Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

161–170 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#161
Not saying that this is the case here, but this may be possible due to having a bad tab open. Especially over cellular. Haven’t looked into it with any depth, but I’ve had correlations on a much shorter timeframe. Suddenly, CloudFlare and/or Google start questioning my humanity, so I close all tabs. Then okay. Sloppy hypothesis with no evidence: JS gone haywire

Re: You don’t want to be on Cloudflare’s naughty list

#162

If you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will neve…

Maybe your mobile ISPs dont do enough to stop malicious/spam traffic. That's not Cloudflare's fault

Re: You don’t want to be on Cloudflare’s naughty list

#163
post #87

Earlier quoted context omitted.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

What's your solution for the grandmother who just wants to make a zoom call to her grandson? Have her log into her router portal and setup a static ip for her laptop and then port forwarding routes for zoom?

STUN servers? Also, while I (not GP) do think UPnP is dangerous, I also think it's only something you disable if you know you can live without.

Re: You don’t want to be on Cloudflare’s naughty list

#164
post #119

Earlier quoted context omitted.

Dear John. What am I — as a normal human being/end-user — supposed to do in this situation? People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? The challenge page doesn’t help the end user understand why this is happening to them. It’s okay if you only see it for two seconds. But the page stays on screen for over a minute. When this happens for…

Once upon a time Matthew made us set the IP reputation of every Cloudflare office to bad so that we experienced the worst case scenario. Helped a lot. I don’t understand why you saw one minute block screens. That’s not right. Should be seconds. I’m talking with the team about your other points.

I haven't been getting challenges that last that long, but I have noticed that the redesigned "security check" challenge pages with the spinner do seem much slower than the old design with the loader that was made of 3 orange dots.

Re: You don’t want to be on Cloudflare’s naughty list

#165
post #95
post #4

If you haven't done anything, someone else might have. Check your router logs for strange devices and activity in your network, also check your machine/s for malware.

(Author here.) Plenty of logging of outgoing connections and DNS. Nothing out of the ordinary.

Is your IP address listed on https://www.abuseipdb.com/ or any other spam blocklists?

Re: You don’t want to be on Cloudflare’s naughty list

#166
post #87

Earlier quoted context omitted.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

What's your solution for the grandmother who just wants to make a zoom call to her grandson? Have her log into her router portal and setup a static ip for her laptop and then port forwarding routes for zoom?

I don't think zoom uses UPnP. If it did, that would cause problems on corporate networks that typically have UPnP disabled.

Re: You don’t want to be on Cloudflare’s naughty list

#168

Earlier quoted context omitted.

there are multiple other large CDNs out there... its a lot more like 5 market leaders tbh

But how many of them: 1) refuse to take responsibility for content they host by claiming they don't host 2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination 3) make the abuse reporting process intentionally difficult and time-consuming 4) want to aggregate all the DNS data they can by making a deal with Firefox to turn on DNS-over-https by default…

tbh I think one of the very few positives of having so many sites going through a few CDNs is that you can make it impossible to block a protocol or site without significant collateral damage, which can be a good thing, things like Tor's meek bridge rely on that.

Re: You don’t want to be on Cloudflare’s naughty list

#169
post #89

Earlier quoted context omitted.

It makes a very broad claim which makes it sound like an extortion racket but doesn't have anything to back it up. I would bet that if it included some evidence it would fare much better. For example, they have a ton of large organizations which are customers. The very first question the average reader is going to have is whether it's really the case that these sites are predominantly attacked by booter services whic…

The claim was discussed in this post: https://news.ycombinator.com/item?id=32709329 Basically DDOS booters use Cloudflare to protect their websites from competitors, since Cloudflare is one of the best. The same people Cloudflare is protecting (and claims to do so on an ethical neutrality basis) is furthering the need for Cloudflare to exist.

Note that I’m not saying whether or not this is true, only that a comment which links to something like that will generally fare better than one which begs the question.

Re: You don’t want to be on Cloudflare’s naughty list

#170
post #119

Earlier quoted context omitted.

Dear John. What am I — as a normal human being/end-user — supposed to do in this situation? People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? The challenge page doesn’t help the end user understand why this is happening to them. It’s okay if you only see it for two seconds. But the page stays on screen for over a minute. When this happens for…

Once upon a time Matthew made us set the IP reputation of every Cloudflare office to bad so that we experienced the worst case scenario. Helped a lot. I don’t understand why you saw one minute block screens. That’s not right. Should be seconds. I’m talking with the team about your other points.

The main problem of course, and it isn’t limited to Cloudflare and I won’t pretend to have the solution, is that if you are caught in this kind of web, you have no recourse but go public and hope the spotlight lands on you. For every problem we see in an upvoted post there’s tons that nobody sees.
Post reply on HN