Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

421–430 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#421

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

if the purpose of cloudflare is to block bots and allow humans in, then they fail miserably at their job. what they're doing instead can be summarized in one word: DISCRIMINATION. welcome to the age of internet apartheid.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#422

Earlier quoted context omitted.

> Bad business, guys. You gotta find another way. Blocking IP addresses is o-ver. no, it's still the front line. And likely always will be. It's the only client identifier bots can't lie about. (or nearly the only) At $OLDJOB, ASN reputation was the single best predictor of traffic hostility. We were usually smart enough to know which we can, or can't block outright. But it's an insane take to say network based block…

I don't use iCloud Relay but it seems Apple's ASN would be 'reputable'.

Only because without consumers using their IPs, they're a well established company with predictable uses. Once people use it for everything, then the reputation will drop.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#423

Earlier quoted context omitted.

I wonder if cloudflare blocks like these affect screen reader users, in which case they may violate the ADA.

And if they did violate the ADA, do you seriously expect this administration's anti-DEI Department of Justice to pursue legal action?

[dead]

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#425

Yesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure…

if the purpose of cloudflare is to block bots and allow humans in, then they fail miserably at their job. what they're doing instead can be summarized in one word: DISCRIMINATION. welcome to the age of internet apartheid.

They are so successful in blocking noob scrapers that an entire industry is blooming around professional web scraping services.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#426

Earlier quoted context omitted.

> using Arc on a M1 MBP; normal browsing habits. Well i've certainly never heard of this browser before and it still seems pretty young. I'd guess it's the same issue.

Arc is almost 3 (4?) years old and was the darling child of dev influencers for the better part of 2 years. It's not a niche browser, especially amongst devs that are likely to work at Cloudflare.

It is a niche browser with no hype going for it.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#427

Earlier quoted context omitted.

How would you do DDoS protection without having something in path?

many ways but they are not plug and play so they would lose a few clients... but that is irrelevant as snooping trafic is their real businnes model.

What are those many ways? Help me understand - I've been doing this shit a long time and I can't think of many ways to provide what Cloudflare does in a way that is cheap, easy, and scalable without working at the HTTP layer. So please help me learn something new, what are those ways?

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#428
post #290

Earlier quoted context omitted.

Do you have the "resist fingerprinting" setting enabled in Firefox? (You can check in about:config)

"privacy.resistFingerprinting" is "true", yes, and it'll stay that way. Why let me solve a puzzle just to block me afterwards anyway?

Businesses that scrape websites for a living hire people in third-world countries to solve captchas 24/7 to keep the scraping bots running.

So when I successfully solve a captcha, that doesn't make me 100% trusted not-a-scraping-bot. Instead it's an input into a statistical model, along with all the other identifying information they can hoover up, and that statistical model may still say no.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#429

Earlier quoted context omitted.

I wonder if cloudflare blocks like these affect screen reader users, in which case they may violate the ADA.

And if they did violate the ADA, do you seriously expect this administration's anti-DEI Department of Justice to pursue legal action?

[flagged]

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#430

Earlier quoted context omitted.

Something like iDeal, which is a payment processing system in the Netherlands. It works so well and is very secure. You get to the checkout page on a website, click a link. If you’re on your phone, it hotlinks to open your banking app. If you’re on desktop, it shows a QR code which does the same. When your bank app opens, it says “would you like to make this €28 payment to Business X?” And you click either yes or no…

What kind of fraud protection does iDeal have for customers?

I’m not actually sure since I never had issues, but I’ve heard it’s not much since they’re basically just an API for transferring money between banks. Each bank app still needs to integrate with the network separately. [1]

I guess you get some security since each party that you transfer to must have their identity verified with a bank, so you could always get the police involved fairly easily

The iDeal website page on security [2] is in Dutch, but it translates to roughly:

> Before you make a purchase, make sure that the webshop or business is a reliable party. For example, you can read experiences of other consumers about webshops on comparison sites. Or you can use a Google search to check what is said (in reviews) about a webshop on the internet. Also check the overview of the police with known rogue trading parties and the page check seller data. Before making a purchase, always use the following rule of thumb: if something is too good to be true, don't do it.

[1] https://en.m.wikipedia.org/wiki/IDEAL

[2] https://www.ideal.nl/veiligheid

Post reply on HN