Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

181–190 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#181

If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your fa…

> And the most infuriating part, you get CF marketing messages right in your face while your browser is calculating hashcash (I guess?)... At this point I can recognize every single one of them: something about bots making up 40% of all internet traffic, Yeah, there's something amazingly aggravating about CF telling you how much traffic is bots while showing that they can't distinguish you from a bot .

CloudFlare are creating a new devision for advertising to bots. They have projected that in the near future, bots will be 90% of spending, so the bot demographic is the most important to target, marketingwise.

The fact that humans are seeing the traffic meant for bots is an unfortunate side-effect.

I personally welcome our future bot overlords (not only because being unwelcome might be unhealthy for me — why would I publicly disagree with an overlord or not want to be their friend?).

Re: You don’t want to be on Cloudflare’s naughty list

#182
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Just 10 minutes ago, I got the following email from a housemate (I'm not home at the moment): > The past few weeks I've been getting tons of redirects to verify my humanity before being allowed to view a webpage. Usually I just have to click the box that says human, not find all the ladders in a photo. SoFi is doing it every single time I log in. Petco, too, along with others who are more sporadic. This is happening…

> I had already started pulling some infra back from Cloudflare after their last appearance in the tech news cycle.

What triggered your reaction? That they terminated a customer with zero notice?

Re: You don’t want to be on Cloudflare’s naughty list

#183

Earlier quoted context omitted.

How does having a personal ID tied to browsing activity help with spam? Are spammers not real people with IDs?

Of course, but the theory is it's restricting 1 real person to 1 account, versus 1 spammer creating 1,000 accounts via automation. And once your spammer has been identified then that's them banned/removed, unable to sign up again.

What's to stop them from using fake IDs

Re: You don’t want to be on Cloudflare’s naughty list

#184

If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your fa…

Cloudflare has mixed up the definitions of "bot" and "abuse". Tor users may or may not be bots, but as long as they don't abuse (spamming or DoS), they ought to be treated the same.

Re: You don’t want to be on Cloudflare’s naughty list

#186
Reputation systems should be based on /abuse/, not on automation. I also ended up on the naughty list for running an archival scraping program. Trying to preserve part of the Internet is apparently against the rules. It's really a shame because my code honors rate limits, doesn't spam, and is completely docile.

Re: You don’t want to be on Cloudflare’s naughty list

#187

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

The other not-so-great approach is to act like a normal user. This stuff doesn't tend to happen to the average Joe who browses the WWW. It's when you're doing unusual (albeit harmless) things.

Re: You don’t want to be on Cloudflare’s naughty list

#188
post #98

There is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router. 2. Use 30 character long random password on the router. 3. Disable UPnP. 4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well…

(Author here.) My router isn’t a domestic router. It’s a MikroTik running RouterOS, completely unsupported by the ISP. Outgoing connections and DNS is logged. UPnP is only allowed for the Xbox, PS4, and off-most-of-the-time gaming PC. Nothing out of the ordinary in the logs.

> It’s a MikroTik running RouterOS

It's almost certainly compromised.

Re: You don’t want to be on Cloudflare’s naughty list

#189
post #155

Earlier quoted context omitted.

So what happens when your ID gets hacked and reused for fraudulent activity? Would you have to submit a dispute with the internet credit agencies? Maybe join a class action suit against the entity that leaked your ID so that they're forced to give you a year of free internet identity monitoring?

The same that happens now when somebody stills your identity and ruins your credit history. You'll have to live in a bureaucratic hell for the next couple of years. And yes, as a compensation, you'll get the $6.99 worth of services from the guilty party. If you win the class action suit, that is.

Exactly. Why on earth would we want to replicate such a terrible system online?

We should be reforming our current credit agency system, not empowering it with a new mandate of judging somebody's social or political creditworthiness.

Re: You don’t want to be on Cloudflare’s naughty list

#190
post #109
post #87

Earlier quoted context omitted.

Disabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it

It’s absolutely required for most multiplayer games. Many need random ports and some even refuse to work if UPnP is blocked even if you manually open a port for them.

I've never had UPnP enabled and I don't have any problems doing online gaming / flight sim / video chatting / etc.
Post reply on HN