Hacker News new | past | comments | ask | show | jobs | submit login

Cloudflare blocks Tor users unless they solve a Google CAPTCHA and accept cookies. By saving money you limit your audience and make the world a worse place.

https://blog.torproject.org/trouble-cloudflare




Have you tried visiting a Cloudflare-protected site using the TBB recently? (as in within the last few years?). We don't block Tor users. I use TBB to browse and don't see this problem.


> Users are either blocked outright with CAPTCHA server failure messages, or prevented from reaching websites with a long (and sometimes endless) loop of CAPTCHAs, many of which require the user to understand English in order to solve correctly. For users in developing nations who pay for Internet service by the minute, the problem is even worse as the CAPTCHAs load slowly and users may have to solve dozens each day with no guarantee of reaching a particular site. Rather than waste their limited Internet time, such users will either navigate away, or choose not to use Tor and put themselves at risk.

So, if we don't make our websites available in languages used by oppressed peoples, if we don't make sure it's very low latency, and if we try to filter out abusive users, we're making the world a worse place. Not just leaving the world in a bad state, but actively increasing the harm done to the world, just by making a website that not everyone can or wants to use.

Not only do I not buy this argument, it makes me want to support Tor less, if for no other reason than blatantly ignoring why the captchas were put up in the first place.


I agree with most of what you're saying but then I don't agree with your assertion that this makes you want to support Tor less.

The part you have a problem with, that it actively increases harm done in the world, wasn't even an assertion made by Tor.


Tor users using this e-commerce service are probably a tiny fraction of a percent of the op’s addressable market: easily a “who cares” demographic.


TOR and most e-commerce aren’t compatible anyhow proper opsec on any anonymizing Network is to not de-anonymize yourself by tying your activity to your identity.

If you use TOR to access services that can be directly correlated to your identity you are simply using a slow VPN at that point.


AFAIK Cloudflare allows site owners to configure that.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: