-
-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cloudflare breaks the HTML form for Tor users. #43
Comments
As far as I can see, the full There are a few things to try to increase the leniency towards Tor users:
Hosting your own Hidden Service for the As Hope this helps. :) |
Thank you, @jamieweb. I got this response from the original bug reporter via email:
|
Regarding the In regards to hosting your own Hidden Service, if you're running the Tor daemon on the same host as the website itself, you can safely forward traffic from Tor to However, if the website and Tor daemon are running on different hosts, specifying a non-local IP address as the forwarding address for the Hidden Service will cause the traffic to be transmitted 'as-is'. As onion sites usually run using HTTP, this means that plaintext HTTP traffic would be transmitted over the internet or your local network, which of course isn't good. The only exception to this is if the protocol you're using has its own encryption/authentication built-in, e.g. SSH or HTTPS (the latter of which is unlikely for an onion site). What I have described above is the reason for needing a local web server to use as a proxy, allowing for the traffic to be securely transmitted between the Tor daemon and remote web server. See my article here for more details including a demonstration with Wireshark captures: https://www.jamieweb.net/blog/forwarding-tor-hidden-services-to-another-server-across-the-internet/ |
Someone brought it to my attention that the form does not work for Tor users because of Cloudflare's WAF rules. We load the JavaScript files from Cloudflare's CDN which is causing trouble for some users. On top of that, the user experience on
securitytxt.org
for Tor users is severely impaired due to the Captchas they have to solve.Some options:
securitytxt.org
website.I am open to other suggestions.
cc: @jamieweb might know more on this subject.
The text was updated successfully, but these errors were encountered: