The forum has enough money to invest in forum related issues and this is a major issue.
I don't think money is the problem:
With regret, I am (for now) admitting defeat on the DDoS front, and we will soon be using using Cloudflare to protect against DDoS attacks. ~
I really don't believe in willingly putting a man-in-the-middle in your HTTPS like this, but my homebrew DDoS mitigation has been one of my biggest time sinks for the last 6 months or so, and the necessary servers are still pretty expensive. If I had more manpower, then I would prioritize maintaining our own DDoS protection, but with me as the only sysadmin and current-software developer, it's become unsustainable.
I especially dislike Cloudflare, which I'm almost certain is basically owned by US intelligence agencies. I considered several alternatives to Cloudflare, but the smaller ones (eg. Stackpath and OVH) didn't strike me as reputable/competent enough, and the enterprise-targeted ones like Incapsula and Akamai are around $3500/month. Even though $3500/month seems absolutely ridiculous to me, I was seriously considering Incapsula due to its pretty good reputation, but then they were having all sorts of technical issues while I was trying to set it up. So I gave up for now and went with Cloudflare.
The Internet is seriously flawed if everyone needs to huddle behind these huge centralized anti-DDoS companies in order to survive...
If you have a better solution than Cloudflare, you should post it. Until then, Cloudflare is a necessary evil.
For what it's worth: I can access Bitcointalk through Tor at the moment.
Privacy of the forum users comes first or the expense?
There's more to it than just money. A
.onion domain without Cloudflare has been suggested before.
Quoting a previous message, hope that theymos will see it:
We are also ready to provide technical assistance in Cloudflare-less DDoS protection setup if it's the case.
Since that post, I've seen several posts about eXch's own website being inaccessible.
That only removes the forum's own Captcha, not Cloudflare.
I don't think that theymos will buy the idea because of the reputation of the forum. Having an onion version might take the government's eyes to the forum and some kind of legal compliances would be required.
Many normal websites also have a
.onion domain. It's not only "for the darknet", it's actually useful for honest people who want privacy too. Examples: Protonmail, Blockchair, Facebook.
I guess now I need to get used to with VPN. It's the last thing I wanted but to maintain the business, from the responsibility I am taking the risk otherwise I would take a break from Bitcointalk until the DF thing was settled.
Once you've compromised your privacy, it's lost forever. If your VPN can't be trusted, it's too late after using it only once.
You could use a virtual desktop on a VPS, and access that through Tor. But that's slow and annoying to work with.