Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

331–340 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#331
post #277

Earlier quoted context omitted.

Citation needed.

I think this is more of an opinion than a matter of fact

It wasn’t framed as an opinion. And even if it was, I’m saying I think it is wrong and I want to know why I should change my mind.

The fact is that CloudFlare distinguishes abuse (DDoS at IP layers 3 and 4) completely separately from bot detection. And it allows user controls to domain owners to allow some bots like Google Search Crawler.

So my statement stands: I want to see a citation of evidence that CloudFlare doesn’t have the ability to distinguish abuse.

Re: You don’t want to be on Cloudflare’s naughty list

#332
post #98

Earlier quoted context omitted.

(Author here.) My router isn’t a domestic router. It’s a MikroTik running RouterOS, completely unsupported by the ISP. Outgoing connections and DNS is logged. UPnP is only allowed for the Xbox, PS4, and off-most-of-the-time gaming PC. Nothing out of the ordinary in the logs.

> It’s a MikroTik running RouterOS It's almost certainly compromised.

No. It isn't.

Re: You don’t want to be on Cloudflare’s naughty list

#333
post #98

Earlier quoted context omitted.

(Author here.) My router isn’t a domestic router. It’s a MikroTik running RouterOS, completely unsupported by the ISP. Outgoing connections and DNS is logged. UPnP is only allowed for the Xbox, PS4, and off-most-of-the-time gaming PC. Nothing out of the ordinary in the logs.

> It’s a MikroTik running RouterOS https://google.com/search?q=mikrotik+botnet These things are the absolute scourge of the internet.

They're a powerful tool that lets you shopt off your foot and half your brains with the same bullet. However, this my router isn't compromised. MikroTik routers can easily be misconfigured to be insecure or misbehave. It's a Cisco clone, so that is the product you're buying.

I don't recommend them to anyone who doesn't enjoy and are familiar with the lower-level intricacies of network operations.

Re: You don’t want to be on Cloudflare’s naughty list

#334

Earlier quoted context omitted.

Easy solution. Go down to your local post office. They physically hand you an identity token on a physical $2 2fa device if you give some evidence you live nearby. You can put down the deposit or hand over the device for an old id which is cleared and reused. It's traceable to the post office but no further, nothing is recorded other than that the token is deployed and roughly when. Local communities can be responsib…

So every country in the world should simultaneously roll out this $2 2FA token? And the governments of the world are going to do this is an anonymous way? Who is going to manufacture these 8 billion (Or at least 3 billion if we only count Facebook's MAU) tokens? And there still needs to be a global database of valid identifiers, else anyone could just create a software token that they can reprogram ever second. And w…

You're projecting use cases that weren't proposed.

The only purpose is to provide evidence of not being a bot. Not to log in or verify identity. You don't need a server or proof that a particular token is owned by a particular person, just a cert chain and a list of postcodes with current public keys. The post office has a private key. They sign a message saying 'the holder of this token walked into the store'. Let servers make whatever judgements they wish about the chain's credibility. If a particular key signs lots of bots then you know where to look for the source of the bot farm and the people that live there know where to look to fix their reputation.

It doesn't need to roll out simultaneously. Just be an alternative to captcha that isn't as abusive as device attestation.

The manufacturers will be the same ones that manufacture the hundreds of billions of usb drives and phones and smart light bulbs.

The only problems are it's not as useful for abusing users or spying on citizens as revoking access to general purpose computing, and idiots who project problems onto it that come from use cases that are not proposed or say 'big number make thing impossible'.

Re: You don’t want to be on Cloudflare’s naughty list

#335
post #304

Earlier quoted context omitted.

> Fact-less conspiranoia. I love how people reflectively answer with cries of "no evidence!" to something that presents the evidence about exactly the thing they are claiming has no evidence. I get a distinct impression that the only person they're trying to convince is themselves, by self-hypnotically denying the reality in public. There's a fact of CF booting sites, there's a fact of CF having IP blacklist, there's…

My entire post was about targeting specific visitors. Zero evidence. > That's nothing. Imagine how tired you'd be when it turns out everything you thought is "paranoia" is actually happening. Every genius and every crackpot experience this. The sad fact is that crackpots outnumber geniuses by a factor of hundreds. You missed my point about means, motive, and opportunity by a mile. None of the web services/app you men…

You don't have to be a genius to see the facts. Just somebody who is not working very hard to not notice what is going on.

> None of the web services/app you mention block specific visitors; only accounts

So? How the situation with visitors is specifically different? Yes, they didn't want to block visitors for now, but what if they feel like it?

Re: You don’t want to be on Cloudflare’s naughty list

#336
post #321

Earlier quoted context omitted.

But neither the newsletter host nor the email user has any input into how dmarc/dkim/spf are implemented. Only the user's email provider does. And if that's a small business domain, it's likely not very strict with the rules.

I thought DMARC/DKIM was necessary for delivering to Gmail for years now; in any case, there should be few who can't use a backup email to subscribe, as your newsletter won't be the only thing that has these anti-spoof requirements.

Not necessary. Just very highly recommended. I can still deliver my cron emails from a rando host successfully.

Re: You don’t want to be on Cloudflare’s naughty list

#337

Earlier quoted context omitted.

> The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? How would we know?

How would we know if a homeless person was the second coming of Jesus Christ? Non-falsifiable claims are easy and limitless. Their credibility without evidence should be proportional.

> How would we know if a homeless person was the second coming of Jesus Christ?

I think the eschaton would be pretty hard to miss, what with the rapture and the final battle at Armageddon and the horsemen and whatnot.

The CIA’s entire bailiwick is covert operations. A government agency that’s been specially trained to engage in illegal covert operations involving lethal force without getting caught isn’t going to leave too much evidence, which means a lack of evidence doesn’t really tell you anything either way.

That having been said, the CIA was involved in the Obama-era drone strike program that ended up killing four US citizens (only one of whom was deliberately targeted). Frank Olson also died in suspicious circumstances connected to MKULTRA in 1953.

Re: You don’t want to be on Cloudflare’s naughty list

#338

Yeah, this just continues to reinforce my opinion Cloudflare. It's not something I would ever recommend, and there are numerous other superior options out there. I see Cloudflare failing frequently enough that if it were something I was responsible for, I'd be embarrassed at the very least.

What superior options would you recommend that are privacy focused and free?

You can't have privacy-focused and free services. You're either the paying customer or the product being sold.

Re: You don’t want to be on Cloudflare’s naughty list

#339

If this happened to me, the first thing I would do is switch to using a VPN. In my experience, Google is far more likely to throw up CAPTCHA challenges to VPN users. I wonder if this is what happened to the OP.

(Author here.) I don't use a VPN from my home connection.

Re: You don’t want to be on Cloudflare’s naughty list

#340
post #257

Sounds like the guy's network was being used as part of a ddos attack. That explains the slow loading of sites as well, CF wouldn't throttle you.

(Author here.) This is possible, but implausible. I log network traffic and haven’t noticed anything out of the ordinary. The point of the article was mostly to complain about the lack of information from Cloudflare, though. I don’t know what caused the blockade, and they’re not telling. How am I — as an end-user — supposed to do anything about the situation? I don’t even know what the situation is.
Post reply on HN