Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

261–270 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#261

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

I moved from a local CGNAT'ed WISP to starlink.

Starlink is at least 10 better (fewer captchas).

I'm really hoping cloudflare gets busted for having backroom deals with big ISPs or something. (For instance, if the cgnat had a cloudflare CDN cache endpoint behind / accociated with it, I suspect the IP would be white listed.)

Re: You don’t want to be on Cloudflare’s naughty list

#262

Earlier quoted context omitted.

Of course, but the theory is it's restricting 1 real person to 1 account, versus 1 spammer creating 1,000 accounts via automation. And once your spammer has been identified then that's them banned/removed, unable to sign up again.

What's to stop them from using fake IDs

Airports seem to be able to spot fake passports pretty reliably.

Re: You don’t want to be on Cloudflare’s naughty list

#263

If you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will neve…

I’ve had a similar experience in India with wired internet from a local ISP: CGNAT is used so there are who knows how many customers on the same IPv4 address, https://iknowwhatyoudownload.com/ shows at least forty hours of movies being downloaded every day, the IP address is on half the blacklists out there because someone is part of an email-sending botnet, and yeah, Cloudflare hates you.

Is there even any way to reliably identify individual users behind a CGNAT without invasive fingerprinting?

Re: You don’t want to be on Cloudflare’s naughty list

#264
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Just 10 minutes ago, I got the following email from a housemate (I'm not home at the moment): > The past few weeks I've been getting tons of redirects to verify my humanity before being allowed to view a webpage. Usually I just have to click the box that says human, not find all the ladders in a photo. SoFi is doing it every single time I log in. Petco, too, along with others who are more sporadic. This is happening…

> I do exactly zero web crawling / scraping / abusive anything from my home connection.

That you know about. Your house mates share the internet connection.

I’m guessing you have WiFi, so you may have unintended guests.

You probably have lots of devices, one of which may be infected.

Your ISP may have issued you a different IP which may have a negative reputation score.

You could be using a malware infected browser or browser extension.

There are lots of variables. You haven’t isolated all of the ones in your control, so assuming CloudFlare is the only possible cause isn’t rational.

Re: You don’t want to be on Cloudflare’s naughty list

#265

If you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will neve…

I get it browsing from a major ISP in the US. I have the gall to browse in private mode and to block trackers and ads because of all the malware they contain. (And I don't use a browser that requires me to login just to browse the web - gasp!) And apparently, that means I'm worthy of this sort of punishment as well.

> I have the gall to browse in private mode and to block trackers and ads because of all the malware they contain.

I do these things as well. It’s been months since I’ve seen a CloudFlare challenge page.

Re: You don’t want to be on Cloudflare’s naughty list

#266

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

Cloudflare said they're working on this- https://blog.cloudflare.com/eliminating-captchas-on-iphones-...

That's... The opposite of working on this. It's moving the internet further away from being an interoperable, endpoint-agnostic medium.

Re: You don’t want to be on Cloudflare’s naughty list

#267
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

Yep. That paragraph made me pause and consider that maybe OP is the victim of some compromised device running on their network.

If two independent sites believe you are a bot, you or something at your address just might be.

Re: You don’t want to be on Cloudflare’s naughty list

#268
post #119

Earlier quoted context omitted.

Dear John. What am I — as a normal human being/end-user — supposed to do in this situation? People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? The challenge page doesn’t help the end user understand why this is happening to them. It’s okay if you only see it for two seconds. But the page stays on screen for over a minute. When this happens for…

> People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? This is the most serious problem with all of the major companies these days. Cloudflare, Google, Apple, etc. When you get on their "bad side", you're just screwed. You'll never even know what got them mad at you, and there's nothing you can do to recover. The only reasonable way to deal with…

[deleted]

Re: You don’t want to be on Cloudflare’s naughty list

#269
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

>"Not sure where the idea that it's about sharing IP reputation data comes from."

One source of that would be a blog post on your company's website that was actually authored by you! Point 2 below:

>"Once enabled, when we detect a bad bot, we will do three things: (1) we’re going to disincentivize the bot maker economically by tarpitting them, including requiring them to solve a computationally intensive challenge that will require more of their bot’s CPU; (2) for Bandwidth Alliance partners, we’re going to hand the IP of the bot to the partner and get the bot kicked offline; and (3) we’re going to plant trees to make up for the bot’s carbon cost. [1]

So it's not such a far-fetched notion is it?

[1] https://blog.cloudflare.com/cleaning-up-bad-bots/

Re: You don’t want to be on Cloudflare’s naughty list

#270
post #193

Earlier quoted context omitted.

There are probably more sophisticated options that would solve your problems than simply blocking it.

Is using CAPTCHAs one of those?

Most captcha services are just used to force users identified as having few other options into giving free tagging labour.
Post reply on HN