Live data from Hacker News

Turns out half the internet has a single-point-of-failure called “Cloudflare”

easydns.com

381–390 of 414 posts

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#381

Earlier quoted context omitted.

I had exactly the same issue. I am surprised how neither cloudflare nor google have been sued for making most of the web inaccessible to people with disabilities.

Shouldn't that liability be with the operators of websites that use those captchas if they're required to be blind-accessible? If they get sued, it'll apply pressure up the supply chain.

As sad as it is, there seems to be a CAP situation when it comes to captchas. It's accessibility, security or privacy. Choose two.

You can go the Google route and choose accessibility and security, do massive user tracking, and don't even show CAPTCHAs at all for normal users. HN users probably see a lot, because they use some anti-js or anti-tracking stuff, but normal users don't.

You can go the Cloudflare route, requiring users to solve visual challenges, sacrificing accessibility, but keeping security and privacy.

You can also implement audio CAPTCHAS, which are easy to solve for robots, get accessibility and privacy, but less security.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#382
post #268

Earlier quoted context omitted.

Thank you for sharing your experience. Cloudflare switched to using hCaptcha a couple months ago, I think and I only just noticed that they do not offer an audio-based captcha. However, hCaptcha integrates with Privacy Pass[0], and you can top up your tokens by solving a captcha at [1] and [2]. What you could do (and I realize this is far from ideal), is getting a sighted friend to solve a couple of captchas so you h…

Perhaps it's only a matter of time before volunteers or well meaning organization [1] add captcha solving to bemyeyes-style solutions. [1] https://en.wikipedia.org/wiki/LightHouse_for_the_Blind_and_V...

There's AIRA and it can do it, if you don't care that another person will see what site you're trying to access and if you're willing to go through a super complicated techy procedure to get a free american phone number, which not everyone knows about. Also, not everyone speaks english.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#383

Honest question: I've never really understood the back of the napkin math of how Cloudflare functions economically, which I feel would go a long way towards my understanding of why/how they were able to become such an integral and generally positive part of the Internet. Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw…

Read our S-1, it's all in there. https://www.sec.gov/Archives/edgar/data/1477333/000119312519...

Since you’re here, any response to the top comment re: inaccessibility to disabled persons?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#384
post #346

Earlier quoted context omitted.

I mean, yes, in an ideal world that's true. Yet, here we are. It's not possible for a dev to go back in time to before hcaptcha was created or when CF decided to switch to them to create said ramp, so until it's built, workarounds are the only real thing a community member can offer someone in the short term.

It's not like trying to find the Fountain of Youth or something. It's a company with billions of dollars making it impossible for certain people with disabilities to access the Internet. Let's not pretend that it just has to be this way. A world where half the Internet can't be broken by one company should be the baseline.

Nobody is saying it has to be this way. As I said, in an ideal world, accessibility happens when development happens and is not an afterthought. But we don't live in an ideal world, and it's clear here that it wasn't thought out when they did the switch, or other forces caused the switch to happen without this piece in place.

So, with that in mind, knowing where we currently are, not where we'd like to be in an ideal world, what, exactly, do you want to be done right now by members of the community?

It's not like we can all go in and change the Cloudflare code to stop using hCaptcha. The most we can all do is give alternatives and workarounds while pushing on Cloudflare and hCaptcha to support this scenario. Which is all being done in this thread already.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#385
post #272
post #268

Earlier quoted context omitted.

Thank you for sharing your experience. Cloudflare switched to using hCaptcha a couple months ago, I think and I only just noticed that they do not offer an audio-based captcha. However, hCaptcha integrates with Privacy Pass[0], and you can top up your tokens by solving a captcha at [1] and [2]. What you could do (and I realize this is far from ideal), is getting a sighted friend to solve a couple of captchas so you h…

This is such an out of touch dev response. The problem is hcaptcha, the solution is stop using hcaptcha. Not placate and evade with work arounds you wouldn't even suggest to non blind people. Also this ask a friend solution is like telling someone in a wheelchair to ask a friend to help them up those steps instead of just installing a ramp. You don't get to take over half the internet and just ignore social responsib…

Yes, there are limitations, and I'm sure hcaptcha will get there, but until then, a helpful person on the internet gave a helpful workaround.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#386
post #235

Earlier quoted context omitted.

Nazis also shop at Macy's and drink at Starbucks. Cloudflare was purely acting out of market based fear, there wasn't a hint of moral impetus. Literally he said: "I don't want people saying they won't work with us" - which is giving into the mob. Where is the ACLU on this? We were all screaming for Net Neutrality just a couple years ago. It's up to communities and governments to make decisions on content, it would ac…

> Cloudflare was purely acting out of market based fear, there wasn't a hint of moral impetus. IIRC, the reason DailyStormer pissed off CloudFlare is because the users claimed (lied) about CloudFlare was somehow participating / sponsoring the site/activities. Sports teams have non-disparagement clauses; I don't see this as much different. The only thing I'm not clear about is if it was just a rando user on DS that sa…

Citation for the CloudFlare / DailyStormer incident:

> The tipping point for us making this decision was that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology.

This is more about enforcing ToS and maintaining reputation than "an internet infrastructure company cancels DailyStormer because of their ideology".

The complicating factor is that CloudFlare was not the only internet infra company to drop them. DS were rapidly dropped or denied accounts from other companies during this news cycle, so they were effectively kept offline because none of the large infra companies they approached wanted to deal with the issue in a "free speech over all other concerns" kind of way.

[1] https://blog.cloudflare.com/why-we-terminated-daily-stormer/

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#387

Earlier quoted context omitted.

> Cloudflare was purely acting out of market based fear, there wasn't a hint of moral impetus. IIRC, the reason DailyStormer pissed off CloudFlare is because the users claimed (lied) about CloudFlare was somehow participating / sponsoring the site/activities. Sports teams have non-disparagement clauses; I don't see this as much different. The only thing I'm not clear about is if it was just a rando user on DS that sa…

> Society didn't walk away from CloudFlare (eg. "vote with your feet/wallet") and Congress didn't choose to create any laws. Neither of those things mean you did the right thing. It’s really easy to pick on a widely unpopular minority group and not get laws passed against you or lose a noticeable amount of customers.

> Neither of those things mean you did the right thing.

I find it hard to believe the right thing would involve either CloudFlare tolerating libel (my interpretation) about them by a customer or that we should always tolerate an unmitigated amount of free speech (at least the obviously political/religious speech originally envisioned) no matter the cost to {business, society, decency, morals, etc}.

What is "the right thing" to you in this situation?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#388

Cloudflare is horrible for blind people. Screen readers, the programs that use synthesized speech to tell us what's on the screen, cannot read images. Good captchas usually have audio equivalents (which come with their own set of problems), but this one doesn't. If you're blind and flagged by Cloudflare for some reason, you're cut off from accessing half the internet, potentially critical banking/governmental/medical…

I have no affiliation with CloudFlare at all, but my interactions with them have all been kind, professional, and courteous.

I might recommend reaching out to the CEO, Matthew Prince, with a succinct explanation of your problem and I would be surprised if that by itself does not kick off some serious positive action!

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#389

Earlier quoted context omitted.

Shouldn't that liability be with the operators of websites that use those captchas if they're required to be blind-accessible? If they get sued, it'll apply pressure up the supply chain.

As sad as it is, there seems to be a CAP situation when it comes to captchas. It's accessibility, security or privacy. Choose two. You can go the Google route and choose accessibility and security, do massive user tracking, and don't even show CAPTCHAs at all for normal users. HN users probably see a lot, because they use some anti-js or anti-tracking stuff, but normal users don't. You can go the Cloudflare route, re…

> You can go the Google route and choose accessibility and security

This is not the case. After just a few captchas the audio challenge will be locked off no matter what browser you use.

> and don't even show CAPTCHAs at all for normal users

You see them in firefox from the start as well as on chrome after around the 2nd or 3rd captcha, this is with the default settings + ublock origin on both browsers.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#390

Earlier quoted context omitted.

Audio captchas are considered broken completely (search for various papers over the past decade, including one from CMU), so it has limited usefulness only in a very narrow context in practice. I suspect this is a harbinger of things to come - as we close the gap on passing the Turing test, captchas are likely to get less effective, and we will need to transition to a very different solution for bot detection.

or, just let the bots be. often it's easier to just use a website as api instead of using some broken xml nightmare that requires knowledge of the database tables. If the concern is rate limiting then just rate limit the website. And if you don't like people operating websites with bots then I don't know, maybe stop making websites.

Easy proxying means rate limiting doesn’t really help all that much to defeat bots. And then if you do something like blocking or severely restricting something like Tor (the world's largest open proxy and hence, primary abusive traffic source; something which it would make sense to throw extra bot walls in front of), privacy and accessibility advocates jump down your throat.

This is a no-win situation. I’m not convinced it’s possible to have ones cake and eat it too, here. Someone upthread said “security, privacy, accessibility, pick any two”, and I have yet to see any evidence of a third option.

Post reply on HN