Blocked by Cloudflare
241–250 of 473 posts
Re: Blocked by Cloudflare
#242Earlier quoted context omitted.
Would you be willing to share a rayID you see during one of these looping challenges? I'm the PM for Cloudflare's challenge platform, and we'd love to look into this. RayIDs contain no PII so you can share publicly, or feel free to drop me an email at amartinetti at cloudflare. We'll also release a reporting mechanism soon, so in the future you can let us know when you see these issues and we can react to them quickl…
Such a classic and incredibly annoying SaaS PM move. Pinky-promise that you mean well, pretend to be invested in the issue, ask customers to supply evidence and say you'll look into it, followed by radio silence and no follow up whatsoever. Incidentally, another Cloudflare PM for Pages asked me to do the same thing--I shared my account ID, the request, the problem, timestamps, etc...never heard back ever, request wen…
A service has injected itself between you and your goal, it's going to periodically impede you from reaching that goal and then lie to you about why, all while making money off of the arrangement.
Re: Blocked by Cloudflare
#243Earlier quoted context omitted.
You're being a little dramatic. It's incredibly unlikely that millions of innocent users have been blocked, and unless you have data to the contrary you shouldn't make such a claim. You know what else is harmful to the concept of the open internet? The enormous malicious botnets and other endemic problems that require a solution like CloudFlare.
For every one user that makes their way on here and finds and posts here on this thread probably represent 1,000,000 plus normal users An open web is open for everyone/thing not just classes of beings you select. Bots and users can both be malicious and both can be positive.
> An open web is open for everyone/thing not just classes of beings you select. Bots and users can both be malicious and both can be positive.
This I agree with. I run an archiver ~monthly on a subset of my month's browsing history, and I'd hate if that got me blacklisted from Cloudflare-backed sites for a benign purpose. (See also the idea of remote attestation)
Re: Blocked by Cloudflare
#244Earlier quoted context omitted.
I’m no Google fanboy but I wasn’t satisfied with this: > Chrome will happily collect as much private information about me and my browsing history and share them with select parties, as needed What information does Chrome provide in this scenario that Firefox doesn’t? It feels like backward logic: it worked in Chrome therefore it must be because Chrome gave extra info. In reality it could be a whole bunch of things, s…
A third browser... like what? Chrome and Firefox are all that exist now, unless you have access to a Mac with Safari.
Re: Blocked by Cloudflare
#245The author did not specify which project he was trying to access so I picked a random one to test from /explore/projects/topics/bioinformatics. No problem accessing it without a web browser. TLS1.3. No SNI.
Re: Blocked by Cloudflare
#246Earlier quoted context omitted.
But today everything but Firefox is Chromium. That's a little different
And 20 years ago everything was IE (at >90% penetration)
Like you have the illusion of choice, that's what I'm talking about and that's different
Re: Blocked by Cloudflare
#247Re: Blocked by Cloudflare
#248Earlier quoted context omitted.
In what way is it an attack? (I know what a mitm is, I'm not asking you to explain that - I'm pretty conversant in the concept of a proxy, I'm asking you to explain why it's an attack specifically)
they block and/or slowdown vast swaths of the internet if that's not an "attack", I don't know what is
Like is it an attack on the site owner - are you saying cloudflare is extorting them or something? That seems unlikely but I agree that would be a form of attack... it also doesn't seem to be what you're saying.
Is it an attack on the user of the website because the website owner successfully denies visitors it does not want? Does that mean that login credentials are a form of attack too? Would an on-prem load balancer or WAF that dropped all traffic from a region or matching patterns still be an attack?
It just doesn't make sense that it's an attack.
Re: Blocked by Cloudflare
#249Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…
The cause of the problem is that your software is faulty by design. 1. IP addresses are to be used for packet routing. Certainly not for assigning "behavior scores" to users in the background. IP addresses say nothing about your visitors, my IP address could have been a complete stranger's IP address yesterday. 2. Deciding who can access half the web based on their TLS signature achieves nothing in the long run excep…
If this was true, Cloudflare wouldn't be a good product used by a lot of sites.