Please Cloudflare, I'm a paying customer and have some IPv6 only users that are very frustrated every time they see a Cloudflare challenge page. Your provider, HCaptcha still do not support IPv6. I have to use workarounds like an alternative domain without CF and this is very frustrating.
A public letter to CloudFlare to fix their snoopy vendor
101–110 of 117 posts
Re: A public letter to CloudFlare to fix their snoopy vendor
#102It’s good to see others experience the downside of centralising the internet. Until reading this, it seemed like everyone blindly loves cloudflare.
Re: A public letter to CloudFlare to fix their snoopy vendor
#103Earlier quoted context omitted.
This is quite common in countries with lots of people and not enough IPs. ipv6+nat64
Why don't they use IPv4 with CGNAT in addition to IPv6? That's what the US providers do.
Re: A public letter to CloudFlare to fix their snoopy vendor
#104Re: A public letter to CloudFlare to fix their snoopy vendor
#105Earlier quoted context omitted.
You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.
Fortunately, if you can't afford IPv4 then no one else can afford it either, which means the incentive to adopt IPv6 is extremely strong and thus you no longer need IPv4.
Re: A public letter to CloudFlare to fix their snoopy vendor
#106Re: A public letter to CloudFlare to fix their snoopy vendor
#107Earlier quoted context omitted.
You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.
Fortunately, if you can't afford IPv4 then no one else can afford it either, which means the incentive to adopt IPv6 is extremely strong and thus you no longer need IPv4.
Re: A public letter to CloudFlare to fix their snoopy vendor
#108> Enabling SSL/TLS between Cloudflare and the origin site is a customer decision. When this protection is not enabled, as is the case here, an ISP can manipulate the requests before they reach Cloudflare. If this behaviour is not desired, the customer must change the settings for the site in the Cloudflare dashboard.
The request in question gets MITMed after it reaches Cloudflare edge servers, the connection between browser and the edge server happens over SSL
Re: A public letter to CloudFlare to fix their snoopy vendor
#109Re: A public letter to CloudFlare to fix their snoopy vendor
#110Earlier quoted context omitted.
In this case, it is not a random party in the CloudFlare--GitHub connection (say a network operator in UK). The snooping intermediary (Airtel) in this scenario is one that has a commercial relationship with CloudFlare and powers CloudFlare's network. CloudFlare has been aware of this issue for years, but it hasn't done anything to get its vendor to fix their network.
Isn't the censorship applied by Airtel, Jio, etc, because of local laws? https://en.wikipedia.org/wiki/Internet_censorship_in_India I don't see how Cloudflare or any other provider can make Airtel "fix" the snooping when Airtel is forced by law to block those sites. This seems to be a policy/government problem, not a Cloudflare or Airtel problem.
Airtel isn’t forced to block these sites. It is blocking these because of a mis-configuration somewhere.