Cloudflare actually went out of their way to make it easy to whitelist Tor IPs that would generally get automatictly blacklisted for abuse.
Cloudflare actually went out of their way to make it easy to whitelist Tor IPs that would generally get automatictly blacklisted for abuse.
EDIT: Maybe not anymore? See replies
What they went out of their way to do, was explicitly make it less painful for legitimate users to use Tor, despite the amount of malicious content they get from Tor. I'd argue for most companies, if 94% of the traffic from somewhere is malicious, the answer is "block it and be done with it", but clearly, Cloudflare actually values Tor and what it stands for enough to come up with a workaround.
nope, you're spreading un-sourced/unconfirmed FUD. Provide a source, or this is just FUD. Tor IPs are treated like any other IP by default, not "more questionable by default".
https://support.cloudflare.com/hc/en-us/articles/203306930-D...
The options for Tor are:
Whitelist (trust)
CAPTCHA (visible challenge which the visitor must interact with to pass)
JavaScript Challenge (visible challenge with less friction, testing the browser)
Block (blacklist -- available only to Cloudflare Enterprise customers)
I'm not sure you actually made a point other than to confirm that we allow website owners to fully whitelist Tor if they'd like to.
The website owner's settings defaults to secure, and they can intentionally take action to make the website less secure if they'd like to. That is their decision, of course we do not default to a less secure posture.