Bitcoin Forum
May 04, 2024, 01:43:29 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Data privacy and this forum (cloudflare)  (Read 241 times)
bluefirecorp_ (OP)
Full Member
***
Offline Offline

Activity: 574
Merit: 152


View Profile
March 25, 2018, 03:19:09 AM
Merited by Vod (3), theyoungmillionaire (1)
 #1

Alright, we understand the need to coware behind cloudflare against the mighty DDoS's of today. No sysadmin can single-handly build a mitigation system (it takes a team and piles of burning cash).

With the fact the US will pass the Cloud Act, cloudflare won't have any rights to defend our privacy, I guess no cloud provider really will.

Does anyone have any technical solutions (because politics aint gonna work) in mind for this problem?

1714830209
Hero Member
*
Offline Offline

Posts: 1714830209

View Profile Personal Message (Offline)

Ignore
1714830209
Reply with quote  #2

1714830209
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714830209
Hero Member
*
Offline Offline

Posts: 1714830209

View Profile Personal Message (Offline)

Ignore
1714830209
Reply with quote  #2

1714830209
Report to moderator
1714830209
Hero Member
*
Offline Offline

Posts: 1714830209

View Profile Personal Message (Offline)

Ignore
1714830209
Reply with quote  #2

1714830209
Report to moderator
DarkStar_
Legendary
*
Offline Offline

Activity: 2758
Merit: 3282


View Profile WWW
March 25, 2018, 03:39:50 AM
 #2

It might be worth it for the forum to consider other DDoS protection services. Not all of them are in the US (EU actually cares about privacy!), and some have different methods of DDoS protection. It might be worth it to consider whatever ProtonMail uses (don't recall the exact company, and too annoying to find on mobile), as I believe everything is still encrypted when they're under DDoS. ProtonMail also only forwards traffic to their DDoS defense when they are under DDoS; it's a direct connection to their servers otherwise.

taking a break - expect delayed responses
bluefirecorp_ (OP)
Full Member
***
Offline Offline

Activity: 574
Merit: 152


View Profile
March 25, 2018, 03:43:51 AM
 #3

It might be worth it for the forum to consider other DDoS protection services. Not all of them are in the US (EU actually cares about privacy!), and some have different methods of DDoS protection. It might be worth it to consider whatever ProtonMail uses (don't recall the exact company, and too annoying to find on mobile), as I believe everything is still encrypted when they're under DDoS. ProtonMail also only forwards traffic to their DDoS defense when they are under DDoS; it's a direct connection to their servers otherwise.

Any idea of their pricing or services? Cause that sounds like a reasonable solution, even more so if there's a way to post "this data may be monitored" when DDoS attacks are happening?

DarkStar_
Legendary
*
Offline Offline

Activity: 2758
Merit: 3282


View Profile WWW
March 25, 2018, 04:12:38 AM
 #4

It might be worth it for the forum to consider other DDoS protection services. Not all of them are in the US (EU actually cares about privacy!), and some have different methods of DDoS protection. It might be worth it to consider whatever ProtonMail uses (don't recall the exact company, and too annoying to find on mobile), as I believe everything is still encrypted when they're under DDoS. ProtonMail also only forwards traffic to their DDoS defense when they are under DDoS; it's a direct connection to their servers otherwise.

Any idea of their pricing or services? Cause that sounds like a reasonable solution, even more so if there's a way to post "this data may be monitored" when DDoS attacks are happening?

It's with Radware. I'm not sure about the specific plan/set up, but ProtonMail said it was cheaper than the other companies who offered to help. You can read a bit about it here, though it doesn't go into much detail: https://protonmail.com/blog/ddos-protection-guide/

Not sure if it would be possible for this forum as ProtonMail set up their own ISP which certainly would give them more freedom. They do say that the SSL keys don't need to be handed over though, which is the way that Cloudflare gets our data.

I've never dealt with much DDoS protection, but it should be reasonable to have a warning if it's enabled.

taking a break - expect delayed responses
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
March 25, 2018, 04:13:53 AM
 #5



Any idea of their pricing or services?
DDoS protection services are generally very expensive. Large companies/providers enjoy great advantages via economies of scale.

I agree that additional steps should be taken to ensure privacy, although this may be a lost cause at this point. A better use of resources might be to fund the cost of fighting the acceptance of evidence obtained via this law.
bluefirecorp_ (OP)
Full Member
***
Offline Offline

Activity: 574
Merit: 152


View Profile
March 25, 2018, 04:15:15 AM
 #6



Any idea of their pricing or services?
DDoS protection services are generally very expensive. Large companies/providers enjoy great advantages via economies of scale.

I agree that additional steps should be taken to ensure privacy, although this may be a lost cause at this point. A better use of resources might be to fund the cost of fighting the acceptance of evidence obtained via this law.

So, donate to the ACLU? Seems like a monetary, non-technical solution to the problem at hand.

Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
March 25, 2018, 04:20:30 AM
 #7



Any idea of their pricing or services?
DDoS protection services are generally very expensive. Large companies/providers enjoy great advantages via economies of scale.

I agree that additional steps should be taken to ensure privacy, although this may be a lost cause at this point. A better use of resources might be to fund the cost of fighting the acceptance of evidence obtained via this law.

So, donate to the ACLU? Seems like a monetary, non-technical solution to the problem at hand.
That might not even be necessary. Theymos can simply be on the lookout for a bitcoin related case in which the law was used and fund the appeal of a ruling allowing the use of the law to obtain information.

The alternative would be to setup your own DDoS protection, which theymos previously tried, without a lot of success. Even with cloudflare, the forum still appears to be under DDoS attack.
sud
Sr. Member
****
Offline Offline

Activity: 826
Merit: 301



View Profile
March 25, 2018, 09:23:09 AM
 #8

Wouldn't blockchain be perfect for DDoS prevention system? Seriously, by now we should have at least few projects with cheap, crypto-based solutions for such problems. I only know Gladius is working on something like this.
Jet Cash
Legendary
*
Offline Offline

Activity: 2702
Merit: 2456


https://JetCash.com


View Profile WWW
March 25, 2018, 10:01:01 AM
 #9

What's the big issue with privacy? All the posts are public, and if you are doing something illegal through PMs, you should be doing it away from a public forum. Is it just that people want to post without accepting responsibility for their opinions?

Offgrid campers allow you to enjoy life and preserve your health and wealth.
Save old Cars - my project to save old cars from scrapage schemes, and to reduce the sale of new cars.
My new Bitcoin transfer address is - bc1q9gtz8e40en6glgxwk4eujuau2fk5wxrprs6fys
bluefirecorp_ (OP)
Full Member
***
Offline Offline

Activity: 574
Merit: 152


View Profile
March 25, 2018, 02:43:50 PM
 #10

What's the big issue with privacy? All the posts are public, and if you are doing something illegal through PMs, you should be doing it away from a public forum. Is it just that people want to post without accepting responsibility for their opinions?

https://en.wikipedia.org/wiki/Nothing_to_hide_argument

The idea is we're giving up data privacy for "security" while in reality it's just giving up our rights with due process.

The fact that any govt can now request records from sites without warrants is scary. Remember when China hacked the Gmail accounts of political activists? Now they just need to submit a formal request and the data is there.

Jet Cash
Legendary
*
Offline Offline

Activity: 2702
Merit: 2456


https://JetCash.com


View Profile WWW
March 25, 2018, 03:38:52 PM
 #11

It seems to me that the real issues aren't privacy, but the the lack of information available on the activities of the puppet masters who are controlling the governments. We should remove the privacy from their communications and actions.

Offgrid campers allow you to enjoy life and preserve your health and wealth.
Save old Cars - my project to save old cars from scrapage schemes, and to reduce the sale of new cars.
My new Bitcoin transfer address is - bc1q9gtz8e40en6glgxwk4eujuau2fk5wxrprs6fys
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
March 25, 2018, 04:15:32 PM
 #12

What's the big issue with privacy? All the posts are public, and if you are doing something illegal through PMs, you should be doing it away from a public forum. Is it just that people want to post without accepting responsibility for their opinions?
It could result in private information about you, such as your IP address being released to the government. It could also result in your PMs being released to the government.

The lack of needing a warrant means the process is ripe for abuse by the government. If for example, you are speaking out against the sheriff, the sheriff could go on a phishing expedition to look for illegal activity and then arrest you on a small technical violation of the law. 
FFrankie
Hero Member
*****
Offline Offline

Activity: 2254
Merit: 960

100% Deposit Match UP TO €5000!


View Profile
March 25, 2018, 04:31:04 PM
 #13

What's the big issue with privacy? All the posts are public, and if you are doing something illegal through PMs, you should be doing it away from a public forum. Is it just that people want to post without accepting responsibility for their opinions?

Our emails and passwords are not public, nor are our IPs (unless we embed a pixel size image in a post to track that info) our shipping Info that we send via PM or privote are not public either.

What is the big issue with privacy? Isn't that one of the reasons why bitcoin was created in order for a fast and private way to send bitcoins?
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
March 25, 2018, 04:32:05 PM
 #14

To clarify, do cloudflare hold the certificate for this site or does the actual site's server posess that? If cloudflare hold it then that's a great issue for anyone in the US (for people outside, it's an issue but not as big as a problem) though the US intelligence agencies seem even worse than places like the UK for keeping their secrets secret.

It could result in private information about you, such as your IP address being released to the government. It could also result in your PMs being released to the government.

The lack of needing a warrant means the process is ripe for abuse by the government. If for example, you are speaking out against the sheriff, the sheriff could go on a phishing expedition to look for illegal activity and then arrest you on a small technical violation of the law. 

You could always switch to a service like tor but that is immensely slow at loading (not sure if there are any good fast and free services that you can use for a vpn/proxy).

It might be worth it for the forum to consider other DDoS protection services. Not all of them are in the US (EU actually cares about privacy!), and some have different methods of DDoS protection. It might be worth it to consider whatever ProtonMail uses (don't recall the exact company, and too annoying to find on mobile), as I believe everything is still encrypted when they're under DDoS. ProtonMail also only forwards traffic to their DDoS defense when they are under DDoS; it's a direct connection to their servers otherwise.

There's a London based cloudflare and other cloudflare offices in mainland EU I think those could be used (not London though due to the IP act).

A direct connection to the server is also a good idea but I don't think theymos would particularly like that idea as it has a likelihood of being abused and the Bitcointalk server isn't a powerful as the ProtonMail datacentre.
It's a shame none of the admins/moderators don't have a mining pool that we could hide behind (gigabytes of data being transmitted per second would be a nice thing to hide behind as no one is going to want to screen all of that just to pull out the packets for this server).



There have been multiple suggestions of having paid-for direct access to the servers which I wouldn't be apposed to paying say 0.01BTC a month to access the server directly from my own private socket into the server (possibly make it so that transmission has to be encrypted with a sort of private key/public key pair that each user randomely generates every month - unless that's too much of an advanced thing to try to incorporate).
DarkStar_
Legendary
*
Offline Offline

Activity: 2758
Merit: 3282


View Profile WWW
March 25, 2018, 05:34:40 PM
 #15

To clarify, do cloudflare hold the certificate for this site or does the actual site's server posess that? If cloudflare hold it then that's a great issue for anyone in the US (for people outside, it's an issue but not as big as a problem) though the US intelligence agencies seem even worse than places like the UK for keeping their secrets secret.

Cloudflare generated and holds the SSL certificate for Bitcointalk. I believe all protection through Cloudflare requires the certificate.

taking a break - expect delayed responses
bluefirecorp_ (OP)
Full Member
***
Offline Offline

Activity: 574
Merit: 152


View Profile
September 19, 2018, 01:11:47 AM
 #16

To clarify, do cloudflare hold the certificate for this site or does the actual site's server posess that? If cloudflare hold it then that's a great issue for anyone in the US (for people outside, it's an issue but not as big as a problem) though the US intelligence agencies seem even worse than places like the UK for keeping their secrets secret.

Cloudflare generated and holds the SSL certificate for Bitcointalk. I believe all protection through Cloudflare requires the certificate.

Right. This is still a problem.

So, with cloudflare doing the TLS termination, every PM can be logged by that third-party entity. Not only can they read, but they can also modify messages in transmission.

jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
September 19, 2018, 08:31:57 AM
 #17

Right. This is still a problem.

So, with cloudflare doing the TLS termination, every PM can be logged by that third-party entity. Not only can they read, but they can also modify messages in transmission.

Theymos can edit what your PMs say and send new PMs. He can't do as much as cloudflare in getting username and passord combinations, however he can do quite a bit on that front.

If you have something significant to say, stake your address somewhere on this forum and sign your message so people can verify it's you (you can also use a PGP key for this).
bluefirecorp_ (OP)
Full Member
***
Offline Offline

Activity: 574
Merit: 152


View Profile
September 20, 2018, 02:00:28 PM
 #18

Right. This is still a problem.

So, with cloudflare doing the TLS termination, every PM can be logged by that third-party entity. Not only can they read, but they can also modify messages in transmission.

Theymos can edit what your PMs say and send new PMs. He can't do as much as cloudflare in getting username and passord combinations, however he can do quite a bit on that front.

If you have something significant to say, stake your address somewhere on this forum and sign your message so people can verify it's you (you can also use a PGP key for this).

Theymos is a trusted source. He could easily get our passwords by adding two to three lines of code to the login function (just log the passwords to plain-text file).

Valid point on the securing communication; I was thinking moving entirely to GPG for communications and signing messages to ensure the integrity. However, just because they can't read my message doesn't mean it's secured. They'd still have the metadata available (bluefirecorp sent message to jackg at this time, on this date).

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!