Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

91–100 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#91

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

> Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying.

I've been noticing this too, and it's why Starlink remains my secondary ISP/bulk transfer connection. If I had to drop one connection, I'd drop Starlink for this reason alone.

There are some sites that I simply can't browse, and it's not Cloudflare errors, either. Lowes, in particular, simply returns error pages for anything but the main landing page on a regular enough basis. Of course, my observed public IP changes so it's not consistent, but it's genuinely annoying.

Re: You don’t want to be on Cloudflare’s naughty list

#92
post #62
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

there are many solid competitors: Amazon, Fastly, Akamai, Imperva to name a few

Re: You don’t want to be on Cloudflare’s naughty list

#93
post #74

Does the author have a fixed IP? If not, figure out how to get a new one and see if the blocking recurs. If it does, the bad activity is probably coming from inside the house -- or CloudFlare has a way to identify you across an IP change.

The author, me, does have a dynamic IP, but it only changes once every two years or so.

Re: You don’t want to be on Cloudflare’s naughty list

#94

Has he tried unplugging the router for 15 minutes and plugging it back in? I jest but I know Comcast and Spectrum will both issue a new IP address in that timeframe.

(Author.) My ISP only rotates IPs when they reboot their central equipment. Not enough to do it on my end.

Re: You don’t want to be on Cloudflare’s naughty list

#95
post #4

If you haven't done anything, someone else might have. Check your router logs for strange devices and activity in your network, also check your machine/s for malware.

(Author here.) Plenty of logging of outgoing connections and DNS. Nothing out of the ordinary.

Re: You don’t want to be on Cloudflare’s naughty list

#96
If your ISP is using CGNAT, sooner or later you'll going to experience this problem. When this happen, I had to use a VPN (I use mullvad) to reduce the amount of cloudflare challenges I get. Pretty funny because usually I got more challenges when using a VPN instead of the other way around. The Privacy Pass extension also seems to help a bit.

Re: You don’t want to be on Cloudflare’s naughty list

#97

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

What archival tool were you using? I've been looking for a replacement for HTTRACK forever.

Re: You don’t want to be on Cloudflare’s naughty list

#98

There is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router. 2. Use 30 character long random password on the router. 3. Disable UPnP. 4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well…

(Author here.) My router isn’t a domestic router. It’s a MikroTik running RouterOS, completely unsupported by the ISP. Outgoing connections and DNS is logged. UPnP is only allowed for the Xbox, PS4, and off-most-of-the-time gaming PC. Nothing out of the ordinary in the logs.

Re: You don’t want to be on Cloudflare’s naughty list

#100
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

> That's not what Bandwidth Alliance is at all. It's about reducing or eliminating egress fees between a cloud provider and Cloudflare. Not sure where the idea that it's about sharing IP reputation data comes from.

It comes from the Cloudflare blog. https://blog.cloudflare.com/cleaning-up-bad-bots/

There’s a support page about it too. https://developers.cloudflare.com/bots/get-started/free/

Post reply on HN