CloudFlare aims to block fewer legitimate Tor users

A mix of short-term fixes and long-term ideas intends to make Tor browsing less cumbersome

CloudFlare is tweaking its systems to make it easier for legitimate Tor users to access websites that use its network to deliver content.

Tor users have complained that CloudFlare-powered websites too frequently display CAPTCHAs, a security gate designed to stop automated web bots and abuse. CAPTCHAs are the squiggly text or puzzles you have to solve to prove you're a real human.

The problem is that many computers employing Tor are engaged in abusive activity, resulting in CloudFlare displaying CAPTCHAs when it detects a computer using the Tor network.

Legitimate Tor users thus have a poor browsing experience given the wide use of CloudFlare's CDN.

Tor is a network of distributed nodes that provides greater privacy by encrypting a person’s browsing traffic and routing it through random proxy servers. It's a critical tool for activists, journalists and dissidents who need more security on the Web.

CloudFlare's systems are designed to provide better defenses for websites against denial of service attacks, content scraping and spam, which often is initiated by attackers using Tor.

CloudFlare scores IP addresses according to the level of abuse it detects. Tor "exit nodes" -- the last touchpoint out of the network before hitting a website -- often rank high for abuse and are blocked. 

So for the last year, CloudFlare has been experimenting with ways to block abusive Tor traffic but still allow good traffic through without the security speed bumps, wrote Matthew Prince, CloudFlare's CEO, in a blog post titled "The trouble with Tor."

It's a difficult challenge. Tracking Tor users around the Web so they're only shown one initial CAPTCHA wouldn't be acceptable, since it would compromise the anonymity Tor provides, he wrote.

A few weeks ago, CloudFlare came up with tools that allow its customers to whitelist some Tor traffic rather than ban all of it.

"Customers can force traffic to see a CAPTCHA, but they can't block traffic entirely," Prince wrote. "However, the choice of how to handle Tor traffic is now in the hands of individual site owners."

Another option for websites is to create their own ".onion" domain -- which signifies a Tor hidden website -- which are subject to fewer automated attacks. Facebook has created such a site, but there is a problem: the SSL certificates needed are expensive, Prince wrote.

CloudFlare engineers have another idea: have users solve a puzzle and then have the browser send an anonymous, cryptographically secure token to CloudFlare "in order to verify that the request is not coming from an automated system." That code is on GitHub now. This solution would require cooperation with The Tor Project.

In the meantime, Prince wrote that CloudFlare will make other changes intended to ease the inconvenience Tor users face.

"We believe that the Internet will be better off if we do so, as sites will not find themselves wanting to ban Tor users completely just because of abuse," he wrote.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Father’s Day Gift Guide

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?