Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

341–350 of 473 posts

Re: Blocked by Cloudflare

#341

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

Is there an easy way to report false positives instead of having to attract the attention of an employee on social media?

Re: Blocked by Cloudflare

#342
post #109

Earlier quoted context omitted.

Playing the devil's advocate: Why shouldn't a server get to decide which clients it wants to talk to?

Why shouldn't a store get to decide the $protected_class of which customers it will do business with?

User Agent is not a protected class. Neither is Intentionally Obtuse for that matter.

Re: Blocked by Cloudflare

#343

Earlier quoted context omitted.

[flagged]

> Completely reasonable and expected response from customer support Absolutely not, it is not reasonable or expected that a credit card company launch a website that doesn't work with Firefox. > Back in the day, my university would load balance based on the browser being used. What on earth?

So cancel your credit card with them? They have a reason field on the cancellation form.

Re: Blocked by Cloudflare

#344
post #84

So many privacy nuts use Chrome and don't realize this: > What about Google Chrome? > I tried all of the above in Firefox. So I naturally tried to access the same page in Google Chrome to see if I’d still be blocked. Thankfully, I wasn’t. > But of course I wasn’t because Chrome doesn’t have the same privacy- and security-enhancing designs that Firefox does. Chrome will happily collect as much private information abou…

The heuristics used to attempt to differentiate between a so-called "bot" and a "human" are, IMHO, inadequate as long as there are "humans" that are allegedly mistaken for "bots" and blocked. "Use Chrome" is not a solution. A person using Firefox or some other non-Google software is still a "human". But not according to these brilliant "site protection" schemes. What level of false positives is acceptable. Using JS t…

Furthermore, all bots worth their salt as far as threats go enable js and do everything they can to appear like a normal browser.

Re: Blocked by Cloudflare

#345
This happened to me just a few days ago. I tried to open a link in an app, which then tried to open it with an in-app WebView. Thus, the Cloudflare captcha loop of death. I could even see a "human verification failed" string appearing after clicking on an "I am human" checkbox. Alongside the annoyance of not being able to browse, this kind of language is awful! Literally being told to my face I am not a human.

Re: Blocked by Cloudflare

#346
post #9

> The next day, I tried accessing a web page internal to my company… […] I couldn’t get past a security check page because of issues in Cloudflare’s software. […] The silliness of it all is that I was on my work device the whole time, which was behind my workplace VPN. This seems more like an "IT department gone mad" problem than a Cloudflare problem. I'm surprised they'd rather switch to Chrome than submit a support…

Passkeys have optional attestation payloads, which is basically what WEI is doing. Google in particular doesn't recommend requiring attestation except in corporate-security scenarios, but the fear is that banking and media sites will require attestation anyway, which locks users into whatever attestation mechanisms supported by the server; so basically Google, Apple and Microsoft.

Does Microsoft have much control over Windows Hello's key attestation? It's not clear to me how they could pull that off, other than just relying on TPM attestations which are easy to obtain as long as you can buy a TPM that works with your motherboard.

Re: Blocked by Cloudflare

#347
post #324

Earlier quoted context omitted.

> but you also have to admit that Cloudflare is tasked with an impossible problem They're not tasked with anything. They choose to sell a bot detection and mitigation platform as a product, and that's a hard business to be in. If they think they can do it, great. If they can't, they shouldn't try.

The thing I don't understand is why all of the blame is being placed on Cloudflare as a company. Why not place the blame on the people who are configuring Cloudflare to behave in this way? I'm a happy Cloudflare Enterprise customer, and our DDoS settings are "Off", we don't present captchas to end users, we don't block any traffic, and we've disabled all of Cloudflare's managed rulesets. It's very possible to use Clo…

> Why not place the blame on the people who are configuring Cloudflare to behave in this way?

Sane defaults. Of course everyone would turn DDoS protection on.

Re: Blocked by Cloudflare

#348
post #337

Earlier quoted context omitted.

People immediately assume if you dislike CF you’re defending one site in particular and once they do that no further discussion is possible.

I'm out of the loop I guess. Which site would that be?

Probably Kiwi Farms or whatever it has evolved into these days.

Re: Blocked by Cloudflare

#349
post #343

Earlier quoted context omitted.

> Completely reasonable and expected response from customer support Absolutely not, it is not reasonable or expected that a credit card company launch a website that doesn't work with Firefox. > Back in the day, my university would load balance based on the browser being used. What on earth?

So cancel your credit card with them? They have a reason field on the cancellation form.

If my own bank/credit card blocked Firefox I would cancel with them. I'm pointing out that this isn't really normal or justifiable.

To your specific point about just moving elsewhere, complaining in public about bad industry practices is part of Capitalism and part of how consumers regulate the free market. "Take your business elsewhere instead of complaining" has never really been how this has worked; businesses don't get to opt out of being shamed just because they have a cancellation form, and they shouldn't have any expectation that users will or should be quiet about their bad business practices. The free market is not a replacement for criticism within social spaces; the free market works alongside that criticism and is reinforced by that criticism.

Public complaining is an essential part of how consumers within a free market coordinate with each other and educate each other about abusive corporate behavior, and it serves as an additional mechanism alongside boycotts and cancellations to help punish bad actors in the market.

Re: Blocked by Cloudflare

#350

Earlier quoted context omitted.

I have to believe you're attempting (but failing) to gaslight me you wrote: "it does seem to indicate that IPv6 is mostly pointless for human users for exactly this reason" ( https://news.ycombinator.com/item?id=37050359 ) he wrote: "If you think IPv6 is mostly pointless, I think you're unaware of the fact that a significant majority of phones already use IPv6 most of the time they're on cellular" ( https://news.ycom…

What are you on about? There's no sign of 'johnklos' quoting me as you claim. It literally appears in his own words, and he even wrote it in a manner that could not possibly be confused with my style of writing. Just check my recent comment history? Frankly, it's just impossible for there to be a 17 word phrase in that comment that can be interpreted as a quotation, even by a teenager who only started learning Englis…

Please accept this award for your outstanding contributions to the field of pedantry.
Post reply on HN