Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

241–250 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#241
post #79

Earlier quoted context omitted.

It’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.

I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"

The story I've heard is--because their direct customers are websites, not end users--that Cloudflare loves to be ostentatious with these branded blocks and have a vested interest in offering services which punish users because it makes people feel like the product really really does something. Do you constantly hear about people being hosted by Akamai or CDNetworks or whatever going down due to DDoS attacks? No. However, despite a bajillion websites being hosted by Akamai--including, for example, virtually everything from Akamai--have you ever accidentally been blocked or severely rate limited by one, or been given a CAPTCHA... even behind Tor? I doubt it (and this is coming from someone who nigh unto tried to cause themselves problems with Apple and all I ever got was a subtle speed cap); and yet, I feel like everyone I know has experienced being stuck behind Cloudflare at various points in their lives :/.

Re: You don’t want to be on Cloudflare’s naughty list

#242
post #91

Earlier quoted context omitted.

> Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. I've been noticing this too, and it's why Starlink remains my secondary ISP/bulk transfer connection. If I had to drop on…

I wonder if a IPv6 tunnel broker to get IPv6 addresses would help with your Starlink problems.

Starlink supports IPv6 addresses, I'm sure it would help. My network infrastructure is just lacking general IPv6 support, as I've not cared to get it set up in great detail, and my testing has demonstrated that my IPv6 addresses behind my router are publically reachable, so... I'll get around to proper firewalling at some point.

I could do a range of things to solve it, but as I have two ISPs, I typically just switch to the one that works better for the solution. I'm aware it's not a technically fancy solution, but it's quick and easy (change the gateway on the machine), and works fine.

Re: You don’t want to be on Cloudflare’s naughty list

#243
The usual response from me when I get a "needs to review the security of your connection" blockade from CF is "fuck off" along with a click of the Back button. Your content is likely not unique, especially if I'm coming from a search result, and I'll just go somewhere else more friendly instead.

Re: You don’t want to be on Cloudflare’s naughty list

#244
post #200

Earlier quoted context omitted.

I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"

Well, apparently they scared this user into installing their browser extension, so it sounds like this incident was a win for them.

That is indeed their goal - this kind of targeted harassment is done deliberately to collect more personal data of the user.

This tactic is quite common among BigTech and something I've experienced with both Google and Amazon - once you are hooked onto their product, one day they will suddenly deny some aspect of their service to you and force you to share more personal data with them to get access to it. For example, Amazon will one day start to ask you to click a link sent to your mobile to access their account, or Google or Microsoft will block your account and ask you for your mobile number to "verify" you etc. When you are blocked from using a service suddenly, however privacy conscious you are, in your desperation you will be forced to comply.

I have experienced this with CloudFlare too once when many website were suddenly blocked for me by CloudFlare on all browsers and I was forced to install their extension to access some information I needed from a website urgently. I have no doubt in my mind that even otherwise, they just deliberately and randomly blocked access to some sites and displayed their "captcha" page just for PR and "brand awareness". Now that CloudFlare has realised this is backfiring on them because of the negative emotions being associated with their brand, they have now redesigned their "captcha harassment" page to give less prominence to their branding than before.

Re: You don’t want to be on Cloudflare’s naughty list

#245

Earlier quoted context omitted.

Maybe your mobile ISPs dont do enough to stop malicious/spam traffic. That's not Cloudflare's fault

It only affects Cloudflare hosted sites though.

That's true, but it's the Cloudflare customer who decides what to block by default with their Firewall setting mode, and custom rules etc

Re: You don’t want to be on Cloudflare’s naughty list

#246

On OP's place I would try Cloudflare Warp. It will connect me right into CF's guts, where limits may be just cancelled. It helped me once or twice when some CF protected sites gave me bad time.

Using a group's service so you don't suffer from the actions of that group? I've heard that pitch before. Francis Ford Coppola made some movies about one of those groups.

Re: You don’t want to be on Cloudflare’s naughty list

#248
post #38
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

My dude, it isn't about money. At least not directly.

I encourage those of you attempting to block Cloudflare to try and host your own website for a bit. Make sure you don't do it on a metered/paid connection. I know one eCommerce site with 1,300 employees that went bankrupt overnight thanks to the AWS bill (and lack of options to get back online, this was prior to companies such as CF). Bankruptcy as in the company filed for bankruptcy and no longer exists. They were profitable for a decade prior. One DDoS attack...

Also make sure you don't have a democratic opinion if you are in the US, like a 50 person manufacturing company. They were shut down completely thanks to saying a single wrong thing about Republicans. CF existed there, but they weren't aware thanks to not having IT folks. They were a non profit.

CF may be evil to some, but there is a reason they exist. I use CF. I don't like throwing money at them every month, however, many of my websites have also been attacked, usually via competitors. We can either deanonymize the internet or allow companies like CF to exist. There is really no other way.

Re: You don’t want to be on Cloudflare’s naughty list

#249

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

I feel like Starlink could at least partially mitigate this by supporting IPv6. T-mobile US supports IPv6, and I hardly notice this as an issue on my phone. Or the time my work ran the business over a 4G mobile while waiting for ISP install.

A genuine question from an ignoramus: how on earth did Starlink launch a brand new ISP in 2020 which doesn't support IPv6? Is IPv6 really so difficult? Does actually nobody care about IPv6 still, after all these years?

Re: You don’t want to be on Cloudflare’s naughty list

#250

The rise of Cloudflare is the first real threat I've seen to ordinary people running webcrawlers.

Tragedy of the commons, unfortunately. There were a bunch of cases where web crawlers and scrapers built competitive services on the back of the services they scraped, some of these ending up in courts [1]. [1] https://www.derstandard.at/story/1389860104020/eu-gerichtsho...

Maybe there are but the specific example you linked is about real-time API use and unrelated to scraping/crawling.
Post reply on HN