[tor-bugs] #24351 [Applications/Tor Browser]: Block Global Active Adversary Cloudflare

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Aug 5 04:49:34 UTC 2019


#24351: Block Global Active Adversary Cloudflare
-------------------------------------------------+-------------------------
 Reporter:  nullius                              |          Owner:
                                                 |  cypherpunks
     Type:  enhancement                          |         Status:
                                                 |  assigned
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Major                                |     Resolution:
 Keywords:  security, privacy, anonymity, mitm,  |  Actual Points:
  cloudflare                                     |
Parent ID:  #18361                               |         Points:  1000
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by cypherpunks):

 Replying to [comment:119 cypherpunks]:


 > 1. Add checkbox "Block Connection to the Cloudflare IP ranges" to the
 about:preferences#privacy so the user can decide.

 the [https://www.cloudflare.com/ips/ ipranges] are public and null routing
 them is easy first step in protection from MitM. as tor browser uses socks
 config it is not via about:config possible yet but it is easy with
 proxy.pac scripts realizeable
 Replying to [comment:119 cypherpunks]:


 >
 > 2. Add Cloudflare icon next to the padlock if the website is behind
 Cloudflare.
 >

 Well, to be honest. not only cloudflare is the problem. so a cloud icon
 (not Cloudflare) would be wiser.

 But no all CDN are in MitM position.

 Replying to [comment:118 cypherpunks]:

 > Calm down, folks. This is a bug tracker which means only constructive
 advises are welcome here.
 > Tor (not Tor Browser) really can do nothing when some site wants to sell
 its users to cloudflare.
 >
 >
 > > Nothing mentioning about this MiTM eavesdropper Cloudflare.
 > >
 > >
 > The only thing Tor Browser can do is to add some icon besides the green
 lock to state that some site is poisoned by cloudflare.

 [cloud logo with a little metallic "∩" above it.][https://github.com
 /mozilla-mobile/focus-android/issues/1743#issuecomment-464382371]

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/24351#comment:121>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list