Live data from Hacker News

Blocked by Cloudflare

jrhawley.ca

51–60 of 473 posts

Re: Blocked by Cloudflare

#51
I cannot access flyertalk.com, which hosts lot of useful airline content from any IP from my country. I tried reaching out via email as mentioned in the error page and admin does even have a valid email posted anywhere.

I know cloudflare is not to blame here, but they provide way easy access to blocking to bad admins.

Re: Blocked by Cloudflare

#52

I've had the exact same problem for a while. Here are some of the sites I've been unable to access (found by searching for "just a moment" in my browser history): - https://gitlab.com/users/sign_in - https://steamdb.info/login/ - https://www.zabbix.com/forum/ - https://casetext.com/ - https://namemc.com/login - https://spinroot.com/ - https://camelcamelcamel.com/ It's really annoying and Cloudflare is apparently doin…

If only there was some open standard for browsers to verify that a real human is visiting a website, so that website owners wouldn't have to rely on bespoke hacks that only work in chrome.

Re: Blocked by Cloudflare

#53

Earlier quoted context omitted.

That's not going to be enough to pass Cloudflare.

Based on what? https://developers.cloudflare.com/support/troubleshooting/ge...

https://developers.cloudflare.com/bots/reference/verified-bo...

https://radar.cloudflare.com/traffic/verified-bots

https://blog.cloudflare.com/friendly-bots/

> At Cloudflare, we manually “verify” good bots, so they don’t get blocked.

Re: Blocked by Cloudflare

#54
post #43

> Worse yet, I know that Cloudflare knows I have those certificates. Why? Because it asked for them! It doesn’t make sense for Cloudflare to request any client certificates. I think there are real bugs somewhere.

Cloudflare allows you to enable mTLS for websites:

https://developers.cloudflare.com/ssl/client-certificates/en...

https://developers.cloudflare.com/cloudflare-one/identity/de...

This would then require Cloudflare to request a client certificate. This is great for securing websites using corporate identity that is derived from AD certs for example to make sure the device being used has a valid cert on it.

Alongside MDM for example forcing the certificate to have a short lifespan (my $CORP uses 7 days) you can validate that the device has the correct security posture to access the resources.

If for example I let my device not update the version of macOS often enough my cert expires and I can't access internal resources until I update my OS and MDM software checks that and provisions me a new device certificate.

Re: Blocked by Cloudflare

#55
post #12

Any time a large portion of internet traffic is controlled by a single source it brings problems like this with it. All cloudflare has to do is arbitrarily decide who and who can't use the internet and effectively their word becomes law. Like most things it starts with an innocent premise (e.g. "an easy way to stop bad actors") and ends up extended to any number of arbitrary things. Worse, the argument from privacy a…

> Companies like Cloudflare, Google, Meta, etc are the reason anti-trust law exists

Only if Cloudflare stops you moving to a competitor.

Re: Blocked by Cloudflare

#56
The big problem I have with Cloudflare's integrity check is that all the spam domains use a fake version which mimics it, and tries to trick you into completing a captcha.

Re: Blocked by Cloudflare

#57

I've had the exact same problem for a while. Here are some of the sites I've been unable to access (found by searching for "just a moment" in my browser history): - https://gitlab.com/users/sign_in - https://steamdb.info/login/ - https://www.zabbix.com/forum/ - https://casetext.com/ - https://namemc.com/login - https://spinroot.com/ - https://camelcamelcamel.com/ It's really annoying and Cloudflare is apparently doin…

It happens to me all the time. And it has been going on for years, but it's getting noticeably worse over time. One way or another you have to pay to use the web, be it costing you loss of access because of your strict privacy settings or paying by giving away your privacy. There's no win here..

Re: Blocked by Cloudflare

#58
post #9

> The next day, I tried accessing a web page internal to my company… […] I couldn’t get past a security check page because of issues in Cloudflare’s software. […] The silliness of it all is that I was on my work device the whole time, which was behind my workplace VPN. This seems more like an "IT department gone mad" problem than a Cloudflare problem. I'm surprised they'd rather switch to Chrome than submit a support…

Passkeys have optional attestation payloads, which is basically what WEI is doing. Google in particular doesn't recommend requiring attestation except in corporate-security scenarios, but the fear is that banking and media sites will require attestation anyway, which locks users into whatever attestation mechanisms supported by the server; so basically Google, Apple and Microsoft.

Re: Blocked by Cloudflare

#59
post #21

Users in Egypt are unable to visit my Fitness website https://musclewiki.com Cloudflare is a huge part of the internet. Often they won't respond and it appears that for whatever reason, their IP range is blocked in Egypt. We probably get 10 support emails per week. I contacted Cloudflare and they simply said there is nothing they can do.

If you don’t want to stop using CloudFlare or need a temporary solution ask your users from Egypt to use VPN- many already do as they come across similar problems for other services

Egypt do block VPNs in much more aggressive way than Cloudflare. Also this is my first time to hear that cloudflare is blocked in Egypt. People will even complain that they cannot connect to their cooperate VPNs.

Blocking cloudflare ip addresses means that half of the internet wouldn't be accessible from Egypt. its closw to blocking port 443 because some people use DNS over https.

disclaimer: I'm Egyptian living in the US.

Re: Blocked by Cloudflare

#60
post #43

> Worse yet, I know that Cloudflare knows I have those certificates. Why? Because it asked for them! It doesn’t make sense for Cloudflare to request any client certificates. I think there are real bugs somewhere.

It's requesting client certs for their internal intranet stuff hosted behind cloudflare.
Post reply on HN