Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

141–150 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#141

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

How does having a personal ID tied to browsing activity help with spam? Are spammers not real people with IDs?

Spammers typically implement bots to carry out tasks. I mean, technically at some point a spammer is a real person, but when you're automating tasks and using bots, it's not at the same scale.

Re: You don’t want to be on Cloudflare’s naughty list

#142

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

How does having a personal ID tied to browsing activity help with spam? Are spammers not real people with IDs?

Of course, but the theory is it's restricting 1 real person to 1 account, versus 1 spammer creating 1,000 accounts via automation.

And once your spammer has been identified then that's them banned/removed, unable to sign up again.

Re: You don’t want to be on Cloudflare’s naughty list

#143
post #62
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

Tor made Tor unusable on non-onion sites. I feed a netfilters table with the list of exit node IPs that Tor publishes (https://check.torproject.org/torbulkexitlist) as a standard part of server deployment, and it's the single most effective way to reduce form and login abuse on hosted sites. I like the idea of Tor, but there's no denying that it's a huge source of nuisances.

Re: You don’t want to be on Cloudflare’s naughty list

#144
post #119

Earlier quoted context omitted.

I need to look into that. Thanks for pointing it out. I had totally forgotten about that post. Edit: team tells me this idea never got off the ground. Did talk with some potential partners (which did NOT include Google) but didn’t happen. So if Google was throwing CAPTCHAs it wasn’t because of our IP reputation.

Dear John. What am I — as a normal human being/end-user — supposed to do in this situation? People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? The challenge page doesn’t help the end user understand why this is happening to them. It’s okay if you only see it for two seconds. But the page stays on screen for over a minute. When this happens for…

> It’s okay if you only see it for two seconds. But the page stays on screen for over a minute.

That doesn't sound right. You shouldn't see a loading page for over a minute. If you're open to providing more details privately I'd love to help troubleshoot. You can drop me an email at amartinetti @ cloudflare.

Re: You don’t want to be on Cloudflare’s naughty list

#145
post #64

Earlier quoted context omitted.

IP bans by modern services like CF can't be solved that easily in my experience.

Clearly CF has a crystal ball /s. Once the IP address I don't own is released and assigned to some other router how do you think CF determines the new IP address for the individual/home? Unless this person is running the CF Dynamic DNS service which gives CF the IP address, I'm not sure CF would have any reasonable validation techniques to determine who is what given the size of residential networks.

Cookie on their validation page? Browser fingerprint hopping IPs in the same block?

Re: You don’t want to be on Cloudflare’s naughty list

#146

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

> Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. I'm not understanding the generalized sentiment here. How would, for example, a retailer benefit from this strategy? How does it protect their bottom line? I can see how a particular kind of "facilitated user economy," such as games, gambling and promotional companies could benefit, but it doesn't seem th…

> I'm not understanding the generalized sentiment here. How would, for example, a retailer benefit from this strategy? How does it protect their bottom line?

The amount of automated and apparently-manual attempted credit card fraud (and exploit attempts, for that matter) any halfway-prominent site with a CC form is subjected to is hard to appreciate if you've never seen it. It's a whole lot. They aren't even necessarily trying to buy what you have, but to validate that their stolen cards work. And they're quite busy. If too much of that gets through—really, any more than a very tiny amount of it gets through—you're gonna have an extremely bad time.

Various CC service providers like Stripe do provide tools to try to block those attempts, but defense in depth is usually a very good idea, including fairly aggressive firewall-level blocking.

Re: You don’t want to be on Cloudflare’s naughty list

#147
post #80

Earlier quoted context omitted.

I'm curious if you've had experience with their enterprise package? I can understand people's gripes about things on the free/cheap packages, where Cloudflare makes decisions for you, sometimes ones you don't like. But as an enterprise customer, I've never found it to be anything short of fantastic - I can tailor it to behave exactly how I want, and not interfere with my customers.

Your response seems to ignore the very article being discussed. Or are you suggesting that if you're having trouble visiting sites because of Cloudflare, you should become an enterprise customer? (slightly sarcastic, but not completely)

My response is simply trying to understand where you are coming from. You've mentioned there are numerous superior options and you would never recommend it.

I'm wondering (genuinely!) if you are speaking as an enterprise customer or a free plan, or what.... both for the sake of meaningful discussion and potentially learning about even better options for my own work.

As to the article - I fully believe the responsibility lies with site owners to pick and choose how they want to serve their sites. Nobody is forcing them to use Cloudflare on a free plan, or to ignore any analytics it provides and make sure it is serving their customers correctly. Cloudflare is one piece of a delivery solution, and only works as well as you configure it. If your decision for your app is "I'll just use the free plan, and let Cloudflare decide everything for me" then you get what you pay for.

If Cloudflare is getting in their way, they can go somewhere else.

Re: You don’t want to be on Cloudflare’s naughty list

#148

If you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will neve…

I get these a lot and I'm from EU. But it's "seasonal".

Re: You don’t want to be on Cloudflare’s naughty list

#149
post #89
post #47

Earlier quoted context omitted.

Quoted post unavailable.

It makes a very broad claim which makes it sound like an extortion racket but doesn't have anything to back it up. I would bet that if it included some evidence it would fare much better. For example, they have a ton of large organizations which are customers. The very first question the average reader is going to have is whether it's really the case that these sites are predominantly attacked by booter services whic…

[deleted]

Re: You don’t want to be on Cloudflare’s naughty list

#150
post #89
post #47

Earlier quoted context omitted.

Quoted post unavailable.

It makes a very broad claim which makes it sound like an extortion racket but doesn't have anything to back it up. I would bet that if it included some evidence it would fare much better. For example, they have a ton of large organizations which are customers. The very first question the average reader is going to have is whether it's really the case that these sites are predominantly attacked by booter services whic…

The claim was discussed in this post: https://news.ycombinator.com/item?id=32709329

Basically DDOS booters use Cloudflare to protect their websites from competitors, since Cloudflare is one of the best. The same people Cloudflare is protecting (and claims to do so on an ethical neutrality basis) is furthering the need for Cloudflare to exist.

Post reply on HN