Live data from Hacker News

CloudFlare is ruining the internet (for me) (2016)

slashgeek.net

31–40 of 83 posts

Re: CloudFlare is ruining the internet (for me) (2016)

#31

I fully agree. It's not only the waste of time when you have to confirm you're a human (that adds up to multiple hours per month). It's also the entire blockage of older or less mainstream systems that no longer can access, sometimes critical, websites at all when the Cloudflare check blocks things entirely because the "browser is out of date" or not on their whitelist. Therefore causing excessive discrimination of p…

(Note I share your sentiment, however)

Is there any data that’s supports this suggestion users with older devices are actually being discriminated? (% of users actually using older devices incapable of upgrading to browser versions supported by cloud flare)

I just find it hard to believe users are actually getting denied access because their device are old. Surely you can still run new versions of Chrome and Firefox on most things [1].

——————

[1] Don’t get me wrong I use Safari and I find it inflammatory when a site tells me to use a modern browser because they doesn’t support safari (the language more so). But I wouldn’t call it discrimination seeing as I have an opinion to run firefox/chrome from time to time.

Re: CloudFlare is ruining the internet (for me) (2016)

#32
post #14

I have almost the same experience. I'm not running my own ISP and I'm not in a country known for originating DDoS attacks (Sweden), yet just using Firefox on Linux seems to be enough to be forced to click on traffic lights many times an hour. If I'm using Mullvad VPN that accelerates to almost every minute. CloudFlare claims to support privacy pass, but their extension implementing it seems to do absolutely nothing.

> I'm not running my own ISP and I'm not in a country known for originating DDoS attacks (Sweden), yet just using Firefox on Linux seems to be enough to be forced to click on traffic lights many times an hour.

I'm in the same situation. Linux, Firefox, Sweden, with a residential IP that has been mine for weeks/months. Who's massively DDoS'ing with residential Telia IPs?!

Re: CloudFlare is ruining the internet (for me) (2016)

#33
post #24
post #9

OP didn’t put this in the title but the article is from 2016. Turns out a lot has changed in the last decade and I think it’s likely that the article should be updated on what it’s like right now.

s/is ruining/has ruined/ ?

g

Re: CloudFlare is ruining the internet (for me) (2016)

#34
post #28

It is not CloudFlare that is ruining the Internet, but the spammers and attackers. On the second level, that catching and punishing them is impractical or even impossible depending on their location. Businesses were perfectly fine to accept the low security of 1990s email, webserver, and all the other configurations and software. They did not suddenly out of nowhere ask for more restrictions (such as email sending re…

> It is not CloudFlare that is ruining the Internet, but the spammers and attackers.

Spammers have been around since forever and it used to be the webmaster/sysadmin's responsibility to deal with spam in a way that would not hinder user experience. With Cloudflare all that responsibility is aggressively passed on to the user, cumulatively wasting _years_.

As for attackers, I wonder if Cloudflare publishes data showing how many of the billions of websites it "protects" have experienced a significant attack. They don't offer free protection to save the internet, but rather for control -- and no single company should have this much control.

Re: CloudFlare is ruining the internet (for me) (2016)

#35
post #14

I have almost the same experience. I'm not running my own ISP and I'm not in a country known for originating DDoS attacks (Sweden), yet just using Firefox on Linux seems to be enough to be forced to click on traffic lights many times an hour. If I'm using Mullvad VPN that accelerates to almost every minute. CloudFlare claims to support privacy pass, but their extension implementing it seems to do absolutely nothing.

Agreed. Same with Firefox on FreeBSD. Constant captchas. It identifies as Linux by the way (it seems to be compiled that way by the maintainers) which is probably better (a 2% desktop marketshare OS vs a 0.01% one is probably better here)

Re: CloudFlare is ruining the internet (for me) (2016)

#36

I fully agree. It's not only the waste of time when you have to confirm you're a human (that adds up to multiple hours per month). It's also the entire blockage of older or less mainstream systems that no longer can access, sometimes critical, websites at all when the Cloudflare check blocks things entirely because the "browser is out of date" or not on their whitelist. Therefore causing excessive discrimination of p…

Without a market CloudFlare wouldn't be able to ruin the internet. You can thank all of the incessant AI bots for that. I can't even browse GitHub anymore without logging in.

Cloudflare doesn't need AI to survive as a business. There are more than enough DDoS attacks to protect from.

Re: CloudFlare is ruining the internet (for me) (2016)

#37
post #34
post #28

It is not CloudFlare that is ruining the Internet, but the spammers and attackers. On the second level, that catching and punishing them is impractical or even impossible depending on their location. Businesses were perfectly fine to accept the low security of 1990s email, webserver, and all the other configurations and software. They did not suddenly out of nowhere ask for more restrictions (such as email sending re…

> It is not CloudFlare that is ruining the Internet, but the spammers and attackers. Spammers have been around since forever and it used to be the webmaster/sysadmin's responsibility to deal with spam in a way that would not hinder user experience. With Cloudflare all that responsibility is aggressively passed on to the user, cumulatively wasting _years_. As for attackers, I wonder if Cloudflare publishes data showin…

> Spammers have been around since forever

Is the fallacy here not obvious? Yes, spammers have been around since forever, but it's not the same amount of spammers. Whether it's two spammers or two million spammers does make a difference.

Re: CloudFlare is ruining the internet (for me) (2016)

#38
post #11

Earlier quoted context omitted.

So, guilty by default, right? We developed human rights and laws through centuries of debates, pain, suffer, revolutions, fights etc just to get mega-corps doing whatever they feel right, externalizing the trade-offs on innocent peoples.

No, just pointing out that it's relatively likely that their ISP's IP ranges have been flagged as DDoS sources.

I know, and I was pointing out that CF outsources the trade-offs of their solutions to innocent users.

Re: CloudFlare is ruining the internet (for me) (2016)

#39

What is a better option for website owners? We don't want to keep people out, we want to keep attackers out.

Genuinely curious, is there a way of tuning how this protection is triggered? If there is, perhaps filter out those ISPs/countries from which most attack originate? Not a cloudflare user myself -- for me it's mostly been a nuisance.

Re: CloudFlare is ruining the internet (for me) (2016)

#40
post #28

It is not CloudFlare that is ruining the Internet, but the spammers and attackers. On the second level, that catching and punishing them is impractical or even impossible depending on their location. Businesses were perfectly fine to accept the low security of 1990s email, webserver, and all the other configurations and software. They did not suddenly out of nowhere ask for more restrictions (such as email sending re…

> It is in the interest of CFs customers to be as accessible as possible, after all.

Well this is where your argument goes a little wrong IMO. When you're on something more niche (eg Firefox on Linux) they just don't care as much about making it work for you because there's so few of us blocked in the process.

And this problem should really be solved with a proper solution, not this fiddly black magic ruleset stuff. The email thing you mention is a good example. DKIM and SPF are good things that makes things more secure in an understandable way. Specifying your legit mail handlers is not a workaround, it's good security. In some ways Altman has a good idea with his WorldCoin eyeballs. But I don't support it for obvious reasons. I don't want my internet identity tied to a single tech bro and some crypto. If we do this kind of thing it has to be a proper government or NGO effort with proper oversight and appeals process.

I've tried to make my Linux Firefox identify as edge on windows and that makes it a lot better on some sites (especially Microsoft breaks a lot of M365 functions on purpose if you're not using the "invented here" browser). And many sites don't give me captchas then. But in some cases Cloudflare goes even more nasty and blocks me outright which is really annoying. If I use Linux a lot more sites break but Cloudflare sticks with captchas.

Anyway I think the age of the captcha is soon over anyway. AI will make it unviable.

> All these annoying restrictions were forced to be implemented by attacks of all kinds.

Ps it's not always attacks but also to block things that are good for consumers but bad for the sites' business model. Like preventing screen scraping which can legit help price comparison sites.

Post reply on HN