Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

251–260 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#251

On OP's place I would try Cloudflare Warp. It will connect me right into CF's guts, where limits may be just cancelled. It helped me once or twice when some CF protected sites gave me bad time.

Using a group's service so you don't suffer from the actions of that group? I've heard that pitch before. Francis Ford Coppola made some movies about one of those groups.

True, but I'd prefer that to just suffering while waiting for that ban to expire.

Re: You don’t want to be on Cloudflare’s naughty list

#252
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

My dude, it isn't about money. At least not directly. I encourage those of you attempting to block Cloudflare to try and host your own website for a bit. Make sure you don't do it on a metered/paid connection. I know one eCommerce site with 1,300 employees that went bankrupt overnight thanks to the AWS bill (and lack of options to get back online, this was prior to companies such as CF). Bankruptcy as in the company…

> I know one eCommerce site with 1,300 employees that went bankrupt overnight thanks to the AWS bill

Had they just called AWS and explained the situation, they would likely still be in business.

I keep a backup DDoS mitigation service for my entire network that costs me less than $200/mo to mitigate up to 100 Gbps.

Re: You don’t want to be on Cloudflare’s naughty list

#253

I'm used to getting assaulted by Cloudflare's browser check interstitials along with random Cloudflare and Google CAPTCHAs because (presumably) I run Firefox and an ad-blocker instead of vanilla Google Chrome. It's already tremendously inconvenient to wait multiple seconds on many page loads and click 20 bicycles, I can only imagine how infuriating it would be if every page load started taking 60 seconds because your…

I'm also on firefox w/ adblockers and had similar issues... the 'privacy pass' plugin solved this for me.

Re: You don’t want to be on Cloudflare’s naughty list

#254
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

You're looking at it all wrong. From Cloudflare's point of view, this kind of blocking is a feature . Anyone doing legitimate web crawling, or offering alternative web services such as Starlink, now needs Cloudflare's permission. Essentially, for a broad class of web-based businesses, they have made themselves gatekeepers. I'm sure they'll find a profitable use for this position. Charging outright would look bad, but…

It's true that any wall around you that protects you from something unavoidably comes with a gate that someone else guards, unless you want to guard your gate personally (and that entails filtering out armies of spambots, worst case manually).

As with any power and control you delegate to any entity, only time and good behavior will earn them your trust. That's theoretically what companies are competing for, your loyalty.

Re: You don’t want to be on Cloudflare’s naughty list

#255

Earlier quoted context omitted.

Spammers typically implement bots to carry out tasks. I mean, technically at some point a spammer is a real person, but when you're automating tasks and using bots, it's not at the same scale.

So what happens when your ID gets hacked and reused for fraudulent activity? Would you have to submit a dispute with the internet credit agencies? Maybe join a class action suit against the entity that leaked your ID so that they're forced to give you a year of free internet identity monitoring?

If you have a better solution, I'm sure it would be very lucrative.

Re: You don’t want to be on Cloudflare’s naughty list

#256

If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your fa…

Cloudflare has mixed up the definitions of "bot" and "abuse". Tor users may or may not be bots, but as long as they don't abuse (spamming or DoS), they ought to be treated the same.

Citation needed.

Re: You don’t want to be on Cloudflare’s naughty list

#258

Earlier quoted context omitted.

Maybe your mobile ISPs dont do enough to stop malicious/spam traffic. That's not Cloudflare's fault

It only affects Cloudflare hosted sites though.

No, it affects visitors of “Cloudflare hosted sites”. It also affects all sites not hosted by CloudFlare.

You are complaining about the use of IP as an imperfect signal. Everyone involved knows that. But it’s still better than the current alternatives.

Re: You don’t want to be on Cloudflare’s naughty list

#259

Earlier quoted context omitted.

I feel like Starlink could at least partially mitigate this by supporting IPv6. T-mobile US supports IPv6, and I hardly notice this as an issue on my phone. Or the time my work ran the business over a 4G mobile while waiting for ISP install.

A genuine question from an ignoramus: how on earth did Starlink launch a brand new ISP in 2020 which doesn't support IPv6? Is IPv6 really so difficult? Does actually nobody care about IPv6 still, after all these years?

Not an answer to your question, but an indicator of shared culture: Tesla vehicles also don’t support IPv6 whatsoever.

Things you might use an internet connection for in your Tesla include triggering air con remotely, live traffic and satellite maps, streaming music or online radio, web browsing, or YouTube/Netflix/Disney+ clients.

It completely refuses to use IPv6 over mobile or wi-fi. Also it refuses to access anything over IPv4 (apart from DNS) which resolves to an RFC1918 address, even if it's connected to said RFC1918 network.

So yes, Starlink and Tesla are different companies, but I see cultural parallels which I'm sure surprises nobody.

Re: You don’t want to be on Cloudflare’s naughty list

#260
post #152

So this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you ? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a ma…

> and we all know how short is the distance between technical capability and doing it

Fact-less conspiranoia.

The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it?

You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity costs, collateral damage, unintended consequences, reputation costs, brand harm.

Hell even ethics and morals of those involved. Who do you know would want to work for a company that did that? Who do you know would program that feature and not say anything about it? Why do you believe that CloudFlare would have so many of those kinds of people working there, but you know so few?

Why not make the same complaint about your ISP, your hardware manufacturer, your OS manufacturer? You have exactly the same amount of evidence they are doing this or could do this.

Remember that US criminal system attributes 3 elements to a crime: {means, motive, and opportunity} and even then we use evidence and an assumption of innocence. You just threw out every part except “means”.

I’m not defending CloudFlare here so much as tired of conspiracy theories and paranoia and social panics. We have enough of those things right now.

Post reply on HN