Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

131–140 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#131
post #97

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

What archival tool were you using? I've been looking for a replacement for HTTRACK forever.

A combination of shotscraper and metascraper; really more web previews than archives. And in a single thread, to different hostnames, maybe one every 10 seconds? Honestly surprised Akamai or anything even noticed. I fake my user agent now, lesson learned.

Re: You don’t want to be on Cloudflare’s naughty list

#132
post #94

Earlier quoted context omitted.

(Author.) My ISP only rotates IPs when they reboot their central equipment. Not enough to do it on my end.

With some ISPs, they will issue a new IP if you change the router's (WAN) MAC address. Might be worth a try next time (crossing fingers you don't need it).

This is what I've always seen too. I've never seen a residential ISP that allocates static DHCP addresses, they typically allocate in days which is why many people can maintain a leased address for months on end. Once you go offline though, all bets are off. Every ISP can determine if the subscriber is disconnected and if they are, they're going to reallocate your address. To your point, once the MAC address is changed, they have to issue a new IP address because using the logic posted above, the other address is allocated to a different MAC.

Re: You don’t want to be on Cloudflare’s naughty list

#133

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

> Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online.

I'm not understanding the generalized sentiment here. How would, for example, a retailer benefit from this strategy? How does it protect their bottom line?

I can see how a particular kind of "facilitated user economy," such as games, gambling and promotional companies could benefit, but it doesn't seem that broadly applicable to what most people would consider a "mainstream" business.

> so we can lay off the IP-based reputation stuff and the geo-blocking: it's tying some form of personal ID to your browsing activity

And a new market for identity theft is born.

Also, as someone who serves content and geo blocks it, that's not up to me, that's up to the owner of the content or whoever happens to be licensing it for them. So, even if you sent me a picture of your government ID, it changes nothing.

Re: You don’t want to be on Cloudflare’s naughty list

#134

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

Cloudflare said they're working on this- https://blog.cloudflare.com/eliminating-captchas-on-iphones-...

Re: You don’t want to be on Cloudflare’s naughty list

#135
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

You're looking at it all wrong. From Cloudflare's point of view, this kind of blocking is a feature . Anyone doing legitimate web crawling, or offering alternative web services such as Starlink, now needs Cloudflare's permission. Essentially, for a broad class of web-based businesses, they have made themselves gatekeepers. I'm sure they'll find a profitable use for this position. Charging outright would look bad, but…

I'm familiar with that perspective, and biased towards it... Cloudflare is certainly in such a position, but they are a relatively young company (for their size and reach) and I've seen good things come from them.

I'd guess the intent is unlikely to be anti-competitive or monopolistic, just over-aggressive. However regardless of intent their position does cause an absence of market forces to put pressure on fixing such issues - Similar to how it's become acceptable to have downtime when it's on AWS, because "everyone is affected".

Re: You don’t want to be on Cloudflare’s naughty list

#136
post #70

Earlier quoted context omitted.

Why would you disable UPnP? You're gonna break most collaboration tools/video games/etc.

To be frank, that's exactly the problem with NAT-PMP et al. assuming that there's no router bugs: the ability to forward ports has been abused to set up bot relays on hacked IoT devices. This is why I predict that even in IPv6 era we would still have to rely on a TURN-equivalent.

That's exactly the problem with NAT-PMP?

So what's your alternative for peer to peer connections? Static routing that the common end user can't figure out? Re-centralize connections?

UPnP is necessary.

Re: You don’t want to be on Cloudflare’s naughty list

#137

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

How does having a personal ID tied to browsing activity help with spam? Are spammers not real people with IDs?

Re: You don’t want to be on Cloudflare’s naughty list

#138
post #87
post #70

Earlier quoted context omitted.

Why would you disable UPnP? You're gonna break most collaboration tools/video games/etc.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

What's your solution for the grandmother who just wants to make a zoom call to her grandson? Have her log into her router portal and setup a static ip for her laptop and then port forwarding routes for zoom?

Re: You don’t want to be on Cloudflare’s naughty list

#139
post #86
post #79

Earlier quoted context omitted.

It’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.

It's even more naive to assume Cloudflare's CTO would tell lies that can be trivially shown to be untrue.

How would you show they are untrue? Ask? :-D

Re: You don’t want to be on Cloudflare’s naughty list

#140

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

> Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. I'm not understanding the generalized sentiment here. How would, for example, a retailer benefit from this strategy? How does it protect their bottom line? I can see how a particular kind of "facilitated user economy," such as games, gambling and promotional companies could benefit, but it doesn't seem th…

> a retailer benefit from this strategy? How does it protect their bottom line?

A couple of examples I can think of is blocking bots from scraping their site for pricing and details and from resellers from buying up all of the stock (see sneakers, electronics, etc). The last example doesn't directly impact their bottom line, but it will make customers go elsewhere.

Post reply on HN