Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

321–330 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#321
post #294

Earlier quoted context omitted.

> It's trivially easy to spoof email addresses. Someone could sign you up easily, for example. Proper DMARC configuration is table stakes to send e-mail, which makes that anything but trivial.

But neither the newsletter host nor the email user has any input into how dmarc/dkim/spf are implemented. Only the user's email provider does. And if that's a small business domain, it's likely not very strict with the rules.

I thought DMARC/DKIM was necessary for delivering to Gmail for years now; in any case, there should be few who can't use a backup email to subscribe, as your newsletter won't be the only thing that has these anti-spoof requirements.

Re: You don’t want to be on Cloudflare’s naughty list

#322

Earlier quoted context omitted.

So what happens when your ID gets hacked and reused for fraudulent activity? Would you have to submit a dispute with the internet credit agencies? Maybe join a class action suit against the entity that leaked your ID so that they're forced to give you a year of free internet identity monitoring?

If you have a better solution, I'm sure it would be very lucrative.

Looks like Cloudflare beat us to it.

Re: You don’t want to be on Cloudflare’s naughty list

#323
This kind of behavior from such companies that have the market dominance should be illegal.

They have the unsupervised power to destroy people's life.

But for me, the biggest problem is not companies from this size doing this, nowadays it is completely expected; the biggest problem are people, including developers, that think they are right and have the right to do it.

Re: You don’t want to be on Cloudflare’s naughty list

#324
post #119

Earlier quoted context omitted.

I need to look into that. Thanks for pointing it out. I had totally forgotten about that post. Edit: team tells me this idea never got off the ground. Did talk with some potential partners (which did NOT include Google) but didn’t happen. So if Google was throwing CAPTCHAs it wasn’t because of our IP reputation.

Dear John. What am I — as a normal human being/end-user — supposed to do in this situation? People can’t do anything without any information about why they’re blocked. Who do you contact? Where do you go? What to do? The challenge page doesn’t help the end user understand why this is happening to them. It’s okay if you only see it for two seconds. But the page stays on screen for over a minute. When this happens for…

No post body was provided.

Re: You don’t want to be on Cloudflare’s naughty list

#326

Earlier quoted context omitted.

> And the most infuriating part, you get CF marketing messages right in your face while your browser is calculating hashcash (I guess?)... At this point I can recognize every single one of them: something about bots making up 40% of all internet traffic, Yeah, there's something amazingly aggravating about CF telling you how much traffic is bots while showing that they can't distinguish you from a bot .

CloudFlare are creating a new devision for advertising to bots. They have projected that in the near future, bots will be 90% of spending, so the bot demographic is the most important to target, marketingwise. The fact that humans are seeing the traffic meant for bots is an unfortunate side-effect. I personally welcome our future bot overlords (not only because being unwelcome might be unhealthy for me — why would I…

Someone has seen a basilisk...

Re: You don’t want to be on Cloudflare’s naughty list

#327

Earlier quoted context omitted.

What's to stop them from using fake IDs

Airports seem to be able to spot fake passports pretty reliably.

Try forcing 100% of online traffic through an airport security checkpoint.

Re: You don’t want to be on Cloudflare’s naughty list

#328

Earlier quoted context omitted.

I feel like Starlink could at least partially mitigate this by supporting IPv6. T-mobile US supports IPv6, and I hardly notice this as an issue on my phone. Or the time my work ran the business over a 4G mobile while waiting for ISP install.

A genuine question from an ignoramus: how on earth did Starlink launch a brand new ISP in 2020 which doesn't support IPv6? Is IPv6 really so difficult? Does actually nobody care about IPv6 still, after all these years?

I've been wondering that too, it's kind of confounding. Particularly since Starlink started with CGNAT to manage a limited IPv4 address allocation.

FWIW there've been hints from time to time that Starlink was working on IPv6; users reported being given working addresses. That mostly stopped though when they handed over ISP operations to Google last year.

Re: You don’t want to be on Cloudflare’s naughty list

#329

Earlier quoted context omitted.

> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity co…

> The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? How would we know?

How would we know if a homeless person was the second coming of Jesus Christ?

Non-falsifiable claims are easy and limitless. Their credibility without evidence should be proportional.

Re: You don’t want to be on Cloudflare’s naughty list

#330
post #304

Earlier quoted context omitted.

> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity co…

> Fact-less conspiranoia. I love how people reflectively answer with cries of "no evidence!" to something that presents the evidence about exactly the thing they are claiming has no evidence. I get a distinct impression that the only person they're trying to convince is themselves, by self-hypnotically denying the reality in public. There's a fact of CF booting sites, there's a fact of CF having IP blacklist, there's…

My entire post was about targeting specific visitors. Zero evidence.

> That's nothing. Imagine how tired you'd be when it turns out everything you thought is "paranoia" is actually happening.

Every genius and every crackpot experience this. The sad fact is that crackpots outnumber geniuses by a factor of hundreds.

You missed my point about means, motive, and opportunity by a mile.

None of the web services/app you mention block specific visitors; only accounts. Again, my entire comment was specific to the hypothetical capability and desire to block per visitor, not domain/account or IP.

Post reply on HN