Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

321–330 of 473 posts

Re: Blocked by Cloudflare

#321

I've had the exact same problem for a while. Here are some of the sites I've been unable to access (found by searching for "just a moment" in my browser history): - https://gitlab.com/users/sign_in - https://steamdb.info/login/ - https://www.zabbix.com/forum/ - https://casetext.com/ - https://namemc.com/login - https://spinroot.com/ - https://camelcamelcamel.com/ It's really annoying and Cloudflare is apparently doin…

Would you be willing to share a rayID you see during one of these looping challenges? I'm the PM for Cloudflare's challenge platform, and we'd love to look into this. RayIDs contain no PII so you can share publicly, or feel free to drop me an email at amartinetti at cloudflare. We'll also release a reporting mechanism soon, so in the future you can let us know when you see these issues and we can react to them quickl…

https://gitlab.com/users/sign_in 7f3cc1d59acd31e5

https://steamdb.info/login/ 7f3cc161bf85dbd9

https://www.zabbix.com/forum/ works

https://casetext.com/ works

https://namemc.com/login 7f3cc182b8c20ccf

https://spinroot.com/spin/whatispin.html works

https://camelcamelcamel.com/ 7f3cc171f96d2b9b

Re: Blocked by Cloudflare

#322

Earlier quoted context omitted.

And who defines is an allowed crawler? Is Google the only allowed company to crawl the web? Isn't that the definition of monopoly? Could anybody still create a new search engine nowadays?

A valid crawler is following robots.txt

[deleted]

Re: Blocked by Cloudflare

#323

Earlier quoted context omitted.

A third browser... like what? Chrome and Firefox are all that exist now, unless you have access to a Mac with Safari.

There are a handful of Webkit based browsers out there, though none that popular except for Safari. But yes, 3 is all we're left with outside of a few bespoke projects...

Honestly the SerenityOS browser (+ its Linux port, Ladybird) is probably the funniest. I wonder if that passes CloudFlare...

Re: Blocked by Cloudflare

#324
post #154

Earlier quoted context omitted.

I sympathize with your frustration, but you also have to admit that Cloudflare is tasked with an impossible problem: from a sea of requests, identify those that are coming from robots that are disguised as humans. So there is no perfect solution. You can't use strong identity because a user can share their identity with a robot. You have to use a crapy heuristic that only works most of the time (or tell site owners i…

> but you also have to admit that Cloudflare is tasked with an impossible problem They're not tasked with anything. They choose to sell a bot detection and mitigation platform as a product, and that's a hard business to be in. If they think they can do it, great. If they can't, they shouldn't try.

The thing I don't understand is why all of the blame is being placed on Cloudflare as a company.

Why not place the blame on the people who are configuring Cloudflare to behave in this way?

I'm a happy Cloudflare Enterprise customer, and our DDoS settings are "Off", we don't present captchas to end users, we don't block any traffic, and we've disabled all of Cloudflare's managed rulesets.

It's very possible to use Cloudflare with all of the security features switched off. The features causing the author's issues are features that can be disabled by the site owner. Cloudflare has power over what they recommend as the default settings, but ultimately it's up to the site owner to choose how to configure Cloudflare for their site.

I think there could be a healthy debate around Cloudflare's default account settings, but I'm surprised by the number of people here dismissing the fact (or maybe not aware of the fact?) that all of these are features that can be turned off. The owner of the site chose to keep bot protection, visitor verification and related features turned on.

Re: Blocked by Cloudflare

#325

Earlier quoted context omitted.

A third browser... like what? Chrome and Firefox are all that exist now, unless you have access to a Mac with Safari.

Chromium isn't Chome. Microsoft Edge is popular. And Opera is still used: my teen daughter seems to have bonded with it on her own.

Edge is now Chromium and Opera is also Chromium, but touché that I said "Chrome" in my original comment.

Re: Blocked by Cloudflare

#327
post #80

The amount of times Cloudflare is making me sit through their 15 to 30 second "checking your connection" page is insane. For people going through life with ADHD such as myself, the impact of all these delays and disruptions throughout the day can be severe. Despite being properly medicated this measure is absolutely debilitating and makes for a dreadful and very taxing online experience.

Cloudflare's Privacy Pass may help here: https://privacypass.github.io/ It should significantly reduce the amount of CAPTCHAs you see in a way that's not terrible for privacy. For Safari, you can enable Private Access Tokens: https://blog.cloudflare.com/how-to-enable-private-access-tok... Both of these mechanisms are similar to Google's web DRM proposal in that they rely on external issuers to generate tokens, but un…

Pay us with your information to make your problem go away.

Re: Blocked by Cloudflare

#328
post #154

Earlier quoted context omitted.

I sympathize with your frustration, but you also have to admit that Cloudflare is tasked with an impossible problem: from a sea of requests, identify those that are coming from robots that are disguised as humans. So there is no perfect solution. You can't use strong identity because a user can share their identity with a robot. You have to use a crapy heuristic that only works most of the time (or tell site owners i…

> but you also have to admit that Cloudflare is tasked with an impossible problem They're not tasked with anything. They choose to sell a bot detection and mitigation platform as a product, and that's a hard business to be in. If they think they can do it, great. If they can't, they shouldn't try.

So are you declaring nobody should be in that business of bot protection then?

Re: Blocked by Cloudflare

#329

I've had the exact same problem for a while. Here are some of the sites I've been unable to access (found by searching for "just a moment" in my browser history): - https://gitlab.com/users/sign_in - https://steamdb.info/login/ - https://www.zabbix.com/forum/ - https://casetext.com/ - https://namemc.com/login - https://spinroot.com/ - https://camelcamelcamel.com/ It's really annoying and Cloudflare is apparently doin…

I've noticed the same issue for years. The Microsoft acquisition pushed me from Github to GitLab. CloudFlare pushed me back.

Re: Blocked by Cloudflare

#330

Earlier quoted context omitted.

Fingerprinting is one of the techniques used to track you across the web. If the site is serving Google, Meta, or ads from other networks, your unique browser fingerprint is one of the tools that makes it possible to target and retarget you.

I think we’re all aware of that. Where’s the specific evidence that Chrome passed the Cloudflare DDOS protection because it gave up more private information than Firefox did?

[deleted]
Post reply on HN