Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

211–220 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#213
Ok kids.. This is Tobin.. but without the Paradigm.

First off.. Gee I wish we had all come together about a decade ago or so and found solutions for what was plainly coming and spelled out by my self and others.

Second before it happens.. Pale Moon is not "old and insecure" It is being mismanaged had has no vision or prospects for future expansion.. It is just whatever XUL they can keep working while chugging away at the modern web features..

Pale Moon is often TOO security patched btw, which have been regularly disclosed and specially noted in the release notes since I convinced Moonchild he should do that for exactly the kind of old and insecure falsehood.

Moonchild's issue as a developer is he will always choose the seemingly simplest path of least resistance and will blindly merge patches without actually testing them. Many security patches are only security patches and not just.. patches because Mozilla redefined the level of security they want their codebase to provide.. But all known Mozilla vulnerabilities and many that would only become vulnerable if surrounding code is changed are patched.. Pale Moon and UXP has become more secure over time and that is an objective fact when you consider the nature of privileged access within a XUL platform which has its own safegaurds as well that persist into Firefox today though less encountered.

Now no one hates that furry bastard more than me (and I challenge you to try) but I will never call out good work as anything other than good work. Besides, there are a MILLION other plainly visible faults with the Pale Moon project and its personnel and my past behavior without having to make stuff up or perpetuate a false mantra like "old and insecure".

Finally, isn't Cloudflare being very unfair to every project save the modern firefox rebuilds listed on thereisonlyxul.org? Like SeaMonkey? Why does seamonkey deserve any hate from anyone.. or systematic discrimination.. What have they ever done but try and have an internet application suite.. Why are they old and insecure despite being patched and progressing a patch queue for Mozilla patches just landed selectively to preserve the bulk of XUL functionality its users adore?

In conclusion, what will be the final cost and how many will burn for trying to going against it.. I know my fate for trying.. how many will join me knowing that?

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#214
post #55

Earlier quoted context omitted.

Cloudflare has been even worse for me on Linux + Firefox. On a number of sites I get the "Verify" challenge and after solving it immediately get a message saying "You have been blocked" every time. Clearing cookies, disabling UBO, and other changes make no difference. Reporting the issue to them does nothing. This hostility to normal browsing behavior makes me extremely reluctant to ever use Cloudflare on any project…

Does it still apply if you change the UA to something more common (Chrome on Windows or something)?

Fwiw, I was getting cloudflare blocked for a long time on Firefox+Linux and the only thing that fixed it was completely disabling the UA adjuster browser extension I had installed.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#215

As a website owner and VPN user I see both sides of this. On one hand, I get the annoying "Verify" box every time I use ChatGPT (and now due its popularity, DeepSeek as well). On the other hand, without Cloudflare I'd be seeing thousands of junk requests and hacking attempts everyday, people attempting credit card fraud, etc. I honestly don't know what the solution is.

If I were hosting a web page, I would want it to be able to reach as many people as possible. So in choosing between CDNs, I would choose the one that provides greater browser compatibility, all other things equal. So in principle, the incentives are there for Cloudflare to fix the issue. But the size of the incentive may be the problem. Not too many customers are complaining about these non-mainstream browsers.

In that case you can turn off / not turn on the WAF feature(s) of Cloudflare - it's optional and configured by the webmaster.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#216

Earlier quoted context omitted.

Many / most bots use Chrome on Linux user agent, so you think it's OK to block Chrome on Linux user agents. That's very broken thinking. So it's OK for them to do shitty things without explaining themselves because they "have access to more data than we do"? Big companies can be mysterious and non-transparent because they're big? What a take!

Can't the user agent be spoofed anyway?

I think they also fingerprint the browser. So changing user agent alone won't help.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#217

How many of you all are running bare metal hooked right up to the internet? Is DDoS or any of that actually a super common problem? I know it happens, but also I've run plenty of servers hooked directly to the internet (with standard *nix security precautions and hosting provider DDoS protection) and haven't had it actually be an issue. So why run absolutely everything through Cloudflare?

I would feel pretty safe running my own hand-written services against the raw Internet, but if I was to host Wordpress or other large/complicated/legacy codebases I'd start to get worried. Also the CDN aspect is useful - having lived in Australia you like connections that don't have to traverse continents for every request.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#218
A very random note.

I try to check the forum post and found out that I was blocked by https://forum.palemoon.org , e.g., https://offline.palemoon.org/blocked/index.html . Don't know and haven't visited this site before.

https://www.palemoon.org works though.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#219
post #44

On one hand, this is a scummy move from CloudFlare. All this has ever done is make browsers spoof their UAs. Mozilla/4.0 anyone? On the other, Pale Moon is an ancient (pre-quantum) volunteer-supported fork of Firefox, with boatloads of known and unfixed security bugs - some fixes might be getting merged from upstream, but for real, the codebases diverged almost a decade ago. You might as well be using IE 11.

I'm not sure why people are mad at Cloudflare. They are not obligated to support browsers outside the general marketshare nor should you expect to.

Cloudflare not supporting Pale Moon has no impact on the rest of us. Matter of fact today is the first time I'm hearing of this browser I will never end up using.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#220
post #5

I'm using chrome on linux and noticed that this year cloudflare is very agressive in showing the "Verify you are a human" box. Now a lot of sites that use cloudflare show it and once you solve the challenge it shows it again after 30 minutes! What are you protecting cloudflare? Also they show those captchas when going to robots.txt... unbelievable.

Same. I'm consistently getting a captcha and some nonsense about a Ray ID multiple times a day.
Post reply on HN