Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

411–420 of 473 posts

Re: Blocked by Cloudflare

#411

Earlier quoted context omitted.

This is untrue, but frequently misunderstood: Privacy and security are two facets of the same problem. If you don't have security, your privacy is at risk. If you don't have privacy, your security is at risk. Case in point: Many of those targeted ads contain malware. :)

Do you have any evidence of your claim.

Evidence of what? That malvertising exists?

Re: Blocked by Cloudflare

#412
post #154

Earlier quoted context omitted.

I sympathize with your frustration, but you also have to admit that Cloudflare is tasked with an impossible problem: from a sea of requests, identify those that are coming from robots that are disguised as humans. So there is no perfect solution. You can't use strong identity because a user can share their identity with a robot. You have to use a crapy heuristic that only works most of the time (or tell site owners i…

> but you also have to admit that Cloudflare is tasked with an impossible problem They're not tasked with anything. They choose to sell a bot detection and mitigation platform as a product, and that's a hard business to be in. If they think they can do it, great. If they can't, they shouldn't try.

But they are doing it and succeeding. No product is 100% perfect. The problem is that when it’s not perfect people can ostensibly (and arguably actually) be harmed if they can’t access content on the Cloudflare network. This is why we need more scrutiny around how large internet platforms deploy bot mitigation technology. We don’t need to tell people “sorry just suffer DoS attacks”.

Re: Blocked by Cloudflare

#413
post #274

Earlier quoted context omitted.

I thought it was the opposite: that instead of fingerprinting users, web services would instead just ask the browser which topics the user is interested in and display the relevant ADs. It's an explicit design goal to reduce the dependence on fingerprinting users, otherwise why would they do it. Topics are supposed to be the locally sourced privacy preserving alternative to invasive tracking. Whether Mozilla/Apple/ot…

For me the issue is a browser shouldn’t be making the information on the topics of sites I visit available to anyone who asks

Browsers don’t do that today and the result is that AD networks fingerprint and track you to try and serve you more relevant content.

The argument from supporters is that this is a step away from the “fingerprint and track” status quo MO. The argument from detractors is that it doesn't quite achieve that goal.

All you need to address your concern is for access to the API to be user-configurable.

Re: Blocked by Cloudflare

#414

Earlier quoted context omitted.

I have to believe you're attempting (but failing) to gaslight me you wrote: "it does seem to indicate that IPv6 is mostly pointless for human users for exactly this reason" ( https://news.ycombinator.com/item?id=37050359 ) he wrote: "If you think IPv6 is mostly pointless, I think you're unaware of the fact that a significant majority of phones already use IPv6 most of the time they're on cellular" ( https://news.ycom…

What are you on about? There's no sign of 'johnklos' quoting me as you claim. It literally appears in his own words, and he even wrote it in a manner that could not possibly be confused with my style of writing. Just check my recent comment history? Frankly, it's just impossible for there to be a 17 word phrase in that comment that can be interpreted as a quotation, even by a teenager who only started learning Englis…

I get it now!

you're a comedian!

thanks for the laughs - anyone who can straightfacedly deny what they wrote, and people referencing it such an obvious manner that you still deny must be in it for the humor value

Re: Blocked by Cloudflare

#415
post #350

Earlier quoted context omitted.

What are you on about? There's no sign of 'johnklos' quoting me as you claim. It literally appears in his own words, and he even wrote it in a manner that could not possibly be confused with my style of writing. Just check my recent comment history? Frankly, it's just impossible for there to be a 17 word phrase in that comment that can be interpreted as a quotation, even by a teenager who only started learning Englis…

Please accept this award for your outstanding contributions to the field of pedantry.

this MichaelZuo character seems to be pretty lost in understanding how to communicate (and then denying he's doing what he's actively doing)

I think he's in it for the humor value

Re: Blocked by Cloudflare

#416
post #350

Earlier quoted context omitted.

Please accept this award for your outstanding contributions to the field of pedantry.

this MichaelZuo character seems to be pretty lost in understanding how to communicate (and then denying he's doing what he's actively doing) I think he's in it for the humor value

MichaelZuo is defending an unnecessarily precise definition of the word "quote" and you are refusing to acknowledge it.

I doubt that either of you are in this for the humor; that simply emerges from the duration and pointlessness of the argument.

Re: Blocked by Cloudflare

#417
post #157

Earlier quoted context omitted.

And even when it doesn't block you completely, it delays website loading, makes you jump through frustrating captchas, etc. It's probably third in the list of frustrating web behaviors in the past couple of years (behind GDPR popups and registration/paywalls that seem to have gotten much worse recently). And somehow there are some sites that I get CF delay walls on every time I visit. This feature is utterly broken f…

It's worth noting that the websites that you are visiting chose Cloudflare, and have enabled the features that irritate you. They have browser integrity enabled, have bot protection enabled, maybe turned the security level up (gitlab famously is a nuisance because they lean heavily on Cloudflare for protection). Sometimes they've wholly barred VPNs or entire geographic areas! And that is entirely the decision of webs…

And this is precisely why I don't bother reporting Cloudflare's failures to site operators anymore. I used to do it, when it was pretty infrequent. Site operators were usually concerned that something was blocking customers, but most were clueless about what was causing it or how to fix it.

Eventually I gave up. I don't even bother with their captchas or other stupid human tricks anymore. Whenever Cloudflare gets between me and the site I'm trying to use, I move on and shop somewhere else. Life's too short for this.

Re: Blocked by Cloudflare

#418

Hi there, I'm the PM for Cloudflare's challenge platform. I'd love to look into what the cause of the problem is, so you don't see these difficulties. > Cloudflare detected the high frequency of requests and denials (but not their faulty loop that caused this pattern of requests, of course), and tagged my browser as suspicious. I can tell you at least that we don't penalize users for this looping behavior, so this wo…

I can’t get through any cloudflare challenges on a standard iPhone when I use iCloud Relay. Your product is as anti-user as it gets. It’s obvious you avoid user testing and instead look the other way because claiming to have solved the bot problem is just too profitable.

Re: Blocked by Cloudflare

#419

Earlier quoted context omitted.

Your alt solution is what?Everyone should build their shit to handle millions TB/s of DoS traffic?

Block the countries it comes from?

It sure would be nice if there was a reason DoS could only come from countries other than those of your customers/users. But that's not the case.

Re: Blocked by Cloudflare

#420

Earlier quoted context omitted.

They have before and after analytics.....

They will presume the before traffic was bots? Unless they also see a drop in sales or ads they won't notice.

I mean if sales didn't drop why would they care?
Post reply on HN