Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

271–280 of 473 posts

Re: Blocked by Cloudflare

#271
post #216

Earlier quoted context omitted.

Yes. And cookie splash screens! I admire GDPR's intention but hasn't it been a massive human time sink. Not to take away from your point, just that it's all a hindrance.

That's more on the websites that track your personal data for non-essential purposes. No tracking means no banners are necessary.

I don't know that most web admins can tell if they should float a banner, so vague is the law.

Technically, I think if you have the default Apache logging configured and you read those logs, you should probably float that banner.

Re: Blocked by Cloudflare

#272
post #176

Earlier quoted context omitted.

Never seen an online shop accept that, nor do I know if it's open to UK citizens. But thanks

In the UK, you have Single European Payment Area payments. (Despite Brexit, the UK chose to stay within the SEPA zone.) The US didn't have a bank-level national service for consumer to consumer payments until FedNow. Just PayPal, Venmo, etc., which are second-tier services, which becomes an issue when they break.

Still better than cutting off most of the world. PayPal have their problems but neither a US-only nor an EU-only system is an improvement.

Re: Blocked by Cloudflare

#273
post #229

Earlier quoted context omitted.

Why are humans only allowed and shouldn't we be proactive and accept robots as equals now. We have a history of prejudice against groups and we seem clueless that we are heading their again.

Have you ever run an open resource with significant traffic before? People are absolutely abusive with their use of public websites and APIs. “This is why we can’t have nice things” is as relevant as ever. Cloudflare provides a vital service that solves a real problem that breaks non-pragmatists brains.

> that breaks non-pragmatists brains

Often times when people say this, what they really mean is that they have different opinions about which tradeoffs are tolerable and which tradeoffs aren't.

Captchas are a nightmare for accessibility. Turnstile was designed to solve that problem, but is a nightmare for privacy-oriented and non-standard setups. Getting rid of both systems and blocking based purely on behavior or building entirely new metrics to block on would absolutely be a nightmare for website security.

It's all tradeoffs, but some of those tradeoffs get labeled as "pragmatic" and some of them get labeled as "idealistic" -- mostly just based on the personal values of whoever is making that distinction. The reality is that no matter which direction we go, somebody is going to get the short end of the stick. We all want to minimize harm, but we disagree about who that somebody getting the short end of the stick should be and how short of a stick they should get.

I agree that it's idealistic to claim that we can just let automated agents access any website and that it wouldn't be a nightmare for security. However it is equally idealistic to claim that it is possible to fully secure websites against automated attacks without restricting disabled people, violating user autonomy, or harming the overall health of the open web. I do have sympathy for Cloudflare; they are trying to solve an impossible challenge. That's the key word: it's actually impossible. It's a challenge that can't be solved, we can only do the best we can do and that means accepting tradeoffs both for site security and for accessibility and access.

I disagree with Cloudflare about the exact degree to which solving that challenge justifies and excuses harming the open web and I disagree with Cloudflare's idealistic fantasy that fully solving that challenge is possible without significantly harming the open web. I disagree with some of their product directions and metrics not because I'm idealistic about alternatives but because I'm realistic about the outcomes of what Cloudflare is doing right now.

Re: Blocked by Cloudflare

#274

Earlier quoted context omitted.

Key words: "in this scenario" Is Cloudflare using an as yet unshipped API as part of DDOS protection?

No, the idea is they're abusing existing APIs for fingerprinting purposes that Firefox privacy settings disallow --canvas font rendering difference detection, detecting your GPU model, and things of that nature. But this new API demonstrates that Google is not on the consumers side when it comes to limiting tracking/data gathering ability, as the new API is explicitly for fingerprinting.

I thought it was the opposite: that instead of fingerprinting users, web services would instead just ask the browser which topics the user is interested in and display the relevant ADs. It's an explicit design goal to reduce the dependence on fingerprinting users, otherwise why would they do it. Topics are supposed to be the locally sourced privacy preserving alternative to invasive tracking.

Whether Mozilla/Apple/others agree is a different story. The blowback has mostly been around how topics aren't perfect and the design still leaves room for abuse and therefor effectively devolves to traditional tracking: https://mozilla.github.io/ppa-docs/topics.pdf.

Re: Blocked by Cloudflare

#275
post #259

Earlier quoted context omitted.

A third browser... like what? Chrome and Firefox are all that exist now, unless you have access to a Mac with Safari.

Check out Vivaldi...?

You mean "Chromium with extra steps"? I know it's a fork, but the actual engine is still mostly Chromium.

Re: Blocked by Cloudflare

#276

Earlier quoted context omitted.

You're basically saying this behavior is acceptable and should be considered normal and should be expected to become the norm. If you think IPv6 is mostly pointless, I think you're unaware of the fact that a significant majority of phones already use IPv6 most of the time they're on cellular.

Last time I checked when I hotspotted my T-Mobile (US) phone, hotspot clients got only an IPv6 address, with 6to4 [edit: no, NAT64] translation used to reach IPv4 addresses. This breaks OpenVPN, which insists on both endpoints being one or the other.

> Last time I checked when I hotspotted my T-Mobile (US) phone, hotspot clients got only an IPv6 address, with 6to4 [edit: no, NAT64] translation used to reach IPv4 addresses.

You would have the same problem without IPv6 - your phone doesn't have a spare IPv4 address to give out, it would have to give you some kind of internal-only address and then NAT it when talking to the public internet.

> This breaks OpenVPN, which insists on both endpoints being one or the other.

That seems unlikely (also why would your server not have a v6 address?). You can't connect to IPv4 addresses by IP because you don't have an IPv4 connection, but connecting to your server by hostname or by v4-address-embedded-in-v6-address should work.

Re: Blocked by Cloudflare

#277
post #246

Earlier quoted context omitted.

And 20 years ago everything was IE (at >90% penetration)

The problem is Chromium ,not Chrome Like you have the illusion of choice, that's what I'm talking about and that's different

Firefox entered into a contract per-install with Google that did no evil while Google iirc was building their own browser secretly.

Browser engines are now open source a lot more than they were.

I don’t think it’s about illusion of choice as much as some browsers actively working to degooglify themselves from Chromium and maintain it.

Some browsers are maintaining their own forks, others aren’t.

Re: Blocked by Cloudflare

#278

Earlier quoted context omitted.

Website owner complains elsewhere in this topic of blocked users (country-specific): https://news.ycombinator.com/item?id=37050774

That's not a lot of information for such a complex subject. Eg. If you live in a dictatorship and use a VPN. You're traffic is together with a lot of people. The website owner can disable cloudflare their checks and that will leave their site unprotected. The choice of that is up to the website owner, no?

The website owner can disable cloudflare their checks and that will leave their site unprotected. The choice of that is up to the website owner, no?

Yeah but what sort of transparency does Cloudflare offer website owners about what kind of traffic was blocked and *why*?

Re: Blocked by Cloudflare

#279

Earlier quoted context omitted.

I dont know which type of Firefox you use, but any reasonably tuned browser (in the privacy sense) fails your systems. I literally didnt have a single instance of passing them without handing over a pixel perfect fingerprint.

Would you be able to send me a rayID of a failed challenge so I can take a loop? It sounds like you can use https://gitlab.com/users/sign_in to generate one. You can either reply in the comments with the ID (no PII), or email me at amartinetti at cloudflare.com and I'd love to dig into it. We're building Turnstile because we want to make challenges a better system than CAPTCHA. It sounds like for you it's worse, and…

7f3bfdf6bee5b9ea

here is one. I'm not on my PC so i used a privacy enchanted fork of Mobile Chrome. Enabled WebGL, WebRTC and WASM. Disabled all the fingerprint resistant features i could easily (the only thing messing with your systems could be the HTTP Referrer or Timezone)

Perhaps its a DNS-level issue? Does cloudflare use any google related APIs to provide the integrity check?

Re: Blocked by Cloudflare

#280
I personally experience this loop all the time on different sites. I’ve completely given up - if a site loops I don’t use it and try again a few weeks later. If it’s something extremely urgent I use my mobile device which for some unknown reason never loops.
Post reply on HN