Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

431–440 of 473 posts

Re: Blocked by Cloudflare

#431

Earlier quoted context omitted.

Would you be willing to share a rayID you see during one of these looping challenges? I'm the PM for Cloudflare's challenge platform, and we'd love to look into this. RayIDs contain no PII so you can share publicly, or feel free to drop me an email at amartinetti at cloudflare. We'll also release a reporting mechanism soon, so in the future you can let us know when you see these issues and we can react to them quickl…

Here's a handful: - 7f395b5ddfe43a54 - 7f395ca09bfa3a54 - 7f395d8afaf73a54 - 7f395f075e33690d - 7f396102afef35fd

Thanks for the examples! Would you be able to share browser and extension information with me? If you don't want to share publicly I've dropped my email in this thread.

Re: Blocked by Cloudflare

#432

Earlier quoted context omitted.

Man in the middle attack typically implies an unwanted third party, which in this case is not true since Cloudfare is explicitly and voluntarily trusted by the host server. It wouldn't be all that different if the web server had the browserintegrity checks developed themselves.

>an unwanted third party This is precisely what Cloudflare is doing to end users - causing problems like OP (and myriad others) experience by slowing down and/or blocking major chunks of the internet

I understand that it may be viewed as unpleasant, but ultimately if you install a proxy on your end that the server does not like (say an ad-blocker), I don't think it would be fair for the server to say its suffering a MITM attack. Likewise, even if the client is not happy with the third party the server is requesting, it still doesn't make sense to call it a MITM, IMO.

Re: Blocked by Cloudflare

#433

Earlier quoted context omitted.

Honestly the SerenityOS browser (+ its Linux port, Ladybird) is probably the funniest. I wonder if that passes CloudFlare...

Servo seems to be more viable than Ladybird

I remember back when you could run the Servo app on macOS, it was a doge inside a cog and you could actually browse the internet, there was an address bar and back/forward buttons. But now they've actually removed that sort of stuff and given up on making a standalone browser in Rust, in favor of augmenting Firefox instead. See Firefox Quantum.

Re: Blocked by Cloudflare

#434
post #336

Earlier quoted context omitted.

OK, but not with a balaclava.

Will a fake nose, moustache and glasses do? (My point? Characterising anonymity with an item of clothing associated with paramilitaries has associations that don't need to be there.)

I think that a randomly generated completely real looking expert disguise is probably best. And a pain in the ass.

Re: Blocked by Cloudflare

#435

Earlier quoted context omitted.

Your alt solution is what?Everyone should build their shit to handle millions TB/s of DoS traffic?

Block the countries it comes from?

This is what Cloudflare already does, and it's hellish for users.

Re: Blocked by Cloudflare

#436

Earlier quoted context omitted.

They will presume the before traffic was bots? Unless they also see a drop in sales or ads they won't notice.

I mean if sales didn't drop why would they care?

If it's a ebsite that doesn't sell anything they won't notice.

Re: Blocked by Cloudflare

#437

Earlier quoted context omitted.

Servo seems to be more viable than Ladybird

I remember back when you could run the Servo app on macOS, it was a doge inside a cog and you could actually browse the internet, there was an address bar and back/forward buttons. But now they've actually removed that sort of stuff and given up on making a standalone browser in Rust, in favor of augmenting Firefox instead. See Firefox Quantum.

Mozilla actually fired the Servo developers to focus solely on Firefox (they still employ Rust developers, just not on Servo). But after some years, other companies picked up development on Servo.

Servo doesn't have a browser but I'd wager that writing a full featured browser for Servo would be much more useful than another Blink browser

Re: Blocked by Cloudflare

#438
post #413

Earlier quoted context omitted.

For me the issue is a browser shouldn’t be making the information on the topics of sites I visit available to anyone who asks

Browsers don’t do that today and the result is that AD networks fingerprint and track you to try and serve you more relevant content. The argument from supporters is that this is a step away from the “fingerprint and track” status quo MO. The argument from detractors is that it doesn't quite achieve that goal. All you need to address your concern is for access to the API to be user-configurable.

Anyone who believes that ad networks won't continue to do fingerprinting in addition to whatever privacy leaks Chrome adds is a fool.

Re: Blocked by Cloudflare

#439
post #84

So many privacy nuts use Chrome and don't realize this: > What about Google Chrome? > I tried all of the above in Firefox. So I naturally tried to access the same page in Google Chrome to see if I’d still be blocked. Thankfully, I wasn’t. > But of course I wasn’t because Chrome doesn’t have the same privacy- and security-enhancing designs that Firefox does. Chrome will happily collect as much private information abou…

This loop happened all the time for me in Kiwi Browser on mobile. I have a couple of fingerprint-reducing extensions installed there. I also use other extensions like Dark Reader to make website backgrounds pitch black to reduce OLED display drain and improve readability in darker environments. It appears to be better lately, happening more often while I am travelling and changing IPs, less when I am at home. Still it wastes time when it does the loop, it forces me to use unmodified Chrome, wasting more battery power and harming eyes at dark with those white backgrounds. Unfortunately more and more websites are proxying through CF, thinking they are 'protecting' their website. But CF acts like the chinese Great Firewall, deciding who can and cannot to access the site.

Re: Blocked by Cloudflare

#440
post #84

So many privacy nuts use Chrome and don't realize this: > What about Google Chrome? > I tried all of the above in Firefox. So I naturally tried to access the same page in Google Chrome to see if I’d still be blocked. Thankfully, I wasn’t. > But of course I wasn’t because Chrome doesn’t have the same privacy- and security-enhancing designs that Firefox does. Chrome will happily collect as much private information abou…

The heuristics used to attempt to differentiate between a so-called "bot" and a "human" are, IMHO, inadequate as long as there are "humans" that are allegedly mistaken for "bots" and blocked. "Use Chrome" is not a solution. A person using Firefox or some other non-Google software is still a "human". But not according to these brilliant "site protection" schemes. What level of false positives is acceptable. Using JS t…

Blocking bots in the first place should not be acceptable since bots only act on behalf of humans. What should be blocked is abusive behavior that actually impacts the site - a single one off GET to what should be a static page should never be blocked, yet that's what CF does.
Post reply on HN