Live data from Hacker News

Cloudflare is turning off the internet for me

blog.dijit.sh

201–210 of 335 posts

Re: Cloudflare is turning off the internet for me

#201
post #54

I've been noticing a larger and larger portion of sites in google results have been taken over by something . They all act the same way, and act similar to cloudfares checks. You get a big green dot on the screen first and then a bunch of redirects. I've not read anything about it, but probably 1/15 of my google result clicks end up there. How does google not know these sites have been taken over and keep them on the…

I have a little tip for you; right-click your back arrow, and choose your search page from the list.

Another tip: block js globally(uBlock Origin) and white list sites you trust.

Re: Cloudflare is turning off the internet for me

#202
post #21

Earlier quoted context omitted.

They blocked Nazis after some attack or something like that. The founder wrote an emotional letter back then, acknowledging how bad is this and how he hates becoming the internet police.

It wasn't some attack. The guy behind the Daily Stormer stated publicly that Cloudflare not shutting off his service means they agree with and support the Daily Stormer's content. > The tipping point for us making this decision was that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology. [0] That's in a blog post which is a follow up to a leaked memo. [1] [0] https://blog.…

Do you have any link to what The Daily Stormer actually said? All I can find is various rewordings of it. They will of course be reworded in the least charitable way in most cases.

Re: Cloudflare is turning off the internet for me

#203
post #17

The problem presented by services like ReCaptcha and Cloudflare is a tough nut to crack. They're silently embedded in a huge portion of modern websites, and the average user will never even know about them. But it seems to be way too easy for them to blanket-ban or serve an absurd amount of captchas to powerusers, linux gurus, privacy geeks, or anyone with the wrong combination of browser+addons. And the failures (as…

Yeah, you can't really talk about downsides of Recaptcha/Cloudflare without also acknowledging the extreme amount of malicious actors and abuse on the internet. We're in a "this is why we can't have nice things" predicament and you have malicious actors to thank for that, yet most people on HN only seem capable of attacking the few affordable solutions to that problem. I'm even down with the theory that Cloudflare is…

> It's easy to shit on everything. Let's hear some real solutions.

My solution more and more is to just not bother with it. If a site is unreadable because I'm using uBlock and uMatrix, and I have to spend more than a minute or two tweaking things, then I just leave.

That said, I don't have any problem with Cloudflare. I'm much more annoyed by the overuse of *.googleapis.com. I'd love if somebody would setup a service that I could point my hosts file at so that googleapis.com silently went somewhere else.

Re: Cloudflare is turning off the internet for me

#204
post #92
post #83

It appears that you may have made some modifications to your user agent string. If you revert your user agent to the one provided by default by your browser vendor everything will be fine.

It appears that setting it to the same as Chromes does indeed work! for context this is what I had set (and, for quite some time it was working): "Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecho/20100101 Firefox/57.0" Ironically I set this so that I could continue logging in to google. Since I had been unable to log in to google-apps without setting this user agent string. What did it fail on? the mis-spelling of "Gec…

It's the severely-outdated Firefox version number. Spambots and crawlers sometimes have user-agent strings corresponding to very old browsers, because they were set once when the bot was created and then never updated. On an unrelated site that I run, we get a lot of traffic with user agent strings corresponding to implausibly-old browsers, and it's ~100% bots.

Re: Cloudflare is turning off the internet for me

#205
post #83

It appears that you may have made some modifications to your user agent string. If you revert your user agent to the one provided by default by your browser vendor everything will be fine.

If omit the user-agent string or, even better, the user-agent header itself, everything will be fine, too.

Tested with Cloudflare and many, many other servers over many years.

On the whole, taking the entire web into account, it is rare for a user-agent string to be required.

However, it has become common for servers to make many assumptions based on user-agent strings.

I would guess there are many tech workers whose entire job rests on the assumption that user-agent strings are always present, rarely manipulated^1 and accurately represent the user's hardware and software.

1. For example, changed using "Developer Tools" in the major browsers. Google's browser has some user-agent presets for "testing" in DevTools (Ctrl-Shift I, Ctrl-Shift P, Drawer Show Network Conditions). Those should be safe to use for logins to Google websites. Try them out, e.g., when logging into Gmail and watch how the user can request vastly different web page styles based only on user-agent string.

Re: Cloudflare is turning off the internet for me

#206
post #148

Earlier quoted context omitted.

Yeah, because most custom browsers are malicious. They have the data to prove it. This isn't a side feature, it's a direct feature that is 100% intentional. They maintain a backend whitelist of known "good" user-agents. Curl is on that list and there are a few others outside of the big players. Most people building custom browsers are doing it to do something Chrome would disallow. One instance would only supporting…

This can't only be based on user agents, otherwise it would be pretty useless. I can set my Firefox's user agent to curl if I feel like it, the same way malicious actors would just set the user agent in their scripts / headless browsers etc.

it's not exclusively UA, but in this post the author does say taking the most up-to-date Chrome UA did resolve his issue I believe.

You would be SHOCKED how many bad actors use an outdated UA or some random string they think is funny. This portion of CFs mitigation isn't meant to be hyper-advanced detection, just bounce out the low hanging fruit. They have other security services that aim to mitigate the more advanced stuff (like the WAF).

Re: Cloudflare is turning off the internet for me

#207
post #92

Earlier quoted context omitted.

It appears that setting it to the same as Chromes does indeed work! for context this is what I had set (and, for quite some time it was working): "Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecho/20100101 Firefox/57.0" Ironically I set this so that I could continue logging in to google. Since I had been unable to log in to google-apps without setting this user agent string. What did it fail on? the mis-spelling of "Gec…

It's the severely-outdated Firefox version number. Spambots and crawlers sometimes have user-agent strings corresponding to very old browsers, because they were set once when the bot was created and then never updated. On an unrelated site that I run, we get a lot of traffic with user agent strings corresponding to implausibly-old browsers, and it's ~100% bots.

November 2017 is “severely outdated”?

https://www.mozilla.org/en-US/firefox/57.0/releasenotes/

Re: Cloudflare is turning off the internet for me

#208
post #200
post #82

I really wish you could just directly pay for services. A hundredth of a cent per visit would make most abuse un-profitable while still allowing very affordable procrastination.

This would make search engines impossible, sadly.

Contrary, I think it would make search engines better!

Re: Cloudflare is turning off the internet for me

#209

I don't see anyone here mentioning this, so I will. CloudFlare supports PrivacyPass, a third-party, privacy-preserving way to do proof-of-work for websites. Basically, you do some small amount of CPU work and get 30 tickets your browser can transparently redeem for access to a site. That's a pretty clever way to both deter bad actors and ensure legitimate users get uninterrupted access to websites.

AFAIK the Privacy Pass protocol has nothing to do with proof-of-work. It's just a way to allow users to solve a CAPTCHA once and re-use that single solution across multiple sites without jeopardizing privacy. Reduces the number of CAPTCHAs you see, but doesn't eliminate them entirely. What you're talking about is more like what Hashcash does, where it essentially replaces CAPTCHAs with a cryptocurrency miner, such th…

Captcha is also a kind of proof-of-work, and a very nasty one, where users are made to do the work instead of computers.

Re: Cloudflare is turning off the internet for me

#210
post #17

The problem presented by services like ReCaptcha and Cloudflare is a tough nut to crack. They're silently embedded in a huge portion of modern websites, and the average user will never even know about them. But it seems to be way too easy for them to blanket-ban or serve an absurd amount of captchas to powerusers, linux gurus, privacy geeks, or anyone with the wrong combination of browser+addons. And the failures (as…

I'd love to use an open source/more beneficial to society version of ReCaptcha - say validating OpenStreetMap data/project Gutenberg/something else. Maybe this already exists and I don't know about it!

Would sites then move to this and reduce the lock in and inflexibility with ReCaptcha?

Post reply on HN