Live data from Hacker News

Firefox appears to be flagged as suspicious by Cloudflare

lwthiker.com

41–50 of 191 posts

Re: Firefox appears to be flagged as suspicious by Cloudflare

#41

I think it's two-fold: rise of tools like curl-impersonate ( https://github.com/lwthiker/curl-impersonate ) and the very consistent Firefox TLS fingerprint across platforms. Unlike Chromium (where you could differentiate a Linux, Mac or Windows computer from its chiphers, and so for example challenge only Linux clients), Firefox has NSS and NSS is used everywhere the Gecko engine is used while Chromium, although has…

Quoted post unavailable.

It's probably not a deliberate attack, but consider the incentive structure and the goals here.

Cloudflare is a site protection service. Their goal is to keep malicious traffic from griefing their customers. To do that, they have to distinguish malicious and non-malicious traffic. That becomes a game of trust, and if the user agent is masking its signal (or, more generally, making its signal less distinct) in the interest of privacy for its user, there are fewer trust hooks for Cloudflare to use to distinguish legit Firefox-shaped traffic from attacks.

Ironically, attempting to keep oneself anonymous can make one lest trustworthy. The server is always at liberty to refuse to serve.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#42
post #26

We're regressing to a state reminiscent of the dark IE years. Except back then when you suggested alternative browsers, people were generally receptive once they saw the practical utility of features like tabs. Now when you suggest alternative browsers, people complain about tens of milliseconds more latency and insist on using Chrome for the speed. It's hard to blame them though, since the practical advantages of Fi…

Even if FOSS fans don't like it, it is iOS/Safari that is the last block preventing the Web platform to be finally renamed to Chrome OS.

Unfortunately there are literally activists promoted to ending that final stand protecting the open web.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#44

I'm using VPN 99.9% of the time, so it's all the same for me. The perks of living in a authoritarian state which tries to limit your access to the Internet.

>The perks of living in a authoritarian state which tries to limit your access to the Internet.

Unfortunately these days this could be virtually anywhere.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#45
post #2

I mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, a…

Really? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accep…

Firefox use, same.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#46

Earlier quoted context omitted.

"The blind signing procedure ensures that passes that are redeemed in the future are not feasibly linkable to those that are signed. We use a privacy-preserving cryptographic protocol based on ‘Verifiable, Oblivious Pseudorandom Functions’ (VOPRFs) built from elliptic curves to enforce unlinkability. The protocol is exceptionally fast and guarantees privacy for the user. As such, Privacy Pass is safe to use for those…

Sorry, can I get a layman's translation? What prevents websites from using Privacy Pass to track user behavior? (Beyond determining who is and is not a bot.)

Basically, you fill a captcha once, and that gives 30 anonymous one-time-use tokens which are stored on the browser. The cryptography used ensures that there's no way to associate the one-time tokens between each other or back to the original captcha. Redeeming the token proves that you've already filled a captcha, and will bypass the captcha for that session.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#47
post #21

Earlier quoted context omitted.

I don't imagine it's deliberate. A bunch of cloudflare engineers are long-term ex-servo, ex-mozilla given their experience on Rust.

Quoted post unavailable.

Jumping to conclusions without much evidence to back it isn't either.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#48
post #2

I mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, a…

Really? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accep…

At work I have to reject a call on slack and ask they make a "huddle" instead.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#49
post #2

I mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, a…

Really? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accep…

I don't even have another browser installed.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#50
post #2

I mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, a…

Really? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accep…

Yeah, I find 99% of the web is fine but the exceptions are jarring. Fedex tracking is totally broken in Firefox. Quite a few sites still struggle without 3p cookies, which also affects Safari. Slack has some issues. It's also come up a few times while looking for a Google Docs replacement—several options are effectively Chromium only, which is ironic when you're only looking at them so you can avoid Google products.
Post reply on HN