If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your fa…
You don’t want to be on Cloudflare’s naughty list
281–290 of 354 posts
Re: You don’t want to be on Cloudflare’s naughty list
#282Earlier quoted context omitted.
Just 10 minutes ago, I got the following email from a housemate (I'm not home at the moment): > The past few weeks I've been getting tons of redirects to verify my humanity before being allowed to view a webpage. Usually I just have to click the box that says human, not find all the ladders in a photo. SoFi is doing it every single time I log in. Petco, too, along with others who are more sporadic. This is happening…
> I do exactly zero web crawling / scraping / abusive anything from my home connection. That you know about . Your house mates share the internet connection. I’m guessing you have WiFi, so you may have unintended guests. You probably have lots of devices, one of which may be infected. Your ISP may have issued you a different IP which may have a negative reputation score. You could be using a malware infected browser…
Scaling to infinity isn't a right, it is a privilege. Any company that builds this sort of no-human-decision systems are abusing that privilege and hoping that anyone who suffers wrongly under their systems doesn't have enough voice (google seems to be the worst for this, though cloudflare seems set to follow).
Re: You don’t want to be on Cloudflare’s naughty list
#283So this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you ? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a ma…
> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity co…
How would we know?
Re: You don’t want to be on Cloudflare’s naughty list
#284Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…
FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…
Re: You don’t want to be on Cloudflare’s naughty list
#285Earlier quoted context omitted.
It’s absolutely required for most multiplayer games. Many need random ports and some even refuse to work if UPnP is blocked even if you manually open a port for them.
I've never had UPnP enabled and I don't have any problems doing online gaming / flight sim / video chatting / etc.
Re: You don’t want to be on Cloudflare’s naughty list
#286Earlier quoted context omitted.
The answer depends on the type of service you host. I don't know what you need to do, but I do know that filtering IP space is merely security-by-obscurity, it is a cheap and broken solution to the hard problems of sybil resistance. If you need IP filtering to operate on a day-to-day basis, then the security of your service is fundamentally broken. Tor users do not have any special properties over clear-net users bes…
This is why I'm strongly against spam filtering for email. Spam filters are fundamentally security-through-obscurity. I mean, they don't protect your email from targeted bombing attacks or phishing. If you need spam filters to operate your email on a day-to-day basis, then the security of your email is fundamentally broken. /s, obviously, I hope. Blocking Tor isn't a security measure, it's a nuisance reduction measur…
You kid, but this is completely true Email is simply an incredibly flawed, outdated and broken system, especially when used without PGP. Phishing is a massive problem, and it has only continued to grow in scale because spam, uh... finds a way. At the same time, spam filters regularly create false positives, making email an unreliable transport (leading "oops, it got lost in my spam folder").
>Blocking Tor isn't a security measure, it's a nuisance reduction measure.
You should block all IP space, this will reduce nuisances by 100%. In fact, this will save you from having to consider any real security practices or do your job properly.
Re: You don’t want to be on Cloudflare’s naughty list
#287Earlier quoted context omitted.
A genuine question from an ignoramus: how on earth did Starlink launch a brand new ISP in 2020 which doesn't support IPv6? Is IPv6 really so difficult? Does actually nobody care about IPv6 still, after all these years?
Not an answer to your question, but an indicator of shared culture: Tesla vehicles also don’t support IPv6 whatsoever. Things you might use an internet connection for in your Tesla include triggering air con remotely, live traffic and satellite maps, streaming music or online radio, web browsing, or YouTube/Netflix/Disney+ clients. It completely refuses to use IPv6 over mobile or wi-fi. Also it refuses to access anyt…
Re: You don’t want to be on Cloudflare’s naughty list
#288Earlier quoted context omitted.
The answer depends on the type of service you host. I don't know what you need to do, but I do know that filtering IP space is merely security-by-obscurity, it is a cheap and broken solution to the hard problems of sybil resistance. If you need IP filtering to operate on a day-to-day basis, then the security of your service is fundamentally broken. Tor users do not have any special properties over clear-net users bes…
This is why I'm strongly against spam filtering for email. Spam filters are fundamentally security-through-obscurity. I mean, they don't protect your email from targeted bombing attacks or phishing. If you need spam filters to operate your email on a day-to-day basis, then the security of your email is fundamentally broken. /s, obviously, I hope. Blocking Tor isn't a security measure, it's a nuisance reduction measur…
Re: You don’t want to be on Cloudflare’s naughty list
#289Earlier quoted context omitted.
Mainly forms -- login forms, comment forms, signup forms. Bots use Tor pretty heavily because it's anonymous and hard to block them without blocking the entire network. Login form abuse is mildly irritating but not a huge deal if you have other measures in place. Comment spam is annoying but there are some options that deal with it pretty well. But the signup spam was a headache. I didn't want to just blackhole Tor t…
I think the workflow is the issue with http(s)-based email list sign-ups. Solution: Require sign-ups by email, so the end account must actively send your mailserver a registration message. This also turns an open-loop control system into a closed loop control system, which is inherently easier to secure / keep safe.
It's also easy to send "from" an addresses that passes SPIF/DKIM but bounces inbound mail -- not sure what reason someone would have for this other than hurting the service reputation or acting as a DoS of sorts, but it can be done.
Re: You don’t want to be on Cloudflare’s naughty list
#290Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…