Live data from Hacker News

Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

news.ycombinator.com

101–110 of 199 posts

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#101
post #97

Earlier quoted context omitted.

You keep framing this as "how do I make sure I don't get into this situation again," but with the attention this is getting (#6 on HN) and just how bad the issue is (both functionally and PR-wise)... Cloudflare should really do a public post-mortem here. It sounds like it's their fault.

This happens all the time. Not sure you can expect a post-mortem on this one specific case

"This" being people being locked out of their critical infrastructure through no fault of their own and with no recourse but to hope for the HN effect?

Yeah I love the future we all live in... :|

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#102

> Your account violated our terms of service specifically fraud. Honestly, this phrase is raising phishing alarm bells in my head, though xxdesmus said it's `likely legitimate`. The punctuation and capitalization is lacking, and really makes it sound... off. Edit: I originally thought this was an email, but upon reading the post again it sounds like a response to OP's support ticket. There's a lot less effort involve…

Yeah, the lack of comma, and the phrase "specifically fraud", are extremely alarming to me. I understand that not all developers are native English speakers, but far more scammers are non-natives than devs are; not to mention, there are likely checks in companies like this to proofread any text before it goes "live".

> there are likely checks in companies like this to proofread any text before it goes "live".

… yeah … there's really not.

I've both found such errors (there are a few that exist in Azure's stuff, for example. One I know exactly how to trigger: attempt to create a SP for an app in the same tenant as you, but while lacking permission to do so. The error is both grammatically malformed as well as illogical. Azure knows about it … but AFAICT, they don't have the internal processes to fix it.)

I've also caught a few of these before the train left the station as a gratuitous code reviewer. There are definitely some that have slipped by.

At a previous employ, my SO found one in ~10 minutes of playing with our product… and rightly gave me some light-hearted jabs about it.

I'd want to see the whole email. Whether it weighs more towards phish or error would depend on the surrounding context, and whether SPF/DKIM/DMARC pass. (The OP says the did (but it was a later comment), so…)

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#103

Earlier quoted context omitted.

> often just a simple mistake More often than not it's not a mistake. Very simply put, fighting abuse is very asymmetrical and a lot of the approaches just even the playfield. They will make you put in more effort for them to put in effort. Unfortunate, but the only way it's sustainable.

> Unfortunate, but the only way it's sustainable. Businesses throughout history have been sustainable without needing to ban people at random with AI. This AI hell is a new phenomenon in the past 10 years and it's purely driven by cost-cutting.

Businesses throughout history haven't had to deal with anonymous global customer bases that could be automated.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#104

Earlier quoted context omitted.

> often just a simple mistake More often than not it's not a mistake. Very simply put, fighting abuse is very asymmetrical and a lot of the approaches just even the playfield. They will make you put in more effort for them to put in effort. Unfortunate, but the only way it's sustainable.

> Unfortunate, but the only way it's sustainable. Businesses throughout history have been sustainable without needing to ban people at random with AI. This AI hell is a new phenomenon in the past 10 years and it's purely driven by cost-cutting.

> Businesses throughout history have been sustainable without needing to ban people at random with AI.

When the cost of abuse lowers, so must the cost of defense. So of course cost-cutting has to happen. Otherwise it's going to be a financial DoS.

All that is though only if you want services to have free tiers. If you're willing to pay for everything then sure, it becomes easier. I'm actually quite certain one will encounter much less "AI" when stuff is actually being paid for.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#105
post #40
post #38

Update: Just received an email from CF. -------------- Hello, With regard to your inquiry, we have restored the domain names in your account to active status. Please allow for normal propagation. You will need to re-add mnf90.com to your account in order to manage it. Our apologies for any inconvenience this may have caused. Kind Regards, Cloudflare Trust & Safety ------------ Not much info lol, but guess its fixed n…

Update 2: ----------------------------- Helo, To clarify the issue, this account was identified in a recent fraud review, however it appears to have been a false positive. We have left a note in this account for future reference. Kind Regards, Cloudflare Trust & Safety

》it appears to have been a false positive

That's a scary answer. Guess I'll put only mirror/backup domains behind CF in the future.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#106
Wow, that's terrible. Thank you for the heads up. Just transferred my domains back to namecheap.

While we're all here venting about Cloudflare, is anyone else frustrated about how they lure you in to their CDN product with "free" bandwidth, but then lock behind so many useful features arbitrarily behind what I can only imagine is a thousands of dollars per month enterprise plan? Just look at their cache-purging page for an example of this, everything other than basic purge by URL is enterprise only: https://developers.cloudflare.com/cache/how-to/purge-cache/

These days Cloudflare is literally my last choice for a CDN for my new projects, and I try to warn against others considering using it. My new go-to is bunny.net, who charges a reasonable usage-based fee for bandwidth and gives you unfettered access to all the features they've built. Though I'd even reach for Cloudfront with their expensive bandwidth costs these days, because at least their pricing is transparent and scales smoothly with usage, and they don't arbitrarily cut you off from useful features.

Even their bandwidth might not really be "free", since I've heard if you actually use any significant amount, the sales people will come knocking on your door to coerce you to get on the same enterprise plan or have your site taken down.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#107

Earlier quoted context omitted.

I'd imagine both fall under "trust and safety". And let's not water it down - targeted harassment is not "being unpleasant".

Both might be considered morally wrong, but only one seems illegal.

I assure you, targeted persistent harassment is in fact not legal in most countries. With caveats for public figures and failing enforcement.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#108
post #63

Earlier quoted context omitted.

> I can’t believe how lightheartedly you are taking this. What is the alternative though? The web has turned in to this massive mess where most of us don't have the ability to do anything without having to rely on some ban happy mega corp. Even something that was built to be decentralized like email has turned in to a (sort of) centralized architecture, try hosting your own email, everything goes in to spam. Host a w…

> What is the alternative though? > The web has turned in to this massive mess where most of us don't have the ability to do anything without having to rely on some ban happy mega corp. That's absolutely not true. You're drinking the HN/startup koolaid if you think everything should be on CloudFlare/AWS/Google/Microsoft/etc and there's no other way. Obviously VCs would love for you to think that but it doesn't make i…

Agree your point. But I think Microsoft doesn’t belong to this group. I never read an auto ban story from Microsoft. And my experience is that you can talk to a human customer service from Microsoft.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#109
post #42

Earlier quoted context omitted.

That's really quite worrying. You'd have been screwed without HN, but not everyone has that recourse. How many other domains have been affected by "false positives" announced with a "we've banned you and we aren't telling you why; now fuck off" type email.

Very worrying. One of the reasons I'd choose a non-huge company like Cloudflare would be I'm less likely to encounter one of these "our automation banned you, we won't tell you why, fuck off" episodes. Looks like more and more companies are cargo-culting this horrible practice. Waiting for my utility company to turn off my heat: "Your house is fraud. We won't tell you how we know. Fuck off and freeze."

Cloudflare is by no means a "non-huge company" - don't they route/cdn like 1/4 of the entire internet?

going with cloudflare is a choice towards centralization.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#110

Earlier quoted context omitted.

Yeah, the lack of comma, and the phrase "specifically fraud", are extremely alarming to me. I understand that not all developers are native English speakers, but far more scammers are non-natives than devs are; not to mention, there are likely checks in companies like this to proofread any text before it goes "live".

>to proofread any text before it goes "live". Not on the internet I use. Even the old school newspapers are failing basic grammar things that anyone calling themself an editor would catch. Mainly, because they are not getting edited at all. Reports get entered into a CMS, a publish button is pressed, viola, first to publish! Yay!!! Only, in the rush, basic grade school grammar is non-existent and makes my brain slow…

> viola

Oh, the irony...

Post reply on HN