Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

41–50 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#41
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

You block this guy from the internet for a week —- for no apparent reason —- and then you come in here with a nitpick about how another related system works? Really?

No post body was provided.

Re: You don’t want to be on Cloudflare’s naughty list

#42

If you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will neve…

I am from Europe and I notice if I use some non residential ip. The captchas are extremely annoying especially when trying to access a site I have already been logged into with 2fa. Who is protected in this case.

Re: You don’t want to be on Cloudflare’s naughty list

#43
post #34
post #26

Earlier quoted context omitted.

Burn the witch! Lets read through that page for a second though: Drop support for obsolete HTTP versions Doesn't seem like that's going to cause much issue for any legitimate client from the past 10-20 years. He only recommends blocking HTTP 0.9/1.0, which fair enough Append a #hash to the form’s action URL Hah. Clever man. I don't see how this is going to stop any legitimate user from loading your website or submitt…

All that stuff is easily defeated by automated browsers anyway (i.e. selenium)

Yes, but those automated browsers are much more expensive to operate than simple HTTP clients pretending to be browsers.

It's an arms race/defense-in-depth situation. If someone truly wants to automate your site in a targeted fashion, and it's profitable for them to do so, you'll have to invest a lot more in stopping it (and decide how much of it is worth stopping).

Re: You don’t want to be on Cloudflare’s naughty list

#45
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

Can you acknowledge the main point of the article? What should someone do if they find themselves misclassified by Cloudflare's systems?

(not the parent commenter)

That person should start with the assumption they haven't been misclassified and eliminate the possibility that a device on their network is compromised.

Re: You don’t want to be on Cloudflare’s naughty list

#46
Yeah, this just continues to reinforce my opinion Cloudflare. It's not something I would ever recommend, and there are numerous other superior options out there. I see Cloudflare failing frequently enough that if it were something I was responsible for, I'd be embarrassed at the very least.

Re: You don’t want to be on Cloudflare’s naughty list

#47

Earlier quoted context omitted.

You block this guy from the internet for a week —- for no apparent reason —- and then you come in here with a nitpick about how another related system works? Really?

Quoted post unavailable.

No post body was provided.

Re: You don’t want to be on Cloudflare’s naughty list

#48
There’s a real lack of education I’ve seen in developers for small projects who go directly to cloudflare for anything and everything. They don’t understand that they are immediately losing a large chunk of their user base who is either from the third world or is privacy literate. Devs working on projects that are targeting those groups need to understand the tradeoffs from using cloudflare.

Re: You don’t want to be on Cloudflare’s naughty list

#49
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

The tone of this reply is a bit shit from a PR perspective.

How about _also_ pointing to a knowledge base article for how an end user could go about working out what network activity from their IP might be flagging Cloudflare’s systems?

Re: You don’t want to be on Cloudflare’s naughty list

#50
If an ordinary user would have to deal with google/CF bs everyday as I do, they'd burn their computer.

PS Proud user of Firefox + resistFingerprinting=true PPS Ain't nothing better than CF guard page constantly-reloading on 20% of sites if you open some url :( No, fella, you first have to open the root '/' page so that guard page finally can either pass me through or show the cloudflare captcha. Ugh. Progress, they say.

Post reply on HN