stop_cloudflare/README.md

8.5 KiB

The Great Cloudwall

"The Great Cloudwall" is CloudFlare, the world's largest MITM proxy(reverse proxy). It sits between you and origin webserver, acting like a border patrol agent. The origin webserver administrator allowed the agent to decide who can access to their "web property" and define "restricted area".

It is called this in reference to the Great Firewall of China which does a comparable job of filtering out many humans from seeing web content (ie everyone in mainland China and people outside) while at the same time those not affected to see a dratically different web, a web free of censorship such as an image of "tank man" and the history of "Tiananmen Square protests".

Cloudflare similarly prevents those in southeast asia and elsewhere who have poor internet connectivity from accessing the websites behind it (for example, they could be behind 7+ layers of NAT or sharing same IP) unless they solve multiple image CAPTCHAs. There is no way to solve the captcha without enabling Javascript and Cookies. Cloudflare is using them to make a browser signature.

Tor users and VPN users are also a victim of Cloudflare. If you didn't try Tor until this moment, we encourage you to download Tor Browser and visit your favorite websites.

Cloudflare also has a massive harassment problem. Cloudflare shares personal information of those who complain about hosted sites. They sometimes ask you to provide your true ID. If you don't want to get swatted or killed, better stay away from Cloudflare.

And their DNS service, 1.1.1.1, is also filtering out users from visiting the website by returning fake IP address owned by Cloudflare or just return nothing.

And here you might think, "I am not using Tor or VPN, why should I care?". If you visit website which use Cloudflare, you are sharing your information not only to website owner but also Cloudflare. It is impossible to analyze without decrypting TLS traffic. Cloudflare knows all your data such as raw password. Cloudbeed can happen anytime. Do you really want to share your data with Cloudflare, and also 3-letter agency?

Cloudflare also offer FREE VPN service called "Cloudflare Warp". If you use it, all your smartphone connections are sent to Cloudflare servers. Cloudflare can know which website you've read, what comment you've posted, who you've talked to, etc. You are voluntary giving all your information to Cloudflare. If you think "Are you joking? Cloudflare is secure." then you need to learn how VPN works.

You might already know about the PRISM scandal. It is true that AT&T lets NSA to copy all internet data for surveillance. Let's say you're working at the NSA, and you want every citizen's internet profile. You know most of them are blindly trusting Cloudflare and using it to proxy their personal website, chat website, forum website, bank website, insurance website, search engine, secret member-only website, auction website, shopping, video website, NSFW website, and illegal website. You also know they use Cloudflare's DNS service ("1.1.1.1") and VPN service ("Cloudflare Warp") for "Secure! Faster! Better!" internet experience. Combining them with user's IP address, browser fingerprint, cookies and RAY-ID will be useful to build target's online profile. You want their data. What will you do?

Cloudflare is a honeypot.

Free honey for everyone. Some strings attached.

Do not use Cloudflare.

Decentralize the internet.

"Cloudflare is not an option."


This repository is a list of websites that are behind The Great Cloudwall, and also actively blocking Tor users.

Domain list - mirrors: NixNet, CodeBerg

Information

There are more details of why what they are doing is wrong available here. Also see Frequently Asked Questions.

What can you do?

Name Firefox Chrome
Block Cloudflare MITM Attack Code Code
Are links vulnerable to MITM? Code Code
Which website rejected me? Code -

WTF

There are other lists, but this one is one where every entry on the list a human being has actually tried to go to, and has been blocked. Human is not a robot.

WARNING: Github.com is very hostile to Tor users. If you create an account on Github via Tor, your account will be automatically flagged for spam and will be deleted. See "List of services blocking Tor" for details.

Who uses this list?

What did YOU do to stop CF?