has been down most of the day now. For Tor users who refuse to connect to sites that means ~34% of the web is unreachable.

@resist1984 It is back now. Can you share with me the best dirt on how Cloudflare is able to identify people on TOR if that is what they can do? I understand technically how they serve their customers by blocking TOR connections.

Follow

@krock Cloudflare can't generally ID Tor users (this is why they treat all Tor users with equal hostility). Exceptionally, if you supply data to a CF site either by logging into hCAPTCHA or logging into the target website, then CF can of course distinguish you from others; as well as by browser printing and the like.

@resist1984 Thank you for explaining. I realize they provide identity management services to their clients like many other companies do based on various fingerprinting techniques. This is why I use different browsers for different profiles.

@krock Tor Browser has anti-fingerprinting features that no other browsers do (AFAIK), but some browser plugins ruin that. There are also shortcomings with TB, so i do as you are, and use a dozen or so profiles with different browsers and never use it in fullscreen. When anonymity is important, TB without plugins is still king.

@krock My comment about Tor users refusing to connect to CF sites is not driven by the threat of CF de-anonymising them, but rather b/c Tor users become intolerant of the CAPTCHAs, and/or they are simply more aware that CF is seeing everyone's traffic. Normies/non-Tor users are mostly blind to Cloudflare, so they don't even know the compromising position they are in.

@krock i've actually come to /like/ the Cloudflare CAPTCHAs, because if i'm in a browser+profile that doesn't have a CF detector, the CAPTCHA serves as a crutch for profiles where I don't have my shit together, ultimately helping me avoid CF. I just hit control-w when I see the captcha.

@resist1984 I completely understand why we need to share safe links. Most people are completely unaware of the ID techniques employed and getting some of my friends and family to basic internet security awareness has taken a long time. CF is just one of many companies providing ID services. If I need to get into a Captcha site, I purposely randomize my clicking which takes a little longer. What CF detector would you recommend if any?

@krock another useful one is ISMM: git.nogafam.es/deCloudflare/de That one will mark up pages you visit to flag CF links, so you know before you click if it's a CF link.

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!