Live data from Hacker News

Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

news.ycombinator.com

521–530 of 554 posts

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#521
After almost ten days of deafening silence and broken Internet access, I guess we have to paraphrase Adam Martinetti, the Cloudflare Product Manager from 2022 and conclude that in 2025:

Cloudflare DOES want to be in the business of saying one browser is more legitimate than another.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#522

at this point, im honestly surprised that all non-mainstream browsers dont emulate the same user-agent and ssl fingerprint order of a mainstream browser - or add a flag to change behavior per "tab" (or if cli per some call or other scope) - coupled with a javascript-operating-system which also aligns with those

In concept that's a good idea, but the fingerprinting potential is VAST: user-agent, TLS, JavaScript quirks, CSS, Canvas, proprietary features like Chrome's Topics, maybe WebGL, WebUSB, etc. In practice it's very hard to do.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#523

Earlier quoted context omitted.

So you too, are saying “its possible” as proof of your argument. Which itself shifted from complaining that you aren’t warned that coffee is hot, to - after implicitly agreeing that it should be obvious it’s hot - complaining that it they didn’t have to make it as hot. Great! Offer an alternative! Everyone would be more than happy.

Not that it's "possible", that it requires them to add nothing new . That is a much much easier to reach bar. It's like if a restaurant sells cheeseburgers, and I want a hamburger. "How do they figure out ~~what~to~cache~~ the cheese to ketchup ratio without adding cheese?" They can just skip that part. I'm not asking for sushi and supporting that by saying "sushi is possible".

So you agree that your argument has shifted from complaining about inadequate disclosure that coffee contains caffeine, to complaints about lack of decaf offerings.

It would also be trivial for google and facebook to turn off all ads and logging of your activity. They would need to do strictly less than they do now. It would benefit all users too!

In CF case they would have to build a completely different infrastructure to detect bots using different technology to what they have now, including different ways around false positives for legitimate users. While perhaps nothing new in the sense that you claim “this is possible”, i see no one else offering this mythical “possible” product.

I would be the first in line to your offering of free cheeseless hamburgers. Where do i sign up?

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#524

Earlier quoted context omitted.

Not that it's "possible", that it requires them to add nothing new . That is a much much easier to reach bar. It's like if a restaurant sells cheeseburgers, and I want a hamburger. "How do they figure out ~~what~to~cache~~ the cheese to ketchup ratio without adding cheese?" They can just skip that part. I'm not asking for sushi and supporting that by saying "sushi is possible".

So you agree that your argument has shifted from complaining about inadequate disclosure that coffee contains caffeine, to complaints about lack of decaf offerings. It would also be trivial for google and facebook to turn off all ads and logging of your activity. They would need to do strictly less than they do now. It would benefit all users too! In CF case they would have to build a completely different infrastruct…

> So you agree that your argument has shifted from complaining about inadequate disclosure that coffee contains caffeine, to complaints about lack of decaf offerings.

My argument has never shifted.

But the reason the argument shifted was because someone specifically asked about how you'd do DDoS protection without those downsides.

And you continued asking how it could be done.

> It would also be trivial for google and facebook to turn off all ads and logging of your activity. They would need to do strictly less than they do now. It would benefit all users too!

Isn't cloudflare supposedly not tracking private information in the websites they proxy...? If you think they make money off it, that's pretty bad...

> In CF case they would have to build a completely different infrastructure to detect bots using different technology to what they have now, including different ways around false positives for legitimate users.

I disagree.

> I would be the first in line to your offering of free cheeseless hamburgers. Where do i sign up?

First you need to put me into a situation where my business can compete with cloudflare while doing exactly the same things they do. Then I will be happy to comply with that request.

The hard part of this situation is not the effect of that tiny change on profitability, it's getting into a position where I can make that change.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#525
post #59
post #53

Do these browsers employ any additional tracking protections? "Browser integrity checks" are browser-specific and they might rely on the "entropy" those tracking vectors provide.

So this would only be "bad" move by cloudflare if you could get around it by recompiling the browser with spoofed UA/strings. Otherwise they'd have to support every possible engine which is infeasible. That saying, the "open web" is indeed dead.

> Otherwise they'd have to support every possible engine which is infeasible.

If I understand correctly, this is why I've said on previous Cloudflare threads that they've managed to design a game they can never win. They project a certain omniscience, but then all this sh*t happens. We need to persuade them to stop playing.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#526

All by design. The idea is to keep older devices, ones with perhaps no government backdoors, and unauthorized software, off the Internet completely. Same reason there's a big push to kill X11 - it runs great on computers from before hardware backdoors were common. With the Trumpenreich looming, these devices will become very useful. IF they are allowed on the Internet.

Can be explained with fewer assumptions.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#527
In the past a Cloudflare representative typically appears in these threads, and if that's happened, I missed it. Not to mention the MVP's comment in the locked Cloudflare thread that

"You should use an up to date major browser. Old Firefox forks are not supported and expected to have problems."

It's all incredibly telling, that they've given up trying to be impartial. When "they" start picking browser winners and losers, are OS's next?

In a way Cloudflare missed an opportunity, because a try()/catch() around the bit of failing JavaScript would have been perfect fingerprinting. Having said that, I don't expect it will take the Pale Moon team very long to patch the problem.

But where to go from here? Is there anybody besides the ACLU and EFF with enough resources to mount a "public nuisance" lawsuit? And what would constitute winning? A court-appointed overseer to make sure Cloudflare is regularly educating its staff on the variety of browsers in use today, and providing near 24–hour turnaround times when issues like this occur? It would be a start.

Personally I wonder if this whole style of security is a fool's errand and any blocking should be server-based and look at behavior, not at arbitrary support of this or that feature. I think it would also be helpful if anybody who finds themselves blocked would be given at least a sliver of why they were blocked, so they could try rectifying the problem with their ISP (bad IP), some blocklist, etc.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#528

Earlier quoted context omitted.

So you agree that your argument has shifted from complaining about inadequate disclosure that coffee contains caffeine, to complaints about lack of decaf offerings. It would also be trivial for google and facebook to turn off all ads and logging of your activity. They would need to do strictly less than they do now. It would benefit all users too! In CF case they would have to build a completely different infrastruct…

> So you agree that your argument has shifted from complaining about inadequate disclosure that coffee contains caffeine, to complaints about lack of decaf offerings. My argument has never shifted. But the reason the argument shifted was because someone specifically asked about how you'd do DDoS protection without those downsides. And you continued asking how it could be done. > It would also be trivial for google an…

> Isn't cloudflare supposedly not tracking private information in the websites they proxy...?

They are at the very least tracking the users and using that tracking as part of the heuristics they use in their product.

Whether they sell the data for marketing, i don’t know, hopefully not but conceivably, yes.

To which, > I disagree.

Yes, we’ve established that you disagree and explicitly claim “it’s possible to offer ddos protection without mitm”

and now further that “dropping the extra feature of caching” would not adversely affect their technology or their business”

Great, claims though entirely unsupported and in the latter case obviously false if you know anything about how it works.

In particular, they would need to sponsor the free accounts via much poorer economies of scale due to not being able to cache anything, and would not help at all with a “legitimate ddos” such as being on the front page here

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#529
post #289

Earlier quoted context omitted.

Not the same poster, but the first "D" in "DDoS" is why rate-limiting doesn't work - attackers these days usually have a _huge_ (tens of thousands) pool of residential ip4 addresses to work with.

Is ten of thousands a big number again?

Depends. Ten thousand what?

I work on a "pretty large" site (was on the alexa top 10k sites, back when that was a thing), and we see about 1500 requests per second. That's well over 10k concurrent users.

Adding 10k requests per second would almost certainly require a human to respond in some fashion.

Each IP making one request per second is low enough that if we banned IPs which exceeded it, we'd be blocking home users who opened a couple of tabs at once. However, since eg universities / hospitals / big corporations typically use a single egress IP for an entire facility, we actually need the thresholds to be more like 100 requests per second to avoid blocking real users.

10k IP addresses making 100 requests per second (1 million req/s) would overwhelm all but the highest-scale systems.

Re: Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers

#530

Earlier quoted context omitted.

> So you agree that your argument has shifted from complaining about inadequate disclosure that coffee contains caffeine, to complaints about lack of decaf offerings. My argument has never shifted. But the reason the argument shifted was because someone specifically asked about how you'd do DDoS protection without those downsides. And you continued asking how it could be done. > It would also be trivial for google an…

> Isn't cloudflare supposedly not tracking private information in the websites they proxy...? They are at the very least tracking the users and using that tracking as part of the heuristics they use in their product. Whether they sell the data for marketing, i don’t know, hopefully not but conceivably, yes. To which, > I disagree. Yes, we’ve established that you disagree and explicitly claim “it’s possible to offer d…

> They are at the very least tracking the users and using that tracking as part of the heuristics they use in their product.

They can do that without seeing the proxied contents. So your analogy to asking facebook or google to stop ads and tracking is completely broken.

> and now further that “dropping the extra feature of caching” would not adversely affect their technology or their business”

Yes. (Well, it was stated much earlier but I guess you didn't notice until now?) You're the one saying it would be a problem, do you have anything to back that up?

> in the latter case obviously false if you know anything about how it works.

Caching costs a bunch of resources and still uses lots of bandwidth, what's so obvious about it? And cloudflare users can already cache-bust at will, so it's not exactly something they're worried about.

https://developers.cloudflare.com/cache/how-to/cache-rules/s...

> would not help at all with a “legitimate ddos” such as being on the front page here

Which is not the scenario people were worrying about.

And an average web server can handle that.

Post reply on HN