Live data from Hacker News

Firefox appears to be flagged as suspicious by Cloudflare

lwthiker.com

51–60 of 191 posts

Re: Firefox appears to be flagged as suspicious by Cloudflare

#51

A workaround is to install the Privacy Pass extension to bypass the captchas [1] [2] It's an open source extension available for Chrome and Firefox. It allows to privately identify you're human, and is the process of going through IETF standardisation, so hopefully someday you won't need to install an extension for it. After you complete a captcha once, you won't need to do it again for a long time. I'm not happy abo…

Deanonymizing yourself just to appease cloudflare is not a valid solution. Any website should work in any browser out of the box. If they don't, the website is broken.

> If they don't, the website is broken.

The Internet is a network with social effects. Whether "this didn't work" means "the website is broken" or "the browser is broken" has always been more about end-user experience and the wisdom of crowds than a more concrete definition.

A website broken only on Firefox works for 96.5% of users. I have personally had to make the hard judgment call (as a fan of Firefox!) to not spend 25% of our engineering debugging time on a problem only 3.5% of users encounter.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#52

Earlier quoted context omitted.

Deanonymizing yourself just to appease cloudflare is not a valid solution. Any website should work in any browser out of the box. If they don't, the website is broken.

"The blind signing procedure ensures that passes that are redeemed in the future are not feasibly linkable to those that are signed. We use a privacy-preserving cryptographic protocol based on ‘Verifiable, Oblivious Pseudorandom Functions’ (VOPRFs) built from elliptic curves to enforce unlinkability. The protocol is exceptionally fast and guarantees privacy for the user. As such, Privacy Pass is safe to use for those…

Unless you're a mathematician or a cryptographer who's qualified to verify these claims, I think all of this amounts to "trust us."

Re: Firefox appears to be flagged as suspicious by Cloudflare

#54
post #49

Earlier quoted context omitted.

Really? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accep…

I don't even have another browser installed.

I'm an ex-webnik who still occasionally dabbles in web design, so have all of them installed.

Unused, mostly, but installed :)

Re: Firefox appears to be flagged as suspicious by Cloudflare

#55

I think it's two-fold: rise of tools like curl-impersonate ( https://github.com/lwthiker/curl-impersonate ) and the very consistent Firefox TLS fingerprint across platforms. Unlike Chromium (where you could differentiate a Linux, Mac or Windows computer from its chiphers, and so for example challenge only Linux clients), Firefox has NSS and NSS is used everywhere the Gecko engine is used while Chromium, although has…

Quoted post unavailable.

That's pretty much what they did with Tor, yes.

Remember that Cloudflare's business model is MITM-as-a-service, they don't really like the idea of privacy.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#56
post #2

I mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, a…

Really? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accep…

Often, just changing the user agent string so that Firefox appears to be Chrome will let those sites work. I.e. they work fine in Firefox, but are restricted by user agent string checks to reject that browser and/or OS.

There are several plugins for Firefox that make this easy.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#57
I've been de-googling all of my services and software over the last couple years including a switch to firefox.

I have noticed cloudflare challenging me more and more often. I assumed it was related to privacy extensions like noscript, ublock, and privacy badger.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#58

Earlier quoted context omitted.

"The blind signing procedure ensures that passes that are redeemed in the future are not feasibly linkable to those that are signed. We use a privacy-preserving cryptographic protocol based on ‘Verifiable, Oblivious Pseudorandom Functions’ (VOPRFs) built from elliptic curves to enforce unlinkability. The protocol is exceptionally fast and guarantees privacy for the user. As such, Privacy Pass is safe to use for those…

Sorry, can I get a layman's translation? What prevents websites from using Privacy Pass to track user behavior? (Beyond determining who is and is not a bot.)

Cloudflare is the one putting up the captcha-wall and deciding whether to forward your request to the destination site. Your browser sends Cloudflare a token, then if Cloudflare accepts the token, it forwards your request. The destination site does not see the token and so cannot use it to track you.

Since Cloudflare does see the token, it's reasonable to consider whether Cloudflare could deanonymize you across different sites. Privacy Pass uses cryptography that claims to prevent that.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#59

Earlier quoted context omitted.

Deanonymizing yourself just to appease cloudflare is not a valid solution. Any website should work in any browser out of the box. If they don't, the website is broken.

> If they don't, the website is broken. The Internet is a network with social effects. Whether "this didn't work" means "the website is broken" or "the browser is broken" has always been more about end-user experience and the wisdom of crowds than a more concrete definition. A website broken only on Firefox works for 96.5% of users. I have personally had to make the hard judgment call (as a fan of Firefox!) to not sp…

That's too bad. If you didn't make that call it would probably have larger market share. What you've done actually feeds in to the problem.

Re: Firefox appears to be flagged as suspicious by Cloudflare

#60
post #2

I mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, a…

Cool Username
Post reply on HN