HomeSecurityCloudflare is looking for a way to remove CAPTCHAs for Tor Users

Cloudflare is looking at a way to remove CAPTCHAs for Tor users

Despite routing a whopping 10 percent of all Internet traffic, Cloudflare is best known for its annoying CAPTCHAs, which often delay Tor users for minutes before letting them access a website.

The Tor Project has not been shy about pointing the finger at Cloudflare publicly. Last February, members of the Tor Project accused Cloudflare of intentionally sabotaging Tor traffic through its CAPTCHAs and using special cookies to track Tor users across the Internet.

Cloudflare is looking at a way to remove CAPTCHAs for Tor users

Cloudflare responded a month later, denying all charges. The company said that only IP addresses with a bad reputation see CAPTCHAs, which are a self-defense measure for websites that Cloudflare is hired to protect.

The company said that 94 percent of all Tor traffic is malicious and is mainly used for automated attacks , which is why regular Tor users see CAPTCHAs. Cloudflare was adamant that it had nothing against the Tor Project or its users.

Given, however, that actions are what count, Cloudflare is now looking for a new system to protect its customers from malicious Tor traffic, without bombarding Tor users with endless CAPTCHAs.

The relevant document was published on GitHub two weeks ago and is called the "Challenge Bypass Specification".

According to this specification, Cloudflare is working on a Tor browser extension that generates one-time authentication tokens, called nonces.

Every time a Tor user accesses a Cloudflare-protected area, they will have to solve an initial CAPTCHA. After that, the browser will provide authentication tokens to the Cloudflare firewall and the user will not have to deal with any CAPTCHAs.

As the malicious traffic is automated with various CLI-tools, attackers will not be able to provide these tokens and the firewall will do its job as it should.

Currently, the draft specification uses a modification of the RSA encryption algorithm to create "blind signatures" that can be used as nonces.

Cloudflare also explains that this system is not specifically tailored for its network. The entire system is modular and other edge providers can use it to handle Tor traffic in the same way.

Furthermore, the initial one-time CAPTCHA is not mandatory and each edge provider could implement its own system for authenticating human users and then use the nonces for subsequent authentication.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS