Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

211–220 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#213

Earlier quoted context omitted.

The sad part is that it's trivial to get around CF's bot protection if you're writing a bot (just use curl-impersonate and buy residential IPs), but it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address.

It's the same for spam email, yet most spam gets caught in spamassassin rules that were written 20 years ago and haven't seen much improvement since then. Most bad guys just don't bother to do anything above the bare minimum. For example, I see lots of email getting caught in a rule that checks for incorrectly formatted pseudo-Outlook mailer header, which is trivial to circumvent if you pay any attention to it (the d…

see also: The surprising effectiveness of simply asking the spam server to try again(sometimes called graylisting). It shouldn't work at all, but proves to filter an awful lot of the worst mail noise.

http://man.openbsd.org/spamd

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#214
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

It feels weird that a completely US based Recruit acquisition shows such a typical Recruit behavior...

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#215

What do you mean impassable challenge...? Why isn't it passable? Are you a robot?

From website perspective, yes. GP is likely using extreme ad-blocking and/or coming from regions where tons of bots and/or unwanted traffic are also from. In those cases, some/many human users could be misidentified as bots with little incentives to website admins to rectify.

And it's discriminatory, yes.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#217

Earlier quoted context omitted.

While you hit the nail on the head, I am still surprised that so many tools targeted at people like me (web hosting, developer tools, etc.) are protected that way.

Most developers I've met were actually similarly lazy... we just use Chrome on Mac, and don't really want to deal with VPNs unless our employers force us to. The last few Firefox holdouts also switched after running into various WebGL/Canvas/etc issues. The same attitude that leads us to focus on "happy path" users and ignore edge cases often also causes us to sheeple into that same basic dev group. Long gone are the…

That is not an excuse to give in to the cloudflare's agenda of centralizing everything. Bad things have happened, is happening and will continue to happen if one entity has this much control over the internet traffic

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#219
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

Makes me wonder. If it's illegal to deploy bot protection on unsubscribe links, and there are massive lists of leaked email addresses available, surely someone has tried to mass-unsubscribe tons of email addresses from tons of mailing lists?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#220
post #2

You're collateral damage in the web's war against bots :( Unfortunately, I think the Cloudflare challenges are designed to filter out users similar to your profile... once you stray far enough from the norm, it just looks like a bot / suspicious traffic to them. Statistically there's not enough users like you (privacy-conscious Linux users on nonstandard browsers) for them to really care enough to do anything about i…

I don't buy this because using Chrome is what most bots probably do right? Headless chrome is easy.
Post reply on HN