Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

311–320 of 473 posts

Re: Blocked by Cloudflare

#311

Earlier quoted context omitted.

I don't get it. They offer a service that that people choose to sign up for and take active steps to use. I don't see how that's an attack. Honestly I'm still trying to understand who is being attacked. Like is it an attack on the site owner - are you saying cloudflare is extorting them or something? That seems unlikely but I agree that would be a form of attack... it also doesn't seem to be what you're saying. Is it…

They block and/or slowdown over 20% of the internet How can you not see that as anything but an "attack"?

Man in the middle attack typically implies an unwanted third party, which in this case is not true since Cloudfare is explicitly and voluntarily trusted by the host server. It wouldn't be all that different if the web server had the browserintegrity checks developed themselves.

Re: Blocked by Cloudflare

#312
post #84

So many privacy nuts use Chrome and don't realize this: > What about Google Chrome? > I tried all of the above in Firefox. So I naturally tried to access the same page in Google Chrome to see if I’d still be blocked. Thankfully, I wasn’t. > But of course I wasn’t because Chrome doesn’t have the same privacy- and security-enhancing designs that Firefox does. Chrome will happily collect as much private information abou…

The heuristics used to attempt to differentiate between a so-called "bot" and a "human" are, IMHO, inadequate as long as there are "humans" that are allegedly mistaken for "bots" and blocked. "Use Chrome" is not a solution. A person using Firefox or some other non-Google software is still a "human". But not according to these brilliant "site protection" schemes. What level of false positives is acceptable.

Using JS to "verify that this is not a bot" is a way to force users to enable JS and expose themselves to more advertising.

Re: Blocked by Cloudflare

#313
post #94

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

Anecdotaly... I use Firefox and have noticed the Cloudflare interception pages verifying I'm human appearing more often recently. Usually it is all automatic and isn't a big deal, but I have noticed a increase in how often I see these the past week.

Same for me. Although i have ublock and canvas block and I have 3rd party cookies blocked.

2-3x per day i get some sort of "click here if you're a human" thing from cloudflare.

Re: Blocked by Cloudflare

#314
post #96
post #84

So many privacy nuts use Chrome and don't realize this: > What about Google Chrome? > I tried all of the above in Firefox. So I naturally tried to access the same page in Google Chrome to see if I’d still be blocked. Thankfully, I wasn’t. > But of course I wasn’t because Chrome doesn’t have the same privacy- and security-enhancing designs that Firefox does. Chrome will happily collect as much private information abou…

I’m no Google fanboy but I wasn’t satisfied with this: > Chrome will happily collect as much private information about me and my browsing history and share them with select parties, as needed What information does Chrome provide in this scenario that Firefox doesn’t? It feels like backward logic: it worked in Chrome therefore it must be because Chrome gave extra info. In reality it could be a whole bunch of things, s…

Why would chrome give that information away? That's Google's most valuable resource.

Re: Blocked by Cloudflare

#315

Earlier quoted context omitted.

I don't get it. They offer a service that that people choose to sign up for and take active steps to use. I don't see how that's an attack. Honestly I'm still trying to understand who is being attacked. Like is it an attack on the site owner - are you saying cloudflare is extorting them or something? That seems unlikely but I agree that would be a form of attack... it also doesn't seem to be what you're saying. Is it…

They block and/or slowdown over 20% of the internet How can you not see that as anything but an "attack"?

The cloudflare customers who benefit from the bot protection do not see it as an attack. On the contrary, they see it as a defense from an attack.

Also, it’s quite disingenuous to label cloudflare as only slowing things down. One of their primary functions is a global CDN/cache which significantly speeds up otherwise bandwidth constrained sites.

Re: Blocked by Cloudflare

#316
I feel like this these days: the right to decide if I am free to choose to use or access a service or website is not based on whether I claim to be human (in captchas tests), but based on the data people collect about me - and decide on them - something that I don't know behind invisible doors.

I thought privacy was on the rise after the data leaks and irresponsibility of the big tech companies, and the public's involvement in the issue of individual privacy, but it seems like everything is still a step backwards.

Re: Blocked by Cloudflare

#317

Earlier quoted context omitted.

Have you visited many stores since 2020? There was an event around that time. I still today wear a mask in every store I enter and I can completely honestly say that I have never gotten a weird look from staff over it; it's never been a problem.

Try a balaclava.

I am pretty sure I could wear a balaclava to Walmart. In fact early on in Covid during mask shortages I'm pretty sure I did wear basically the functional equivalent of a balaclava into a Walmart because I couldn't find N95s.

Admittedly France has tried this bullcrap with burkas before, but that's not exactly something anyone should be emulating, I think we'd pretty much all agree that "I'm sorry but for security reasons you can't buy groceries wearing a burka" is not an acceptable argument. Security doesn't grant free license to override other people's rights.

Bear in mind that the actual real-world examples of the argument "people shouldn't be able to wear masks in stores because of security risks" have for the most part mostly been examples of security being used as a justification to infringe on religious rights or to block marginalized/disabled people from taking reasonable safety measures to protect themselves from infectious disease.

If you're going to bring up an example of security overriding other concerns, at least bring up an example where security hasn't observably immediately become a slippery slope to infringing on people's rights and excluding them from society. Is "stores can ban you for wearing a mask" supposed to make me more comfortable with websites fingerprinting me? I mean, I know where that argument ends up in the real world, it never ends with balaclavas, we've had that argument in the real world and where it actually ends is with immunocompromised people not being able to buy groceries.

So I'm not sure any of this is really supporting your point. Anonymity should not be punished in physical or virtual spaces, and there are huge debates about de-anonymization, facial recognition, and tracking in both public and private physical spaces and for the most part we don't accept security as a justification for de-anonymization.

Re: Blocked by Cloudflare

#318

Earlier quoted context omitted.

> No, the idea is they're abusing existing APIs for fingerprinting purposes that Firefox privacy settings disallow But that’s exactly what I’m saying: the author asserts as fact the reason Chrome worked was because it gives up more personal information but there’s no interrogation of whether that’s actually true and if true, how it’s achieved. I’m no defender of Google I just believe we should be making arguments we’…

Fingerprinting is one of the techniques used to track you across the web. If the site is serving Google, Meta, or ads from other networks, your unique browser fingerprint is one of the tools that makes it possible to target and retarget you.

I think we’re all aware of that. Where’s the specific evidence that Chrome passed the Cloudflare DDOS protection because it gave up more private information than Firefox did?

Re: Blocked by Cloudflare

#319

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

The cause of the problem is that your software is faulty by design. 1. IP addresses are to be used for packet routing. Certainly not for assigning "behavior scores" to users in the background. IP addresses say nothing about your visitors, my IP address could have been a complete stranger's IP address yesterday. 2. Deciding who can access half the web based on their TLS signature achieves nothing in the long run excep…

Your alt solution is what?Everyone should build their shit to handle millions TB/s of DoS traffic?

Re: Blocked by Cloudflare

#320
post #96

Earlier quoted context omitted.

I’m no Google fanboy but I wasn’t satisfied with this: > Chrome will happily collect as much private information about me and my browsing history and share them with select parties, as needed What information does Chrome provide in this scenario that Firefox doesn’t? It feels like backward logic: it worked in Chrome therefore it must be because Chrome gave extra info. In reality it could be a whole bunch of things, s…

When I started having this problem logging into a certain credit card co.'s website beginning with about Firefox 105.0.2 on Fedora 38, I was told by their apparently outsourced customer service that I had to use Chrome, which I don't have installed there and couldn't try. Yeah, they wanted me to use LogMeIn so they could fix the problem, too. Right. Firefox on Android was still working, though, loathe as I am to put…

PayPal's "secure browser" effectively becomes broken by Firefox's first part isolation. that took some time to figure out.

In terms of being blocked by CloudFront (not cloudflare),I actually got a website to fix their policies by just emailing their tech support and showing that simple user-agent changes bypasses their policy anyhow.

Post reply on HN