Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

81–90 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#81
post #60

Earlier quoted context omitted.

I believe that might happen, but then I also believe it's the ISP's responsibility to ensure that its IP addresses are kept clean

For sure, the point I'm making is that there's a multi party transaction here, with systemic complexity. Makes it hard to pin responsibility on just Cloudflare (or just the user or just the ISP, etc).

Cloudflare is the one blocking a user based on things that aren't their fault; I'm happy to blame them.

Re: You don’t want to be on Cloudflare’s naughty list

#82

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

I think this is true. It also reminds me of one possible purpose of regulation and government, given the majority will usually be happy to throw any sort of minority under the bus for the "greater good."

This also reminds me of the anxiety of Google deciding to just ban my account for some reason. They can't be bothered to commit resources to making sure mistakes can be resolved. They don't care to lose a fleetingly small percentage of customers.

Not sure I have an answer. Just a thought.

Re: You don’t want to be on Cloudflare’s naughty list

#83

If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your fa…

> And the most infuriating part, you get CF marketing messages right in your face while your browser is calculating hashcash (I guess?)... At this point I can recognize every single one of them: something about bots making up 40% of all internet traffic,

Yeah, there's something amazingly aggravating about CF telling you how much traffic is bots while showing that they can't distinguish you from a bot.

Re: You don’t want to be on Cloudflare’s naughty list

#84
Imagine all the people in countries deemed less desirable by Cloudflare that go through this all the time. Cloudflare, whether it's their stated goal or not, is re-stratifying and re-centralizing the Internet because of their desire to be a monopoly, and we'll all suffer as a result.

Re: You don’t want to be on Cloudflare’s naughty list

#85

Earlier quoted context omitted.

For sure, the point I'm making is that there's a multi party transaction here, with systemic complexity. Makes it hard to pin responsibility on just Cloudflare (or just the user or just the ISP, etc).

Cloudflare is the one blocking a user based on things that aren't their fault; I'm happy to blame them.

That's fine, but you are ignoring the broader picture if you do. You've correctly identified a detail, but haven't placed that detail in context.

Re: You don’t want to be on Cloudflare’s naughty list

#86
post #79
post #30

Earlier quoted context omitted.

FYI you're responding to the cloudflare CTO

It’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.

It's even more naive to assume Cloudflare's CTO would tell lies that can be trivially shown to be untrue.

Re: You don’t want to be on Cloudflare’s naughty list

#87
post #70

There is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router. 2. Use 30 character long random password on the router. 3. Disable UPnP. 4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well…

Why would you disable UPnP? You're gonna break most collaboration tools/video games/etc.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools

UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

Re: You don’t want to be on Cloudflare’s naughty list

#88
post #70

There is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router. 2. Use 30 character long random password on the router. 3. Disable UPnP. 4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well…

Why would you disable UPnP? You're gonna break most collaboration tools/video games/etc.

To be frank, that's exactly the problem with NAT-PMP et al. assuming that there's no router bugs: the ability to forward ports has been abused to set up bot relays on hacked IoT devices. This is why I predict that even in IPv6 era we would still have to rely on a TURN-equivalent.

Re: You don’t want to be on Cloudflare’s naughty list

#89
post #47

Earlier quoted context omitted.

Quoted post unavailable.

Quoted post unavailable.

It makes a very broad claim which makes it sound like an extortion racket but doesn't have anything to back it up. I would bet that if it included some evidence it would fare much better. For example, they have a ton of large organizations which are customers. The very first question the average reader is going to have is whether it's really the case that these sites are predominantly attacked by booter services which use Cloudflare for hosting? That seems unlikely and as general rule here the broader the claim the more people are going to expect you to show that you did your homework first.

Re: You don’t want to be on Cloudflare’s naughty list

#90

Earlier quoted context omitted.

Cloudflare is the one blocking a user based on things that aren't their fault; I'm happy to blame them.

That's fine, but you are ignoring the broader picture if you do. You've correctly identified a detail, but haven't placed that detail in context.

I'm not ignoring the context, I'm saying that it's irrelevant. Cloudflare made the choice to block real people based on factors outside of their control, and then to market that product as a panacea; they don't get to pass the buck, doubly so when they don't expose enough information to let other people fix the things they broke.
Post reply on HN