Live data from Hacker News

Cloudflare is turning off the internet for me

blog.dijit.sh

291–300 of 335 posts

Re: Cloudflare is turning off the internet for me

#291

Earlier quoted context omitted.

I think you're confusing what you wish was true with what is actually true. For instance, here was a post from a few weeks ago about how one annoyed user was able to take down a Mastodon instance until the admin gave up and put it behind CF: https://news.ycombinator.com/item?id=21719793 . Bear in mind, if you're running a Mastodon instance, you're probably well-aware of the downsides of centralization and would only…

> I think you're confusing what you wish was true with what is actually true. And you are cherry-picking poorly sourced anecdotes to better suite your position. A VPS with 100Mbps virtual adapter physically can't withstand DoS from single attacker with fiber connection (or equivalent of it). This does not have much to do with anatomy of DoS attacks, just simple math. Cloudflare subsidizes their free users by giving a…

Huh?

"All Cloudflare plans offer unlimited and unmetered mitigation of distributed denial-of-service (DDoS) attacks, regardless of the size of the attack, at no extra cost."

https://www.cloudflare.com/ddos/

Do you know of an example of an attacker "easily demolishing" Cloudflare's free DDoS protection for a website with a few hundred dollars worth of botnet?

Re: Cloudflare is turning off the internet for me

#292

Earlier quoted context omitted.

> automatically increase the prices of requests by a fraction of a cent to compensate Great concept. CPU, bandwidth, electricity, it's all just energy. And to a significant degree, money is just energy stored. I generate energy with my own work, store it in the form of money, and then transfer that energy to someone else, maybe to heat my home or cook me a meal. Before money, I had to barter for those things. Maybe c…

Isn't the reason we are freed from barter in daily life is because the government is intimately involved in the financial/banking system, and regulates it and issues money and so on? Maybe we continue to struggle with the internet because it started out unregulated and has never really transcended that because people insist on thinking freedom is best for commerce without appreciating the nuances.

There are alternatives to that. For all of the hype and vaporware of the cryptocurrency movement, the idea of digital-native programmable internet money is a powerful one. I’m personally excited by the idea of involving currency at the protocol level and having it interact naturally over tcp/ip and http. There is an alternative to ads if we can make it work.

Re: Cloudflare is turning off the internet for me

#293
post #220

Earlier quoted context omitted.

At least on iOS Safari there's this bug (feels like it's always been there, maybe content blocker related?) where sometimes a search simply gets eaten. The browser somehow thinks you went from nowhere straight to the page you're on, even though you went past a Google results page. I assume it's somehow redirect-related and that's why these sites tend to trigger it.

I’m thinking of two situations: - you tapped the “Siri suggestion” result which completely skips the SERP. I hate that “back” doesn’t bring you back to what I typed in the search/URL bar - I regularly visit The Verge, open a story and then the back button doesn’t take me to the homepage but to the page before it. I blame their crappy JavaScript but maybe we’re experiencing the same thing.

Nope. It's as if that happens, though going past a regular Google search results page, which is dropped (hence along with the search itself) from history.

Re: Cloudflare is turning off the internet for me

#294
post #17

The problem presented by services like ReCaptcha and Cloudflare is a tough nut to crack. They're silently embedded in a huge portion of modern websites, and the average user will never even know about them. But it seems to be way too easy for them to blanket-ban or serve an absurd amount of captchas to powerusers, linux gurus, privacy geeks, or anyone with the wrong combination of browser+addons. And the failures (as…

ReCaptcha works because any captcha works.

https://kevv.net/you-probably-dont-need-recaptcha/

https://blog.codinghorror.com/captcha-effectiveness/

Re: Cloudflare is turning off the internet for me

#295
post #212

Earlier quoted context omitted.

> malicious actors and abuse It's hard to consider simply viewing content to be malicious or abusive, no matter how automated.

I used to work for a data-scraping firm and very often we would accidentally knock many web sites offline when we pointed our crawlers at them. I'd love to agree with you, but the crawler problem is 100x worse today than it was a decade ago

This would be much better solved with IP-based rate limits. And if IP-based doesn't work, then you're dealing with a DDOS, and it doesn't sound like this case was DDOS protection.

Re: Cloudflare is turning off the internet for me

#296
post #17

The problem presented by services like ReCaptcha and Cloudflare is a tough nut to crack. They're silently embedded in a huge portion of modern websites, and the average user will never even know about them. But it seems to be way too easy for them to blanket-ban or serve an absurd amount of captchas to powerusers, linux gurus, privacy geeks, or anyone with the wrong combination of browser+addons. And the failures (as…

> Two steps backwards in every conceivable way. The giants gain more invisible power and powerusers suffer decreased productivity/privacy. Not going to happen. I agree with the first two sentences, but disagree with the third. I believe that this state is actually the intended end goal. Previously, for many years, I browsed the web with Javascript disabled. At the time, this had very little impact on my browsing expe…

I have javascript disabled by default, most of internet works fine.

Re: Cloudflare is turning off the internet for me

#297
post #95

Earlier quoted context omitted.

Yes, and Cloudflare provides a fairly reasonable solution to this problem. Or, at least, it seems reasonable in the eyes of someone like me who never had to work on something that attempts to solve this problem, so there might be some serious caveats, but I am not aware of those. If someone with more domain knowledge can chime in on this, that would be appreciated as well.

Caveats: Won't protect against scrapers that execute JS (like ones based on headless browsers -- This includes some modern search engines!) Won't protect against anyone who takes some time to read their 80-some lines of minified "obfuscated"* JavaScript and hook up a simple text transform to their crawler of choice. So basically it'll only protect against truly trivial scrapers, but not against anyone who wants to ge…

What you're missing is that this is effort by the botter. Headless costs more, writing another step in the scraping process and de-obfuscating seems reasonable but again: That is effort by the botter.

If a botter really wants to it's easy to get emails scraped. But they don't care. The demographic of people having obfuscated emails on their page via Cloudflare (since you probably don't know every obfuscation solution out there you target the big ones) is also the demographic with a good spam filter (or just using Gmail).

Botters don't care about everything small. If you're bigger you do get better ones who probably specifically target you and then you have more problems then just having your email stolen.

The 99% solution from Cloudflare is complex enough to not get botted by shitty wannabe hackers.

Re: Cloudflare is turning off the internet for me

#298
post #224

Earlier quoted context omitted.

I know the SPLC has paid out in defamation suits rather than allow the cases to go to trial. Pretty good sign they knew they'd lose as it has severely hurt their reputation. Here's a particularly egregious case where a UN affiliated group was labeled an extremist hate group and the SPLC wouldn't relent even after evidence was presented: https://www.newsweek.com/splc-nawaz-million-apologizes-98187...

How to you go from SPLC backing down after '"human rights advocates affiliated with the United Nations" praised Nawaz's work.' to Quilliam being UN affiliated, and SPLC not backing down? At least read your own link, please. I get what you're saying about the settlement but they could've just paid out and not gone to such lengths explaining how they felt they'd gotten things wrong.

Could they have, or was an apology a part of the settlement? We'll never know - but since it got to the point of a settlement, I'm betting the apology was a requirement of avoiding court.

Re: Cloudflare is turning off the internet for me

#299

Earlier quoted context omitted.

Bad actors who are bad at being bad actors, which is actually the bulk of bad actors. It's maddening, but it's true. I've seen tale of people having to modify resource auto-generators that created URLs with hexadecimal identifiers in them because the sequence "ad" in a URL would trip ad-blocking browser plugins. You might ask yourself "how many ad companies worth their salt have 'ad' in the URL path?" and the answer…

There's somebody who can build a custom browser but can't figure out how to change the user agent string?

They're called "script kiddies" and the trick is: they don't build the browser, they download a kit someone else built that has a user agent in it and use it for whatever purpose they intend to.

I went to school at a place that had a policy of soft-blocking network access for any machine that a portscan detected had TCP or UDP 12345 opened, because Back Orifice defaults to that port and people who built trojan horses to allow remote access didn't change the default. It caught a reasonable number of owned machines every year.

Don't overestimate criminals; if most were good at being criminals, they could be successful in society without having to break the law. ;)

Re: Cloudflare is turning off the internet for me

#300
post #99

Earlier quoted context omitted.

I have run a number of small and medium websites (20 users per month up to 2 million). At least 50% of the traffic I see in my logs includes some sql injection or other mass script kiddie bs.

Why care about such traffic? Blocking it seems like a pointless exercise.

I was responding to OPs question. Iirc, we discussed it and never implemented any blocking.
Post reply on HN