Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

251–260 of 473 posts

Re: Blocked by Cloudflare

#251

Earlier quoted context omitted.

> He quoted you: > >it does seem to indicate that IPv6 is mostly pointless for human users for exactly this reason Huh? There is no quote in that comment: https://news.ycombinator.com/item?id=37051011 . Unless you are referring to a different comment?

I'm referring to your comment that he quoted - https://news.ycombinator.com/item?id=37050359 Maybe you're misremembering - but you wrote it :)

> I'm referring to your comment that he quoted - https://news.ycombinator.com/item?id=37050359 Maybe you're misremembering - but you wrote it :)

'johnklos' did not quote a single word from anyone in the comment I linked, nor a single word from my original comment you linked, let alone an entire phrase, and that was the only response he made from what I can see.

Are you confusing him with a different HN user?

You don't have to believe me, it's accessible to every passing reader right there in the comment chain...

Re: Blocked by Cloudflare

#252

Earlier quoted context omitted.

FWIW I see this with Firefox when I route my traffic through ProtonVPN. It could be caused by someone else's bad behavior on the VPN but I'd hazard a guess that it's more than that.

Do you see the challenge and then you're able to pass? Or does the challenge loop forever?

I see the challenge almost always and most of the time it passes after I manually interact with it but I'll get a looping challenge every once in a while and it persists until I change VPN servers.

I don't think I've seen it for a week or two now but I've certainly encountered it in the past for spans where it'd occur at a frequency of maybe once every two or three days and then go away for a while.

Re: Blocked by Cloudflare

#253
post #228
post #179

Earlier quoted context omitted.

I don't quite understand the "ads it deems necessary for me to see" comment. You will always get ads on sites that serve ads. The thing the tracking might do, is change which particular ads you get. The right solution to that, is to use an ad blocker, and to pay for sites that have an ad-free alternative. Also, fingerprinting isn't always "bad" -- any business who takes credit cards online, wants to try to exclude pe…

That's implausible. Using finger printing for fraud detection would only catch someone using different cards on the same machine. Once a card is deemed stolen it stops working so it's unnecessary for that scenario. That doesn't even go into fake fingerprinting some browsers/plugins. The price is the highest the market will pay. Increasing that price means few customers lower revenue. Fraud is a cost to the business t…

It can be an aspect of it. For example, if there are suddenly many unique fingerprints making purchases from the same residential IP, that might look suspicious.

Granted, I'm not aware of a lack of fingerprint being penalized. That said, there are products that allow custom rules, in which case anything is possible.

I work for a company in this space. Opinions are my own.

Re: Blocked by Cloudflare

#254
post #147

Earlier quoted context omitted.

> If you care about anything these days, don't use Chrome. Or Cloudflare.

funny enough... I called out Cloudflare for the pariah it is, and got downvoted and flagged

I have done the same to the same result. We must be the lunatics, as everyone keep defending their decision to put everything, even their personal blog, behind a single company, because "they might get DDOSed".

The absolute state of software engineers and systems administrators in here, man. Talk about overengineering and premature optimisation, let alone being totally oblivious that their laziness is what creates a monopoly.

Re: Blocked by Cloudflare

#255

Earlier quoted context omitted.

I dont know which type of Firefox you use, but any reasonably tuned browser (in the privacy sense) fails your systems. I literally didnt have a single instance of passing them without handing over a pixel perfect fingerprint.

Would you be able to send me a rayID of a failed challenge so I can take a loop? It sounds like you can use https://gitlab.com/users/sign_in to generate one. You can either reply in the comments with the ID (no PII), or email me at amartinetti at cloudflare.com and I'd love to dig into it. We're building Turnstile because we want to make challenges a better system than CAPTCHA. It sounds like for you it's worse, and…

Not OP, but GitLab always cycles for me on LibreWolf, even with "enhanced tracking protection" turned off. It's likely because I disable WebGL?

7f3b42d2bee22efb

Re: Blocked by Cloudflare

#256
post #229
post #154

Earlier quoted context omitted.

I sympathize with your frustration, but you also have to admit that Cloudflare is tasked with an impossible problem: from a sea of requests, identify those that are coming from robots that are disguised as humans. So there is no perfect solution. You can't use strong identity because a user can share their identity with a robot. You have to use a crapy heuristic that only works most of the time (or tell site owners i…

Why are humans only allowed and shouldn't we be proactive and accept robots as equals now. We have a history of prejudice against groups and we seem clueless that we are heading their again.

Have you ever run an open resource with significant traffic before? People are absolutely abusive with their use of public websites and APIs. “This is why we can’t have nice things” is as relevant as ever.

Cloudflare provides a vital service that solves a real problem that breaks non-pragmatists brains.

Re: Blocked by Cloudflare

#257

Earlier quoted context omitted.

Passkeys have optional attestation payloads, which is basically what WEI is doing. Google in particular doesn't recommend requiring attestation except in corporate-security scenarios, but the fear is that banking and media sites will require attestation anyway, which locks users into whatever attestation mechanisms supported by the server; so basically Google, Apple and Microsoft.

You know I knew there was going to be something I really didn’t like about passkeys, and here it is

Yeah, unfortunately the point of passkeys is to replace multi-factor authentication. Usually you have a username+password as the primary factor, and a secret that's hard to copy and replay as a second factor (TOTP, non-resident WebAuthn credential/FIDO, SMS code). Passkeys replace the primary factor with a signed challenge, but the second factor is up to the authenticator (such as biometrics). WebAuthn relying parties verify that the authenticator is locking the primary factor behind the second factor, and they do that with attestation.

Re: Blocked by Cloudflare

#258

Earlier quoted context omitted.

When I started having this problem logging into a certain credit card co.'s website beginning with about Firefox 105.0.2 on Fedora 38, I was told by their apparently outsourced customer service that I had to use Chrome, which I don't have installed there and couldn't try. Yeah, they wanted me to use LogMeIn so they could fix the problem, too. Right. Firefox on Android was still working, though, loathe as I am to put…

[flagged]

> Completely reasonable and expected response from customer support

Absolutely not, it is not reasonable or expected that a credit card company launch a website that doesn't work with Firefox.

> Back in the day, my university would load balance based on the browser being used.

What on earth?

Re: Blocked by Cloudflare

#259
post #96

Earlier quoted context omitted.

I’m no Google fanboy but I wasn’t satisfied with this: > Chrome will happily collect as much private information about me and my browsing history and share them with select parties, as needed What information does Chrome provide in this scenario that Firefox doesn’t? It feels like backward logic: it worked in Chrome therefore it must be because Chrome gave extra info. In reality it could be a whole bunch of things, s…

A third browser... like what? Chrome and Firefox are all that exist now, unless you have access to a Mac with Safari.

Check out Vivaldi...?

Re: Blocked by Cloudflare

#260
post #228
post #179

Earlier quoted context omitted.

I don't quite understand the "ads it deems necessary for me to see" comment. You will always get ads on sites that serve ads. The thing the tracking might do, is change which particular ads you get. The right solution to that, is to use an ad blocker, and to pay for sites that have an ad-free alternative. Also, fingerprinting isn't always "bad" -- any business who takes credit cards online, wants to try to exclude pe…

That's implausible. Using finger printing for fraud detection would only catch someone using different cards on the same machine. Once a card is deemed stolen it stops working so it's unnecessary for that scenario. That doesn't even go into fake fingerprinting some browsers/plugins. The price is the highest the market will pay. Increasing that price means few customers lower revenue. Fraud is a cost to the business t…

>Using finger printing for fraud detection would only catch someone using different cards on the same machine.

In this context the goal of fingerprinting is to detect requests coming from an attacker. It does not care about the ability to distinguish between individual machines.

>Once a card is deemed stolen it stops working so it's unnecessary for that scenario.

The whole point of automating it is so you can cash out many stolen credit cards. If you only have one you might as well do it manually.

>Increasing that price means few customers lower revenue

Making more revenue doesn't matter if that extra revenue ends up getting eaten by chargebacks.

Post reply on HN