Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

161–170 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#161

Earlier quoted context omitted.

> Do that globally. We already do a simpler version of that with TLS and HTTPS, there are globally trusted root certs that ship with most OSes and browsers. It's just that we haven't extended the same approach to client certs and identity verification, instead having a bunch of walled gardens and governments running legacy methods of figuring out who someone is, as opposed to various eID mechanisms. If I trust news.y…

We cannot get them to agree on cookie banners and you’re talking about something much more complicated. Hey, by the way, would you trust some Chinese or Russian root certificate? The question is irrelevant, frankly. Consider this: you’re living in Germany today. You trust the German government. They handle all your logins using that eID. What if in February AfD comes to power? Do you still trust the German government…

> We cannot get them to agree on cookie banners and you’re talking about something much more complicated.

Another good example of something that’s technically feasible and not that complex, but was made infeasible due to either ignorance or malice, with all of the dark UI patterns and scummy behaviour.

> Hey, by the way, would you trust some Chinese or Russian root certificate?

Most people already do: https://chromium.googlesource.com/chromium/src/+/main/net/da...

For example:

  CN=CFCA EV ROOT,O=China Financial Certification Authority,C=CN
  CN=GDCA TrustAUTH R5 ROOT,O=GUANG DONG CERTIFICATE AUTHORITY CO.,LTD.,C=CN
  CN=UCA Global G2 Root,O=UniTrust,C=CN
  CN=UCA Extended Validation Root,O=UniTrust,C=CN
  CN=vTrus ECC Root CA,O=iTrusChina Co.,Ltd.,C=CN
  CN=vTrus Root CA,O=iTrusChina Co.,Ltd.,C=CN
If there’d be an issue of not wanting to support a certain country, then removing such a group of CAs from a store would be trivial for a particular service, same as with the above.

Plus, the opposite is also viable, if for example the Russian govt. wanted to allow anyone to verify whether particular requests come from their citizens, they might also run their own CA akin to https://www.bleepingcomputer.com/news/security/russia-create... except that the attack vector would change from MitM to fake identities being issued by them as needed (but since the server is the one doing the verification, it might as well drop the CA when desired).

> What if in February AfD comes to power?

Revoking the eID and anything dependent on it would be akin to your passport being taken away.

Essentially the modern day digital equivalent of getting your Google account banned by some bot, if you use that account for auth in a bunch of places.

Fundamentally, that’s no different from the reality that we already face - my regular eID could also be taken away if my own government felt like it, same as with my bank account and other assets.

Client certs themselves are nothing new, same for PKI. It’s a cool technology that could but presently cannot solve the problem of client identity globally, because we just can’t have nice things and order.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#162
i recommend everyone test the web with TOR to see how dead the public internet is. Reddit won't respond. Many sites have a 10-minute captcha challenge (e.g. substack).

So many sites have deployed countermeasures like Cloudflare, but they aren't actively monitoring the failure mode on those countermeasures.

The web is on it's knees and these countermeasures are another nail in the coffin if we don't act fast.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#163
post #57
post #32

Earlier quoted context omitted.

what is the advantage here over just running 'firefox -ProfileManager' and making a clean profile?

All host info not accessible via X11 protocol is hidden, for example font list, is replaced with generic one. For even more protection, run VNC server with common resolution in the container and connect to it using VNC viewer. In this case firefox provides a super generic profile (latest debian with mesa GPU), making this browser very hard to distinguish from others. This has some downsides however: First, you cannot…

mullvad browser is pretty much this, but without messing around with containers. One fingerprint for all users, with the same font list, resolution, canvas behavior, etc.

https://mullvad.net/browser

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#164

Cloudflare works much, much better than Google - Google captchas for me, on Tor, are flatly impossible, always. They never let get through, no matter whether you get them right or wrong. You always get "try again". The problem I do have with CF is their captchas seem to require human interaction on the page, and this makes getting through them problematic when you open half a dozen tabs, and each loads a CF captcha,…

But at least with Google captchas you can use AI to solve them. I use the buster captcha extension to solve them. It moves the mouse around like a human and solves automatically. I pay for captcha solvers for hcaptcha which is worse but cloudflare is just cancer. It’s made the web unusable

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#165

Cloudflare works much, much better than Google - Google captchas for me, on Tor, are flatly impossible, always. They never let get through, no matter whether you get them right or wrong. You always get "try again". The problem I do have with CF is their captchas seem to require human interaction on the page, and this makes getting through them problematic when you open half a dozen tabs, and each loads a CF captcha,…

Ehhh... maybe...

Last week I had a run of (legacy) Cloudflare captchas on sites protected by CF to solve of "select all the boxes with motorcycles in", and despite doing it fastidiously and correctly (although I never know how to handle the boxes with like 3 pixels of object in but are otherwise clear), I had to do it like 5 times with different images, until suddenly it was happy.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#166
I absolutely hate cloudflare for the same reason you have. Besides traveling and using a VPN, I like in Hong Kong, a country that many sites have decided to block completely. It's very frustrating that cloudflare easily enables those kind of blanket bans for no reasons.

Cloudflare is the enemy of open web.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#167

Earlier quoted context omitted.

They are not targeting people like you. Bots are the target. If you look like a bot, how are they going to distinguish?

> If you look like a bot, how are they going to distinguish? Some non-existant system of attesting that I'm person X (possibly through an e-ID card) who has issued a client certificate Y (cert chain, using my e-ID cert to sign) to be used with my device Z (presumably with a device fingerprint or IP range attached to the cert). Of course, this would mean no privacy, but that's not that different from being signed in t…

Ok, what does the venn diagram of:

1) People who anonymize their IP, use Linux, a browser with noscript, etc

2) People who are OK with having a government issued digital id and having to use it to access the internet

...look like, in your opinion?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#168

CrimeFlare is not interested in these problems for the users. If you have access to the hosting side, you can adjust the bot score for specific connections/clients. But consumers don't matter to CF so apart from jumping through their hoops, there's nothing better you can do. Unless you accept the racket of course, start paying them and proxy your traffic through the CF workers https://github.com/pellaeon/cloudflare-w…

> If you have access to the hosting side, you can adjust the bot score for specific connections/clients

Only for Enterprise customers [1].

[1]: https://developers.cloudflare.com/bots/plans/bm-subscription...

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#169
post #102

Earlier quoted context omitted.

https://jychp.medium.com/how-to-bypass-cloudflare-bot-protec... and many other posts. Haven't looked into this in a while, so can't tell you exactly how effective it is today. (Definitely corrects the high bot score of your IP though)

Sounds like all it does is make your IP reputation slightly better than tor, which is a pretty low bar to cross. You'd likely get the same effect from using any other VPN service, so it's not exactly evidence that cloudflare is running a "racket" with its worker product. The linked blog post even touts the fact it's free as an advantage. Rackets typically aren't free.

You also change the headers / TLS signature, because it's their worker doing the connection. That covers quite a lot already.

The racket is not in the workers themselves, but rather cloudflare both protecting from internet abuse and protecting sites which sell the abuse services. (For example hosting WebStresser) I meant that by giving them more traffic and accepting that as a workaround, we'd be saying "I'm ok with that".

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#170

Earlier quoted context omitted.

We cannot get them to agree on cookie banners and you’re talking about something much more complicated. Hey, by the way, would you trust some Chinese or Russian root certificate? The question is irrelevant, frankly. Consider this: you’re living in Germany today. You trust the German government. They handle all your logins using that eID. What if in February AfD comes to power? Do you still trust the German government…

> We cannot get them to agree on cookie banners and you’re talking about something much more complicated. Another good example of something that’s technically feasible and not that complex, but was made infeasible due to either ignorance or malice, with all of the dark UI patterns and scummy behaviour. > Hey, by the way, would you trust some Chinese or Russian root certificate? Most people already do: https://chromiu…

> Revoking the eID and anything dependent on it would be akin to your passport being taken away.

Is it? If my eID is used for logging in to my bank and said eID is revoked, I can no longer log in to my bank account. That’s completely different than a locked up passport.

> Essentially the modern day digital equivalent of getting your Google account banned by some bot, if you use that account for auth in a bunch of places.

Use a custom domain, don’t make your kingdom dependent on the gmail.com address.

I don’t know, for me the perfect amount of government oversight is “as little as possible”. There’s zero need for the government to mediate between me and my bank, or some random service provider on the internet.

What you’re describing sounds like a fun technical challenge assuming a perfect world. For example: who decides which countries’ certificates should be revoked? Who decides who is the rogue one? Even that is stretching it too far. Can I simply download a browser without some selected certificates? If the technology is so great, why isn’t it widely adopted today

Those are all rhetorical questions. You don’t have explain PKI to me.

Post reply on HN