Live data from Hacker News

Tell HN: Cloudflare Is Blocking Piped

news.ycombinator.com

61–70 of 127 posts

Re: Tell HN: Cloudflare Is Blocking Piped

#61

By now Cloudflare is more of an obstacle to the free web than it is helping. A centralized entity, whose scripts from randomly named subdomains you must allow to run on your machine, or be stuck at their obnoxious "checking your browser" page endlessly reloading, because some web dev decided to put their website behind Cloudflare. Cloudflare is one of the most prominent reasons for me to simply close the browser tab…

Crawling websites behind Cloudflare can also be problematic if they (CF) decide that your bot doesn't fit their definition of OK. This is problematic for new search engine entrants and a multitude of other services, particularly given how many sites now live behind CF. Years back their DNS service also stopped honouring ns_t_any requests (for reasons of DDOS amplification apparently). I do tend to agree with you abou…

You can't run around and crawl other peoples sites. That time is long gone.

Re: Tell HN: Cloudflare Is Blocking Piped

#62
post #17

By now Cloudflare is more of an obstacle to the free web than it is helping. A centralized entity, whose scripts from randomly named subdomains you must allow to run on your machine, or be stuck at their obnoxious "checking your browser" page endlessly reloading, because some web dev decided to put their website behind Cloudflare. Cloudflare is one of the most prominent reasons for me to simply close the browser tab…

I remember working on denial-of-service protection code for an embedded device. One problem was that if the code was TOO aggressive in protecting from a denial of service attack, you could actually help an attack or be the culprit yourself by denying legitimate traffic. I think this is what cloudflare is doing. They are imprecise and they are denying legitimate traffic.

I don't think that ever happens. If anything they are too lenient. Our own alarms kicks in way before Cloudflares DDOS protection is activated.

Re: Tell HN: Cloudflare Is Blocking Piped

#63

CloudFlare again.. Offering their service to crime forums, credit card fraud shops and phishing websites, while making usage of Tor and VPNs nearly impossible or atleast a pain. Coupled with the hypocrisy of an open web and freedom of speech, it makes CloudFlare arguably one of the worst threats to the web as we know it. Whereas the freedom of speech ala Cloudflare stops as soon as it can generate cheap PR, because t…

There is nothing in Cloudflare that blocks anything like that by default. Site owners decides what to block. The problem with VPNs and TOR is that there is a lot of rouge traffic from these services. Also, there is no feature that blocks VPNs in CF. Some get blocked for not coming from consuming ISPs but more commonly whole ASNs are blocked if the majority of the traffic is bad.

Re: Tell HN: Cloudflare Is Blocking Piped

#64
post #11

Why would anybody in the right mind centralize his/her infrastructure? I doubt that people actually need something like Cloudflare.

I couldn't run search.marginalia.nu without it. I've seen up to 50,000 bot queries per hour (and peak out at about 500 human queries per hour). I don't have the hardware to cater to the bots. I also don't have the money to buy the hardware to eat the cost. The options are hide behind cloudflare or shut down the service.

It's not about traffic costs, but processing power.

Re: Tell HN: Cloudflare Is Blocking Piped

#65

By now Cloudflare is more of an obstacle to the free web than it is helping. A centralized entity, whose scripts from randomly named subdomains you must allow to run on your machine, or be stuck at their obnoxious "checking your browser" page endlessly reloading, because some web dev decided to put their website behind Cloudflare. Cloudflare is one of the most prominent reasons for me to simply close the browser tab…

On a theoretical level, a service like Cloudflare is the most terrifying entity on the Internet I'm aware of. They've accumulated an insane degree of insight into the traffic flow of the web (since their entire service is essentially acting as a HTTPS middle man), and their business is offering protection against bot spam that could ruin most websites. Even if they aren't operating the bots themselves, they're essent…

ALL big tech companies have the same setup. There is nothing unique with Cloudflare. People are just talking about Cloudflare cause it is accessible for free and they sell it as a service.

Re: Tell HN: Cloudflare Is Blocking Piped

#67

By now Cloudflare is more of an obstacle to the free web than it is helping. A centralized entity, whose scripts from randomly named subdomains you must allow to run on your machine, or be stuck at their obnoxious "checking your browser" page endlessly reloading, because some web dev decided to put their website behind Cloudflare. Cloudflare is one of the most prominent reasons for me to simply close the browser tab…

On a theoretical level, a service like Cloudflare is the most terrifying entity on the Internet I'm aware of. They've accumulated an insane degree of insight into the traffic flow of the web (since their entire service is essentially acting as a HTTPS middle man), and their business is offering protection against bot spam that could ruin most websites. Even if they aren't operating the bots themselves, they're essent…

Internet security has, in my experience, always been about "being just hard enough a target the bad actors decide to go torment somebody else."

It was true twenty years ago too, the only difference I can see between then and now is that you can outsource that task for a (relatively) small amount of money if you want to.

Then again, the last time I dealt with a site under DDoS, something in their stack was leaking the underlying IP (never did figure out what) but it turned out that "finding a provider who'd sell them a decent sized server and charge them for the bandwidth" was perfectly economical for their use case because their haters' firepower was insufficient compared to their revenue.

(I'd love to be less vague here but I'm sure readers can see the obvious professional ethics issues with doing so)

Re: Tell HN: Cloudflare Is Blocking Piped

#69

Earlier quoted context omitted.

Crawling websites behind Cloudflare can also be problematic if they (CF) decide that your bot doesn't fit their definition of OK. This is problematic for new search engine entrants and a multitude of other services, particularly given how many sites now live behind CF. Years back their DNS service also stopped honouring ns_t_any requests (for reasons of DDOS amplification apparently). I do tend to agree with you abou…

You can't run around and crawl other peoples sites. That time is long gone.

Not sure if you're being sarcastic!

In the end for any scraping they're just raising the barrier of entry. Automated browsers, residential proxies, captcha services just make it more involved for those determined to hit a URL successfully.

Not necessarily a bad thing, but the line and grey area and the definition of a 'legitimate' request varies, and one entity as a middle-man deciding that is less than ideal.

Re: Tell HN: Cloudflare Is Blocking Piped

#70

CloudFlare again.. Offering their service to crime forums, credit card fraud shops and phishing websites, while making usage of Tor and VPNs nearly impossible or atleast a pain. Coupled with the hypocrisy of an open web and freedom of speech, it makes CloudFlare arguably one of the worst threats to the web as we know it. Whereas the freedom of speech ala Cloudflare stops as soon as it can generate cheap PR, because t…

There is nothing in Cloudflare that blocks anything like that by default. Site owners decides what to block. The problem with VPNs and TOR is that there is a lot of rouge traffic from these services. Also, there is no feature that blocks VPNs in CF. Some get blocked for not coming from consuming ISPs but more commonly whole ASNs are blocked if the majority of the traffic is bad.

rogue traffic, unless you mean pink powder
Post reply on HN