| There's a natural contradiction between security and privacy. For security, an actor needs to be tested and marked as secure, or else tested again before every interaction. For privacy, an actor must not be marked, lest observers could correlate several interactions and make conclusions undesirable for the actor. It does not make the infinite loop produced by CLoudflare any more reasonable though. |
CloudFlare claims to support Privacy Pass, which is supposed to use a zero-knowledge scheme to solve for this for Tor users.
Unforunately, the integration has been broken for a very long time and bug reports aren't tended to.
https://blog.cloudflare.com/cloudflare-supports-privacy-pass...
https://privacypass.github.io/
https://github.com/privacypass/challenge-bypass-extension/is...