Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

151–160 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#151

Earlier quoted context omitted.

How does having a personal ID tied to browsing activity help with spam? Are spammers not real people with IDs?

Spammers typically implement bots to carry out tasks. I mean, technically at some point a spammer is a real person, but when you're automating tasks and using bots, it's not at the same scale.

So what happens when your ID gets hacked and reused for fraudulent activity?

Would you have to submit a dispute with the internet credit agencies? Maybe join a class action suit against the entity that leaked your ID so that they're forced to give you a year of free internet identity monitoring?

Re: You don’t want to be on Cloudflare’s naughty list

#152
So this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a major part of the Internet? And you can do absolutely nothing about it?

I know they haven't done anything like that yet. But the technical capability is there, and we all know how short is the distance between technical capability and doing it, when the appropriate pressure is applied. So I wonder, how long before activists start demanding for CF to boot people from the internet, and how long before CF caves in to that...

Re: You don’t want to be on Cloudflare’s naughty list

#153
post #38
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Just 10 minutes ago, I got the following email from a housemate (I'm not home at the moment):

> The past few weeks I've been getting tons of redirects to verify my humanity before being allowed to view a webpage. Usually I just have to click the box that says human, not find all the ladders in a photo. SoFi is doing it every single time I log in. Petco, too, along with others who are more sporadic. This is happening with and without uBlock on. Same browser I've always used. ...

SoFi and Petco both use Cloudflare. I do exactly zero web crawling / scraping / abusive anything from my home connection.

I'm noticing a recent increase in volume of complaints about Cloudflare's human verification filter. I'm starting to wonder if they touched a dial.

I had already started pulling some infra back from Cloudflare after their last appearance in the tech news cycle. Now I've got an additional reason to continue doing that.

Re: You don’t want to be on Cloudflare’s naughty list

#154

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

They are already testing out digital IDs. Now link that to the social score... and make the browsers and the sites exchange these data on the background, and make frontend services providers refuse connections from non-supporting browsers as "bots"...

Re: You don’t want to be on Cloudflare’s naughty list

#155

Earlier quoted context omitted.

Spammers typically implement bots to carry out tasks. I mean, technically at some point a spammer is a real person, but when you're automating tasks and using bots, it's not at the same scale.

So what happens when your ID gets hacked and reused for fraudulent activity? Would you have to submit a dispute with the internet credit agencies? Maybe join a class action suit against the entity that leaked your ID so that they're forced to give you a year of free internet identity monitoring?

The same that happens now when somebody stills your identity and ruins your credit history. You'll have to live in a bureaucratic hell for the next couple of years. And yes, as a compensation, you'll get the $6.99 worth of services from the guilty party. If you win the class action suit, that is.

Re: You don’t want to be on Cloudflare’s naughty list

#157

Earlier quoted context omitted.

Spammers typically implement bots to carry out tasks. I mean, technically at some point a spammer is a real person, but when you're automating tasks and using bots, it's not at the same scale.

So what happens when your ID gets hacked and reused for fraudulent activity? Would you have to submit a dispute with the internet credit agencies? Maybe join a class action suit against the entity that leaked your ID so that they're forced to give you a year of free internet identity monitoring?

Nobody said it wouldn't suck. The only question is whether it sucks less than the alternatives.

Re: You don’t want to be on Cloudflare’s naughty list

#158

Earlier quoted context omitted.

To be frank, that's exactly the problem with NAT-PMP et al. assuming that there's no router bugs: the ability to forward ports has been abused to set up bot relays on hacked IoT devices. This is why I predict that even in IPv6 era we would still have to rely on a TURN-equivalent.

That's exactly the problem with NAT-PMP? So what's your alternative for peer to peer connections? Static routing that the common end user can't figure out? Re-centralize connections? UPnP is necessary.

I'm simply pointing the problem, a real-world an realistic problem, and you're acting like it's a non-issue. Point me a CGNATted network which has enable port forwarding. Does it break a lot of things? Oh, absolutely. Did the carriers still not activated it? Yes. Automatic port forwarding is only beautiful when you know how would your device react. It's ugly when you're a network administrator who don't control all devices.

There is no "perfect" solution here because the real world is a messy place with devices that you cannot personally vouch for.

Re: You don’t want to be on Cloudflare’s naughty list

#160
post #62

Earlier quoted context omitted.

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

Tor made Tor unusable on non-onion sites. I feed a netfilters table with the list of exit node IPs that Tor publishes ( https://check.torproject.org/torbulkexitlist ) as a standard part of server deployment, and it's the single most effective way to reduce form and login abuse on hosted sites. I like the idea of Tor, but there's no denying that it's a huge source of nuisances.

I live in a country with censored internet. What you are doing is harmful. I can only hope whatever you provide is irrelevant enough.
Post reply on HN