Live data from Hacker News

Cloudflare is turning off the internet for me

blog.dijit.sh

301–310 of 335 posts

Re: Cloudflare is turning off the internet for me

#301
post #113
post #99

Earlier quoted context omitted.

I have run a number of small and medium websites (20 users per month up to 2 million). At least 50% of the traffic I see in my logs includes some sql injection or other mass script kiddie bs.

That's fairly black and white. Blocking an unusual user-agent because you "think" it might be malicious is another thing.

It might be a poor business decision, but probably not for the reason most people would think.

An unusual UA is unlikely to move the needle on top line metrics, but it is a distraction and a misuse of resources to play cat and mouse. (Unless your business would be materially harmed by someone scraping your data... in which case, you’re doomed anyway.)

Re: Cloudflare is turning off the internet for me

#302
post #213
post #207

Earlier quoted context omitted.

November 2017 is “severely outdated”? https://www.mozilla.org/en-US/firefox/57.0/releasenotes/

Two full years for an evergreen web browser, which contains probably the largest surface area for software exploits of anything on the machine? I’d argue absolutely yes. As others have echoed, this is probably a huge marker for malicious bots to Cloudflare.

[deleted]

Re: Cloudflare is turning off the internet for me

#303
post #213
post #207

Earlier quoted context omitted.

November 2017 is “severely outdated”? https://www.mozilla.org/en-US/firefox/57.0/releasenotes/

Two full years for an evergreen web browser, which contains probably the largest surface area for software exploits of anything on the machine? I’d argue absolutely yes. As others have echoed, this is probably a huge marker for malicious bots to Cloudflare.

The evergreen browser is a thing, but the idea that everyone can trivially upgrade those browsers is promulgated as true when it's a bit of a myth.

It is sometimes expensive for people to upgrade browsers, called evergreen by developers so they can avoid annoying support expenses for a few percent of people.

I had a phone running a Mozilla browser, which received updates until it didn't any more.

Then the only way to upgrade browser was to purchase a new smartphone.

Unfortunately it was a superb device with no newer replacement, so to upgrade browser I had to downgrade my smartphone for other uses, and pay the cost of an expensive new smartphone despite not really wanting one. But sites saw it as "you are running an old Firefox, you obviously can trivially upgrade".

I still have a perfectly great old Android tablet running an old version of Chrome which cannot be updated. Other than website compatibility, everything on it that it is used for is still working flawlessly. Perfect screen, sound, wifi, memory, battery.

For now, enough sites work on it that I still use it. That can be replaced easily with another tablet, but it is disappointing to have to spend cash and throw away a working product to e-waste, just to replace it with a functionally identical device because of the way the software treadmill works. (It doesn't have to work like that, it's a choice made by developers collectively.)

Re: Cloudflare is turning off the internet for me

#304
post #144

Earlier quoted context omitted.

Support options would be good info to put on that CAPTCHA page instead of having to find that somewhere deep down in an HN thread. Wasn't HN also behind CloudFlare? Looks like that changed, but maybe it will be again in the future.

I do believe that there was a point where HN was using CF, but that hasn't been true for a while if memory serves. As for the support@ not being on those error page; decent feature request. I image the reason they want to avoid that is many of these errors are delivered at request of the site owner or related to the site not working (404s, 503s, IP firewall blocks, etc) so they do not want to funnel people into Cloud…

It's not rocket science, they just don't want to solve the problem.

"many of these errors are delivered at request of the site owner" For those, put the site owner's contact method there. Even a physical mailing address, fine by me, I'll send a letter (something a spammer would not do) if it's important enough to me to do so.

"or related to the site not working (404s, 503s" those pages don't deliver a Google CAPTCHA or don't say "You have been blocked". If they can determine whether a page should have a captcha and/or that text, then that if statement can also include showing contact info.

Re: Cloudflare is turning off the internet for me

#305

Earlier quoted context omitted.

> This isn't a side feature, it's a direct feature that is 100% intentional. So Cloudflare is intentionally breaking the web? Good to know.

No they are doing their job of filtering out garbage from most websites, and it's an option that the site-owner can enable. Is this such a novel thing to look for outliers in web traffic and offer ways to mitigate risks?

Both what I said and what you said can be true simultaneously. I have been increasingly down on Cloudflare because Cloudflare is cutting me out of an increasingly large portion of the web.

Re: Cloudflare is turning off the internet for me

#306
post #213

Earlier quoted context omitted.

Two full years for an evergreen web browser, which contains probably the largest surface area for software exploits of anything on the machine? I’d argue absolutely yes. As others have echoed, this is probably a huge marker for malicious bots to Cloudflare.

The evergreen browser is a thing, but the idea that everyone can trivially upgrade those browsers is promulgated as true when it's a bit of a myth. It is sometimes expensive for people to upgrade browsers, called evergreen by developers so they can avoid annoying support expenses for a few percent of people. I had a phone running a Mozilla browser, which received updates until it didn't any more. Then the only way to…

Yes, plus one of FF's upgrade slipped in the change that ignored your setting on "allow unsigned extensions" which broke a vital UX app I had been maintaining after it got abandoned (pentadactyl: I had gotten so used to clicking links from the keyboard that it was really frustrating when I suddenly couldn't; fortunately there have been similar projects since that carried the torch).

I mean, they said they gave long notice for the change, but I didn't think that a browser that "empowered users" and "gave them control of their machines" would ever do that. I mean, if every change has to be approved by Mozilla, why not just shrink wrap the browser and make me get it from Microsoft at Best Buy?

https://www.youtube.com/watch?v=taGARf8K5J8

Re: Cloudflare is turning off the internet for me

#307
post #304

Earlier quoted context omitted.

I do believe that there was a point where HN was using CF, but that hasn't been true for a while if memory serves. As for the support@ not being on those error page; decent feature request. I image the reason they want to avoid that is many of these errors are delivered at request of the site owner or related to the site not working (404s, 503s, IP firewall blocks, etc) so they do not want to funnel people into Cloud…

It's not rocket science, they just don't want to solve the problem. "many of these errors are delivered at request of the site owner" For those, put the site owner's contact method there. Even a physical mailing address, fine by me, I'll send a letter (something a spammer would not do) if it's important enough to me to do so. "or related to the site not working (404s, 503s" those pages don't deliver a Google CAPTCHA…

I think the truth is somewhere in the middle here. Yes, Cloudflare could do a bit more to predict this, but I don't think it's as trivial as you make it. The routing between you to a site through Cloudflare includes a lot of complex interactions.

The captcha page, sure, maybe. I can't think off the top of my head what would happen on that page that wouldn't be related to Cloudflare/reCaptcha. I yielded that is a decent feature request. But plenty of actual interstitial pages served by Cloudflare aren't necessarily caused by Cloudflare. Like the fact you get a Captcha at all isn't Cloudflares choice most of the time, it's the site owners. And having support@cloudflare.com on that page would 100% cause people to write in saying they don't want to see captchas. That's not the appropriate party to reach out to requesting to stop seeing captchas for a specific site. Now, SOMETIMES it's an automated incident because of your IP, so then you DO want to reach out to Cloudflare.

Same with 500 series errors. Sometimes it's the website not responding, but sometimes it's Cloudflare not interacting properly.

So yeah, I think the truth of the matter is in the middle here. In terms of priorities, I have no doubt this is pretty low on their list. Why would it be any higher when they serve the technical purpose they were created for? The rest of that is QoL with minimal impact on customers compared to many other issues that go wrong with the network that have considerable impact on customers and visitors.

Re: Cloudflare is turning off the internet for me

#308

Earlier quoted context omitted.

I find it very annoying that the authors thought it would be cute to use another full name for MITM.

My wild unfounded guess: they’re trying to make it gender-neutral.

Pretty much. Link to probably the first article I saw using it: https://news.ycombinator.com/item?id=20673409

> It’s the same thing, recognizing that the MITM is neither male, nor human at all.

I don't see why this is important for a technical term. People hear the term as a slug, a group of words, not as discrete ones. No one actually pictures a man or anything else in the middle upon hearing the term. The difference is that the purpose of language is to communicate with others, and everyone understands man in the middle. I look up the "alternative" and get more results for "Henry the Hugglemonster" than I do for network traffic interception.

Re: Cloudflare is turning off the internet for me

#309
post #207

Earlier quoted context omitted.

It's the severely-outdated Firefox version number. Spambots and crawlers sometimes have user-agent strings corresponding to very old browsers, because they were set once when the bot was created and then never updated. On an unrelated site that I run, we get a lot of traffic with user agent strings corresponding to implausibly-old browsers, and it's ~100% bots.

November 2017 is “severely outdated”? https://www.mozilla.org/en-US/firefox/57.0/releasenotes/

Between the huge and complex attack surface and being exposed to a huge number of untrusted websites, running a browser without security updates is pretty risky. So I'd call any unsupported browser "severely outdated".

Long term support (ESR) Firefox releases are supported for about 15 months from release. And even that means using a major version that old, not a point version that old. Firefox 57 wasn't even an ESR, so it went out of support a couple of months after release.

Re: Cloudflare is turning off the internet for me

#310
post #262

Earlier quoted context omitted.

> Part of the reason why everyone is trying to detect bots is because bots will very, very rapidly eat up your bandwidth and CPU time. It is? Thought bot detection was only done during registration etc. to stop them from sending spam etc. to real users. If anything the javascript world we live in helps combat this. You need insane resources on the client just to have a page open. Several orders of magnitude more than…

In that case, an IP or IP block throttling is good enough. Except then there are those pesky CGNATs to handle including Chinese Great Wall. Anyway, high profile spammers will emulate enough of the browser to render any measure based on browser anomaly detection worthless. Including using a headless browser. The only way to defeat them would be too put some quite computationally intensive JS operation... (On par with…

high profile spammers will emulate enough of the browser to render any measure based on browser anomaly detection worthless

Based on actual experience of fighting spammers, that isn't the case. Like a lot of people new to spam fighting you're making assumptions about the adversaries that aren't valid.

Post reply on HN