Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

201–210 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#201

Earlier quoted context omitted.

> We cannot get them to agree on cookie banners and you’re talking about something much more complicated. Another good example of something that’s technically feasible and not that complex, but was made infeasible due to either ignorance or malice, with all of the dark UI patterns and scummy behaviour. > Hey, by the way, would you trust some Chinese or Russian root certificate? Most people already do: https://chromiu…

> Revoking the eID and anything dependent on it would be akin to your passport being taken away. Is it? If my eID is used for logging in to my bank and said eID is revoked, I can no longer log in to my bank account. That’s completely different than a locked up passport. > Essentially the modern day digital equivalent of getting your Google account banned by some bot, if you use that account for auth in a bunch of pla…

> Is it?

Pretty much the same failure mode, just with different immediacy. No more travel, no more ability to start using new banking services, no more proving identity for becoming employed, pretty much anything that needs you to provide valid governmental ID (ID card or passport) and doesn't accept alternatives.

On the opposite end of that, both those services might accept something like a driver's license and the banking service might allow you to log in with their app, or a similar identity provider as a backup.

> There’s zero need for the government to mediate between me and my bank, or some random service provider on the internet.

Who else should we depend upon for verifying the identity of someone? Because currently it's a hodgepodge, especially when some places treat the equivalent of an SSN as a secret or have other half baked mechanisms, whereas in actuality it's a problem that's been solved far better, the same way how e-signatures work here when a single competent authority implements them well (certs on the e-ID card, you choose what to sign, but there's both data integrity and non-repudiation, a service that everyone integrates with and it is basically treated as a commonplace utility).

> What you’re describing sounds like a fun technical challenge assuming a perfect world. ...

Yeah, that's about it. Have a good one!

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#202

The problem is that any solution so far proposed for this is very privacy-unfriendly. For example, Google proposed https://github.com/explainers-by-googlers/Web-Environment-In... and this was shot down by privacy advocates (for very good reasons). So basically the choice for website operators is either to fight the bots and accept that their service will be unusable for some subset of their users or not fight the bot…

> either to fight the bots and accept that their service will be unusable for some subset of their users or not fight the bots, which will lead to their service becoming unusable for everyone.

2/3 of the issues OP listed would not make the service unusable for anyone if the botcheck were removed. 1. What would be the problem with allowing "bots" to opt out of receiving marketing emails? Why do I need to be a human to tell you to stop spamming me? Who is running such a bot, for what purpose? 2. What would be the problem with allowing a "bot" to log in to an already-verified human account a single time?

The only situations where you actually need to confirm that a user "looks human" is for repeated connection attempts in quick enough succession to matter (DDoS prevention), or when they want to do something that someone would actually write a nefarious bot to do (mainly just creating posts/messages visible to other users).

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#204
AWS WAF is even worse. I recently moved from Australia to India, and quite a few high-profile websites are now completely inaccessible to me because WAF seems to be legitimately broken. Two such sites: https://officeworks.com.au/ and https://centrecom.com.au/. You successfully complete their annoying thingummy, and it redirects you… to the same Human Verification CAPTCHA. This has been the case for at least half a year, so it’s not a recent breakage.

If I tunnel via my VPS which is still in Australia, then I can access it.

But complete blocks via Cloudflare have also been a problem: I had to do something with VicRoads as part of selling my car, and was blocked outright when I got to the actual form page. Had I not had my VPS in Australia, I don’t know what I would have done.

My IP address is massively shared (CGNAT) with plenty of botnet around, so I’m frequently troubled by Cloudflare, but not often outright blocked, and if challenged rather than blocked, I’ve never had any problem with it. Linux, Firefox.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#205
post #2

You're collateral damage in the web's war against bots :( Unfortunately, I think the Cloudflare challenges are designed to filter out users similar to your profile... once you stray far enough from the norm, it just looks like a bot / suspicious traffic to them. Statistically there's not enough users like you (privacy-conscious Linux users on nonstandard browsers) for them to really care enough to do anything about i…

The sad part is that it's trivial to get around CF's bot protection if you're writing a bot (just use curl-impersonate and buy residential IPs), but it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address.

We bypassed it by switching to starlink. Now my IP address is a too-big-to-fail CGNAT.

The old IP address was a mom-and-pop CGNAT.

Thanks CF, for protecting us from capitalism, I guess?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#206
Cloudflare is so embedded into so many important services (like some other companies, including Google), that they need to be thinking of their role as having some government-like responsibilities.

For example, for starters, Cloudflare and Google need to find ways so that individual people who're wrongly being locked out of services by the company, have some way to get that unlocked. Not "sux2bu we dont do support bro".

(Then they can start thinking about the next step, which is due process, and what it means to wrongly lock out someone in the first place.)

That said, as an immediate pragmatic matter, one debugging tip with your Firefox is to go to the `about:profiles` URL, and temporarily create a new profile, and without using any Firefox sync feature, and see if Cloudflare lets you through, and then incrementally add back in your extensions and preference customizations, and see if/when CF stops letting you in. (Not that it will necessarily identify the sole and exact trigger, since they might be using scores of multiple factors, but it will be evidence of one thing that pushes it over the edge. And maybe get you to a compromise setup that lets you do your work for now.) Also helpful is to have alternate browsers installed; personally, I keep Chromium installed, as my "violate me every possible way, if you'll just let me access this one page/site I really need right now".

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#207
post #129

Earlier quoted context omitted.

The sad part is that it's trivial to get around CF's bot protection if you're writing a bot (just use curl-impersonate and buy residential IPs), but it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address.

This is great for bypassing the server side bot detection but not the client side one, where it will attempt to verify the integrity of your browser environment.

Well yeah, if you’re a legitimate user, CF will block you.

It’s only easy to bypass if you’re scraping or doing nefarious stuff.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#208

Earlier quoted context omitted.

Please do not use that term! I cannot fly! I don't believe in that sort of thing, either. I'm libertarian, and would rather not sue over much of anything! Especially something that would lack standing. Oddly enough, I haven't been interrupted by CloudFlare too much. I do use Firefox on Windows, but haven't gotten into Linux as of yet. Although it might be fun, I'd probably break it too much lol! I do run adblock, mos…

(1) I was working for a small town web design shop in a town dominated by two higher ed institutions circa 2005 where I was finishing up a system which handled applications for an internship program run by the NSF. (e.g. complex forms, scanners to stop people from uploading CVs in Word that are full of malware, etc.) I was talking w/ the principal about how bad the usability was of applications in higher ed and that…

Polling for time sensitive things sucks. But for RSS, why not just poll once a day? Even if you're polling once an hour, a 304 response is, what, a few hundred bytes?

I just checked my own server logs, and HTTP 200 responses were 12.7% of the total requests against my rss.xml. Which is suboptimal I guess (I haven't made a single post this year) but isn't outrageously terrible.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#209

Earlier quoted context omitted.

I'm in a similar boat. A UK bank thinks I'm one of their customers (someone with a similar name). The reply address is no-reply@ and I'm not about to call a foreign bank.

Quick note that if you use a proper email hosting service, or host yourself, you can add a sender block rule to eliminate this nuisance.

Are there email services which don't allow you to block addresses or keywords?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#210
post #196

Earlier quoted context omitted.

Ehhh... maybe... Last week I had a run of (legacy) Cloudflare captchas on sites protected by CF to solve of "select all the boxes with motorcycles in", and despite doing it fastidiously and correctly (although I never know how to handle the boxes with like 3 pixels of object in but are otherwise clear), I had to do it like 5 times with different images, until suddenly it was happy.

legacy Cloudflare captchas? I thought they eliminated them back in 2023? Their announcement is pretty clear on them: "Cloudflare will never issue another visual puzzle to anyone, for any reason." https://blog.cloudflare.com/turnstile-ga/ Are you sure it's not fake? For example archive.is sometimes sends me orange-colored CAPTCHAs (with "select all the boxes" style) that are never accepted; but if one looks closer at…

I thought they had as well, which was why I was surprised to see them.

I can't remember the site I saw them on, so I don't know for certain, but the site was definitely protected by Cloudflare, and I'm not really sure what you mean by "fake" - they were definitely CAPTCHAs with image tiles, but I guess I don't know for certain they were coming from Cloudflare servers.

Post reply on HN