Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

311–320 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#311
post #300
post #292

Earlier quoted context omitted.

Lost sales due to 2fa are greater than losses due to refunds

Why would 2FA cause lose sales? One would imagine it’s because people are being auto charged for shit they don’t want but haven’t noticed or forgot to cancel.

Because it's more work? Also 2fa often fails for the rightful card owner. And Cloudflare overzealous "security" is one of the reasons for failure.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#312
post #5

I'm using chrome on linux and noticed that this year cloudflare is very agressive in showing the "Verify you are a human" box. Now a lot of sites that use cloudflare show it and once you solve the challenge it shows it again after 30 minutes! What are you protecting cloudflare? Also they show those captchas when going to robots.txt... unbelievable.

It's not just Linux, I'm using Chrome on my macOS Catalina MBP and I can't even get past the "Verify you are a human" box. It just shows another captcha, and another, and yet another... No amount of clearing cookies/disabling adblockers/connecting from a different WiFi does it. And that's on most random sites (like ones from HN links), I also don't recall ever doing anything "suspicious" (web scraping etc.) on that device/IP.

Somehow, Safari passes it the first time. WTF?

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#313
post #206

Earlier quoted context omitted.

At least you can get past the challenge. For me, every-single-time it is an endless loop of "select all bikes/cars/trains". I've given up even trying to solve the challenge anymore and just close the page when it shows up.

that's not Cloudflare, they stopped doing pictures years ago. You can tell because Cloudflare always puths their brand name on their page. Cloudflare just blocks you without recourse nowdays.

It is Cloudflare, I see it too. It's a Cloudflare page, with all branding, the spinning circle, then a captcha pops up on the same Cloudflare-branded page.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#314
post #308

Earlier quoted context omitted.

> blocking obvious datacenter ASNs You block all VPN users then, and currently many countries have some kind of censorship, please don't do that. I use a personal VPN for over 5 years and that's annoying. I understand the other side and captcha/POW captchas/additional checks is okay. But give people a choice to be private/non-censorable. Enabling/disabling a VPN each minute to access the non-censored local site which…

That's a fair point, probably the best approach would be to do a client side challenge where the server side challenge fails but at that point it's no longer as simple of a setup. Toggling a VPN is definitely annoying but a captcha or something like POW do come with an impact to user experience as well and in my experience are easier (and cheaper) to deal with for bots, a good quality residential proxy where you pay…

Yes, but you can use captcha/POW challenges based on IP reputation, which leaves usual users intact. I don't mind captchas too much, that's my choice to use the VPN.

What I mean is that it's better to give VPN users the choice to solve captchas instead of being banned completely.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#315
post #300
post #292

Earlier quoted context omitted.

Lost sales due to 2fa are greater than losses due to refunds

Why would 2FA cause lose sales? One would imagine it’s because people are being auto charged for shit they don’t want but haven’t noticed or forgot to cancel.

[deleted]

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#316

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

Vendors who block iCloud Relay are the worst. I'm sure they don't even know they're doing it. But some significant percentage of Apple users -- and you'd have to think it's only gonna grow -- comes from those IP address ranges. Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver .

This would be weird, esp. given that Cloudflare is one of the vendors who act as exit nodes for iCloud Relay.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#317

Earlier quoted context omitted.

> how would they know what to cache? That's a weird question to ask to someone that went out of their way to describe a non-caching situation. > Also, how would their certificates work if they don’t see content? Can you be more specific? I'm not sure which feature you're asking about or how it uses certificates. But the answer is likely "that feature isn't necessary to provide DDOS protection".

Sorry, they did not go much out of their way, to simply claim “solutions exist”. Sure, you could invent other ways of protecting your traffic but what CF offers in the free tier always includes SSL termination with their own certificates (if you enable ssl), and always includes caching.

> invent other ways

Just turning off some features gets them just about there. It wouldn't take rearchitecting things. Those features being bundled by default means very little for the difficulty.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#318
post #252

Earlier quoted context omitted.

Try clearing your cookies and disabling all extensions, if that still results in a block you can try a mobile hotspot. You're either failing some server side check (IP, TCP fingerprint, JA3 etc.) or a client side check of your browser integrity (generally this is tampered with by privacy focused extensions, anti-fingerprint settings etc.). It's not a "fix" but can at least give you an indication of why it is happenin…

I think it's unfair this comment has been flagged or downvoted or whatever. It's pragmatic information! The mobile hotspot thing... I have to do that to do anything involving Okta. For some frustrating reason my IPv4 address, which I pay extra to my ISP to have, has been blocklisted by Okta. A login flow failure in one of the apps work uses triggered my address getting banned indefinitely is my best guess. My works O…

Thank you, I'm a bit surprised people took issue with my comment but I suppose I could have worded it better.

As for your case, I wonder if Okta is relying on an external service like IPQS to get a score, that could explain why they don't really have any control over it.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#319

How many of you all are running bare metal hooked right up to the internet? Is DDoS or any of that actually a super common problem? I know it happens, but also I've run plenty of servers hooked directly to the internet (with standard *nix security precautions and hosting provider DDoS protection) and haven't had it actually be an issue. So why run absolutely everything through Cloudflare?

I run a Mediawiki instance for an online community on a fairly cheap box (not a ton of traffic) but had a few instances of AI bots like Amazon's crawling a lot of expensive API pages thousands of times an hour (despite robots.txt preventing those). Turned on Cloudflare's bot blocking and 50% of total traffic instantly went away. Even now, blocked bot requests make up 25% of total requests to the site. Without blockin…

AI bots are a huge issue for a lot of sites. Just putting intentional DDoS attacks aside, AI scrapers can frequently tip over a site because many of them don't know how to back off. Google is an exception really, their experience with creating GoogleBot as ensured that they are never a problem.

Many of the AI scrapers don't identify themselves, they live on AWS, Azure, Alibaba Cloud, and Tencent Cloud, so you can't really block them and rate limiting also have limited effect as they just jump to new IPs. As a site owner, you can't really contact AWS and ask them to terminate their customers service in order for you to recover.

Post reply on HN