Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

341–350 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#341

Cloudflare is slowly but surely turning the web into a walled garden.

Slowly? Have you not watched the pot boil around you for the past decade? There are zero good search engines. Everything returns propaganda. This is all as it was intended.

> There are zero good search engines. Everything returns propaganda.

Kagi exists and has been production quality and better than Google for over two years already. (At this point I think it is even better than old google.)

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#342

Earlier quoted context omitted.

America does have laws against this kind of thing. So instead of banning America, report the IP addresses to their American hosts for spam and malicious intent. If the host refuses to do anything, report it to law enforcement. If law enforcement doesn't do anything... then you're proving my point.

So you are saying that if 95% of world population, including Chinese, Russians, etc reports American bot farm to American police, somebody would really review that and go after Americans? BTW, how they should report it, if they are a small business/physical person without lawyers? Does US police have some kind of online hotline to report US criminals for foreigners or smth?

It's almost as if there should be an international body of laws which covers fraud...

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#343
post #305

Earlier quoted context omitted.

I think it's also EOL/not getting updates now? I mean I never used it, their only selling point seem to have been hype.

Definitely not EOL; https://resources.arc.net/hc/en-us/articles/20498293324823-A...

I assume they are talking about the company moving on to develop a new browser: https://www.theverge.com/2024/10/24/24279020/browser-company...

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#344

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

To access any site protected by cloudflare captcha i have to change browsers from firefox to chrome. and i have basically default suite of addons (ublock is the only one affecting the pages themselves). VPN doesn't matter, i probably share IP with someone "flagged" via ISP. Every site, that is except their cloudlfare dashboard.

Maybe you have anti-fingerprinting protection on? I've heard it can cause issues.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#346
post #325

Earlier quoted context omitted.

This would be weird, esp. given that Cloudflare is one of the vendors who act as exit nodes for iCloud Relay.

I believe your parent comment means when the target website blocks, not Cloudflare. YouTube is a perfect example. Using iCloud Private Relay can now frequently label you as a bot, which stops you from watching videos until you login.

It happens to me a lot, I just created a small automation to use https://cobalt.tools to download the content. Their loss, not mine.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#347

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

I think this is on Cloudflare. Perhaps there is a demand for such a service, but it is another to implement it. And this is very bad for a free and therefore safe net.

I don't even know which attack vectors an integrity check for a browser could help against. Against infected clients? It is in any way evidently not effective.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#348
post #325

Earlier quoted context omitted.

I believe your parent comment means when the target website blocks, not Cloudflare. YouTube is a perfect example. Using iCloud Private Relay can now frequently label you as a bot, which stops you from watching videos until you login.

It happens to me a lot, I just created a small automation to use https://cobalt.tools to download the content. Their loss, not mine.

Nice tool.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#349
post #282

Earlier quoted context omitted.

Rate limiting could help when an automated process is scanning arbitrary, generated URLs, inevitably generating a shitton of 404 errors -- something your rate limiting logic can easily check for (depending on server/proxy software of course). Normal users or even normal bots won't generate excessive 404's in a short time frame, so that's potentially a pretty simple metric by which apply a rate limit. Just an idea tho…

I did that and it works great. Specifically, I use fail2ban to count the 404s and ban the IP temporarily when certain threshold is exceeded in a given time frame. Every time I check fail2ban stats it has hundreds of IPs blocked.

Same here - fail2ban then adds the IP to my nftables fw

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#350
post #31

Earlier quoted context omitted.

> How many of you all are running bare metal hooked right up to the internet? I do. Many people I know do. In my risk model, DDoS is something purely theoretical. Yes it can happen, but you have to seriously upset someone for it to maybe happen.

From my experience, if you tick off the wrong person, the threshold for them starting a DDoS is surprisingly low. A while ago, my company was hiring and conducting interviews, and after one candidate was rejected, one of our sites got hit by a DDoS. I wasn't in the room when people were dealing with it, but in the post-incident review, they said "we're 99% sure we know exactly who this came from".

What the hell is wrong with people? Honestly the lack of substantive human interaction in a lot of folks' lives, except via the Internet, is a real problem.

Take that story for instance. Here's how that goes in the physical world, just to show how unbelievably ridiculous it is.

So you didn't get the job? What's your next step?

I'll stop by their office and keep people from entering the front doors by running around in front of them. That'll show those bastards.

Post reply on HN