Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

291–300 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#291
post #104

Yes. I wrote about this on my blog six months ago [1]. CloudFlare has positioned itself as the doorman of the Internet, deciding who gets to visit shitty websites written by AIs and who doesn't. Every time I try to visit a website and get blocked by this company and its unnecessary services, I congratulate myself for avoiding yet another terrible website and move on with my life. [1] https://ido50.net/content/what-ch…

Indeed, and cloudflare has also improved search engine effectiveness. If I'm looking for the answer to a technical question and four out of the top five hits are cloudflare captchas, the primary source is readily identifiable.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#292

Earlier quoted context omitted.

Yes, sure, but 5% includes stock firefox, zero modifications, zero plugins. Might still be a business decision, but it's like saying "we'll drop any emails that indicate a mail client other than apple mail/gmail/outlook".

While not that strict, see how far you get hosting your own email as far as not being rejected or automatically classified as spam

I don’t understand the “automatic” here-yes, reputation takes time to build, but if you run your own mail server with SPF/DKIM/DMARC set up correctly why is the default posture “block it” before there’s any reputation?

Just like other cases, I won’t accept that it’s “just lazy” on the part of big tech companies. They clearly know how to adjust their internal view/reputation of a domain once it starts being used for “misbehaviour” and spam such that they start blocking it.

Thus they could clearly start by not doing so-and, maybe, they’re “really touchy” about domains with no initial “internal score” such that if a new domain pops up and starts spamming people they catch it fast. Its not necessary to break open Internet protocols, though, unless they want the breakage.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#293
It used to be just for profit companies web dev's ignorantly putting themselves behind default cloudflare deploys and blocking everyone. But now big academic players like science.org/aaas elsevier and other publishers and individual journals are and I can't even read scientific papers anymore. Even sillier is the RSS/Atom feeds science.org ran have the same cloudflare rules so all actual feed readers were blocked (support told me only real feed readers as a service like Feedly corporation were allowed). It took me months of email back and forth to get them to realize their error and get to someone who could fix it. And that is what I consider a good response. Most just ignore the email.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#294
post #2

You're collateral damage in the web's war against bots :( Unfortunately, I think the Cloudflare challenges are designed to filter out users similar to your profile... once you stray far enough from the norm, it just looks like a bot / suspicious traffic to them. Statistically there's not enough users like you (privacy-conscious Linux users on nonstandard browsers) for them to really care enough to do anything about i…

The sad part is that it's trivial to get around CF's bot protection if you're writing a bot (just use curl-impersonate and buy residential IPs), but it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address.

That's same for almost all surveillance/tracking tech. It's always trivial for criminals/abusers to bypass. The surveillance is just about controlling the sheep.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#295
Everyone reading this should start to contact websites/companies who use cloudflare and tell them in simple and few words that it's a problem and link them to a video or article that explains more, maybe even to this HN topic. We are not many, maybe 1-2% of their users/customers I keep reading people saying but I have in the past been able to get big tech companies to change to a friendlier tech. You would be surprised how effective it is to contact them about it. Maybe they have a tech support who already has same opinion as you but they can't make any change until a customer makes a complaint about it, then they happily see it as their opporunity to finally make a change.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#296
post #130
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.

I know that feeling all too well. There's an Australian guy with a very similar email address that keeps entering it incorrectly, and I end up with the promo emails for these accounts. And because some of them are geolocked to Australian IPs, it's impossible to unsubscribe via the links in the footer.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#297
post #130
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.

I get emails all the time for some person in the US who must misspell his own email address. So far I’ve cancelled his haircut and car garage booking.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#298

Earlier quoted context omitted.

> either to fight the bots and accept that their service will be unusable for some subset of their users or not fight the bots, which will lead to their service becoming unusable for everyone. 2/3 of the issues OP listed would not make the service unusable for anyone if the botcheck were removed. 1. What would be the problem with allowing "bots" to opt out of receiving marketing emails? Why do I need to be a human to…

Just an idea, what if malicious bots started unsubscring thousands of email addresses to harm your business. Even if you send a confirmation email afterwords that's potentially millions of emails you are sending because of bots.

> what if malicious bots started unsubscring thousands of email addresses to harm your business.

GP said:

>> need to confirm that a user "looks human" is for repeated connection attempts in quick enough succession to matter (DDoS prevention)

And even in that case, you could implement other solutions. For example, for unsubscription links, you could pass a "token" in the query string that "verifies" that it's the address' owner unsubscribing. You could generate such token either stateless (JWT, for example, then verify it) or store it somewhere along with the address.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#299
Cloudflare challenges seem to be becoming more and more frequent on my general internet use. Yep, "Cloudflare loop" is a thing. No, I'm not going to download and install a different web browser, dump all my cookies, or whatever other nonsensical "solution" they recommend.

I've become to hate Cloudflare with a seething passion.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#300

Earlier quoted context omitted.

Unfortunately the government seems to have given up on enforcing the CAN-SPAM act. If they actually enforced it spam companies like Salesforce would face massive fines.

You can press charges yourself and get lawyer fees for your efforts. Probably not worth it, but you don't need the government to do this.

Individuals cannot "press charges", nor can the police. Only a state/federal government attorney can file charges against someone.

A person or police officer might recommend some action to a DA, but it's completely up to their discretion what to do with that information.

Post reply on HN