Viewing profile — slothsarecool
slothsarecool
HN member- Joined
- Wed, Aug 31, 2022, 1:36 PM UTC
- HN karma
- 57
- Public activity
- 21 items
- HN profile
- View on Hacker News ↗
About slothsarecool
No profile information was provided.
Recent public activity
-
comment
Comment #47105073
Their WAF isn't there yet, the moment it can build the expressions you can build with CF (and allows you to have as much visibility into the traffic as CF does), then it might be a…
-
comment
Comment #47105061
L7 DDoS protection and global routing + CDN, there is not a single paygo provider that can handle the capacity CF can, especially not at this price range (mitigated attacks distrib…
-
comment
Comment #47104809
There are no alternatives, and those alternatives that did exist back in the day, had to shut down due to either going out of business or not being able to keep a paygo model. Not …
-
comment
Comment #43386954
Those are different products. BIC prevents requests such as empty UAs or corrupted HTTP requests to pass CF without a challenge. Turnstile/Challenges per se don't rely on the UA at…
-
comment
Comment #43019938
I think it's pretty clear you have never worked on fraud protections or bot detections, otherwise you'd understand the struggles of supporting many environments with a single solut…
-
comment
Comment #42956829
I think the issue is that Cloudflare tends to be a toggle-and-forget, it's very easy to use and it works for most people. The problem with this setup, is that it sacrifices on both…
-
comment
Comment #42955932
You can create a new browser, there are plenty of modern new browsers that aren't considered major and work just fine because they run on top of recent releases of chromium. There …
-
comment
Comment #42955634
> * If your visitors are using an up-to-date version of a major browser * > * they will receive the challenge correctly. * I'm unsure what part of this isn't clear, major browsers,…
-
comment
Comment #42955234
Cloudflare is actually pretty upfront about which browsers they support. You can find the whole list right in their developer docs. This isn't some secret they're trying to hide fr…
-
comment
Comment #36376079
BunnyCDN DDoS protection is made to protect their servers and the customers, it's not meant to serve your service as a shield against attacks. This is a common misconception with m…
-
comment
Comment #34220463
Banking sites and anybody who suffers from any sort of attack, whether it's scraping, DDoS, bots, bruteforcing... Does everybody get those attacks? Probably not, however, Cloudflar…
-
comment
Comment #33999001
Things are significantly better now, I can't comment on how good the aid is if you are under attack since we always had a team ready to handle DDoS, however, their follow-up has al…
-
comment
Comment #33998891
We get attacked several times a month, we rely on Cloudflare & Corero to mitigate attacks. Cloudflare handles HTTP/s attacks and Corero handles network level attacks. Both require …
-
comment
Comment #33990309
We report each DDoS attack our company receives to a special department our police has, your country likely has something similar and I guess it doesn't hurt reaching out to them. …
-
comment
Comment #33769652
This is what hCaptcha is currently doing, they are switching the image category every 24-72 hours. How useful is it? Not very. Modern ML models such as mobilenet, resnet or yolo re…
-
comment
Comment #33769434
However, that's not a solution but a patch. Google accounts give you a good score and tend to deliver easy captchas while dealing with Recaptcha; however, for this reason, google a…
-
comment
Comment #33768932
Ever since ML has reached the "general public", developing models against hearing or vision based CAPTCHAS has become trivial. Sure, you have to emulate or simulate the client JS c…
-
comment
Comment #33746567
You do not get attacked from Cloudflare with TCP attacks. Somebody is spoofing the IP header and make it seem like Cloudflare is DDoSing you. The only way for somebody to DDoS from…
-
comment
Comment #33002962
Adding raw TCP is a big deal, it skips all the existing security stack that focuses on HTTP/S. There is Spectrum and Transit to provide network level protection but... only a few c…
-
comment
Comment #32707149
Just adding some light to the escalations; there were bomb and shoot threats over the last few days. The userbase on the site upped the tone of their "jokes"/threats after the last…
-
comment
Comment #32661918
I understand the point CF is trying to make; however, I still have a hard time trying to ignore many of the content that is being protected by CF. With that being said; I have seen…