Earlier quoted context omitted.
cloudflare can just allow a fair crawl rate instead of a captcha on first request
The problem is that bad actors can masquerade as a lot of independent clients (The first D in DDoS stands for "distributed"). Figuring out whether a site is under a DDoS attack or getting legitimate requests from many sources is a very hard problem, and can just be worded "telling good actors from bad actors" -- no simple solution works; also, who YOU consider a good actor and who the website owner considers a good a…
We're talking about virtually unknown blogs that get 1 http request from my server's IP, which is not blacklisted anywhere. It's not hard at all , i just think cloudflare's tech s not that good