Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

1–10 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#3
Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day.

Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare. It might have received the reputation data from a partner, and it just propagated through the Bandwidth Alliance network.

That's not what Bandwidth Alliance is at all. It's about reducing or eliminating egress fees between a cloud provider and Cloudflare. Not sure where the idea that it's about sharing IP reputation data comes from.

https://www.cloudflare.com/bandwidth-alliance/

So, if Google Search started showing a CAPTCHA that's not Cloudflare.

Re: You don’t want to be on Cloudflare’s naughty list

#6
Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi...

It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutely no sympathy for him.

Re: You don’t want to be on Cloudflare’s naughty list

#7
Is it plausible some ISP shared some IP address that was on Cloudflare's list of suspicious IPs, or that some IoT device on this person's network created a burst of suspicious traffic?

I get that this sucks for the end user, but I wonder how much we should blame Cloudflare vs the wider systemic challenges of managing DDOS protection on the web.

Re: You don’t want to be on Cloudflare’s naughty list

#8
There is a chance you might’ve been hacked.

You would be surprised to see how easy it is to hack domestic routers.

1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router.

2. Use 30 character long random password on the router.

3. Disable UPnP.

4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well, especially IOT ones.

Re: You don’t want to be on Cloudflare’s naughty list

#9
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

Even if that were the case (which we can debate), him being wrong before does not prevent him from being right now. Being de facto banned from the common internet due to centralization is absolutely scary.

Re: You don’t want to be on Cloudflare’s naughty list

#10
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

The techniques described in that article are pretty reasonable and shouldn't significantly impact users - swapping name/email fields' names won't do a thing to you. There's also a difference between "this one website doesn't work for me" and "I've been blocked from half the Internet".
Post reply on HN