Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

101–110 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#101

Imagine all the people in countries deemed less desirable by Cloudflare that go through this all the time. Cloudflare, whether it's their stated goal or not, is re-stratifying and re-centralizing the Internet because of their desire to be a monopoly, and we'll all suffer as a result.

there are multiple other large CDNs out there... its a lot more like 5 market leaders tbh

Re: You don’t want to be on Cloudflare’s naughty list

#102
post #45

Earlier quoted context omitted.

Can you acknowledge the main point of the article? What should someone do if they find themselves misclassified by Cloudflare's systems?

(not the parent commenter) That person should start with the assumption they haven't been misclassified and eliminate the possibility that a device on their network is compromised.

(Author here.) That’s missing from the article. But I have logs of the network. There’s nothing out of the ordinary. “I don’t know what I did wrong,” as I started the article, means “I’ve checked logs and such and there’s no indication of anything wrong on my end.”

Re: You don’t want to be on Cloudflare’s naughty list

#103
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

[deleted]

Re: You don’t want to be on Cloudflare’s naughty list

#104
post #26
post #6

Daniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutel…

Burn the witch! Lets read through that page for a second though: Drop support for obsolete HTTP versions Doesn't seem like that's going to cause much issue for any legitimate client from the past 10-20 years. He only recommends blocking HTTP 0.9/1.0, which fair enough Append a #hash to the form’s action URL Hah. Clever man. I don't see how this is going to stop any legitimate user from loading your website or submitt…

>> Verify the Host and Origin request headers > > Yes. You should be doing that.

(Author here.) If I remember correctly, his browser of choice predates the Origin header.

Re: You don’t want to be on Cloudflare’s naughty list

#105
post #62

Earlier quoted context omitted.

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

there are many solid competitors: Amazon, Fastly, Akamai, Imperva to name a few

Bunny

Re: You don’t want to be on Cloudflare’s naughty list

#106
post #100
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

> That's not what Bandwidth Alliance is at all. It's about reducing or eliminating egress fees between a cloud provider and Cloudflare. Not sure where the idea that it's about sharing IP reputation data comes from. It comes from the Cloudflare blog. https://blog.cloudflare.com/cleaning-up-bad-bots/ There’s a support page about it too. https://developers.cloudflare.com/bots/get-started/free/

I need to look into that. Thanks for pointing it out. I had totally forgotten about that post.

Edit: team tells me this idea never got off the ground. Did talk with some potential partners (which did NOT include Google) but didn’t happen. So if Google was throwing CAPTCHAs it wasn’t because of our IP reputation.

Re: You don’t want to be on Cloudflare’s naughty list

#107
post #26

Earlier quoted context omitted.

Burn the witch! Lets read through that page for a second though: Drop support for obsolete HTTP versions Doesn't seem like that's going to cause much issue for any legitimate client from the past 10-20 years. He only recommends blocking HTTP 0.9/1.0, which fair enough Append a #hash to the form’s action URL Hah. Clever man. I don't see how this is going to stop any legitimate user from loading your website or submitt…

> This one's a little user hostile to folks who use assistive devices like screen readers. As long as you're using a or aria-label attribute, that shouldn't be an issue.

(Author here.) I am. There’s plenty of accessibility labels in place. It’s literally just the name attributes. No user ever sees this, whether they’re using accessive technologies or not. It only confused bots that assumes that the field named email is for the email address.

Re: You don’t want to be on Cloudflare’s naughty list

#108
post #80

Yeah, this just continues to reinforce my opinion Cloudflare. It's not something I would ever recommend, and there are numerous other superior options out there. I see Cloudflare failing frequently enough that if it were something I was responsible for, I'd be embarrassed at the very least.

I'm curious if you've had experience with their enterprise package? I can understand people's gripes about things on the free/cheap packages, where Cloudflare makes decisions for you, sometimes ones you don't like. But as an enterprise customer, I've never found it to be anything short of fantastic - I can tailor it to behave exactly how I want, and not interfere with my customers.

Your response seems to ignore the very article being discussed.

Or are you suggesting that if you're having trouble visiting sites because of Cloudflare, you should become an enterprise customer? (slightly sarcastic, but not completely)

Re: You don’t want to be on Cloudflare’s naughty list

#109
post #87
post #70

Earlier quoted context omitted.

Why would you disable UPnP? You're gonna break most collaboration tools/video games/etc.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

It’s absolutely required for most multiplayer games. Many need random ports and some even refuse to work if UPnP is blocked even if you manually open a port for them.

Re: You don’t want to be on Cloudflare’s naughty list

#110

Earlier quoted context omitted.

You block this guy from the internet for a week —- for no apparent reason —- and then you come in here with a nitpick about how another related system works? Really?

The point is that Cloudflare does not beam IP reputation data to Google. If Google and CF are blocking this IP separately, what's the chance there's some malicious device or hacked IoT device on the network, participating in DDOS attacks or unauthorized vulnerability scanning of random websites?

According to another comment, it's a wrong point: https://blog.cloudflare.com/cleaning-up-bad-bots/

> Once enabled, when we detect a bad bot, we will do three things: (1) we’re going to disincentivize the bot maker economically by tarpitting them, including requiring them to solve a computationally intensive challenge that will require more of their bot’s CPU; (2) for Bandwidth Alliance partners, we’re going to hand the IP of the bot to the partner and get the bot kicked offline; and (3) we’re going to plant trees to make up for the bot’s carbon cost.

Post reply on HN