Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

11–20 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#11
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

To be fair there's a difference between doing it for one site, and doing it for a significant portion of the internet.

Re: You don’t want to be on Cloudflare’s naughty list

#12

The rise of Cloudflare is the first real threat I've seen to ordinary people running webcrawlers.

Tragedy of the commons, unfortunately. There were a bunch of cases where web crawlers and scrapers built competitive services on the back of the services they scraped, some of these ending up in courts [1].

[1] https://www.derstandard.at/story/1389860104020/eu-gerichtsho...

Re: You don’t want to be on Cloudflare’s naughty list

#13
post #9
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

Even if that were the case (which we can debate), him being wrong before does not prevent him from being right now. Being de facto banned from the common internet due to centralization is absolutely scary.

No post body was provided.

Re: You don’t want to be on Cloudflare’s naughty list

#14
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

They do have a threat score

https://developers.cloudflare.com/firewall/recipes/block-ip-...

I was surprised to learn Cloudflare was born out of Project Honeypot, so I am guessing Cloudflare does share data with them:

https://www.projecthoneypot.org/cloudflare_beta.html

Re: You don’t want to be on Cloudflare’s naughty list

#15
post #9
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

Even if that were the case (which we can debate), him being wrong before does not prevent him from being right now. Being de facto banned from the common internet due to centralization is absolutely scary.

I completely agree. I am against Cloudflare and the centralization it implies 100%. I never use it for sites I develop.

I just have no sympathy for Daniel since up until just now he was trying to get everyone to do this.

Re: You don’t want to be on Cloudflare’s naughty list

#16
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

None of those techniques affect normal browsing

Re: You don’t want to be on Cloudflare’s naughty list

#17
Notice that he suspects that some of the problems with podcast rss feeds and assets that can’t be captcha confirmed may be caused by websites who are on the free tier and that don’t have the ability to specify that some subdomains shouldn’t be blocked by captchas.

I have absolutely no sympathy for website owners who are depending on a free service.

Re: You don’t want to be on Cloudflare’s naughty list

#18
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

You block this guy from the internet for a week —- for no apparent reason —- and then you come in here with a nitpick about how another related system works?

Really?

Re: You don’t want to be on Cloudflare’s naughty list

#19
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

I don't know the author or his reputation, but his suggestions that you linked are (in my opinion) standard actions for any dev/server admin getting spammed by their forms... And the suggestions really only impact malicious actors accessing your website from a script... Virtually none of those would be an issue for any browser made in the last 15-20 years, or headless browsers, but would break rudimentary scripts like entry level hackers/spammers might use.

He also specifically called out CAPTCHA as user-hostile.

Re: You don’t want to be on Cloudflare’s naughty list

#20
post #9
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

Even if that were the case (which we can debate), him being wrong before does not prevent him from being right now. Being de facto banned from the common internet due to centralization is absolutely scary.

It's almost as though sufficiently large communications providers should be regulated as utilities.
Post reply on HN