Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

191–200 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#191
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

You block this guy from the internet for a week —- for no apparent reason —- and then you come in here with a nitpick about how another related system works? Really?

A wrong nitpick, even! Way to look like the asshole.

Re: You don’t want to be on Cloudflare’s naughty list

#192

Earlier quoted context omitted.

Clearly CF has a crystal ball /s. Once the IP address I don't own is released and assigned to some other router how do you think CF determines the new IP address for the individual/home? Unless this person is running the CF Dynamic DNS service which gives CF the IP address, I'm not sure CF would have any reasonable validation techniques to determine who is what given the size of residential networks.

Cookie on their validation page? Browser fingerprint hopping IPs in the same block?

Bingo

Re: You don’t want to be on Cloudflare’s naughty list

#193

Earlier quoted context omitted.

I live in a country with censored internet. What you are doing is harmful. I can only hope whatever you provide is irrelevant enough.

I'm sorry. I have a colleague based out of Venezuela. We've had to work together to get tunnels and vpns configured so that he can get uncensored and secure internet access. But Tor is an enormous source of abusive traffic and if I don't filter it, then that's harmful to site owners. I'm being forced to choose between the needs of people that I know, work with, and depend on financially, and the needs of people in co…

There are probably more sophisticated options that would solve your problems than simply blocking it.

Re: You don’t want to be on Cloudflare’s naughty list

#194

Earlier quoted context omitted.

there are multiple other large CDNs out there... its a lot more like 5 market leaders tbh

But how many of them: 1) refuse to take responsibility for content they host by claiming they don't host 2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination 3) make the abuse reporting process intentionally difficult and time-consuming 4) want to aggregate all the DNS data they can by making a deal with Firefox to turn on DNS-over-https by default…

1) refuse to take responsibility for content they host by claiming they don't host >CDNs don't host content, they proxy it

2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination >Not large parts of the internet, scammy and attacky parts of the internet. If the rules were public they wouldn't be effective.

3) make the abuse reporting process intentionally difficult and time-consuming >simply untrue, every abuse report i have filed has had an answer back within 24hrs

4) want to aggregate all the DNS data they can by making a deal with Firefox to turn on DNS-over-https by default without asking or even informing end users >this is a good thing as they are audited as having not keeping logs of dns queries

5) want to re-centralize the Internet, in part so they can mix bad actors with good, in ways that make blocking next to impossible >again every cdn centralizes the internet, and many sites need this protection

Re: You don’t want to be on Cloudflare’s naughty list

#195
post #79
post #30

Earlier quoted context omitted.

FYI you're responding to the cloudflare CTO

It’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.

I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"

Re: You don’t want to be on Cloudflare’s naughty list

#197

Earlier quoted context omitted.

I live in a country with censored internet. What you are doing is harmful. I can only hope whatever you provide is irrelevant enough.

I'm sorry. I have a colleague based out of Venezuela. We've had to work together to get tunnels and vpns configured so that he can get uncensored and secure internet access. But Tor is an enormous source of abusive traffic and if I don't filter it, then that's harmful to site owners. I'm being forced to choose between the needs of people that I know, work with, and depend on financially, and the needs of people in co…

I'm a noob, can you give me a pointer?

What kind of abusive traffic is coming through Tor and why do they do it?

Re: You don’t want to be on Cloudflare’s naughty list

#198

Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…

An alternative that preserves some privacy also doesn't seem that hard to imagine... though it probably has its own can of worms*. Basically, the core problem is digital identities (accounts, IPs, phone #s etc.) are cheap to create (even considering captchas and all) so fraud is easy. The solution could be just to make it "costly" to create new digital identities. For example, you could get a "verified but anonymous"…

Your idea is comes from a good place, but identity theft is already a thing in the real world. Digital identities would also be very stealable. This malware more harmful in the long term. Imagine if your Twitter gets hacked and your digital identity makes it so your Gmail gets blocked.

Similar, the internet is already very difficult for the people with limited means. This would make it even harder.

Re: You don’t want to be on Cloudflare’s naughty list

#200
post #79

Earlier quoted context omitted.

It’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.

I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"

Well, apparently they scared this user into installing their browser extension, so it sounds like this incident was a win for them.
Post reply on HN