to it if true and attempt to fix the issue.
- rfrank 11y agoThe number of hn users replying solely to tone and not content is pretty disappointing.
- nxzero 11y agoPossible it's tone, but also given the relatively low volume of voting, and it's unclear to me what if any steps HN takes to reduce abuse and fine tune community comment policies, it's very possible that something else is going on. For example, some users appear to have comment histories that are highly irregular; one comment suggesting Snowden should be invited to return to the US without any chance of being behind bars or worst, and in another appearing to state that the US has not overstepped their rights; which is possible, though strikes me as bit odd; 100% sure my comments to some are a bit odd, though do try to respond if a direct statement is expressed.
- grey-area 11y agoInstead of addressing the very real problems with usage of Tor, they try to pick holes in the 94% figure from cloudflare (which isn't actually very important), and go on to cite a study by cherry picking stats: https://news.ycombinator.com/item?id=11405101 https://news.ycombinator.com/item?id=11405101. They don't mention that it explicitly states something which backs up cloudflare's position: Tor exit nodes were far more likely to contain malicious requests and even: Risk averse companies may wish to block all Tor traffic The article then goes on to suggest that it is perfectly reasonable to use the word 'block' to mean showing a captcha - in common usage block means block - deny requests, not attempt to determine if a user is human with a captcha or some other method - that's not blocking, it's annoying and potentially pointless, but it's certainly not simply blocking users and it's disingenuous to describe it as such. All of that adds up to a response which seems to be more interested in scoring points than finding a solution for legitimate Tor users. I'm not sure I'd describe it as immature, but it's not a very constructive response, to an article which went out of its way to be Tor friendly and propose solutions. It would be much easier for cloudflare to really block Tor traffic, they would probably suffer very little from doing so.
- lazyjones 11y agoI find the 94% figure believable (for requests, not source IP addresses), Tor is after all the obvious choice for low bandwidth DoS attacks and unwanted scraping (i.e. a few individuals will generate a large percentage of Tor-routed requests at any time). The real issue with CF for me isn't the hassle with captchas, but the fact that CloudFlare can track users across all its sites, generate profiles and even read unencrypted traffic. It's a privacy hazard by design that makes Tor particularly attractive. But as long as Tor is used only by a small minority, it will be treated this way.
- pfg 11y ago> 5) A report by CloudFlare competitor Akamai found that the percentage of legitimate e-commerce traffic originating from Tor IP addresses is nearly identical to that originating from the Internet at large. (Specifically, Akamai found that the "conversion rate" of Tor IP addresses clicking on ads and performing commercial activity was "virtually equal" to that of non-Tor IP addresses). This point seems rather odd. I'm not following the connection between a large percentage of Tor requests being malicious and the fact that Tor users have almost the same conversion rate. Malicious requests are coming from botnets and/or fraudsters. They're, for the most part, not in the subset of Tor users which click ads or do anything else that would be tracked as part of a site's conversion rate. What's funny about this is that the linked report even confirms that requests from exit nodes are far more likely to be malicious: Tor exit nodes were far more likely to contain malicious requests: • 1:11,500 non-Tor IPs contained malicious requests • 1:380 Tor exit nodes contained malicious requests I'm a huge supporter of Tor and have been running a relay node for years, but it seems their stance on this topic is quite fundamentalist and they chose to ignore any arguments or facts that they don't like while basically grasping at straws in their counterarguments. It's okay to be concerned about CloudFlare having such a huge market share. They're a huge target for nation states and others alike. Global passive¹ adversaries are a problem for things like Tor, and they might very well be forced to become one at some point. It's essential to have more competition in this area, and that's a fair argument to make. However, with regards to how they're handling Tor, I don't think there's anything wrong with what they're doing, and the explanations presented in their blog post seemed sound to me. ¹ Or, rather, possibly an active adversary too?
- AnthonyMouse 11y ago> I'm not following the connection between a large percentage of Tor requests being malicious and the fact that Tor users have almost the same conversion rate. The point is that blocking or de facto blocking an IP address which is shared by many different users just because one is malicious is costing CloudFlare's customers money.
- pfg 11y agoThe reason some e-commerce sites are blocking Tor is not because of low conversion rates (that would be silly), but because of fraud (and attacks) coming from Tor users. Those two numbers are not related, and it has nothing to do with why CloudFlare shows captchas for Tor users. The argument doesn't address the fact that a large percentage of Tor traffic is malicious at all. It's a straw man argument, really. On top of that, it's not as easy as "blocking some legitimate users = losing money". The cost of fraud caused by Tor users might very well exceed the additional revenue Tor users generate - or not.
- scurvy 11y agoMaybe I'm a cranky, old-school network operator, but this is a very cut and dry problem. Tor runs a network that is rife with abuse and fraud. Tor needs to clean up and police its network. If it doesn't, it will be put on blacklists and customers will take active measures to block traffic from it. This is no different than a network or AS that is spammer friendly, botnet friendly, carder friendly, etc. All of those networks eventually end up on blacklists or Spamhaus lists and their efficacy goes down. Eventually, the network dies out and the criminals move somewhere else. Yes, it's a game of whack-a-mole, but it's proven to work well. I know Tor doesn't want to be in the network regulation business, but they need to be if they want their product to thrive. Otherwise, good bye Tor.
- _Codemonkeyism 11y agoThe main point I took away from the article, that from one exit node many users originate. Some users are spammer. They contaminate the exit node IP. CF blocks an IP for spam, but does not remove the block after some time (when the spammer moved on).
- scurvy 11y agoThat's definitely a legitimate point, but not the main point IMHO. The main point is that Tor makes zero effort to clean up the problem and uses the legitimate Tor users as helpless, scapegoated victims and a bullying tactic. "But think of the oppressed users!" Sorry, not buying it. The blacklisted IP lifetime problem is real though. It's a problem I've had to raise several times with our product and network teams. People would see an abusive IP and just ban it...without a TTL or lifetime. This really upset me as they seemed to think that was OK not just for the time being, but that it was good enough. When I describe IPv6 to them, their faces just melt as it sinks in that they can't just keep banning IP's and must do something higher up the stack to detect and block fraud.
- _Codemonkeyism 11y agoInteresting point, what would "Tor cleans up" mean?
- eastdakota 11y agoTor has acknowledged their "botnet problem" since at least 2013: https://research.torproject.org/techreports/botnet-tr-2013-11-20.pdf https://research.torproject.org/techreports/botnet-tr-2013-1... That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. As I wrote in our post on the topic, there's a trade off between security, anonymity, and convenience. CloudFlare provides security to our customers. We believe in the importance of anonymously accessing the Internet. Unfortunately, that means we have to sacrifice some convenience. If you haven't read it, I encourage you to see the post I wrote on the topic: https://blog.cloudflare.com/the-trouble-with-tor/ https://blog.cloudflare.com/the-trouble-with-tor/ The two long-term solutions we proposed — blinded tokens or CloudFlare supporting .onion addresses — we believe could reduce the inconvenience, but they'll require help from the Tor developers. While public posts like this are discouraging in terms of coming up with a better solution, I'm encouraged by private conversations we've had with Tor developers who acknowledge this is a hard problem and want to find solutions.
- ryanlol 11y ago>Tor has acknowledged their "botnet problem" since at least 2013: >https://research.torproject.org/techreports/botnet-tr-2013-1.. https://research.torproject.org/techreports/botnet-tr-2013-1.... >That same paper walks through the challenges of dealing with it and doesn't find any satisfactory solutions. But that's all utter nonsense! These botnets only access stuff inside the Tor network (i.e the C&C, that the operators want to hide), they don't use Tor to access clearnet content. Even a small botnet will have more nodes than there exists tor exit nodes (966 as of right now), what possible benefit could there be for the botnet operator from doing that?
- zzzcpan 11y agoWhy don't you just drop IP-based reputation system for Tor IPs completely and develop something else for these IPs, something based on data from actual requests and responses? Because it sounds like you want to preserve an incorrect system and are pushing this problem on Tor.
- eastdakota 11y ago
- bogomipz 11y agoThe trouble with Clouflare is that they receive disproportionate amount of attention on Hackernews. Sometimes HN feels like an extension of their marketing machine. I'm not so sure they every single blog post of their needs to be an item on HN. Anyway that's my .02 cents.
- nxzero 11y agoDo you use Tor?
- kristofferR 11y agoThe main problem with CloudFlare is how dumb their "protection" is. It doesn't make sense at all to block Tor users from just accessing read-only content, like CloudFlare does today. Forms/login pages/comment boxes etc should be protected of course, and most people wouldn't have anything against solving a captcha for logging in, but preventing people from just reading stuff anonymously/securely is borderline evil from a user experience point of view. However it's obviously much easier from an engineering standpoint though to just block people outright.
- angry-hacker 11y agoHave you ever had problems with malicious botnets/spam targeting your site and they are all behind TOR? It's not really that simple. If an IP, or IP range, behaves badly - goodbye. It's a TOR problem to solve it, it's not the problem of web servers and also CloudFlare.
- kristofferR 11y agoThat's my whole point. Feel free to require a captcha for the login form etc and other pages where botnets/spam can be a problem, but don't ban people from pages where they only have read-access anyway. It's like preventing people from reading books just because a few authors write a lot of crappy/illegal stuff. Sure - make it a little bit harder to "become an author" (by using a captcha), but don't make it harder to read stuff.
- pfg 11y agoThis was addressed in CloudFlare's blog post: > One suggestion has been that we treat GET requests for static content differently than we do more risky requests like POSTs. We actually already do treat more dangerous requests differently than less risky requests. The problem is Tor exit nodes often have very bad reputations due to all the malicious requests they send, and you can do a lot of harm just with GETs. Content scraping, ad click fraud, and vulnerability scanning are all threats our customers ask us to protect them from and all only take GET requests.
- 11y ago
- BEEdwards 11y agoThis is a terrible reply, it's basically say's "It's all your fault, we're all good over here." They then either because they legitimately can't understand the problem, which would be scary, or because they're being stubborn fail to address the suggestions by cloudflare to address the issues.
- JDDunn9 11y agoI think CloudFlare's security measures are insane. I use a VPN and I can tell which sites use CloudFlare because I consistently get a Error 520, where it claims the browser and CloudFlare are working, but the website is not responding. Yet I turn of the VPN and magically it works fine. That's dishonest. At least own that you are the one blocking my visit. I'm also developing with Dwolla's API, and CloudFlare blocks all HTTP requests from my local IP, so I can't develop locally. Thanks CloudFlare.
- throwaway-10439 11y agoYeah, this is beyond just Tor - they're breaking VPN and carrier-grade NAT traffic too. Even if Tor bowed to their demands those would stay broken, and scammers would still fill out the captchas manually. But they seem very set on their chosen solution!
- ryan-c 11y agoI would expect most of the malicious traffic coming out of Tor isn't using Tor browser. I wonder what the attack numbers look like for Tor browser vs not Tor browser. Cloudflare has client side checks already, which could be extended to check whether the browser is Tor browser, and if so, don't block it.
- r2pleasent 11y agoPayments originating from TOR IP addresses absolutely are more likely to be fraudulent. Anyone running an online business could tell you that.
- fabulist 11y agoHassling Tor users shouldn't become the Internet's default. If you're having trouble, consider informing Tor users checking out that you won't process the payment without their providing additional information. This raises the cost to carders a lot more than needing to rent a SOCKS proxy in a residential area.
- agrajag 11y agoIt's not worth the development costs and extra verification costs to try to weed a small number of legitimate purchases from a sea of illegitimate ones though.
- fabulist 11y agoIt isn't that there is a sea of illegitimate traffic so much that their methodology is incredibly flawed, and they have little financial incentive to fix it. As a society, we have to give them that incentive, or we will lose access to a shared resource. We can have our Internet heavily censored or heavily censored with a ray of sunshine. Is that worth the engineering costs?
- floatboth 11y agoI wouldn't even consider doing any payments through Tor. All I want is to read fucking blog posts without CAPTCHAs!
- pharrington 11y agoMaybe I either missed this or forgot, but what percentage of overall internet traffic handled by Cloudflare is deemed malicious?
- nulbyte 11y agoIn fact, I'd like to see CloudFare segment out other populations and provide similar statistics. With carrier-grade NAT, corporate proxies, VPNs, ... Surely Tor is not the only segment that behaves similar. As I see it, CloudFare is taking one group and applying stereotypes to justify a draconian technique. I suspect they may be doing the same with other undeserving groups. Seems to be the way the world goes, when money gets involved.
- yazaddaruvala 11y agoSomeone with more knowledge of these thing, let me know: Why does Tor not "charge" per request? i.e. Using some decentralized currency, to pay for requests. 1. Make it cheep enough such that users don't care, however, financially disincentives spammers/malicious users. 2. It would continue to be anonymous. - cycle through wallets - all transactions would also be proxied. 3. It would incentivize proxying and exit nodes (exit nodes would effectively collect a bunch of virtual money to be resold to clients for USD).
- nulbyte 11y agoIf users don't care, spammers don't care; spammers will get a financial return.
- ronaldo1 11y agoI understand what CloudFlare is saying but I still think that the benefits of allowing legitimate TOR users access websites freely (without cumbersome captchas) outweighs the troubles malicious users might cause. Public computers such as in Libraries are also often used to do reprehensible things, but still, we understand the benefits of having them. It is also worrying that CloudFlare has this much power. One of the greatest things about the internet is the openness of the platform and the non existence of gate keepers. Also, here is an annotated version of the TOR paper for those who want to read more about it http://fermatslibrary.com/s/tor-the-second-generation-onion-router http://fermatslibrary.com/s/tor-the-second-generation-onion-...
- Laaw 11y agoI'm getting "Attackers might be trying to steal your information from blog.torproject.org (for example, passwords, messages, or credit cards). NET::ERR_CERT_AUTHORITY_INVALID" When trying to visit this blog post.
- nxzero 11y ago>> Laaw: "But I don't want end to end encryption" Sorry, but I thought you didn't want encryption. Bit puzzled, just click ignore error to fix the issue. Clearly this advice is based on you not wanting end-to-end encryption; heads up, NSA flags users that visit Tor's website, though clearly, you've done nothing wrong. (Yes, I'm making a point, hope it's clear.)
- Laaw 11y agoSince they use HSTS, I literally can't click "ignore" or I would have. I, and (I assume) anyone else who uses the latest version of Chrome cannot access this content right now. Or it might just be me, but I don't know what the solution is. You also missed the point if you think what I said included the words "all the time" in the other thread we were talking in.
- nxzero 11y agoI'm on Tor and able to see the file, no idea why you're getting that error, or I'd try to help. Assume you know this, but Google has a cached version as text if you Google... [cache:http...] ^^ where you remove the open/close brackets and insert the full URL after "cache:"
- Laaw 11y agoI'll try that, thanks.
- jgrahamc 11y agoI [I'm CloudFlare's CTO] have been engaging with the Tor folks through their Trac interface here for about 6 weeks: https://trac.torproject.org/projects/tor/ticket/18361 https://trac.torproject.org/projects/tor/ticket/18361 and been very open about CloudFlare is addressing this. My plan is to continue to do so through that ticket as I've made various commitments there (some of which, like whitelisting, we've already rolled out). It's worth reading the entire ticket to get a sense of the conversation. We are in no way finished improving the situation.
- stingraycharles 11y agoOut of curiosity, did you also write the previous blog post from CloudFlare that sparked this reaction from Tor?
- jgrahamc 11y agoNo, that was written by the CEO (eastdakota here). He asked me to copy edit it which I did. I wrote the conclusion (because he was sleeping) and I added the two charts. On the CloudFlare blog if someone's name is on it they wrote it .
- CloudFlrFeedbck 11y agoI'm a long-time Tor user that's been affected by CloudFlare captchas for a few years. I appreciate that you (CloudFlare) are trying to tackle the problem, but I feel that both CloudFlare and the Tor community have defeatist attitudes toward this issue. I have the following suggestions for CloudFlare: 1. Can you provide better documentation for your customers about what Tor is, and reasons for/against white/blacklisting Tor? For example, when a customer selects to Block or Captcha Tor, a tiny link could show up somewhere that says something like "This affects users who seek privacy, find out more." 2. In addition to better docs, can you setup something that lets site operators view the site as a Tor user? The screenshot on this site does not do the Tor+Captcha experience justice: https://support.cloudflare.com/hc/en-us/articles/203306930-Does-CloudFlare-block-Tor- https://support.cloudflare.com/hc/en-us/articles/203306930-D... In particular, the screenshot assumes the Tor browser is running Javascript and that all the user has to do is click that button. In reality, Tor users have to click a bunch of checkmarks, try again once or twice, then copy a code into a textbox then hit submit. If you provided a "view site as Tor user" demo (JS and non-JS versions), then site operators might be more reluctant to enable Captcha for Tor users. 3. The latest CloudFlare blog post on Tor says "you can do a lot of harm just with GETs." I wish you would give more thought to the idea of a read-only option for non-whitelisted Tor users. If GET requests are harmful (I'm skeptical), reducing the harm of GET requests seems like a much easier problem than the overall problem. Afterall, what good is a CDN that can't handle lots of requests for static content? I also have the following suggestions for the Tor community: 1. Continue to improve the Tor user experience to gain users! The more people use Tor, the harder it is to ignore (by CloudFlare and others) and the safer it gets. Acquiring more users is one of the best ways to fight back against Captchas. One way to get lots of new users is Firefox integration. 2. Fix hidden services. It's awesome that CloudFlare wants to give the option to setup hidden services for their customers. Make that possible for them! 3. If CloudFlare doesn't want to provide some sort of read-only mode, build that functionality yourselves! For example: when the Tor Browser detects a CloudFlare captcha, it could give the user the option to read a read-only cache from some other CDN.
- avip 11y agoAnonymity ("privacy") and security are conflicting requirements. Tor users take a legit stance, and would be served an equally legit CAPTCHA (if lucky).
- nulbyte 11y agoYou're assuming anonymity and security belong on opposite sides. They don't.
- hackuser 11y ago> Users are either blocked outright with CAPTCHA server failure messages, or prevented from reaching websites with a long (and sometimes endless) loop of CAPTCHAs Is it really a loop or are users just failing to solve the CAPTCHAs? A loop would be obnoxious: Just tell the user they are blocked; giving them more than 2 or infinite CAPTCHAs is a passive aggressive way to communicate.
- pfg 11y agoMy best guess is that reCAPTCHA doesn't just have two states (pass/fail), but rather something like a confidence factor and a threshold you have to reach to continue to the site (which might depend on your reputation).
- cft 11y agoWe are free speech advocates, and yet we had to make a cron that downloads and adds Tor IPs to an ipset, due to botnets.
- devit 11y agoThe really questionable thing CloudFlare seems to be doing is that they captcha traffic depending on the overall reputation of only the source IP rather than whether the source IP is attacking that specific site or even whether the site is under attack. What they should do instead is this: 1. If the server is not overloaded, do not captcha any traffic at all 2. If the server starts being overloaded, only captcha traffic from IPs that have been detected as attacking THAT specific site 3. If the server is still overwhelmed, only then switch to captchaing all IPs with "bad reputation" Most websites are probably almost never under attack, so this would make encountering CloudFlare captcha extremely rare in the wild while still providing DDOS protection. They could even only do this for Tor exit nodes and other IPs that are known to be used by lots of people. If a site is being DDOSsed a lot and the slower start up of this technique is a problem, then they can revert for those sites to the current behavior of using reputation.
- fabulist 11y agoServices like CloudFlare are responsible for more and more of the DNS. When they are poor net citizens, they are poor net citizens at a massive scale. Heuristics that end up being equivalent to "Tor users are guilty until proven innocent" can't become the default mode of the Internet. As customers, Tor users, and just people who have a stake in the Internet as a shared resource, we need to demand that they try harder than that.
- throwaway-10439 11y agoThe GET solution seems too lightly waved off considering that 90% of Tor requests will be nearly identical to those from trusted IP addresses.
- morsmodr 11y agolol, CloudFlare vs Tor (hope its not disappointing like BvS)
- greggman 11y agoHow about this solution: (yes, it's only 5% serious) From every publically available internet do something that appears malicious until cloudflare's servers annoy everyone. At that point they'll be forced to find a new solution. This only occurred to be because I get their captchas on public wifi in Starbucks and other public wifi in Japan
- fleitz 11y agoCleary cloudflare's customers prefer this behavior, it's their website, they are free to block tor traffic if they like.
- merb 11y agoI dislike CloudFare adoption. More and more I come to sites and need to wait 5 seconds, caused by their DDoS protection. Such things make the less more and more aweful.
- homero 11y agoLol
- fapjacks 11y agoCloudFlare looks for ways to justify doing less. First ANY queries, then "free" HTTPS stopping at the first CloudFlare hop, and now the stuff with Tor. I don't trust CloudFlare at all, because they say they're holding a torch for the good of humanity, when actually, they're just making "cut costs" business decisions. If you want to do something becuase it costs less, I understand, then do that. But don't sit there and try to tell me that you're somehow doing it to make the world a better place. That, to me, is super scummy.
- stegosaurus 11y agoTo me personally all of this just seems like fluff. I can't be the only one that feels this way. I don't want to 'prove I'm a human' to view your crappy site. I'll go and look at the other bits of the Internet instead. As an individual browsing, the only contact I have with CloudFlare is a bouncer telling me 'no shoes no entry'. Your entire company to me feels like a pointless gatekeeper because of these shenanigans (on and off of Tor). To be perfectly clear - CloudFlare, as a brand, is tainted to me, and I expect to many others. Fundamentally I don't think CloudFlare cares because their customers are not the viewers of websites - and if the viewers of websites come to think of CloudFlare as toxic - it still doesn't matter to them directly.
- AndyMcConachie 11y agoI have a question that I'm hoping will spur some discussion and maybe I can learn some stuff. "Is anonymity in Tor incompatible with low-latency?" I ask this having read this: http://freehaven.net/anonbib/cache/pets13-flow-fingerprints.pdf http://freehaven.net/anonbib/cache/pets13-flow-fingerprints.... I suspect that countermeasures to defeat deanonimization all have a negative impact on latency(e.g. inserting extra packets, pausing between sends). If the answer to my question is yes, then maybe the best thing the Tor project can do is abandon its push for low latency, and instead focus on anonymity. If Tor we're a much higher latency network attackers would probably find it less interesting.
- ailanthus 11y agoCloudFlare uses a flawed algorithm that penalizes developing countries and anyone who uses 1 IP address for many users. And that means that it censors Tor users and impedes human rights.