Re: ietf.org unaccessible for Tor users

Christian de Larrinaga <cdel@firsthand.net> Tue, 15 March 2016 11:59 UTC

Return-Path: <cdel@firsthand.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5AAC512D993 for <ietf@ietfa.amsl.com>; Tue, 15 Mar 2016 04:59:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.801
X-Spam-Level:
X-Spam-Status: No, score=-1.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); domainkeys=neutral reason="invalid (public key: not available)" header.from=cdel@firsthand.net header.d=firsthand.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7QNFh8_mPLxj for <ietf@ietfa.amsl.com>; Tue, 15 Mar 2016 04:59:27 -0700 (PDT)
Received: from bmtwo.vm.bytemark.co.uk (mail.firsthand.net [212.110.188.53]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 37C0612D989 for <ietf@ietf.org>; Tue, 15 Mar 2016 04:59:27 -0700 (PDT)
X-No-Relay: not in my network
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=firsthand.net; b=NWwtHYz+/MmiO9Wa3e59bPAOYxk5hmaZBndDwZcZVKnR0RMzjlDQ+FgGuKE/CKfced4zjEkDSd9IEWRMzSWu0W2lk5Xh46nAhKC4OrZt5FCKmfQ7p8tANzxpgBHmknkT; h=X-No-Relay:X-No-Relay:X-No-Relay:X-No-Relay:Received:Message-ID:Date:From:Reply-To:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:X-Enigmail-Version:Content-Type:Content-Transfer-Encoding;
X-No-Relay: not in my network
X-No-Relay: not in my network
X-No-Relay: not in my network
X-No-Relay: not in my network
Received: from Christians-MacBook-Pro.local (60.88.155.90.in-addr.arpa [90.155.88.60]) by bmtwo.vm.bytemark.co.uk (Postfix) with ESMTPSA id CED88E03C4; Tue, 15 Mar 2016 11:59:24 +0000 (GMT)
Message-ID: <56E7F91B.8010109@firsthand.net>
Date: Tue, 15 Mar 2016 11:59:23 +0000
From: Christian de Larrinaga <cdel@firsthand.net>
User-Agent: Postbox 4.0.8 (Macintosh/20151105)
MIME-Version: 1.0
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Subject: Re: ietf.org unaccessible for Tor users
References: <20160313143521.GC26841@Hirasawa> <m2a8m0y72q.wl%randy@psg.com> <F04B3B85-6B14-43BA-9A21-FC0A31E79065@piuha.net> <56E7E09D.7040100@cisco.com> <56E7E16C.4050803@firsthand.net> <56E7E327.2090803@cisco.com> <56E7F273.4030708@firsthand.net> <56E7F352.8050506@firsthand.net> <56E7F470.1090104@cs.tcd.ie>
In-Reply-To: <56E7F470.1090104@cs.tcd.ie>
X-Enigmail-Version: 1.2.3
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/2ajzqB6On5NDz0A75Bvvedjz-ow>
Cc: Yui Hirasawa <yui@cock.li>, IETF Disgust List <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: cdel@firsthand.net
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Mar 2016 11:59:29 -0000

If it is necessary then that suggests a prioritised IETF workplan.
C
> Stephen Farrell <mailto:stephen.farrell@cs.tcd.ie>
> 15 March 2016 at 11:39
>
> I believe there have been attacks in the past that had they
> been at larger scale could have taken the IETF site offline.
> CF are a mitigation for that. I think some such mitigation
> is sadly necessary. But I also think we want that to work
> better, to not track folks and to not get in the way of access,
> unless taking such actions is really necessary. (I don't think
> it is myself, at least not in the normal course of events, but
> then I don't see the operations stuff.)
>
> Cheers,
> S.
>
> Christian de Larrinaga <mailto:cdel@firsthand.net>
> 15 March 2016 at 11:34
> With respect that is not the reasoning.
>
> Cloudflare are intercepting access from some IPs and imposing a man in
> the middle dialogue before "granting" access to
> https://www.ietf.org/rfc.html
>
> e.g. This is the report I get below a captcha - CloudFlare Ray ID:
> 283f99aee908294a • Your IP: 93.115.95.206 • Performance & security by
> CloudFlare
>
> There may be other usability issues with the ietf site such as
> javascript use but that is a separate issue I think to having a traffic
> policeman standing permanently in the middle of the road.
>
> The question is does IETF need that policeman to do that filtering? Is
> it desirable? I don't get the sense that it is.
>
> Christian
> Christian de Larrinaga <mailto:cdel@firsthand.net>
> 15 March 2016 at 11:30
> With respect that is not the reasoning.
>
> Cloudflare are intercepting access from some IPs and imposing a man in
> the middle dialogue before "granting" access to
> https://www.ietf.org/rfc.html
>
> e.g. This is the report I get below a captcha -  CloudFlare Ray ID:
> 283f99aee908294a • Your IP: 93.115.95.206 • Performance & security by
> CloudFlare
>
> There may be other usability issues with the ietf site such as
> javascript use but that is a separate issue I think to having a
> traffic policeman standing permanently in the middle of the road.
>
> The question is does IETF need that policeman to do that filtering? Is
> it desirable? I don't get the sense that it is.
>
> Christian
> Eliot Lear <mailto:lear@cisco.com>
> 15 March 2016 at 10:25
>
> By the logic nobody should use a Tor browser. That way we have one
> Internet.
>
>
> Christian de Larrinaga <mailto:cdel@firsthand.net>
> 15 March 2016 at 10:18
> One Internet or something?
>
>

-- 
Christian de Larrinaga  FBCS, CITP,
-------------------------
@ FirstHand
-------------------------
+44 7989 386778
cdel@firsthand.net
-------------------------