5 ms·
>Access Denied >You don't have permission to access "http://www.nasdaq.com/articles/an-interns-guide-to-trading-2021-07-01 http://www.nasdaq.com/articles/an-in
by AudienceFakeout 5y ago
>Access Denied
>You don't have permission to access "http://www.nasdaq.com/articles/an-interns-guide-to-trading-2021-07-01 http://www.nasdaq.com/articles/an-interns-guide-to-trading-2..." on this server.
>Reference #18.e0745968.1625685764.2ef97a3a
Why do sites do this? Yes, I'm using Tor Browser to protect my privacy and stop big companies from tracking me. But I can just plug the URL into an archive service and read it from there.
- slownews45 5y agoBecause the amount of abuse / scam / crap via Tor is incredible?
- AudienceFakeout 5y agoI suspect it's just a passive aggressive way to punish people who value their privacy.
- sigstoat 5y agoyou are so beneath their notice that the idea they want to punish you is hilarious. you’re simply not their target audience. everything else is fantasy.
- AudienceFakeout 5y agoEverybody's a target for data collection, it's the very basis of the comprehensive tracking and ads industry. No need to get so defensive - this isn't exactly a stunning revelation.
- anoncake 5y agoThis is a blog post.
- slownews45 5y agoThis is nasdaq.com Any major player with an actual security dept is going to have evaluated just blocking Tor - or they are wildly irresponsible. It's a relative low effort way to get a win on security with minimal harm to customers and particularly paying customers. Their sec ops team will be subscribed to things like DHS CISA alerts. Alert (AA20-183A) Defending Against Malicious Cyber Activity Originating from Tor They will evaluate the least effort approach and potentially follow it.
- anoncake 5y agoNo. It's a blog post. End of story, I don't care who made it. Letting someone view a blog post is not a security risk, anyone who treats it as one is wildly incompetent.
- dsr_ 5y agoIt's a lot easier to have the consistent policy "we block Tor exit nodes" than "we block Tor exit nodes, except on this site". Then they have to make that decision about every site. And re-evaluate that decision every so often.
- anoncake 5y agoOf course. If you aren't competent enough to make good decisions, you have to make easy ones.
- dsr_ 5y agoI'm not really talking to you. I'm talking to some other HN reader who thinks this is an actual debate between two reasonable sides. Every time a security practitioner has to make a new decision, that opens up the possibility of making a mistake. Therefore, it is good practice to limit the number of decisions that you have to make. That's why the standard policy for firewalls is default deny, and you have to make an affirmative decision to let packets in. That's why we make cost-benefit decisions about blocking policy. Does it cost NASDAQ to block Tor exit nodes from reading their blog? Not materially. Anyone that desperate to read that material anonymously can ask the Internet Archive for it, or get some other proxy to pull it for them. None of their actual or potential clientele will feel the need to use Tor. Does it benefit NASDAQ to have a general policy of blocking Tor exit nodes? Yes, it definitely does. If you want to probe a site's security, Tor and rented botnets are the sources of choice. I don't know whether NASDAQs security people are competent or not in general, but in this specific example, they made a good choice.
- tekromancr 5y agoBecause if you set up something like fail2ban to automate blocking abusive traffic, it's going to quickly block tor exit nodes and public vpn servers
- unholythree 5y agoNasdaq.com will block you temporarily for the sin of not running all the JavaScript they want. It’s pretty annoying but I guess it mostly affects users they don’t care about. I don’t visit enough to know the exact mix I’d have to allow in noscript to earn their trust.