Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

241–250 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#241

Earlier quoted context omitted.

Please do not use that term! I cannot fly! I don't believe in that sort of thing, either. I'm libertarian, and would rather not sue over much of anything! Especially something that would lack standing. Oddly enough, I haven't been interrupted by CloudFlare too much. I do use Firefox on Windows, but haven't gotten into Linux as of yet. Although it might be fun, I'd probably break it too much lol! I do run adblock, mos…

(1) I was working for a small town web design shop in a town dominated by two higher ed institutions circa 2005 where I was finishing up a system which handled applications for an internship program run by the NSF. (e.g. complex forms, scanners to stop people from uploading CVs in Word that are full of malware, etc.) I was talking w/ the principal about how bad the usability was of applications in higher ed and that…

Sure I believe in accessibility, just not lawsuits, yes two different things! If I don't like the way a service works, I cut ties with that particular service, and don't complain. Sometimes I'll contact them first, to advise them they have an accessibility issue, but I'm nice about it. I did this last year actually, I was testing feeder, I contacted them, to let them know I would be testing the service. When it really wasn't working for me, I needed them to make some tweaks, when the tweaks they made didn't work for me, mostly change the tabbed navigation that I wasn't using, I left. That being said, I like RSS a lot! However RSS readers these days leave a whole lot to be desired! I've been looking for one since 2013. I did use Miniflux for a while, until the service that was managing it for me shut down. I didn't learn terminal when I was young lol. I also have chronic migraines, so not sure if I could try and fix that now.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#242

Earlier quoted context omitted.

Yes, sure, but 5% includes stock firefox, zero modifications, zero plugins. Might still be a business decision, but it's like saying "we'll drop any emails that indicate a mail client other than apple mail/gmail/outlook".

While not that strict, see how far you get hosting your own email as far as not being rejected or automatically classified as spam

And I'd include that as well: if your server rejects emails because of your spam-decisions, you can't claim "we've never received that email". Either you don't use email for any legally-binding communication ever, or spam-filtering is a you-problem, not an everyone-else-problem.

It's not surprising that the strongest protections always happen on the unsubscribe links, but not on the subscribe-links. That just needs to be fined out of existence, just like "you can order with one click, but you need 50 clicks and a three-hour-conversation to cancel".

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#243
post #130

Earlier quoted context omitted.

Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.

I'm in a similar boat. A UK bank thinks I'm one of their customers (someone with a similar name). The reply address is no-reply@ and I'm not about to call a foreign bank.

I had the same happen with a AU insurance company that also made it hard to reach them.

I sent an email to their regulator that this company keeps sending me confidential information about one of their clients. It took one day until I received an email from the company informing me that they've corrected the mistake and I shall no longer receive any emails, and it worked, I haven't received a single one since.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#245

i recommend everyone test the web with TOR to see how dead the public internet is. Reddit won't respond. Many sites have a 10-minute captcha challenge (e.g. substack). So many sites have deployed countermeasures like Cloudflare, but they aren't actively monitoring the failure mode on those countermeasures. The web is on it's knees and these countermeasures are another nail in the coffin if we don't act fast.

Why would anyone care about how a site displays on TOR aside from privacy nerds? The average internet user doesn't even know what TOR is. Though they might have heard the words "Dark Web" once or twice.

it's a canary

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#246
post #2

You're collateral damage in the web's war against bots :( Unfortunately, I think the Cloudflare challenges are designed to filter out users similar to your profile... once you stray far enough from the norm, it just looks like a bot / suspicious traffic to them. Statistically there's not enough users like you (privacy-conscious Linux users on nonstandard browsers) for them to really care enough to do anything about i…

> Site owners don't care either since you're usually like 1-2% of users at most, and typically also the same ones who block ads, etc., so they don't mind blocking you

I do believe that it is true that many site owners wouldn't care. But I suspect that in the vast majority of cases they don't actually know. Cloudflare probably shows them a nice dashboard about all of these blocked "threats" and they don't know better than to question it.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#247
post #221

Vaguely related, youtube is lately doing a lot of unnecessary forced logouts & reconfirm password. I'm literally on a static IP. On the same computer & browser. With the same cookies. Not accessing anything particularly sensitive. There is no way in hell they don't know precisely who I am & that its me.

Is it possible your account is being attacked in the background?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#248

AWS WAF is even worse. I recently moved from Australia to India, and quite a few high-profile websites are now completely inaccessible to me because WAF seems to be legitimately broken. Two such sites: https://officeworks.com.au/ and https://centrecom.com.au/ . You successfully complete their annoying thingummy, and it redirects you… to the same Human Verification CAPTCHA. This has been the case for at least half a y…

As another aussie expat abroad, leaving a box behind at my parents place for an Australian residential IP has got to be one of the most unexpectedly great things I've done.

Wireguard/Tailscale and my parents having access to cheap renewable power are the real enablers ofc.

To anyone moving abroad in the near future - leave a box behind with your parents/close friends, it's well worth the trouble if they're ok with you occasionally mooching some bandwidth. You absolutely won't regret it

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#249
Cloudflare puts challenges on their abuse contact page and rate limits it to much slower than human speed. It's also still broken after years in that you can't report abusers who register domains through Cloudflare and/or host their DNS using Cloudflare.

They really don't want feedback from people who don't pay them.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#250
post #130
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.

Is this Hertz? Somehow Hertz in Mexico decided to add my email address to their mailing list, and I tried to complain to every level of Hertz to get them to stop. Their hosters didn't care, their upstream didn't care.

I decided to download larger files from their web site a few tens of millions of times, which I think cost them a few hundred dollars. Unethical? Perhaps, but I'm not the kind of person who just accepts that companies are too large to have humans that can communicate and that I should just accept their harassment.

It worked, though. I finally got a response from Hertz saying they were going to "get to the bottom of it", and I finally stopped getting their spam.

Post reply on HN