Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

271–280 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#271

Earlier quoted context omitted.

I'm a noob, can you give me a pointer? What kind of abusive traffic is coming through Tor and why do they do it?

Mainly forms -- login forms, comment forms, signup forms. Bots use Tor pretty heavily because it's anonymous and hard to block them without blocking the entire network. Login form abuse is mildly irritating but not a huge deal if you have other measures in place. Comment spam is annoying but there are some options that deal with it pretty well. But the signup spam was a headache. I didn't want to just blackhole Tor t…

> Mainly forms -- login forms, comment forms, signup forms. Bots use Tor pretty heavily because it's anonymous and hard to block them without blocking the entire network. Login form abuse is mildly irritating but not a huge deal if you have other measures in place. Comment spam is annoying but there are some options that deal with it pretty well.

Then put the form behind your monopolistic internet gatekeeper. There's no reason for a GET to redirect to a sysiphean captcha treadmill.

Re: You don’t want to be on Cloudflare’s naughty list

#273
post #79

Earlier quoted context omitted.

It’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.

I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"

[deleted]

Re: You don’t want to be on Cloudflare’s naughty list

#274
post #45

Earlier quoted context omitted.

Can you acknowledge the main point of the article? What should someone do if they find themselves misclassified by Cloudflare's systems?

(not the parent commenter) That person should start with the assumption they haven't been misclassified and eliminate the possibility that a device on their network is compromised.

Do you expect the average user to know how to "eliminate the possibility that a device on their network is compromised"? That is untenable.

Re: You don’t want to be on Cloudflare’s naughty list

#275

Earlier quoted context omitted.

An alternative that preserves some privacy also doesn't seem that hard to imagine... though it probably has its own can of worms*. Basically, the core problem is digital identities (accounts, IPs, phone #s etc.) are cheap to create (even considering captchas and all) so fraud is easy. The solution could be just to make it "costly" to create new digital identities. For example, you could get a "verified but anonymous"…

Your idea is comes from a good place, but identity theft is already a thing in the real world. Digital identities would also be very stealable. This malware more harmful in the long term. Imagine if your Twitter gets hacked and your digital identity makes it so your Gmail gets blocked. Similar, the internet is already very difficult for the people with limited means. This would make it even harder.

Easy solution.

Go down to your local post office.

They physically hand you an identity token on a physical $2 2fa device if you give some evidence you live nearby. You can put down the deposit or hand over the device for an old id which is cleared and reused.

It's traceable to the post office but no further, nothing is recorded other than that the token is deployed and roughly when.

Local communities can be responsible for cleaning up local messes. No need for the scammers two cities over to effect your reputation. No need for a corrupt employee handing out tokens to effect the reputation of the token you got ten years ago.

Re: You don’t want to be on Cloudflare’s naughty list

#276
post #45

Earlier quoted context omitted.

(not the parent commenter) That person should start with the assumption they haven't been misclassified and eliminate the possibility that a device on their network is compromised.

Do you expect the average user to know how to "eliminate the possibility that a device on their network is compromised"? That is untenable.

No, but I wouldn't expect the average user to write a blog post with unsubstantiated technical claims, either.

I do think Cloudflare could do better here to let the owner of an IP know why they're suffering from poor reputation.

However, it's not immediately clear to me how they could accomplish this without weakening their side of the car vs. mouse game.

Re: You don’t want to be on Cloudflare’s naughty list

#277

Earlier quoted context omitted.

Cloudflare has mixed up the definitions of "bot" and "abuse". Tor users may or may not be bots, but as long as they don't abuse (spamming or DoS), they ought to be treated the same.

Citation needed.

I think this is more of an opinion than a matter of fact

Re: You don’t want to be on Cloudflare’s naughty list

#278
post #224

Earlier quoted context omitted.

So i've turned cookies off and switched to my ipad to browse the internet for the evening, they have no fingerprint, and no cookie... now what?

Are you on a different IP block? ISPs sometimes just switch the last number. I had to use a VPN (a whole new IP) and clean chrome install to bypass one those "IP blocks" which was combined with fingerprinting.

It's random. I've been on 24.x.x.x, 66.x.x.x, and 98.x.x.x.

https://postmaster.comcast.net/dynamic-IP-ranges.html

Re: You don’t want to be on Cloudflare’s naughty list

#279
As much as it sucks, DDoS attacks seem to keep ramping up. Google recently blocked one doing 46M requests/sec [1]. It seems like the problem with credit card fraud or spam all over again. People hate being lumped in with malicious actors, but false positives are a thing and a few bad actors can and will demolish the entire system if its not secured.

[1] https://cloud.google.com/blog/products/identity-security/how...

Re: You don’t want to be on Cloudflare’s naughty list

#280
post #152

So this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you ? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a ma…

> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity co…

[deleted]
Post reply on HN