Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

401–410 of 473 posts

Re: Blocked by Cloudflare

#401

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

Adam, the problem I'm running into is due to the IP proxy I normally use having been changed from ARIN to RIPE due to an ownership change at the hosting datacenter, which is still in NYC. Thus, nevertheless, I show up as coming from the UK, it looks like, when I access Cloudflare-protected sites in the US, and I'm running into more and more of them. The local newspaper, grocery store, credit card co's, etc., It seems that Cloudflare IPv6 geolocation is broken, and interferes even if you're coming from an IPv4. This is just asking for trouble if you ask me.

Troubleshooting done. If it's any consolation, I don't think Cloudflare is the only offender. Geolocation is a crappy idea to begin with, if you ask me.

Re: Blocked by Cloudflare

#402
post #216

Earlier quoted context omitted.

That's more on the websites that track your personal data for non-essential purposes. No tracking means no banners are necessary.

I don't know that most web admins can tell if they should float a banner, so vague is the law. Technically, I think if you have the default Apache logging configured and you read those logs, you should probably float that banner.

I believe you're mistaken. GDPR allows you to record IP addresses for normal operation of a site, which specifically includes logging. No banner is required.

GDPR is not "vague" about this; perhaps you haven't read it (as laws go, it's pretty easy to read).

Re: Blocked by Cloudflare

#403

Earlier quoted context omitted.

On that note... https://www.folklore.org/StoryView.py?project=Macintosh&stor... "Well, let's say you can shave 10 seconds off of the boot time. Multiply that by five million users and thats 50 million seconds, every single day. Over a year, that's probably dozens of lifetimes. So if you make it boot ten seconds faster, you've saved a dozen lives. That's really worth it, don't you think?" Imagine if people still thoug…

ReCAPTCHA was designed with this in mind: given that we had the need to distinguish humans from bots, it presents problems that are hard for bots to solve, where the resulting output is valuable. So the time consumed isn't wasted.

Valuable to whom?

Re: Blocked by Cloudflare

#404
post #293

Earlier quoted context omitted.

Easy to say don't use Chrome, harder to say don't use Cloudfare. And if we're taking things to task for monopolizing a market and being a threat to the future of the open internet, I'd say Cloudfare is and will always be a bigger threat. The moment the Cloudfare dictatorship becomes less benevolent, everyone is gonna feel it.

> The moment the Cloudflare dictatorship becomes less benevolent…[] In my eyes they have already done that. ICYMI I highly suggest checking out their response and subsequent blog post around the Kiwifarms incident. That whole debacle was enough to prove to me they learned nothing and are going to continue down this path. I migrated web services and closed my account with them shortly after that whole thing. Cloudflar…

Wait, Cloudflare stopped being benevolent by NOT abusing their power enough? You have two different opinions one is that Cloudflare should respect privacy and one is that is should moderate the internet, these are fundamentally at odds.

Re: Blocked by Cloudflare

#405
post #350

Earlier quoted context omitted.

What are you on about? There's no sign of 'johnklos' quoting me as you claim. It literally appears in his own words, and he even wrote it in a manner that could not possibly be confused with my style of writing. Just check my recent comment history? Frankly, it's just impossible for there to be a 17 word phrase in that comment that can be interpreted as a quotation, even by a teenager who only started learning Englis…

Please accept this award for your outstanding contributions to the field of pedantry.

Since presumably your a different person from 'warrenm', though with some degree of uncertainty due to the pseudonym, why lower your account's built up credibility with obvious low-effort trolling?

'warrenm' clearly needs some help with resolving confusion regarding HN norms, or something along those lines, not piling on and exploiting the odd comment chain at his expense.

Re: Blocked by Cloudflare

#406
post #388

Earlier quoted context omitted.

That's typically deployed on sites under heavy DDOS attacks. Nobody wants for their users to see that, they are forced to.

No need to simplify so much that only false dichotomies remain. My brain might be wired up differently but its capacity for nuance and reason is fully intact :) No one is forcing the website owners to sign up with Cloudflare to enable this service with these aggressive configurations, and yet I understand why they would even just pre-emptively. It's cheap and effective, there's no denying that. It is Cloudflare Inc.…

I'm pretty sure anyone who deploys aggressive cloudflare DDOS protection knows the impact and believes it's the lesser evil.

If there was just as effective a way to tell cheap bots from legitimate browsers without making users wait I'm pretty sure it would have been used.

Re: Blocked by Cloudflare

#407

Earlier quoted context omitted.

I agree with the premise that most people don't know how to identity or visibly complain about a given technical problem, and so an HN thread with N anecdotes about the problem likely corresponds to N * F actual amount of real-world incidents, for some value of F > 1.... but claiming it's a factor of a million without any backing evidence is absolutely an overreach. > An open web is open for everyone/thing not just c…

That's a pretty good idea. Do you randomly sample, or just exclude some domains? Is there some tool out there that does it for you?

Assembling the list of links to archive is a manual process--I just log them in an Obsidian notebook with a category and summary, and I later post it to my blog. (I don't really think other people care, it's more for me to be able to find past things I've found interesting.)

For the archival process I use ArchiveBox[1] running as a container on my NAS; I just grep through the note for `http|https` and feed the resulting list to the archiver. For everything not-hackernews I set the depth to 1, but for HN threads I do 2 so I grab whatever people may have linked in the comments.

I think there's ways to hook into like, ALL Firefox history or saved posts on reddit, but that's way heavier than what I care for.

[1]: https://archivebox.io/

Re: Blocked by Cloudflare

#408

Earlier quoted context omitted.

I don't know that most web admins can tell if they should float a banner, so vague is the law. Technically, I think if you have the default Apache logging configured and you read those logs, you should probably float that banner.

I believe you're mistaken. GDPR allows you to record IP addresses for normal operation of a site, which specifically includes logging. No banner is required. GDPR is not "vague" about this; perhaps you haven't read it (as laws go, it's pretty easy to read).

It's easy to read because it's vague, and it's going to allow some regulator to decide whether my use of IP addresses constitutes "normal operation." Puts a hell of a lot of trust in government officials to decide who is worthy of prosecution.

It reminds me of the war on drugs in a lot of ways.

Re: Blocked by Cloudflare

#409

Earlier quoted context omitted.

You're going by the specified, designed use cases of those technologies. Every spec is a three-edged sword: the spec, the intent of the spec, and the use of the spec in the wild. In practice, Cloudflare does a pretty good job on far-more-than average of gluing together some heuristics in an unspec'd way to filter traffic. It sucks because you can't plan around it, but that's rather the point because the malicious act…

Why does HN have such aggressive and seemingly illogical post rate limits anyway? Is it a theory about increasing quality of communications? It can't be a tech bottleneck.

I don't have this information first hand, but that's my assumption.

Dang was handing them out like candy on January 6th. And I think he was justified in doing so; there was a coup in progress in the United States, so discourse here went completely off the rails.

But it's a very easy to implement method of throttling volume, which helps improve the conversation by minimizing opportunities for people to gish-gallop. You can email and ask to have it removed; I have refrained from doing so because it serves as a gentle reminder not to get dragged down in the lowest common denominator of what passes for discourse on the site from time to time.

Re: Blocked by Cloudflare

#410

Earlier quoted context omitted.

Not OP, but GitLab always cycles for me on LibreWolf, even with "enhanced tracking protection" turned off. It's likely because I disable WebGL? 7f3b42d2bee22efb

Could also be web workers if you're restricting those? Turnstile won't even load if web workers are disabled, it has no backup logic for that scenario. I can get into the linked site but only if I turn on web workers (I also have WebGL turned off), and while I don't have the RayIDs on me, I have run into scenarios where Turnstile refuses to let me on websites before. I'll add a second vote on here that Turnstile has…

Enabled them and restarted, still nothing (although there's a chance I messed it up somewhere, I haven't tested it thoroughly). But honestly, I don't really care given that 99% of the web works otherwise.
Post reply on HN