Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

411–420 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#411

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

> I would be pretty upset if I implemented Cloudflare and it started to inadvertently hurt my sales figures. The problem is that all these Cloudflare forensics-based throttling and blocking efforts don't hurt sales figures. The number of legitimate users running Arc is a rounding error. Arc browser users often come to Cloudflare without third-party tracking and without cookies, which is weird and therefore suspicious…

I wonder if cloudflare blocks like these affect screen reader users, in which case they may violate the ADA.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#412

Earlier quoted context omitted.

> On the other hand, without Cloudflare I'd be seeing thousands of junk requests and hacking attempts everyday, people attempting credit card fraud, etc. Yup! > I honestly don't know what the solution is. Force law enforcement to enforce the laws. Or else, block the countries that don't combat fraud. That means... China? Hey isn't there a "trade war" being "started"? It sure would be fortunate if China (and certain o…

Slightly more complicated because a ton of the abuse comes from IPs located western countries, explicitly to evade fraud and abuse detection. Now you can go after the western owners of those systems (and all the big ones do have have large abuse teams to handle reports) but enforcement has a much higher latency. To be effective you would need a much more aggressive system. Stronger KYC. Changes in laws to allow for l…

And that assumes that the Western owners of those systems have any reason to listen to you, the one raising the complaint. How would they check that you are not lying?

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#413
post #392
post #358

Earlier quoted context omitted.

There is some political-philosophical irony that the Chinese prefer their government to do the blocking and take away their freedom, while the US prefers their monopolistic capitalistic corporate world to do it. A rose by any other name. Chose your friends carefully.

To trivialize totalitarian regimes that carry out terror against their own citizens, that can outright kill you and whole your family, by comparing them to capitalistic corporate world where, in the worst case, you can simply choose another, less fancy option, is the height of madness.

Your snide comment might have had some weight if there had been zero instances of the US government [0] or US corporations [1] killing people.

[0] https://en.wikipedia.org/wiki/List_of_assassinations_by_the_...

[1] https://en.wikipedia.org/wiki/List_of_worker_deaths_in_Unite...

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#414
post #392
post #358

Earlier quoted context omitted.

There is some political-philosophical irony that the Chinese prefer their government to do the blocking and take away their freedom, while the US prefers their monopolistic capitalistic corporate world to do it. A rose by any other name. Chose your friends carefully.

To trivialize totalitarian regimes that carry out terror against their own citizens, that can outright kill you and whole your family, by comparing them to capitalistic corporate world where, in the worst case, you can simply choose another, less fancy option, is the height of madness.

https://apnews.com/article/wisconsin-asthma-medicine-lawsuit...

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#415
post #109

As a website owner and VPN user I see both sides of this. On one hand, I get the annoying "Verify" box every time I use ChatGPT (and now due its popularity, DeepSeek as well). On the other hand, without Cloudflare I'd be seeing thousands of junk requests and hacking attempts everyday, people attempting credit card fraud, etc. I honestly don't know what the solution is.

What is a "junk" request? Is it hammering an expensive endpoint 5000 times per second, or just somebody using your website in a way you don't like? I've also been on both sides of it (on-call at 3am getting dos'd is no fun), but I think the danger here is that we've gotten to a point where a new google can't realistically be created. The thing is that these tools are generally used to further entrench power that mono…

+1 for spite-driven development.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#417

Earlier quoted context omitted.

From my experience, if you tick off the wrong person, the threshold for them starting a DDoS is surprisingly low. A while ago, my company was hiring and conducting interviews, and after one candidate was rejected, one of our sites got hit by a DDoS. I wasn't in the room when people were dealing with it, but in the post-incident review, they said "we're 99% sure we know exactly who this came from".

What the hell is wrong with people? Honestly the lack of substantive human interaction in a lot of folks' lives, except via the Internet, is a real problem. Take that story for instance. Here's how that goes in the physical world, just to show how unbelievably ridiculous it is. So you didn't get the job? What's your next step? I'll stop by their office and keep people from entering the front doors by running around i…

[deleted]

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#418

How many of you all are running bare metal hooked right up to the internet? Is DDoS or any of that actually a super common problem? I know it happens, but also I've run plenty of servers hooked directly to the internet (with standard *nix security precautions and hosting provider DDoS protection) and haven't had it actually be an issue. So why run absolutely everything through Cloudflare?

I run my "server" [1] straight to my home internet, and maybe I should count my blessings but I haven't had any issues with DDoS in the years I've done this.

I have relatively fast internet, so maybe it's fast enough to absorb a lot of the problems, but I've had good enough luck with some basic Nginx settings and fail2ban.

[1] a small little mini gaming PC running NixOS.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#419

Earlier quoted context omitted.

> I would be pretty upset if I implemented Cloudflare and it started to inadvertently hurt my sales figures. The problem is that all these Cloudflare forensics-based throttling and blocking efforts don't hurt sales figures. The number of legitimate users running Arc is a rounding error. Arc browser users often come to Cloudflare without third-party tracking and without cookies, which is weird and therefore suspicious…

I wonder if cloudflare blocks like these affect screen reader users, in which case they may violate the ADA.

And if they did violate the ADA, do you seriously expect this administration's anti-DEI Department of Justice to pursue legal action?

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#420

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

> I would be pretty upset if I implemented Cloudflare and it started to inadvertently hurt my sales figures. The problem is that all these Cloudflare forensics-based throttling and blocking efforts don't hurt sales figures. The number of legitimate users running Arc is a rounding error. Arc browser users often come to Cloudflare without third-party tracking and without cookies, which is weird and therefore suspicious…

What about all false positives in aggregate?

The problem is site owners do not know - it just adds to the number of blocked threats in cloudflare's reassuring emails.

Post reply on HN