cloudflare-tor/README.md

88 lines
6.2 KiB
Markdown
Raw Normal View History

2017-05-01 18:26:27 +02:00
# The Great Cloudwall
2019-02-24 06:13:28 +01:00
"The Great Cloudwall" is [CloudFlare](https://www.cloudflare.com/), the world's [largest](https://w3techs.com/technologies/history_overview/proxy) MITM proxy([reverse proxy](https://en.wikipedia.org/wiki/Reverse_proxy)).
2019-02-19 03:20:38 +01:00
2019-02-21 02:40:06 +01:00
![](image/cloudflaredearuser.png)
2019-02-19 01:27:31 +01:00
2019-02-19 03:37:17 +01:00
It is called this in reference to the [Great Firewall of China](https://www.comparitech.com/privacy-security-tools/blockedinchina/) which does a comparable job of filtering out *some* people from seeing web content(ie everyone in mainland china and some people outside) while at the same time those not affected to see a dratically different web, a web free of censorship of such images as ["tank man"](https://en.wikipedia.org/wiki/Tank_Man).
2019-02-19 01:26:47 +01:00
2019-02-21 02:40:06 +01:00
![](image/onemorestep.jpg)
2019-02-19 03:20:38 +01:00
2019-02-21 02:40:06 +01:00
Cloudflare similarly prevents those in southeast asia and elsewhere who have poor internet connectivity from accessing the websites behind it(for example, they could be behind 7+ layers of NAT) unless they solve multiple image CAPTCHAs. Cloudflare also has a massive [harassment problem](https://web.archive.org/web/20171024040313/http://www.businessinsider.com/cloudflare-ceo-suggests-people-who-report-online-abuse-use-fake-names-2017-5). [Tor users](https://www.torproject.org/) and [VPN users](https://airvpn.org/topic/23090-cloudflare-often-bans-my-ip-address/) are a victim.
2019-02-19 03:20:38 +01:00
2019-02-21 02:40:06 +01:00
![](image/banvpn.jpg)
2017-05-01 18:26:27 +02:00
2019-03-04 08:50:01 +01:00
And their DNS service, [1.1.1.1](https://1.1.1.1/), is also filtering out users from visiting the website by returning fake IP address owned by Cloudflare or just return nothing. See NEWS.md for more information.
![](image/dnscensor.jpg)
2019-03-17 02:55:05 +01:00
And here you might think, "_I am not using Tor or VPN, why should I care?_".
If you visit website which use Cloudflare, you are sharing your information not only to website owner _but also Cloudflare_.
2019-03-17 02:59:36 +01:00
It is impossible to analyze without [decrypting TLS traffic](https://github.com/nym-zone/block_cloudflare_mitm_fx/issues/15#issuecomment-354773389). Cloudflare knows all your data such as raw password.
2019-03-17 02:55:05 +01:00
[Cloudbeed](https://en.wikipedia.org/wiki/Cloudbleed) can happen anytime.
2019-03-17 03:23:17 +01:00
Do you really want to share your data with Cloudflare, and also 3-letter agency?
![](image/dhssaid.jpg)
2019-04-07 04:02:33 +02:00
Cloudflare also offer FREE VPN service called "[Cloudflare Warp](https://blog.cloudflare.com/1111-warp-better-vpn/)". If you use it, all your smartphone connections are sent to Cloudflare servers. Cloudflare can know which website you've read, what comment you've posted, who you've talked to, etc. You are voluntary giving [all your information](https://github.com/privacytoolsIO/privacytools.io/issues/374#issuecomment-478686469) to Cloudflare. If you think "_Are you joking? Cloudflare is secure._" then you need to learn how [VPN works](https://en.wikipedia.org/wiki/VPN).
2019-04-10 01:31:02 +02:00
![](image/prismattnsa.jpg)
You might already know about the [PRISM](https://en.wikipedia.org/wiki/PRISM_(surveillance_program)) scandal. It is true that AT&T lets NSA to [copy all internet data](https://www.cnet.com/news/at-t-lets-nsa-hide-and-surveil-in-plain-sight-the-intercept-reports/) for surveillance. Let's say you're working at the NSA, and you want every citizen's internet profile. You know most of them are blindly trust Cloudflare and using it to proxy personal website, chat website, forum website, bank website, insurance website, search engine, secret member-only website, auction website, shopping. You also know they use Cloudflare's DNS service and VPN service for "yay! Faster!" internet experience. You want their data. [What will you do](https://www.reddit.com/r/privacy/comments/1gb0pa/how_prism_actually_works_1520_att_fiber_optic/)?
2019-04-07 03:37:36 +02:00
### Cloudflare is a honeypot. Cloudflared websites are dangerous.
2019-03-17 02:55:05 +01:00
---
2019-03-04 08:50:01 +01:00
2018-09-02 04:19:43 +02:00
This repository is a list of websites that are behind The Great Cloudwall, and also actively blocking Tor users.
2017-05-01 18:26:27 +02:00
2019-02-24 06:13:28 +01:00
2019-03-17 02:59:36 +01:00
Domain list
2019-02-24 08:20:55 +01:00
* [Domains using Cloudflare](split/)
2019-03-05 03:31:39 +01:00
* [Non-Cloudflare but filtering/blocking Tor users](not_cloudflare/)
2019-02-24 06:13:28 +01:00
2019-02-24 06:15:27 +01:00
Information
2019-03-17 02:59:36 +01:00
* [Padlock icon indicates a secure SSL connection established w MitM-ed](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=831835) by Anonymous
* [Block Global Active Adversary Cloudflare](https://trac.torproject.org/projects/tor/ticket/24351) by nym-zone
* [Problem with CloudFlare](https://github.com/privacytoolsIO/privacytools.io/issues/374#issuecomment-460077544) by libBletchley
* [Criticism and controversies](https://en.wikipedia.org/wiki/Cloudflare#Criticism_and_controversies) by Wikipedia
2019-04-07 03:37:05 +02:00
* [Cloudflare's Advertisement is just wrong](https://notabug.org/themusicgod1/cloudflare-tor/issues/123)
2017-05-01 18:26:27 +02:00
2018-09-06 14:04:17 +02:00
There are more details of why what they are doing is wrong available [here](cloudflare-philosophy.md).
2018-10-20 04:56:26 +02:00
Also see [Frequently Asked Questions](faq.md).
2018-01-17 20:14:50 +01:00
2017-05-01 18:26:27 +02:00
2019-02-19 04:34:06 +01:00
![What did YOU do to stop CF?](image/stopcf.jpg)
2019-02-19 04:36:09 +01:00
# What can you do?
2019-02-24 06:15:27 +01:00
* Read [our list of recommended actions](what-to-do.md) and share it with your friends
2019-03-12 02:39:47 +01:00
* Read [other user's voice](PEOPLE.md) (if you write a blog, tell us your URL)
2019-03-05 03:31:39 +01:00
* Update the domain list: [List instructions](instructions.md)
2019-02-19 03:30:32 +01:00
* Add WTF-Cloudflare news to [NEWS.md](NEWS.md)
2019-02-28 12:35:41 +01:00
* Search something on [Searxes Tor](http://searxes.nmqnkngye4ct7bgss4bmv5ca3wpa55yugvxen5kz2bbq67lwy6ps54yd.onion/) or [clearnet](https://searxes.danwin1210.me/) (this will help collecting Searxes' "MITM domains")
2019-02-28 12:40:05 +01:00
* Take a look at [add-on code](ismitmlink/) (how to use "MITM test API")
2019-03-19 04:00:48 +01:00
* Subscribe to ![](image/feed.png) RSS feed: "[The Great Cloudwall News](https://ieji.de/users/crimeflare.rss)" or follow ![](image/mstdn.jpg) [crimeflare@ieji.de](https://ieji.de/@crimeflare)
2018-01-17 20:14:50 +01:00
2019-02-28 12:40:05 +01:00
2019-02-19 03:34:58 +01:00
![WTF](image/wtfcf.jpg)
2018-09-02 04:20:17 +02:00
There are other lists, but this one is one where every entry on the list a human being has actually tried
to go to, and has been blocked.
2018-09-02 04:19:43 +02:00
Human is not a robot.
* [List of services blocking Tor](https://trac.torproject.org/projects/tor/wiki/org/doc/ListOfServicesBlockingTor) by Tor project contributors
* [Sites using cloudflare](https://github.com/pirate/sites-using-cloudflare) by pirate
WARNING:
2019-02-24 06:15:27 +01:00
Github.com is very hostile to Tor users. If you create an account on Github via Tor, your account will be automatically
2018-09-02 04:19:43 +02:00
flagged for spam and will be deleted. See "List of services blocking Tor" for details.
2018-05-04 00:40:35 +02:00
# Who uses this list?
2018-09-03 12:31:16 +02:00
* [Searxes](https://searxes.danwin1210.me/) meta-search engine
2018-10-09 04:14:19 +02:00
* [Block Cloudflare MITM Attack](https://addons.mozilla.org/en-US/firefox/addon/bcma/) add-on