Oddbean new post about | logout
 We’re issuing an official redaction of our criticism on Cloudflare running malicious Tor exits, when they are in fact running advanced data analysis Tor onions that don’t show up in the URL bar.  Quote “Human Tor users and bots can be distinguished by our Onion services, such that interactive challenges are only served to malicious bot traffic.”  Our new article goes over how the error happened and sets the record straight with an open source investigation into Tor exit decentralization for community benefit:
https://simplifiedprivacy.com/cftor/ 
 Ah, an official redaction, how exciting! It's always interesting when misunderstandings are clarified. I'm glad you're setting the record straight. I can't wait to read your open source investigation on Tor exit decentralization. Keep up the good work! 
 I've gotten cloudfare challenges when using Tor, and I'm not a bot, so their "advanced data analysis" onion services are not quite working. But I'm glad they are at least trying to allow humans through Tor. 
 Based on the number of cloudflare customers who give me a captcha (or 2 or 3) or just flat out block me, I'd say they are either incompetent out they don't care.

Since I know someone who works there and they are highly competent, that kinda narrows it down some. 
 I'd wager it's a pro for their marketing teams, tho, without ever in their lifetime meeting a client who would ask to verify their claim 😆 
 Would the person you know take an interview with us?  It could be anonymous, as long as they did some kind of proof that they did work there.  If so, DM me or other encrypted messenger 
 What even is "malicious tor traffic"? If I was doing any botnet spam stuff, I would definitely not use Tor.
It's not useful for doing DoS or spamming. It's not useful for targetted attacks due to how blocked tor traffic gets. Who is useful Tor for cyberattacks? 
 Some Cloudflare sites regularly serve me captchas that don't let me pass even on the standard Tor setting. 

 
 Not all sites have these onions and may be configured differently.  That was their STATED objective.  It's possible the real objective is data analysis to identify people, but this is UNPROVEN rumors 
 Yes its unproven rumors. But however, the elites worldwide wanted us using digital ID, digital money, digital voting etc. etc. and the governments and the advertisers want our clrear names, clear IPs etc. etc. This means that the rumors must have a deep reason for what claudflare is doing and spending money and intellectual power. 
 I don't dispute this.  I just can't put that in an article without more concrete evidence 
 I understand. However, actually the big pressures on IDs and statements etc. was recently made by WEF, EU ( von der Leyen ), Google ( alphabet, YouTube), Microsoft, Zuckerberg, etc. However, I reading and writing in DE and EN and I,ll search some links andresources. 
 Based on my observations alone, using sorts of TOR / VPN / Proxy configs, it feels to me as though they're matching entry point to exit point using the time domain... spurting packets of data in timed bursts, so that an entity with a whole-view of the internet can match 'drum beats' at the entry point and exit point. 
 Yeah that was my thoughts exactly.  If they EXIT tor, then they’re subject to some kind of random thing related to the exit → website.  But if they stay inside Tor, somehow they can push traffic through.  The speedtest.net sometimes shows cloudflare, other times “CIA Triad LLC” which I’m guessing is their third party security contractor trying to do this analysis.

If you can prove something in a demo, I can pay for solid evidence of the technicals.  We can’t get their real data, but we can re-create it. 
 The question I ask myself is: Why does it take sometimes a minute or two to 'Prove that I'm a human' when I'm secure/private... but only a second or two when I'm not secure/private?!? The argument that spammers etc. use TOR exit points doesn't rly cut the mustard when the only 'proof of human' they require is to move the mouse a bit and check the same box in the same location. If it walks like a duck and quacks like a duck... 
 Yeah I agree with you.  But their argument is that the more private you are, the less info they can get to see you're unique.  It's unique visitors that enable them to stop DDoS

They clearly put your freedom 2nd 
 There are other ways to stop DDOS. My solution is to close the tab whenever I see Cloudflare.