Re: ietf.org unaccessible for Tor users

Jari Arkko <jari.arkko@piuha.net> Tue, 15 March 2016 08:20 UTC

Return-Path: <jari.arkko@piuha.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA85112D8EF for <ietf@ietfa.amsl.com>; Tue, 15 Mar 2016 01:20:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9g2CM8lyJDUf for <ietf@ietfa.amsl.com>; Tue, 15 Mar 2016 01:20:48 -0700 (PDT)
Received: from p130.piuha.net (p130.piuha.net [IPv6:2a00:1d50:2::130]) by ietfa.amsl.com (Postfix) with ESMTP id 7181D12D53B for <ietf@ietf.org>; Tue, 15 Mar 2016 01:20:48 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by p130.piuha.net (Postfix) with ESMTP id 80F7E2CEE6; Tue, 15 Mar 2016 10:20:47 +0200 (EET) (envelope-from jari.arkko@piuha.net)
X-Virus-Scanned: amavisd-new at piuha.net
Received: from p130.piuha.net ([127.0.0.1]) by localhost (p130.piuha.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OjOrdLrlU7WJ; Tue, 15 Mar 2016 10:20:47 +0200 (EET)
Received: from [127.0.0.1] (p130.piuha.net [IPv6:2a00:1d50:2::130]) by p130.piuha.net (Postfix) with ESMTP id C2B842CC9A; Tue, 15 Mar 2016 10:20:46 +0200 (EET) (envelope-from jari.arkko@piuha.net)
Subject: Re: ietf.org unaccessible for Tor users
Mime-Version: 1.0 (Mac OS X Mail 7.3 \(1878.6\))
Content-Type: multipart/signed; boundary="Apple-Mail=_EA7C0D46-963A-4F94-8706-0B2FA2F4D7B4"; protocol="application/pgp-signature"; micalg="pgp-sha512"
X-Pgp-Agent: GPGMail 2.5.2
From: Jari Arkko <jari.arkko@piuha.net>
In-Reply-To: <m2a8m0y72q.wl%randy@psg.com>
Date: Tue, 15 Mar 2016 08:20:45 +0000
Message-Id: <F04B3B85-6B14-43BA-9A21-FC0A31E79065@piuha.net>
References: <20160313143521.GC26841@Hirasawa> <m2a8m0y72q.wl%randy@psg.com>
To: Randy Bush <randy@psg.com>, Yui Hirasawa <yui@cock.li>
X-Mailer: Apple Mail (2.1878.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/ryg6kALhA5qJlDjiJRAMYUsGlv8>
Cc: IETF Disgust List <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Mar 2016 08:20:51 -0000

I don’t have a solution, but I wanted to say that I feel the pain.

It is important that IETF documents are accessible via Tor. It is important that whatever CAPTCHA's are being employed, they are accessible to everyone. It is important that we at the IETF are able to deal with DoS attacks.

I’m not ready to believe that the above requirements are fundamentally in conflict.

I have a question thought and couple of other observations.

The question: Yui: I was under the (perhaps mistaken) assumption that ietf.org is generally accessible to everyone in the usual way, but that some blacklisted nodes will have to go through a CAPTCHA process before being able to continue. Is this so, or is there an experience that says nodes are blocked and there isn’t even a possibility to go through a CAPTCHA? Or is the problem that there is a CAPTCHA but you do not feel that it is done in a way that is appropriate? Does all this relate to http or https traffic?

The observations:

o   I do not feel that contracted running of multiple copies of our servers constitutes a man-in-the-middle arrangement.

o   I have asked the matter to be discussed in our IT/tools/IAOC meetings, but I’ll note that we may not have any more magical answers than what is already being discussed on the list.

Jari