6 ms·
>Still, the exceptionally privacy-conscious folks might not want to reveal their IP address to the resolver at all, and we respect that. Who was it again that
by gant 8y ago
>Still, the exceptionally privacy-conscious folks might not want to reveal their IP address to the resolver at all, and we respect that.
Who was it again that puts ReCAPTCHA on so many popular websites when using Tor, which could be used for traffic correlation? Oh. Cloudflare.
Ref: https://news.ycombinator.com/item?id=12122268 https://news.ycombinator.com/item?id=12122268
- jgrahamc 8y agoAnd who was it that worked with researchers on Privacy Pass to provide anonymous access for web users? Oh. Cloudflare. [1] And who was it that changed their algorithm for handling TorBrowser traffic so that there's no need to show those CAPTCHAs? Oh. Cloudflare. And who was it that gave our customers control over how Tor traffic is handled? Oh. Cloudflare. [2] [1] https://blog.cloudflare.com/cloudflare-supports-privacy-pass/ https://blog.cloudflare.com/cloudflare-supports-privacy-pass... [2] https://support.cloudflare.com/hc/en-us/articles/203306930-Does-Cloudflare-block-Tor- https://support.cloudflare.com/hc/en-us/articles/203306930-D...
- stingraycharles 8y ago(For those of you who missed it. parent poster @jgrahamc is CTO of Cloudflare. ) Don’t get too snarky, John. Thanks for working with the Tor community, but haters gonna hate.
- d0lph 8y agoI for one would like to see more snarky CTOs on HN
- bogomipz 8y agoSo someone expressing an opinion contrary to your own makes them a "hater"? Wow.
- lossolo 8y agoI think changing "And who was it that" in every sentence to "We" and removing "? Oh. Cloudflare." automatically would remove the snarkiness.
- stingraycharles 8y agoYes indeed, that comment was more about tone than content.
- zaarn 8y agoI think "We did" would be better, especially when you play the appropriate The Simpson's song in the background...
- vrex 8y agohave to give props for that, using Tor for daily browsing was annyoing and horrible a few years back, it got a lot better
- jgrahamc 8y agoGood. And if it ever degrades again because we've broken something and not realized my email address is jgc (you guess the domain).
- hendi_ 8y ago> And who was it that changed their algorithm for handling TorBrowser traffic so that there's no need to show those CAPTCHAs? Oh. Cloudflare. Thanks, that'd be great news! I couldn't find any information about that, any chance you could pull out a link like for your other points?
- jgrahamc 8y agoI don't believe we ever wrote it up, it was just an internal algorithm change made in 2016. I can see the internal pull request but don't think we blogged about it.
- jerheinze 8y agoThanks for that, don't forget to change it to conform with the upcoming Tor Browser for Android and ESR60-based alpha releases.
- hendi_ 8y agoThank you!
- dmix 8y agoSeems like an oversight to not promote this change. The way Cloudflare completely crippled the user experience of using Tor, plus the subsequent condescending and poorly handed PR responses I saw on HN and elsewhere, was the reason why I completely stopped using Cloudflare and stopped recommending it to people.
- hendi_ 8y agoThank you, it looks like you have your moral compass pointed to the right direction :-) While I applaud the things above I'm concerned about Cludflare's (growing) size. If it handles so many websites' traffic it's an interesting target for NSA, hackers and other malicious actors. I assume that most of your users use the free SSL certs, meaning Cloudflare possesses their private keys. The more Cloudflare grows, the faster and the more encrypted "the internet" becoems. But the more Cloudflare grows, the bigger the single point to attack gets (I'm even assuming Cloudflare is and always will be a good actor). What's your stance on this? Could you comment on this?
- jgrahamc 8y agoI/we worry about hackers and malicious actors all the time. One of the reasons we're greatly expanding our infosec department and hired Joe Sullivan [1] is to help keep us safe. We're doing a lot of work with memory-safe languages (hello, Rust!) to help stop Cloudbleed from repeating itself. [2] We're doing stuff around physical location of private keys [3]. And so on and so on. We're open about government requests [4] and we've been pretty robust with stuff like NSLs; we went to court to be able to release NSLs [5] and were able to release two. [6] [1] https://blog.cloudflare.com/why-im-joining-cloudflare/ https://blog.cloudflare.com/why-im-joining-cloudflare/ [2] https://blog.cloudflare.com/writing-complex-macros-in-rust-reverse-polish-notation/ https://blog.cloudflare.com/writing-complex-macros-in-rust-r... [3] https://blog.cloudflare.com/geo-key-manager-how-it-works/ https://blog.cloudflare.com/geo-key-manager-how-it-works/ [4] https://www.cloudflare.com/transparency/ https://www.cloudflare.com/transparency/ [5] https://blog.cloudflare.com/ninth-circuit-rules-on-nsl-gag-orders/ https://blog.cloudflare.com/ninth-circuit-rules-on-nsl-gag-o... [6] https://blog.cloudflare.com/cloudflares-transparency-report-for-second-half-2016-and-an-additional-disclosure-for-2013-2/ https://blog.cloudflare.com/cloudflares-transparency-report-...
- bogomipz 8y ago>" One of the reasons we're greatly expanding our infosec department and hired Joe Sullivan [1] is to help keep us safe." I am assuming this is the same Joe Sullivan, the former CSO at Uber who was fired for failing to disclose the 2016 data breach to regulatory officials or notifying the 600K drivers and 57 million customers that were affected? [1][2][3] And keeping it secret for more than a year? I am not sure that association instills confidence. [1] https://www.darkreading.com/informationweek-home/ubers-response-to-2016-data-breach-was-legally-reprehensible-lawmaker-says/d/d-id/1330997 https://www.darkreading.com/informationweek-home/ubers-respo...? [2] https://www.engadget.com/2017/12/01/uber-but-for-toxic-techbro-culture/ https://www.engadget.com/2017/12/01/uber-but-for-toxic-techb... [3] https://www.technologyreview.com/s/609539/uber-paid-off-hackers-to-hide-massive-data-breach/ https://www.technologyreview.com/s/609539/uber-paid-off-hack...
- gant 8y agoHey, that's pretty cool, glad you sorted the second one out. Never heard about the first one and the third, well, double edged sword.
- crapflare 8y agoYour company is pure cancer and your clients are stupid as hell. Nobody in their right mind should use your services.
- stefantalpalaru 8y ago> And who was it that changed their algorithm for handling TorBrowser traffic so that there's no need to show those CAPTCHAs? Oh. Cloudflare. If you're checking for a custom user agent, you're doing it wrong. Not all people using Tor to try and browse the web limit their browser choice like that. I still have the terrible experience of having to train Google's ANNs every 5 minutes when using regular Firefox and Chromium over a Tor SOCKS proxy and I blame CloudFlare for single-handedly destroying web browsing over Tor.
- torenthusiast 8y agoYour selective whitelisting of the Tor Browser has made things worse in some respects. Formerly, under the old regime, one could complete the CAPTCHA challenge for a blocked domain and as long as one's user-agent included the returned RECAPTCHA cookie with each request, it would pass through unmolested. Presently, however, it is not uncommon for circumstances to arise where issuing a straightforward GET request elicits no CAPTCHA (excellent!) but certain requests, such as XHR POSTs, particularly against a third-party CF-gated domain, are blocked, with no CAPTCHA being displayed (because the reply is not rendered), and no way to easily solicit a CAPTCHA for that domain. This completely breaks many web sites. One can work around this by manually rendering the returned POST data and completing the CAPTCHA, or simply using a browser which is not whitelisted, but few people are savvy and patient enough to do this, producing a very small anonymity pool and negating to a large degree many of the benefits of using the Tor Browser. Are you aware of this issue? Any plans to address it?
- deno 8y agoThat’s the problem with anthropomorphising companies. As far as I can tell Cloudflare single-handedly destroyed the usability of Tor Browser. It was just getting pretty fast when Cloudflare put literally half the Internet behind a spywall. So should I be angry at them? Should I dismiss this valuable service to then remain consistent with my anger? Is Microsoft now “good” or “bad”? Every action needs to be evaluated on its own. Our evolutionary social adaptation just doesn’t work in this case. In the end all Cloudflare did is expose how centralized the Internet has become. The immediate emotion is anger because that is how you react when you’re suddenly awakened out of blissful ignorance and forced to face reality.
- zackbloom 8y agoJust as your Tor browsing experience was becoming faster, it was becoming a more and more viable tool for DoS attackers. Someone has to protect the sites enough that they can stay up for traffic, Tor or otherwise.
- deno 8y agoThere are many ways to do that are more efficient, less intrusive and provide for better UX than Cloudflare’s gatekeeper approach. However no one forced website owners to use Cloudflare, so it doesn’t matter. > Someone has to protect the sites enough that they can stay up for traffic, Tor or otherwise. That’s true for HTTP. You need a big corporate sponsor to allow you to host your website. Too bad when they don’t like what you have to say, right?[1] [1] https://www.nytimes.com/2017/09/13/opinion/cloudflare-daily-stormer-charlottesville.html https://www.nytimes.com/2017/09/13/opinion/cloudflare-daily-...