If you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will neve…
Maybe your mobile ISPs dont do enough to stop malicious/spam traffic. That's not Cloudflare's fault
You don’t want to be on Cloudflare’s naughty list
221–230 of 354 posts
Re: You don’t want to be on Cloudflare’s naughty list
#222Earlier quoted context omitted.
Tor made Tor unusable on non-onion sites. I feed a netfilters table with the list of exit node IPs that Tor publishes ( https://check.torproject.org/torbulkexitlist ) as a standard part of server deployment, and it's the single most effective way to reduce form and login abuse on hosted sites. I like the idea of Tor, but there's no denying that it's a huge source of nuisances.
How often is the list of exit nodes updated?
Re: You don’t want to be on Cloudflare’s naughty list
#223Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…
Re: You don’t want to be on Cloudflare’s naughty list
#224Earlier quoted context omitted.
Bingo
So i've turned cookies off and switched to my ipad to browse the internet for the evening, they have no fingerprint, and no cookie... now what?
I had to use a VPN (a whole new IP) and clean chrome install to bypass one those "IP blocks" which was combined with fingerprinting.
Re: You don’t want to be on Cloudflare’s naughty list
#225If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your fa…
Re: You don’t want to be on Cloudflare’s naughty list
#226Some VPN exit addresses have obviously been flagged as "bad" by Cloudflare and I get challenged with CAPTCHAs from some countries. It's an interesting experience, but luckily my VPN provider has enough exits that I can usually switch to one that has better reputation with Cloudflare.
Obviously, none of this is helping the internet be a better place from my point of view. I get that it's part of the ongoing fight against bots and spam, but it always feels so arbitrary. IP addresses are interchangeable, folks - they say nothing about the nature of the request. Or rather, for a large majority they do, but there's us minority that don't obey those rules and resent getting caught up in it.
Re: You don’t want to be on Cloudflare’s naughty list
#227Earlier quoted context omitted.
Burn the witch! Lets read through that page for a second though: Drop support for obsolete HTTP versions Doesn't seem like that's going to cause much issue for any legitimate client from the past 10-20 years. He only recommends blocking HTTP 0.9/1.0, which fair enough Append a #hash to the form’s action URL Hah. Clever man. I don't see how this is going to stop any legitimate user from loading your website or submitt…
>> Verify the Host and Origin request headers > > Yes. You should be doing that. (Author here.) If I remember correctly, his browser of choice predates the Origin header.
In general though the whole tone of parent of “I am owed access to someone else’s computer system on my and my terms alone” just doesn’t jive with me. It’s also not remotely comparable to Cloudflare’s approach of sitting in the middle snd then appropriating end-user compute resources without their consent to fuel their business.
Re: You don’t want to be on Cloudflare’s naughty list
#228Why would anyone need to know what they did "wrong"?^1
That would mean they could correct their choice of software and usage patterns to conform with what Cloudflare believes is "right".
IMO, anti-"bot" (anti-automation measures) can effectively identify
(a) computer users with something of value to offer to website operators (usually, that means personal data/metadata at no cost), as distinct from
(b) computer users who
(i) do not send personal data to and/or generate metadata for website operators that indicates the user has something of value, and/or
(ii) are not using the software preferred by website operators (usually, that means software that requires interactive use that generates behavioural metadata for website operators).^2
The measures taken by Cloudflare presume any automation by computer users is "wrong".^3 Meanwhile, websites and CDNs are free to use automation however they wish.Of course automation can be used in a way that poses threats to websites. It can also be used in ways that do not pose any threats. The "protection" measures used by Cloudflare cannot distinguish between the two. IMO, these measures are deemed acceptable by website operators (Cloudflare's customers) because computer users blocked accidentally are more likely to be in catogory (b) not (a).
A more egalitarian approach IMO would be to publicise detailed rules for website usage. That is, provide an explanation of what the website operator/CDN considers "wrong". For example, a list of permitted software, the maximum allowable number of requests in a given time period, etc. IMO, the rules would likely be incriminating. For example, they might be discriminatory and/or anti-competitive and subject to legal challenge.
1. Another interesting question is why the website operator/CDN believes it is "wrong". It appears the OP's www usage is not posing any "threat" to Cloudflare's customers or partners. As such, there is no justifcation for blocking the OP.
2. For example, software that sends personal data to website operators, software that prominently displays advertising, software that provides "payment handlers", and so on.
3. Forcing computer users to choose "interactive" software that is generally unsuitable for automation, such as popular web browsers or mobile apps.
Re: You don’t want to be on Cloudflare’s naughty list
#229Earlier quoted context omitted.
A task that would be made much easier and less likely to miss something if the affected person had some indication as to what the problem was.
Devil's advocate - would it not then be pretty easy to engineer malicious bots to avoid detection?
Re: You don’t want to be on Cloudflare’s naughty list
#230Earlier quoted context omitted.
I need to look into that. Thanks for pointing it out. I had totally forgotten about that post. Edit: team tells me this idea never got off the ground. Did talk with some potential partners (which did NOT include Google) but didn’t happen. So if Google was throwing CAPTCHAs it wasn’t because of our IP reputation.
Dear John. What am I — as a normal human being/end-user — supposed to do in this situation? People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? The challenge page doesn’t help the end user understand why this is happening to them. It’s okay if you only see it for two seconds. But the page stays on screen for over a minute. When this happens for…