Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

281–290 of 473 posts

Re: Blocked by Cloudflare

#281

Earlier quoted context omitted.

Data point of N+1, but I haven't been able to place online orders at Petco for about a year now because they use some Cloudflare feature that hates my browser + home internet connection. Other Cloudflare-proxied sites seem unaffected, and I'm not doing any botting/crawling, nor do I have any IoT devices on my home network. There's not enough information provided to be able to do any substantive troubleshooting. This…

So you're mad at Cloudflare because Petco enabled a feature that blocked you? If Petco had developed something in-house that blocked you, would you be mad at the compiler?

Cloudflare offers this service. If Cloudflare offered a service that enabled Petco to do something amazing would you be grateful to Cloudflare? If Cloudflare advertised on its homepage about blocking a DDOS attack on a website would you say, "meh, Cloudflare wasn't responsible for blocking that attack, they only provided a feature. The website blocked the attack."? If not, then why should Cloudflare be immune from criticism when the opposite happens?

Cloudflare offered Petco the features to do this as a product and makes money off of Petco's usage of those features. I do sympathize with the perspective that ultimately tools need to be somewhat neutral and it can be dangerous to forward around responsibility. But "tools are neutral" can also be taken to an absurd degree. This isn't 5 levels of indirection here and it's not Petco going and installing a neutral piece software that they downloaded from Github. Petco is a client. They're turning on toggles that Cloudflare built into their user interface and advertises as features.

There's some level of moral accountability there for how those features are abused. I'm not saying it should be illegal, I'm not saying it shouldn't be allowed, but Cloudflare is definitely at least eligible for criticism. This is a product, it's not Petco abusing Cloudflare's infrastructure; they're using the product as intended and advertised.

Re: Blocked by Cloudflare

#282

Earlier quoted context omitted.

That's not a lot of information for such a complex subject. Eg. If you live in a dictatorship and use a VPN. You're traffic is together with a lot of people. The website owner can disable cloudflare their checks and that will leave their site unprotected. The choice of that is up to the website owner, no?

The website owner can disable cloudflare their checks and that will leave their site unprotected. The choice of that is up to the website owner, no? Yeah but what sort of transparency does Cloudflare offer website owners about what kind of traffic was blocked and *why*?

Every blocked request is logged with the corresponding rule. I’ve had multiple times where someone complained about being blocked and didn’t realize that they had malware on their PC.

Re: Blocked by Cloudflare

#283
post #217
post #157

Earlier quoted context omitted.

And even when it doesn't block you completely, it delays website loading, makes you jump through frustrating captchas, etc. It's probably third in the list of frustrating web behaviors in the past couple of years (behind GDPR popups and registration/paywalls that seem to have gotten much worse recently). And somehow there are some sites that I get CF delay walls on every time I visit. This feature is utterly broken f…

Why not take a screenshot of the CF error and send it to the website owner? It would freak me out if I thought a significant number of my website's users were being blocked by CF.

I’ve done this before, and the response is always “this is the first time I’ve seen this” and “you must be a bot operator”.

Re: Blocked by Cloudflare

#284

Earlier quoted context omitted.

Key words: "in this scenario" Is Cloudflare using an as yet unshipped API as part of DDOS protection?

No, the idea is they're abusing existing APIs for fingerprinting purposes that Firefox privacy settings disallow --canvas font rendering difference detection, detecting your GPU model, and things of that nature. But this new API demonstrates that Google is not on the consumers side when it comes to limiting tracking/data gathering ability, as the new API is explicitly for fingerprinting.

> No, the idea is they're abusing existing APIs for fingerprinting purposes that Firefox privacy settings disallow

But that’s exactly what I’m saying: the author asserts as fact the reason Chrome worked was because it gives up more personal information but there’s no interrogation of whether that’s actually true and if true, how it’s achieved.

I’m no defender of Google I just believe we should be making arguments we’re able to actually back up.

Re: Blocked by Cloudflare

#285

Earlier quoted context omitted.

I seriously never get people that love CF (or any company for that matter). Praising 1.1.1.1, giving it free advertising. CF is basically handing over your website in return for some less work on your part. I get the advantages of it (like less engineer credits wasted, less server maintaining work and probably cost, faster) but actively giving it free PR just doesnt fit right with me. Pay your bucks and sit. They are…

>CF is basically handing over your website in return for some less work on your part. The older you get, the more valuable being able to just dump your shit on other people becomes.

No i totally get it, i can see myself doing the same compromise. I cant see myself recommending such practice, however.

Re: Blocked by Cloudflare

#286
post #266

Earlier quoted context omitted.

Try walking into a real place with a mask on and you might also get treated less pleasantly.

Walking into real places with a mask on has been normal for the past three years.

OK, but not with a balaclava.

Re: Blocked by Cloudflare

#287
post #199

Earlier quoted context omitted.

Tracking is establishing your identity. Try using a private mode Firefox via a VPN. Half of the web is completely unusable. You get put in unsolvable catchpa hell as punishment for being anonymous.

Try walking into a real place with a mask on and you might also get treated less pleasantly.

Have you visited many stores since 2020? There was an event around that time.

I still today wear a mask in every store I enter and I can completely honestly say that I have never gotten a weird look from staff over it; it's never been a problem.

Re: Blocked by Cloudflare

#288
post #147

Earlier quoted context omitted.

> If you care about anything these days, don't use Chrome. Or Cloudflare.

funny enough... I called out Cloudflare for the pariah it is, and got downvoted and flagged

People immediately assume if you dislike CF you’re defending one site in particular and once they do that no further discussion is possible.

Re: Blocked by Cloudflare

#289

I've had the exact same problem for a while. Here are some of the sites I've been unable to access (found by searching for "just a moment" in my browser history): - https://gitlab.com/users/sign_in - https://steamdb.info/login/ - https://www.zabbix.com/forum/ - https://casetext.com/ - https://namemc.com/login - https://spinroot.com/ - https://camelcamelcamel.com/ It's really annoying and Cloudflare is apparently doin…

If only there was some open standard for browsers to verify that a real human is visiting a website, so that website owners wouldn't have to rely on bespoke hacks that only work in chrome.

The problem isn't that the hack only works in Chrome, it's that the system being proposed is inherently terrible regardless of how it's implemented.

There is no such thing as a reliable standard for browsers to verify that users are human that does not harm the open web or threaten user autonomy and accessibility. Every single accessibility standard and user choice about extensions and access is abusable by malicious actors, and every security measure to block abuse of automated scraping or access also blocks valid use cases.

Making it a web standard won't change that fact.

Re: Blocked by Cloudflare

#290
post #236

Earlier quoted context omitted.

For every one user that makes their way on here and finds and posts here on this thread probably represent 1,000,000 plus normal users An open web is open for everyone/thing not just classes of beings you select. Bots and users can both be malicious and both can be positive.

I agree with the premise that most people don't know how to identity or visibly complain about a given technical problem, and so an HN thread with N anecdotes about the problem likely corresponds to N * F actual amount of real-world incidents, for some value of F > 1.... but claiming it's a factor of a million without any backing evidence is absolutely an overreach. > An open web is open for everyone/thing not just c…

That's a pretty good idea. Do you randomly sample, or just exclude some domains? Is there some tool out there that does it for you?
Post reply on HN