Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

481–490 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#481
post #51

This echoes the user agent checking that was prevalent in past times. Websites would limit features and sometimes refuse to render for the "wrong" browser, even if that browser had the ability to display the website just fine. So browsers started pretending to be other browsers in their user agents. Case in point - my Chrome browser, running on an M3 mac, has the following user agent: "'Mozilla/5.0 (Macintosh; Intel…

Slack was doing this with their huddle feature for the longest time (still were last I checked). Drives me crazy.

Doesn't drive me crazy - gives me a "Get Out of Huddles Free" card.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#482

Earlier quoted context omitted.

I call your bluff. Do it.

https://www.forbes.com/sites/gusalexiou/2023/06/30/website-a... https://www.the215guys.com/blog/ada-lawsuits-targeting-websi...

the first link had one comment in support of the move, and a single, dissenting (yet reasonable) reply.2nd article had no comments whatsoever. Remember, the claim I'm responding to was "literally hundreds of posts from people insisting that ADA is nothing but a small-business-killing shakedown, that it's makework for lawyers, that it's doing nothing to help the disabled"

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#483

Earlier quoted context omitted.

The number of legitimate users on "not chrome, edge, safari, or firefox" is about 10% of the browser market. I don't know about you, but if I'm running a shop, and the whole point of my website is to make sales, but my front door is preventing 10% of those sales? That door is getting replaced.

If you were running a shop, you would realize that nearly 100% of the fraud is "not chrome, edge, safari, or firefox" It's unfortunate yes but that's what drives the threat signatures

Why would fraudsters use a browser that's likely to be blocked? They'll be using the standard browsers like (mostly) everyone else.

edit: it's noted downthread that automated testing of card details to find valid ones is a reason.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#484

Earlier quoted context omitted.

> I would be pretty upset if I implemented Cloudflare and it started to inadvertently hurt my sales figures. The problem is that all these Cloudflare forensics-based throttling and blocking efforts don't hurt sales figures. The number of legitimate users running Arc is a rounding error. Arc browser users often come to Cloudflare without third-party tracking and without cookies, which is weird and therefore suspicious…

Something tells me that if you asked the store owner that the poster tried to give money to, they'd be furious at cloudflare for stopping the transaction.

Yeah maybe if you somehow managed to email them without their email provider stopping that email from reaching them…

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#485
post #368

Earlier quoted context omitted.

Wait, this comment made me aware of the existence of iCloud Relay. Apple built their own Tor only for Apple users? Why would they do that? Why not use Tor???

You can use iCloud Relay without even noticing that you are using it, this is not true with Tor as you'll spend most of your time waiting for reconnecting circuits.

That doesn't line up with my experience at all.

You will still notice when some sites completely block you, of course.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#486

Earlier quoted context omitted.

> I would be pretty upset if I implemented Cloudflare and it started to inadvertently hurt my sales figures. The problem is that all these Cloudflare forensics-based throttling and blocking efforts don't hurt sales figures. The number of legitimate users running Arc is a rounding error. Arc browser users often come to Cloudflare without third-party tracking and without cookies, which is weird and therefore suspicious…

What about all false positives in aggregate? The problem is site owners do not know - it just adds to the number of blocked threats in cloudflare's reassuring emails.

It is difficult to gauge the size of the Cloudflare effect.. if the usage statistics the site owner is collecting.. are also not collected for those undesirables.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#487

Can't you set your user agent to something else? Like Firefox or Chrome.

They flat out refuse to show what the origin server sent, unless you run some Javascript. Which is sufficient to no longer care about what the browser states in the request headers.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#488
May be the case is that filtering user by browser UA is no longer a feasible solution(new browsers and alike are growing), and neither running javascript(headless chrome everywhere).

For local physical store, geo-location is a naturally filter for customers as long as beaming a person from a spaceship to earth is not invented. For web, a equally effective solution is very hard to find.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#489

Earlier quoted context omitted.

> invent other ways Just turning off some features gets them just about there. It wouldn't take rearchitecting things. Those features being bundled by default means very little for the difficulty.

So you too, are saying “its possible” as proof of your argument. Which itself shifted from complaining that you aren’t warned that coffee is hot, to - after implicitly agreeing that it should be obvious it’s hot - complaining that it they didn’t have to make it as hot. Great! Offer an alternative! Everyone would be more than happy.

Not that it's "possible", that it requires them to add nothing new.

That is a much much easier to reach bar.

It's like if a restaurant sells cheeseburgers, and I want a hamburger. "How do they figure out ~~what~to~cache~~ the cheese to ketchup ratio without adding cheese?" They can just skip that part. I'm not asking for sushi and supporting that by saying "sushi is possible".

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#490

Earlier quoted context omitted.

Because it's more work? Also 2fa often fails for the rightful card owner. And Cloudflare overzealous "security" is one of the reasons for failure.

in europe 2fa is mandatory for all (or almost all) online purchases, especially first time purchase from a merchant when your card hasn't been authorized. Sites using stripes' link get away with no 2fa most of the time, but not all the time. Make it mandatory on visa/mastercards level, and you won't loose much sales, as all transactions would require it and people will have to 2fa everywhere.

Yeah, and this is actually a huge pain for visitors. I was in Europe a couple months ago and couldn't buy stuff like train tickets online. Why? Because everything wants to verify with a text, and I couldn't do that because I had gotten a European SIM card because my US plan doesn't do international roaming.

There are several colliding problems there (cheap cell phone plan, 2fa being via text, online purchases requiring 2fa) but it still illustrates to me the pain of doing simple stuff in the modern tech space. I wish the powers that be would work harder on solutions that don't require extra work from the people doing small, normal stuff. It would be better to have a lot more fraud occur but a lot more of the perpetrators pursued and caught. A lot of anti-fraud measures seem to be largely about passing the buck to someone else instead of actually eliminating the humans who are driving the fraud.

Post reply on HN