Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

291–300 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#291
post #43

Earlier quoted context omitted.

Yes, but those automated browsers are much more expensive to operate than simple HTTP clients pretending to be browsers. It's an arms race/defense-in-depth situation. If someone truly wants to automate your site in a targeted fashion, and it's profitable for them to do so, you'll have to invest a lot more in stopping it (and decide how much of it is worth stopping).

Even youtube fails with yt-dlp going as far as a internal python file that parses javascript and execute them.

There is nothing they can do, anything they can imagine to use as a signal for a bot user can be made to look legitimate. There is no way to win.

My college English professor was so obsessed with beating cliff notes that all of tests were hyper focused on the most obscure details he could dream up. It was just impossible to maintain a full course load and memorize what was the 1st, 3rd, 5th, 7th , last, etc word on every page and which character spoke it. Did the sentence contain any commas? How many times was the nurse mentioned in chapter X, etc.

Google can always follow his lead and make their data impossible to access, but impossible doesn’t increase ad views, so they will never do it. People using ytdlp is just the cost of doing business.

Re: You don’t want to be on Cloudflare’s naughty list

#292
post #193

Earlier quoted context omitted.

There are probably more sophisticated options that would solve your problems than simply blocking it.

Is using CAPTCHAs one of those?

captchas are fine. recaptcha is not.

between 2015 and ~2020, my home ISP was blessed with every recaptcha being 3 rounds of slow fade-in bullshit. I have also seen infuriating gaslighting of "please try again" after certainly correct solutions, as well as 5+ rounds followed by a notification that my network is entirely blocked.

I've developed a reflex to Ctrl+W upon seeing it, unless that is absolutely vital for me to get past it - which is exceedingly rare.

if I had a genie lamp, I'd waste one of my 3 wishes to do terrible things to the people responsible for that shit.

Re: You don’t want to be on Cloudflare’s naughty list

#293

I use a VPN, for perfectly legitimate reasons (I travel a lot, and most internet services assume that your IP address also indicates your nationality, citizenship, language, bank account country, etc. Being able to change IP source country is vital). Some VPN exit addresses have obviously been flagged as "bad" by Cloudflare and I get challenged with CAPTCHAs from some countries. It's an interesting experience, but lu…

[deleted]

Re: You don’t want to be on Cloudflare’s naughty list

#294

Earlier quoted context omitted.

I think the workflow is the issue with http(s)-based email list sign-ups. Solution: Require sign-ups by email, so the end account must actively send your mailserver a registration message. This also turns an open-loop control system into a closed loop control system, which is inherently easier to secure / keep safe.

How would this be better? It's trivially easy to spoof email addresses. Someone could sign you up easily, for example. It's also easy to send "from" an addresses that passes SPIF/DKIM but bounces inbound mail -- not sure what reason someone would have for this other than hurting the service reputation or acting as a DoS of sorts, but it can be done.

> It's trivially easy to spoof email addresses. Someone could sign you up easily, for example.

Proper DMARC configuration is table stakes to send e-mail, which makes that anything but trivial.

Re: You don’t want to be on Cloudflare’s naughty list

#295
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

What happened to PrivacyPass? It seems to have stopped working completely when connecting over Tor several months back. I say this from having spent several hours trying to get it work on multiple devices with different OS/client software (chromium/FF), both with the store versions and bundling the extension from source.

We did have it working mostly fine for some time back in 2021 but haven't been able to since.

There are multiple open issues reporting this on the GH repo with no real follow-up from maintainers apart from maybe a "should be fixed, open again if still an issue".

ie https://github.com/privacypass/challenge-bypass-extension/is...

Re: You don’t want to be on Cloudflare’s naughty list

#296

Earlier quoted context omitted.

Just 10 minutes ago, I got the following email from a housemate (I'm not home at the moment): > The past few weeks I've been getting tons of redirects to verify my humanity before being allowed to view a webpage. Usually I just have to click the box that says human, not find all the ladders in a photo. SoFi is doing it every single time I log in. Petco, too, along with others who are more sporadic. This is happening…

> I do exactly zero web crawling / scraping / abusive anything from my home connection. That you know about . Your house mates share the internet connection. I’m guessing you have WiFi, so you may have unintended guests. You probably have lots of devices, one of which may be infected. Your ISP may have issued you a different IP which may have a negative reputation score. You could be using a malware infected browser…

I'm not sure how to phrase this without sounding like a prick, but I'm not exactly new at this stuff. You missed on all of those examples. I appreciate the point you're trying to make, but Cloudflare is in fact the primary factor here.

Re: You don’t want to be on Cloudflare’s naughty list

#297
post #200

Earlier quoted context omitted.

Well, apparently they scared this user into installing their browser extension, so it sounds like this incident was a win for them.

That is indeed their goal - this kind of targeted harassment is done deliberately to collect more personal data of the user. This tactic is quite common among BigTech and something I've experienced with both Google and Amazon - once you are hooked onto their product, one day they will suddenly deny some aspect of their service to you and force you to share more personal data with them to get access to it. For example…

Privacy pass uses [VOPRFs](https://datatracker.ietf.org/doc/draft-irtf-cfrg-voprf/) with the express goal of avoiding tracking, so all this talk about "targeted harassment" is a bit much.

Re: You don’t want to be on Cloudflare’s naughty list

#298
post #288

Earlier quoted context omitted.

This is why I'm strongly against spam filtering for email. Spam filters are fundamentally security-through-obscurity. I mean, they don't protect your email from targeted bombing attacks or phishing. If you need spam filters to operate your email on a day-to-day basis, then the security of your email is fundamentally broken. /s, obviously, I hope. Blocking Tor isn't a security measure, it's a nuisance reduction measur…

The correct analogy here would be implementing spam filtering by blocking large segments of email addresses. Eg, dropping mail from all non microsoft/gmail domains (as a nuisance reduction measure!), with predictable impact on smaller providers and self hosted email.

I think it would be sensible to block new account registrations with addresses from email address aliasing services (e.g. duck.com) or disposable email address services (e.g. mailinator.com).

Re: You don’t want to be on Cloudflare’s naughty list

#299
post #62

Earlier quoted context omitted.

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

there are many solid competitors: Amazon, Fastly, Akamai, Imperva to name a few

There is an easy way to get the banhammer from Amazon, and it is possible host a JavaScript page that triggers it for any visiting user.

I did tell Amazon about it, but it fell for deaf ears. The ban lasts for about a week and the internet is mostly unusable in that period

Re: You don’t want to be on Cloudflare’s naughty list

#300
post #62
post #38

Earlier quoted context omitted.

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc. The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

> how they made Tor basically unusable on non-onion sites

I wonder if that's such a bad thing. Tor is safer when the traffic never leaves the network. In the ideal world, everything that matters would be inside the Tor network instead of being merely accessible through it.

Post reply on HN