Re: ietf.org unaccessible for Tor users

Alec Muffett <alecm@fb.com> Tue, 15 March 2016 13:30 UTC

Return-Path: <prvs=2882ba8273=alecm@fb.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6424812D59B for <ietf@ietfa.amsl.com>; Tue, 15 Mar 2016 06:30:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.72
X-Spam-Level:
X-Spam-Status: No, score=-2.72 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=fb.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id v3G_LoXx_wdC for <ietf@ietfa.amsl.com>; Tue, 15 Mar 2016 06:30:37 -0700 (PDT)
Received: from mx0a-00082601.pphosted.com (mx0a-00082601.pphosted.com [67.231.145.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3183412D5B9 for <ietf@ietf.org>; Tue, 15 Mar 2016 06:30:37 -0700 (PDT)
Received: from pps.filterd (m0044008.ppops.net [127.0.0.1]) by mx0a-00082601.pphosted.com (8.16.0.11/8.16.0.11) with SMTP id u2FDAqK7013855; Tue, 15 Mar 2016 06:11:48 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fb.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=facebook; bh=K7f3AmPP903m5gqtRWByXyQgLyi7Vr0vxxjXfWfWW5A=; b=Ceh9zn/bJVyzP88ZF+/G6nhnGRavwCid7EFoYBJNvM5rplDmOhaaexPnAvpJ/lnET+s1 djQMDZsHE1IgVlOIyhiujFXMHuocsg7/JLwTqSN8XcVOgMRaf28bAJjAK6yn1dnVG0gu ZHAY6WM6CNr7duIV/AgZnaXsxGimfoLkB4M=
Received: from mail.thefacebook.com ([199.201.64.23]) by mx0a-00082601.pphosted.com with ESMTP id 21pjdag5hf-1 (version=TLSv1 cipher=AES128-SHA bits=128 verify=NOT); Tue, 15 Mar 2016 06:11:48 -0700
Received: from PRN-MBX02-4.TheFacebook.com ([169.254.2.215]) by PRN-CHUB11.TheFacebook.com ([fe80::80d:37ff:4b6a:a4fc%12]) with mapi id 14.03.0248.002; Tue, 15 Mar 2016 06:11:47 -0700
From: Alec Muffett <alecm@fb.com>
To: Eliot Lear <lear@cisco.com>
Subject: Re: ietf.org unaccessible for Tor users
Thread-Topic: ietf.org unaccessible for Tor users
Thread-Index: AQHRfgLB+RUL/0piL0GFmq6KqbJrIZ9aCzuAgACVPICAAB/kgIAABnmAgAAFdgCAAAQZAIAACAGAgAAVxQCAAAOcgA==
Date: Tue, 15 Mar 2016 13:11:46 +0000
Message-ID: <C09D111E-188D-48EB-BD5E-B4CAF1B287BA@fb.com>
References: <20160313143521.GC26841@Hirasawa> <m2a8m0y72q.wl%randy@psg.com> <F04B3B85-6B14-43BA-9A21-FC0A31E79065@piuha.net> <56E7E09D.7040100@cisco.com> <4349AFDD-350C-4217-9BEE-3DBD2F608F95@nohats.ca> <56E7EAA0.1050907@cs.tcd.ie> <56E7EE10.9000802@cisco.com> <56E7F4C7.6080808@mnt.se> <56E8070A.7070901@cisco.com>
In-Reply-To: <56E8070A.7070901@cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [192.168.52.123]
Content-Type: multipart/alternative; boundary="_000_C09D111E188D48EBBD5EB4CAF1B287BAfbcom_"
MIME-Version: 1.0
X-Proofpoint-Spam-Reason: safe
X-FB-Internal: Safe
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2016-03-15_04:, , signatures=0
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/HkNhr9MJE0fe-wdicSUm8rR0QZs>
Cc: "ietf@ietf.org" <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Mar 2016 13:30:40 -0000

Hi Eliot!

On Mar 15, 2016, at 12:58, Eliot Lear <lear@cisco.com<mailto:lear@cisco.com>> wrote:
Yes, but we at least can spot the C&C on the Internet.  See upthread about how hard that is with Tor.

I just want to round back and check that we're all discussing the same thing.

The thread so far seems to be regards "People who use Browsers over Tor have problems accessing IETF because CAPTCHA from IETF's Hosting Provider".

Elsewhere, other people have made clear arguments that perhaps this is an issue, because IETF broad participation and open access, and has written principles against surveillance.

My understanding is that you are making an argument that making life hard for people who access IETF's website over Tor is justified, because some DDoS botnets use Tor as command-and-control backhaul - which is not a unique situation, other botnets use IRC, or HTTP and some with SSL.

So, yes, sometimes Tor gets used by bad people to do bad stuff.  That much is correct, and is a criticism which can actually be thrown at HTTP or the Internet in general.

So - with this understanding - why pick on people who want to access the IETF over Tor?  Perhaps you wish to make some kind of moral stand against network protocols which are sometimes used to do bad things?

If so, why not start with TCP?

    -a