summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--what-to-do.md65
1 files changed, 28 insertions, 37 deletions
diff --git a/what-to-do.md b/what-to-do.md
index 3aed0b3b..8845e10d 100644
--- a/what-to-do.md
+++ b/what-to-do.md
@@ -1,84 +1,75 @@
##### What you can do to resist Cloudflare?
-* As a website consumer
+###### Website consumer
- If the website you like is using Cloudflare, tell them not to use Cloudflare.
> You are just helping corporate censorship and mass surveillance.
> https://trac.torproject.org/projects/tor/ticket/24351
-- Try not to use their service. There are many alternatives and opportunites on the internet!
+- Try not to use their service. Remember you are being watched by Cloudflare.
+
+- Search for other website. There are many alternatives and opportunites on the internet!
- If your browser is Firefox, use [Block Cloudflare MITM Attack!](http://ea5faa5po25cf7fb.onion/projects/tor/attachment/ticket/24351/block_cloudflare_mitm_attack-1.0.14.1-an%2Bfx.xpi) add-on.
- Convince your friends to use [Tor Browser](https://www.torproject.org/) on the daily basis. Anonymity should be the standard of the open internet!
-* As a website owner / web developer
+###### Website owner / Web developer
-- Do not use Cloudflare solution. You are loser if you fall to that easy solution. You can do better than that.
+- Do not use Cloudflare solution. You are loser if you fall to that easy solution. You can do better than that, right?
-- Install Web Application Firewall and Fail2Ban on _your_ server and configure it properly.
+- Install Web Application Firewall and Fail2Ban on _your_ server and configure it _properly_.
- Set up [Tor Onion Service](https://www.torproject.org/docs/onion-services.html.en) if you believe in freedom and welcome anonymous users.
- Ask for advice from other [Clearnet/Tor dual website operators](https://trac.torproject.org/projects/tor/wiki/org/projects/WeSupportTor) and make anonymous friends! :)
-* As a software user
-
+###### Software user
- If you use Debian GNU/Linux, or any derivative, subscribe to bug #831835 ( https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=831835 ). And if you can, help verify the patch, and help the maintainer come to the right conclusion on whether it should be accepted.
-- Always recommend [Tor Browser](https://www.torproject.org/) or Orfox. Other software's privacy is JUST A ILLUSION.
-
-- For example, if you really need to use Firefox, pick "Firefox ESR". ESR is developed for company and organizations, thus some spyware code is disabled by default.
-
-- Remember, Mozilla is [using Cloudflare service](https://www.robtex.com/dns-lookup/www.mozilla.org). They also using Cloudflare's DNS service on their product.
-
-
-
-
-
-
-
+- Always recommend [Tor Browser](https://www.torproject.org/) or [Orfox](). Other software's privacy is JUST A ILLUSION.
+Let's talk about _other software's privacy_...
+- If you really need to use Firefox, pick "[Firefox ESR](https://www.mozilla.org/en-US/firefox/organizations/)". ESR is developed for company and organizations, thus _some_ spyware code is disabled by default. Portable version is [here](https://portableapps.com/apps/internet/firefox-portable-esr).
-* If you use one of the websites on this list, contact the webmasters if you still can, and tell them not to use Cloudflare.
+- Remember, Mozilla is [using Cloudflare service](https://www.robtex.com/dns-lookup/www.mozilla.org). They're also using [Cloudflare's DNS service on their product](https://www.theregister.co.uk/2018/03/21/mozilla_testing_dns_encryption/) D'oh!
-* If they can't leave CloudFlare(perhaps they are merely tech support at the website, and management has decreed that Cloudflare MUST be used) get them to exercise option to whitelist Tor without changing to the "basic level of security" within Cloudflare's options. CloudFlare customers can use this tool(?) to whitelist tor. Advise them, however, that using CloudFlare(or any Cloudflare-like competitors, see [philosophy](cloudflare-philosophy.txt) and [non-cloudflare list](non-cloudflare-list.txt) ) exposes readers/viewers/customers to a giant supplier MitM. This is a questionable practice, regardless of whitelists.
+- Mozilla officially [rejected this ticket](https://bugzilla.mozilla.org/show_bug.cgi?id=1426618).
-* Tell others around you about the dangers of Cloudflare.
+- PaleMoon developer [likes Cloudflare](https://github.com/mozilla-mobile/focus-android/issues/1743#issuecomment-345993097).
-* Help improve this repository, both the lists, the arguments against it and the details
+- Chrome is a [spyware](https://www.gnu.org/proprietary/malware-google.en.html).
-* Document and make very public where things go wrong with Cloudflare (and similar companies), making sure to mention this repository when you do so
-* Get more people using Tor by default so they can experience the web from the perspective of different parts of the world.
+###### Action
-* Start groups, in social media and meatspace, dedicated to liberating the world from Cloudflare.
+- Tell others around you about the dangers of Cloudflare.
-* Where appropriate, link to these groups on this repository - this can be a place for coordinating working together as groups
+- Help improve this repository, both the lists, the arguments against it and the details.
-* Start a coop that can provide a meaningful non corporate alternative to Cloudflare
+- Document and make very public where things go wrong with Cloudflare (and similar companies), making sure to mention this repository when you do so
-* let us know of any alternatives to help at least provide multiple layered defence against Cloudflare
+- Get more people using Tor by default so they can experience the web from the perspective of different parts of the world.
-* Try using [globalist](globalist.txt) to maintain this list!
+- Start groups, in social media and meatspace, dedicated to liberating the world from Cloudflare.
-* If you are in the United States of America
+- Where appropriate, link to these groups on this repository - this can be a place for coordinating working together as groups.
-** If the website is a bank or an accountant
+- Start a coop that can provide a meaningful non corporate alternative to Cloudflare.
-*** try to bring legal pressure under the Gramm–Leach–Bliley Act https://en.wikipedia.org/wiki/Gramm%E2%80%93Leach%E2%80%93Bliley_Act and report back to us
-how far you get
+- Let us know of any alternatives to help at least provide multiple layered defence against Cloudflare.
-** if the website is a government site
+- Try using [globalist](globalist.txt) to maintain this list.
-*** try to bring legal pressure under the 1st Amendment of the US Constitution
+- If you are in the **United States of America** and the website in question is a bank or an accountant, try to bring legal pressure under the Gramm–Leach–Bliley Act https://en.wikipedia.org/wiki/Gramm%E2%80%93Leach%E2%80%93Bliley_Act and report back to us how far you get.
-* For companies that claim to offer service on their website try reporting them as "false advertising" to consumer protection organizations and BBB
+- If the website is a government site, try to bring legal pressure under the 1st Amendment of the US Constitution.
+- For companies that claim to offer service on their website try reporting them as "false advertising" to consumer protection organizations and BBB.