Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

361–370 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#361

How many of you all are running bare metal hooked right up to the internet? Is DDoS or any of that actually a super common problem? I know it happens, but also I've run plenty of servers hooked directly to the internet (with standard *nix security precautions and hosting provider DDoS protection) and haven't had it actually be an issue. So why run absolutely everything through Cloudflare?

I've been hosting web sites on my own bare metal in colo for more than 25 years. In all that time I've dealt with one DDoS that was big enough to bring everything down, and that was because of a specific person being pissed at another specific person. The attacker did jail time for DDoS activities. Every other attempt at DDoS has been ineffective, has been form abuse and credential stuffing, has been generally amateu…

Same basic experience. The colo ISP soaks up most actual DDoS. We had a couple mid-sized ones when we were hosting irc.binrev.net from salty b& users. No real effect other than the colo did let us know it was happening and that it was "not a significant amount of DDoS by our standards."

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#362

Ok kids.. This is Tobin.. but without the Paradigm. First off.. Gee I wish we had all come together about a decade ago or so and found solutions for what was plainly coming and spelled out by my self and others. Second before it happens.. Pale Moon is not "old and insecure" It is being mismanaged had has no vision or prospects for future expansion.. It is just whatever XUL they can keep working while chugging away at…

For context, this is presumably the Tobin who caused significant tangible damage to the Pale Moon project on his way out. https://forum.palemoon.org/viewtopic.php?t=28265

Yeah except that's not the way it happened. My crimes are taking my ball and going home after being all but forced out for the second time just weeks after my father passed away from cancer and 2 months after I moved across the country.

It isn't like half the Pale Moon userbase ever wanted me there to begin with despite giving them not just an Add-ons Site and a developer wiki/doc site, the Pale Moon for Linux website, but a fully functional XUL platform that survives my involvement and a Pale Moon that is STILL Pale Moon when Moonchild as early as Pale Moon 27 was going to go the cyberfox route of Australis with CTR. So context of a decade of selfless unpaid work of 10-16 hour days every day, forum drama, bad decisions and behavior on my part in response to the response of my selfless work, and relentless attacks such as these no matter if I pop my head out or not?

If you want the full story of the end look it up on Kiwifarms (This was all before them being removed from clearnet so before the stuff you are thinking of) where I was maneuvered towards by 4chan anon people because that was the ONLY venue I had afterwards. For some reason they engaged then moved on.. Left me intact. I don't know why. But it is all there.. A cleaner version is codified in Interlink release notes on the internet archive. I encourage you to learn what actually happened and when and then make your judgement.. If you do that I will accept it even if I disagree with it because I disagree with a lot about my self these days.

Doesn't matter anyway. There are much larger issues now in the world than years old drama that still in the end.. Created the Unified XUL Platform (Take 2, the one that worked) and helps give hope to those otherwise subsumbed by the monoculture. Not that Pale Moon culture is much better but the fact it persists means more than one thing can. I can do better.. and so can we all.. Let's do that while we still can.

-nsITobin

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#363
post #325

Earlier quoted context omitted.

I believe your parent comment means when the target website blocks, not Cloudflare. YouTube is a perfect example. Using iCloud Private Relay can now frequently label you as a bot, which stops you from watching videos until you login.

It happens to me a lot, I just created a small automation to use https://cobalt.tools to download the content. Their loss, not mine.

I do something similar. Over 90% of my YouTube consumption is with Alfred workflows which use mpv and yt-dlp under the hood. I just press a keyboard shortcut and the frontmost tab closes in the browser and starts playing in mpv.

The remaining percentage is still annoying, as it happens from the phone.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#364
post #300
post #292

Earlier quoted context omitted.

Lost sales due to 2fa are greater than losses due to refunds

Why would 2FA cause lose sales? One would imagine it’s because people are being auto charged for shit they don’t want but haven’t noticed or forgot to cancel.

Because it just doesn't work with shocking frequency.

Maybe 10% of the time I make a purchase online, it shows me a screen where it says it's waiting for my bank to verify, I'll have to input a code or accept a notification or something.

A solid half the time it fails. Either the site decides the transaction was rejected before I even get a chance to respond (within seconds), or I just don't get any notification or code or anything, or I do authorize it and it still gets rejected.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#365

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

Vendors who block iCloud Relay are the worst. I'm sure they don't even know they're doing it. But some significant percentage of Apple users -- and you'd have to think it's only gonna grow -- comes from those IP address ranges. Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver .

Wait, this comment made me aware of the existence of iCloud Relay. Apple built their own Tor only for Apple users? Why would they do that? Why not use Tor???

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#366

Earlier quoted context omitted.

Vendors who block iCloud Relay are the worst. I'm sure they don't even know they're doing it. But some significant percentage of Apple users -- and you'd have to think it's only gonna grow -- comes from those IP address ranges. Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver .

Wait, this comment made me aware of the existence of iCloud Relay. Apple built their own Tor only for Apple users? Why would they do that? Why not use Tor???

Because it is 1. Not Tor and 2. Fast

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#367

Earlier quoted context omitted.

Vendors who block iCloud Relay are the worst. I'm sure they don't even know they're doing it. But some significant percentage of Apple users -- and you'd have to think it's only gonna grow -- comes from those IP address ranges. Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver .

This would be weird, esp. given that Cloudflare is one of the vendors who act as exit nodes for iCloud Relay.

I don't think that's weird. That's what I would want from an honest vendor who is involved in both services - block anonymization/obfuscation users if I'm paying you to block them. Apple/Cloudflare don't sell/support iCloud Relay as a service that is guaranteed to get you treated nicely by the parties on the other end, so they're not being deceptive with that part either.

What I'd worry about is Cloudflare using their knowledge of their VPN clients to allow services behind their attack protection to treat those clients better, because maybe they're leaking client info to the protected services.

Not that I think Cloudflare/Apple/etc. are supremely noble/honest/moral, or that it's good that semi-anonymous connections are treated so badly by default; this juxtaposition just doesn't seem like a problem to me.

EDIT: OK, I back off of this position somewhat. Apple's marketing of iCloud Relay might allow users to believe it's more prestigious and reputable than a VPN/Tor. They do have fine print explaining that you might be treated badly by the remote services, but it's, you know, fine print, and Apple knows that they have a reputation for class and legitimacy.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#368

Earlier quoted context omitted.

Vendors who block iCloud Relay are the worst. I'm sure they don't even know they're doing it. But some significant percentage of Apple users -- and you'd have to think it's only gonna grow -- comes from those IP address ranges. Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver .

Wait, this comment made me aware of the existence of iCloud Relay. Apple built their own Tor only for Apple users? Why would they do that? Why not use Tor???

You can use iCloud Relay without even noticing that you are using it, this is not true with Tor as you'll spend most of your time waiting for reconnecting circuits.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#369

Ok kids.. This is Tobin.. but without the Paradigm. First off.. Gee I wish we had all come together about a decade ago or so and found solutions for what was plainly coming and spelled out by my self and others. Second before it happens.. Pale Moon is not "old and insecure" It is being mismanaged had has no vision or prospects for future expansion.. It is just whatever XUL they can keep working while chugging away at…

For context, this is presumably the Tobin who caused significant tangible damage to the Pale Moon project on his way out. https://forum.palemoon.org/viewtopic.php?t=28265

For additional context it might be wise to include links that can't be edited by the author or webmaster.. While I didn't include links looking BinOC up on the IA isn't difficult to do and I am sure if you want to read the posts of events AS they happened you can look up the other thread.

This cited version is the revised version. Moonchild has revised his version of events multiple times in the nine months after. Pfft that isn't even the latest version lol. There are many now hidden threads on the Pale Moon forum that also showed events as they happened or as told when they happened.. All gone now.. Some of them contradict the later retellings.. I simply refer to events as they happened at the time and the Interlink release notes summery there of.

Can't wait to see if it changes anything...

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#370

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

Vendors who block iCloud Relay are the worst. I'm sure they don't even know they're doing it. But some significant percentage of Apple users -- and you'd have to think it's only gonna grow -- comes from those IP address ranges. Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver .

Well its primarily because the security vendors for say WAFs and other tools list these IPs in the "Anonymizers" or "VPN" category and most typically these are blocked as seldom do you see legitimate traffic originating to your store front or accounts pages from these. Another vendor we use lists these under "hacking tools" So your option as a security professional is to express to your risk management team we allow "hacking tools" or lose iCloud Relay customers. Which way do you think they steer? In alternative cases a site may use a vendor for their cart/checkout page and don't even have control over these blocks as they are also blocking "hacking tools" or "anonymizers" from hitting their checkout pages.
Post reply on HN