The Great Cloudwall
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Robin Wils 380a7af6d5 Add 2019-Tor_Censorship_Arms_Race.pdf to pdf/ 1 day ago
addon Update 'addon/about.urjm.md' 6 days ago
cloudflare_inc Update 'cloudflare_inc/cloudflare_members.txt' 6 days ago
cloudflare_users cloudflare_z.txt 5 days ago
globalist update links 5 months ago
image Upload files to 'image' 6 days ago
not_cloudflare Delete 'not_cloudflare/list_other.txt' 4 days ago
pdf Add 2019-Tor_Censorship_Arms_Race.pdf to pdf/ 1 day ago
subfiles Update 'subfiles/add-ons.md' 3 days ago
tool Update 'tool/getCFDomainFromList.php' 1 week ago
HISTORY.md Update 'HISTORY.md' 3 months ago
LICENSE.md Update 'LICENSE.md' 3 weeks ago
PEOPLE.md Update 'PEOPLE.md' 3 days ago
README.md Update 'README.md' 1 week ago
README_ethics.md Update 'README_ethics.md' 1 week ago
README_short.md Update relative links in README_short.md 1 week ago
article.txt update links 5 months ago
instructions.md Update 'instructions.md' 4 days ago
myth_catalog.md new file to catalog the myths about CloudFlare; 403 sites added 1 month ago
what-to-do.md Update 'what-to-do.md' 3 days ago

README.md

The Great Cloudwall


Table of contents


No Cloudflare

“The Great Cloudwall” is Cloudflare Inc., the U.S. company. It is the world’s largest MITM proxy(reverse proxy). It sits between you and origin webserver, acting like a border patrol agent. The origin webserver administrator allowed the agent to decide who can access to their “web property” and define “restricted area”.



Take a look at the first image posted below. You will think Cloudflare block only attackers. You will think Cloudflare is always online(never go down). However it is not true.



It is called this in reference to the Great Firewall of China which does a comparable job of filtering out many humans from seeing web content (ie everyone in mainland China and people outside) while at the same time those not affected to see a dratically different web, a web free of censorship such as an image of “tank man” and the history of “Tiananmen Square protests”.

Cloudflare also block legit robots/crawlers such as Google, Yandex, Yacy, and API clients.



Cloudflare similarly prevents those in southeast asia and elsewhere who have poor internet connectivity from accessing the websites behind it (for example, they could be behind 7+ layers of NAT or sharing same IP) unless they solve multiple image CAPTCHAs. Many humans are being blocked by Cloudflare every day. There is no way to solve the captcha without enabling Javascript and Cookies. Cloudflare is using them to make a browser signature.



Tor users and VPN users are also a victim of Cloudflare. If you didn’t try Tor until this moment, we encourage you to download Tor Browser and visit your favorite websites. (advice: Do not login to your bank website or government webpage or they will flag your account. Use VPN for those websites.)

You might want to say “Tor is illegal! Tor is criminal’s browser! Tor is bad!”. No. Tor was developed by US Army, but current Tor is developed by the Tor project. There are many people and organizations who use Tor including your future friends. So, if you are using Cloudflare on your website you are blocking real humans. You will lose potential friendship and business deal.



And their DNS service, 1.1.1.1, is also filtering out users from visiting the website by returning fake IP address owned by Cloudflare, localhost IP such as “127.0.0.x”, or just return nothing. Cloudflare DNS also break online software from smartphone app to computer game because of their fake DNS answer.



And here you might think, “I am not using Tor or VPN, why should I care?”. If you visit website which use Cloudflare, you are sharing your information not only to website owner but also Cloudflare. It is impossible to analyze without decrypting TLS traffic. Cloudflare knows all your data such as raw password. Cloudbeed can happen anytime.



Do you really want to share your data with Cloudflare, and also 3-letter agency? Internet user’s online profile is a “product” that the government and big tech companies wants to buy.

US Department of Homeland Security said:

Do you have any idea how valuable the data you have is?
Is there any way you would sell us that data?


Cloudflare also offer FREE VPN service called “Cloudflare Warp”. If you use it, all your smartphone (or your computer) connections are sent to Cloudflare servers. Cloudflare can know which website you’ve read, what comment you’ve posted, who you’ve talked to, etc. You are voluntary giving all your information to Cloudflare. If you think “Are you joking? Cloudflare is secure.” then you need to learn how VPN works.

Cloudflare said their VPN service make your internet fast. But VPN make your internet connection slower than your existing connection.



You might already know about the PRISM scandal. It is true that AT&T lets NSA to copy all internet data for surveillance. Let’s say you’re working at the NSA, and you want every citizen’s internet profile. You know most of them are blindly trusting Cloudflare and using it - only one centralized gateway - to proxy their personal website, chat website, forum website, bank website, insurance website, search engine, secret member-only website, auction website, shopping, video website, NSFW website, and illegal website. You also know they use Cloudflare’s DNS service (”1.1.1.1”) and VPN service (”Cloudflare Warp”) for “Secure! Faster! Better!” internet experience. Combining them with user’s IP address, browser fingerprint, cookies and RAY-ID will be useful to build target’s online profile. You want their data. What will you do?



Cloudflare is a honeypot.

Free honey for everyone. Some strings attached.

Do not use Cloudflare.

Decentralize the internet.

Next: Cloudflare Ethics


Data & More Information

This repository is a list of websites that are behind “The Great Cloudwall”, and also blocking Tor users.

Data

More Information

What can you do?

WTF