I- "Cloud Cloudwall" enkulu iCloudflare Inc., inkampani yase-U.S. Inikezela ngezinsizakalo ze-CDN (inethiwekhi yokulethwa kokuqukethwe), ukuncishiswa kwe-DDoS, ukuphepha kwe-inthanethi, kanye nezinsizakalo ze-DNS (zesizinda segama lesizinda) ezisatshalaliswa. |
 |
I-Cloudflare yommeleli omkhulu we-MITM emhlabeni (ummeleli ophambukayo). I-Cloudflare inabanini abangaphezulu kwama-80% wezabelo zemakethe ze-CDN kanye nenani labasebenzisi befu. Bangezelele inethiwekhi yabo emazweni angaphezu kwe-100. I-Cloudflare isebenza nge-web traffic kakhulu kune-Twitter, i-Amazon, i-Apple, i-Instagram, i-Bing ne-Wikipedia ehlanganisiwe. I-Cloudflare inikeza uhlelo lwamahhala futhi abantu abaningi bayayisebenzisa esikhundleni sokumisa amaseva abo kahle. Babedayisa ubumfihlo ngokungcono. |
 |
I-Cloudflare ihlala phakathi kwakho nomsuka webserver, esebenza njenge-ejenti yokuhamba umngcele. Awukwazi ukuxhuma endaweni oyikhethile. Uxhuma ku-Cloudflare futhi yonke imininingwane yakho iyathuliswa futhi idluliselwe endibeni. |
 |
Umqondisi we-webserver odabuka wavumela i-ejenti - iCloudflare - ukuthi inqume ukuthi ngubani ongangena "empahleni yewebhu" yabo futhi ichaze "indawo ekhawulelwe". |
 |
Bheka isithombe esifanele. Uzocabanga ukuthi i-Cloudflare block kuphela abantu ababi. Uzocabanga ukuthi iCloudflare ihlala iku-inthanethi (ungaze wehle). Uzocabanga ukuthi ama-bots bots nabakhandi bangakhombisa iwebhusayithi yakho. |
 |
Kodwa-ke lokho akulona iqiniso nakancane. I-Cloudflare ivimba abantu abangenacala ngaphandle kwesizathu. I-Cloudflare ingaya phansi. I-Cloudflare ivimba ama-bots bots. |
 |
Njenganoma iyiphi insizakalo yokusingathwa, iCloudflare ayiphelele. Uzobona lesi sikrini noma ngabe iseva yomsuka isebenza kahle. |
 |
Ngabe ucabanga ukuthi i-Cloudflare ine-100% isikhathi esengeziwe? Awunangqondo ukuthi iCloudflare yehla kangaki. Uma iCloudflare yehla ikhasimende lakho alikwazi ukungena kuwebhusayithi yakho. |
![]]/media/branch/master/image/cloudflareoutage2020.jpg) |
Lokhu kubizwa ngokuthi kubhekiselwa kwi-Great Firewall yaseChina eyenza umsebenzi wokuqhafaza abantu abaningi bangakuboni okuqukethwe kwewebhu (okusho wonke umuntu ezweni lase China nabantu bangaphandle) ngenkathi ngasikhathi sinye labo abangathintekanga ukubona iwebhu ehlukile kakhulu , iwebhu engenakho ukucabanga okufana nesithombe se- "tank man" nomlando wokubhikisha "kweTiananmen Square". |
 |
I-Cloudflare inamandla amakhulu. Ngomqondo othile, balawula lokho okubonwa ngumsebenzisi ekugcineni. Uvinjelwe ukuphequlula iwebhusayithi ngenxa ye-Cloudflare. |
 |
I-Cloudflare ingasetjenziselwa ukucubungula. |
 |
Awukwazi ukubuka iwebhusayithi efakwe amafu uma usebenzisa isiphequluli esincane i-Cloudflare engacabanga ukuthi yi-bot (ngoba ababaningi abantu abayisebenzisayo). |
 |
Awukwazi ukudlulisa lokhu "isiphequluli" esingahlaseli ngaphandle kokunika amandla iJavascript. Lokhu ukuchitha imizuzwana emihlanu (noma ngaphezulu) yempilo yakho ebalulekile. |
 |
I-Cloudflare futhi ivimba ngokuzenzakalelayo amarobhothi/abakhaseli njenge-Google, Yandex, Yacy, kanye namakhasimende e-API. I-Cloudflare iqapha ngentshiseko umphakathi "odlula Cloudflare" umphakathi ngenhloso yokuhlephula i-bots yocwaningo. |
 |
I-Cloudflare ngokufanayo ivimbela abantu abaningi abanokuxhumana okungaxhunyiwe kwe-inthanethi ukufinyelela amawebhusayithi ngemuva kwayo (ngokwesibonelo, bangaba ngemuva kwezendlalelo ezingama-7+ ze-NAT noma babelane nge-IP efanayo, ngokwesibonelo i-Wifi yomphakathi) ngaphandle kokuthi baxazulule ama-picha amaningi amaCAPTCHA. Kwezinye izimo, lokhu kuzothatha imizuzu eyi-10 kuye kwengama-30 ukwanelisa iGoogle. |
 |
Ngonyaka ka-2020 iCloudflare ishintshe isuka kuRecaptcha yakwaGoogle yaya ku-hCaptcha njengoba iGoogle ihlose ukuyokhokhisa ukusetshenziswa kwayo. I-Cloudflare ikutshele ukuthi bayayikhathalela ubumfihlo bakho ("kuyasiza ukulungisa ukukhathazeka kobumfihlo") kepha ngokusobala kungamanga. Imayelana nemali. "I-hCaptcha ivumela amawebhusayithi ukuthi enze imali ukwenza le mfuno ngenkathi ivimba i-bots nezinye izindlela zokuhlukumezeka" - Ngokombono womsebenzisi, lokhu akushintshi kakhulu. Uyaphoqelelwa ukuthi uyixazulule. |
 |
Abantu abaningi nesoftware bavinjwa yi-Cloudflare nsuku zonke. |
 |
I-Cloudflare icasule abantu abaningi emhlabeni jikelele. Bheka uhlu bese ucabanga ukuthi ukwamukela i-Cloudflare kusayithi lakho kulungile kulwazi lomsebenzisi. |
 |
Yini inhloso ye-inthanethi uma ungakwazi ukwenza lokho okufunayo? Abantu abaningi abavakashela iwebhusayithi yakho bazomane babheke amanye amakhasi uma bengakwazi ukulayisha ikhasi le-web. Ungahle ungavimbeli noma yiziphi izivakashi, kepha isibhengezo somlilo esizenzakalelayo se-Cloudflare siqine ngokwanele ukuvimba abantu abaningi. |
![] "/media/branch/master/image/omsappl.jpg) |
Ayikho indlela yokuxazulula i-Captcha ngaphandle kokunika amandla iJavascript kanye namakhukhi. I-Cloudflare iyabasebenzisa ukwenza isignesha sesiphequluli ukukubona. I-Cloudflare idinga ukwazi ubunikazi bakho ukunquma ukuthi ngabe u-eligeble ukuze uqhubeke ukuphequlula isiza. |
 |
Abasebenzisi be-Tor nabasebenzisi be-VPN nabo bayisisulu se-Cloudflare. Zombili lezi zixazululo zisetshenziswa ngabantu abaningi abangakwazi ukukhokhela i-inthanethi engafundile ngenxa yenqubomgomo yezwe/yabo yenhlangano/yenethiwekhi noma abafuna ukwengeza ungqimba olungeziwe ukuvikela ubumfihlo babo. I-Cloudflare ihlasela ngokungenamahloni labo bantu, ibaphoqa ukuthi bacishe isixazululo sommeleli. |
 |
Uma ungazange uzame iTor kuze kube manje, sikukhuthaza ukulanda i-Tor Browser futhi uvakashele amawebhusayithi akho owathandayo. (Iseluleko: Musa ukungena ngemvume kuwebhusayithi yakho yasebhange noma ekhasini lewebhu likahulumeni noma bazomaka i-akhawunti yakho. Sebenzisa i-VPN kulawo mawebhusayithi.) |
 |
Ungahle uthande ukusho ukuthi "iTor ayikho emthethweni! Abasebenzisi be-Tor bayizigebengu! I-Tor is bad!". Cha. Ungase ufunde ngeTor kumabonakude, uthi iTor ingasetshenziswa ukubhekisisa izibhamu ezimnyama nezokuhweba, izidakamizwa noma i-chid porn. Yize isitatimende esingenhla siliqiniso ukuthi ziningi iwebhusayithi zemakethe lapho ungathenga khona izinto ezinjalo, lawo masayithi nawo avela naku-clearnet. |
 |
I-Tor yathuthukiswa Amasosha ase-US, kepha iTor yakhona yathuthukiswa yiphrojekthi yeTor. Kunabantu abaningi kanye nezinhlangano ezisebenzisa iTor kufaka abangane bakho bakusasa. Ngakho-ke, uma usebenzisa iCloudflare kuwebhusayithi yakho uvimba abantu bangempela. Uzolahlekelwa ubungani obunokwenzeka kanye nesivumelwano sebhizinisi. |
 |
Futhi insizakalo yabo ye-DNS, engu-1.1.1.1, ibuye ihlunge abasebenzisi ukuthi bavakashele iwebhusayithi ngokubuyisa ikheli le-IP elingelolabakwa-Cloudflare, IPh yasendaweni efana ne- "127.0.0.x", noma babuyise nje lutho. |
![] "/media/branch/master/image/cferr1016sp.jpg) |
I-Cloudflare DNS ibuye igqekeze isoftware eku-inthanethi kusuka kuhlelo lokusebenza lwe-smartphone iye kumdlalo wekhompyutha ngenxa yempendulo yabo engamanga ye-DNS. I-Cloudflare DNS ayikwazi ukubuza amanye amawebhusayithi asebhange. |
![] "/media/branch/master/image/dnsfailtest.jpg) |
Futhi lapha ungacabanga, "Angisebenzisi iTor noma i-VPN, kungani kufanele nginakekele?" "Ngiyethemba ukumaketha kwe-Cloudflare, kungani kufanele nginakekele" "Iwebhusayithi yami i-https kungani kufanele nginakekele " |
 |
Uma uvakashela iwebhusayithi esebenzisa i-Cloudflare, wabelana ngemininingwane yakho hhayi kumnikazi wewebhusayithi kuphela kepha futhi ne-Cloudflare. Le ndlela isebenza kanjena isebenza kanjani. |
 |
Akunakwenzeka ukuhlaziya ngaphandle kokubeka isiminyaminya i-TLS traffic. |
 |
I-Cloudflare yazi yonke imininingwane yakho efana ne-password eluhlaza. |
 |
I-Cloudbeed ingenzeka noma nini. |
 |
I-Cloudflare's https ayikaze iphele-ukuphela. |
 |
Ngabe uyafuna ngempela ukwabelana ngemininingwane yakho ne-Cloudflare, kanye ne-ejensi eyi-3? |
 |
Iphrofayili yomsebenzisi we-inthanethi "umkhiqizo" uhulumeni nezinkampani ezinkulu ze-tech abafuna ukuzithenga. |
 |
UMnyango Wezokuphepha KwaseMelika uthe: "Uyazi yini ukuthi imininingwane yakho ibaluleke kangakanani? Ngabe ikhona indlela ongasithengisa ngayo leyo datha?" |
 |
I-Cloudflare iphinde inikeze insizakalo ye-MAHHALA ye-VPN ebizwa nge- "Cloudflare Warp". Uma uyisebenzisa, konke ukuxhumana kwakho kwe-smartphone (noma ikhompyutha yakho) kuthunyelwa kumaseva we-Cloudflare. I-Cloudflare iyakwazi ukuthi iyiphi iwebhusayithi oyifundile, yikuphi ukuphawula okuthumele, okhulume nobani, njll. Ngokuzithandela unikela yonke imininingwane yakho ku-Cloudflare. Uma ucabanga ukuthi "Uyahlekisa? I-Cloudflare iphephile." lapho-ke kufanele ufunde ukuthi i-VPN isebenza kanjani. |
 |
I-Cloudflare ithe inkonzo yabo ye-VPN yenza i-inthanethi yakho isheshe. Kodwa i-VPN yenza ukuxhumana kwakho kwe-inthanethi kube kancane kunokuxhuma kwakho okukhona. |
 |
Kungenzeka ukuthi usuvele uyazi ngesehlakalo se-PRISM. Kuliqiniso ukuthi i-AT & T ivumela i-NSA ukuthi ikopishe yonke idatha ye-inthanethi ukuze ihlolwe. |
 |
Ake sithi usebenza kwa-NSA, futhi ufuna yonke imininingwane ye-inthanethi yezakhamizi. Uyazi ukuthi iningi labo lithembela ngokungagxili ku-Cloudflare futhi bayisebenzisa - isango elilodwa elihlanganisiwe - ukubanga uxhumano lweseva yenkampani yabo (SSH/RDP), iwebhusayithi yomuntu siqu, iwebhusayithi yokuxoxa, iwebhusayithi yeforamu, iwebhusayithi yebhange, iwebhusayithi yomshuwalense, injini yokusesha, ilungu eliyimfihlo Iwebhusayithi -yodwa, iwebhusayithi ye-auction, ukuyothenga, iwebhusayithi yevidiyo, iwebhusayithi yeNSFW, newebhusayithi engekho emthethweni. Uyazi futhi ukuthi basebenzisa insizakalo ye-DNS ye-Cloudflare ("1.1.1.1") nensizakalo ye-VPN ("Cloudflare Warp") ye- "Safe! Faster! Better!" isipiliyoni se-inthanethi. Ukuwahlanganisa nekheli le-IP lomsebenzisi, isithonjana seminwe yesiphequluli, amakhukhi kanye ne-RAY-ID kuzosiza ekwakheni iphrofayli le-inthanethi kwelitshe |
 |
Ufuna idatha yabo. Uzokwenzani? |
 |