Which FPGA would you use? High-end FPGAs (and FPGA software) are very proprietary and locked down.
Can you whitelist Tor on blog.cloudflare.com, at least? :-)
Can you please whitelist Tor in the Cloudflare settings for this site?
Good point. That did not occur to me. edit: Thanks for the dialogue thus far.
> What I am working on is an overall solution so that the need for CAPTCHAs at all is diminished. I like that idea, but my worry is it will take years to reach that point, and in the meantime Tor/VPN users will just…
Tor users are complaining about the captchas. I'm not sure why you think it's so hard to create a sample captcha page to demonstrate the experience. You just need two pages: one with JS-enabled captchas and one with…
>> 2. In addition to better docs, can you setup something that lets site operators view the site as a Tor user? > > That seems like an enormous amount of work when anyone can just get the Tor Browser and test it out.…
A respectable CDN should be able to handle lots of GET requests, even if by attack. As others have pointed out, the Tor network can't support much traffic, so DDoS by GET requests does not seem like a big concern.
When are GET requests unsafe?
I'm a long-time Tor user that's been affected by CloudFlare captchas for a few years. I appreciate that you (CloudFlare) are trying to tackle the problem, but I feel that both CloudFlare and the Tor community have…
Which FPGA would you use? High-end FPGAs (and FPGA software) are very proprietary and locked down.
Can you whitelist Tor on blog.cloudflare.com, at least? :-)
Can you please whitelist Tor in the Cloudflare settings for this site?
Good point. That did not occur to me. edit: Thanks for the dialogue thus far.
> What I am working on is an overall solution so that the need for CAPTCHAs at all is diminished. I like that idea, but my worry is it will take years to reach that point, and in the meantime Tor/VPN users will just…
Tor users are complaining about the captchas. I'm not sure why you think it's so hard to create a sample captcha page to demonstrate the experience. You just need two pages: one with JS-enabled captchas and one with…
>> 2. In addition to better docs, can you setup something that lets site operators view the site as a Tor user? > > That seems like an enormous amount of work when anyone can just get the Tor Browser and test it out.…
A respectable CDN should be able to handle lots of GET requests, even if by attack. As others have pointed out, the Tor network can't support much traffic, so DDoS by GET requests does not seem like a big concern.
When are GET requests unsafe?
I'm a long-time Tor user that's been affected by CloudFlare captchas for a few years. I appreciate that you (CloudFlare) are trying to tackle the problem, but I feel that both CloudFlare and the Tor community have…