Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

191–200 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#191
post #57

Earlier quoted context omitted.

All host info not accessible via X11 protocol is hidden, for example font list, is replaced with generic one. For even more protection, run VNC server with common resolution in the container and connect to it using VNC viewer. In this case firefox provides a super generic profile (latest debian with mesa GPU), making this browser very hard to distinguish from others. This has some downsides however: First, you cannot…

mullvad browser is pretty much this, but without messing around with containers. One fingerprint for all users, with the same font list, resolution, canvas behavior, etc. https://mullvad.net/browser

looking at https://mullvad.net/en/browser/hard-facts , Mullvad browser is much more extreme: many APIs blocked, always incognito mode... I would not be surprised if this blocks some sites.

the container approach on the other hand is bog-standard firefox.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#192

The problem is that any solution so far proposed for this is very privacy-unfriendly. For example, Google proposed https://github.com/explainers-by-googlers/Web-Environment-In... and this was shot down by privacy advocates (for very good reasons). So basically the choice for website operators is either to fight the bots and accept that their service will be unusable for some subset of their users or not fight the bot…

Why "fight the bots" anyway? If software that is acting out the will of some humans somewhere is retrieving static contents, what's the big deal?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#193
post #44

Earlier quoted context omitted.

The sad part is that it's trivial to get around CF's bot protection if you're writing a bot (just use curl-impersonate and buy residential IPs), but it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address.

> it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address There are residential-IP-backed VPN services that you can use just like commercial VPN services — but they're mostly built on the backs of botnets, so it's ethically questionable to use them.

To note, IP is only a part of it, and the full extent of what's baked into a CF score will never be explicited (for obvious reasons).

CloudFront being way past the simple blocking of IP addresses, I wouldn't be surprised if a mismatch between your IP block and your language/cookies would be enough to lower your score.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#194
post #104

Yes. I wrote about this on my blog six months ago [1]. CloudFlare has positioned itself as the doorman of the Internet, deciding who gets to visit shitty websites written by AIs and who doesn't. Every time I try to visit a website and get blocked by this company and its unnecessary services, I congratulate myself for avoiding yet another terrible website and move on with my life. [1] https://ido50.net/content/what-ch…

The doorman for the internet. well said. Someone need to study how this is likely the most successful marketing campaign ever for a cloud provider.

I don't think they needed much marketing? A lot of website operators want bot/DDoS protection, and cloudfare offers service which works (at least for overwhelming majority of users), and is absolutely free.

Offering free stuff which works and that many people want is how internet companies get big.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#195
My workaround for this as a person who travels a lot was to buy 2 raspberry Pi’s and put them at my family houses in different countries and use Tailscale on them as exit nodes, behaving like my own VPN. The residencial IP address makes things a lot easier when connecting from random places.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#196

Cloudflare works much, much better than Google - Google captchas for me, on Tor, are flatly impossible, always. They never let get through, no matter whether you get them right or wrong. You always get "try again". The problem I do have with CF is their captchas seem to require human interaction on the page, and this makes getting through them problematic when you open half a dozen tabs, and each loads a CF captcha,…

Ehhh... maybe... Last week I had a run of (legacy) Cloudflare captchas on sites protected by CF to solve of "select all the boxes with motorcycles in", and despite doing it fastidiously and correctly (although I never know how to handle the boxes with like 3 pixels of object in but are otherwise clear), I had to do it like 5 times with different images, until suddenly it was happy.

legacy Cloudflare captchas?

I thought they eliminated them back in 2023? Their announcement is pretty clear on them:

"Cloudflare will never issue another visual puzzle to anyone, for any reason."

https://blog.cloudflare.com/turnstile-ga/

Are you sure it's not fake? For example archive.is sometimes sends me orange-colored CAPTCHAs (with "select all the boxes" style) that are never accepted; but if one looks closer at them, it actually never says "cloudflare" on them anywhere, nor there is a logo (it does this because it has a long-standing feud with cloudflare re users' privacy).

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#197
post #130
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.

I'm in a similar boat. A UK bank thinks I'm one of their customers (someone with a similar name). The reply address is no-reply@ and I'm not about to call a foreign bank.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#198
post #130

Earlier quoted context omitted.

Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.

I'm in a similar boat. A UK bank thinks I'm one of their customers (someone with a similar name). The reply address is no-reply@ and I'm not about to call a foreign bank.

Quick note that if you use a proper email hosting service, or host yourself, you can add a sender block rule to eliminate this nuisance.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#199
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

Don't worry, the next administration is likely to eliminate any rules like that.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#200
Slightly off topic, but Microsoft ones are even worse - when I tried to sign up to OpenAI/get a new Microsoft account, the captcha were so difficult that it took me 5 minutes to solve (unsuccessfully). As a libre wolf user with very strict settings, I think privacy-aware users bear the externalities of this bot vs server arms race.
Post reply on HN