Yes. I wrote about this on my blog six months ago [1]. CloudFlare has positioned itself as the doorman of the Internet, deciding who gets to visit shitty websites written by AIs and who doesn't. Every time I try to visit a website and get blocked by this company and its unnecessary services, I congratulate myself for avoiding yet another terrible website and move on with my life. [1] https://ido50.net/content/what-ch…
Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
291–300 of 312 posts
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#292Earlier quoted context omitted.
Yes, sure, but 5% includes stock firefox, zero modifications, zero plugins. Might still be a business decision, but it's like saying "we'll drop any emails that indicate a mail client other than apple mail/gmail/outlook".
While not that strict, see how far you get hosting your own email as far as not being rejected or automatically classified as spam
Just like other cases, I won’t accept that it’s “just lazy” on the part of big tech companies. They clearly know how to adjust their internal view/reputation of a domain once it starts being used for “misbehaviour” and spam such that they start blocking it.
Thus they could clearly start by not doing so-and, maybe, they’re “really touchy” about domains with no initial “internal score” such that if a new domain pops up and starts spamming people they catch it fast. Its not necessary to break open Internet protocols, though, unless they want the breakage.
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#293Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#294You're collateral damage in the web's war against bots :( Unfortunately, I think the Cloudflare challenges are designed to filter out users similar to your profile... once you stray far enough from the norm, it just looks like a bot / suspicious traffic to them. Statistically there's not enough users like you (privacy-conscious Linux users on nonstandard browsers) for them to really care enough to do anything about i…
The sad part is that it's trivial to get around CF's bot protection if you're writing a bot (just use curl-impersonate and buy residential IPs), but it's pretty much impossible to bypass as a human if their magical black box doesn't like your browser and/or IP address.
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#295Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#296> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…
Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#297> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…
Thanks for that note. I receive „spam“ by a US based Car Rentel/Leasing Company, cause they prevent me from unsubscribing because i am in European IP-Range (geo-blocking). Especially „nice“ cause they send me contract specific details of one of their customers, who misspelled his email address.
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#298Earlier quoted context omitted.
> either to fight the bots and accept that their service will be unusable for some subset of their users or not fight the bots, which will lead to their service becoming unusable for everyone. 2/3 of the issues OP listed would not make the service unusable for anyone if the botcheck were removed. 1. What would be the problem with allowing "bots" to opt out of receiving marketing emails? Why do I need to be a human to…
Just an idea, what if malicious bots started unsubscring thousands of email addresses to harm your business. Even if you send a confirmation email afterwords that's potentially millions of emails you are sending because of bots.
GP said:
>> need to confirm that a user "looks human" is for repeated connection attempts in quick enough succession to matter (DDoS prevention)
And even in that case, you could implement other solutions. For example, for unsubscription links, you could pass a "token" in the query string that "verifies" that it's the address' owner unsubscribing. You could generate such token either stateless (JWT, for example, then verify it) or store it somewhere along with the address.
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#299I've become to hate Cloudflare with a seething passion.
Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
#300Earlier quoted context omitted.
Unfortunately the government seems to have given up on enforcing the CAN-SPAM act. If they actually enforced it spam companies like Salesforce would face massive fines.
You can press charges yourself and get lawyer fees for your efforts. Probably not worth it, but you don't need the government to do this.
A person or police officer might recommend some action to a DA, but it's completely up to their discretion what to do with that information.