Live data from Hacker News

CloudFlare is ruining the internet for me (2016)

slashgeek.net

91–100 of 182 posts

Re: CloudFlare is ruining the internet for me (2016)

#91
post #40
post #24

There is some presumption that Cloudflare's behavior related to "second class" regions is based on statistics - percentage of traffic that is of ill-intent. Maybe that's not the case, but I suspect so. CF customers probably know that any delays cost viewers/visitors, but losing a few good visitors is worth preventing a ton of bad visitors. And CF generally seems very thoughtful about their actions. If they make somet…

Most properties protected by Cloudflare appear to be webpages that could easily be cached without any ill effects, for hours to days or weeks. Why exactly do they need captcha protection?

That’s like asking a gun shop why americans need so many guns

Re: CloudFlare is ruining the internet for me (2016)

#92
post #72
post #67

Earlier quoted context omitted.

You can set the security level to “essentially off” and the vast vast majority of your users shouldn’t have to face the JS browser check. That’s what I do on all of my sites. The default is medium, and the sites where you run into checks all the time are probably on high. Ref: https://support.cloudflare.com/hc/en-us/articles/200170056-W...

Does anyone know why you can't turn off Cloudflare's security?

IIRC you can only turn it off completely on a business or enterprise plan. Probably a bandwidth-saving measure, or an upgrade incentive, or both.

Re: CloudFlare is ruining the internet for me (2016)

#93
post #87

Companies like CloudFlare are contributing to the erosion of user privacy in the name of security. I experience the same kind of issues that the author of the article highlights, just because I take some privacy measures. It's my view that so-called security on the Internet, which implies confidentiality, integrity, and availability, is getting increasingly worse for end users. If I want to give up all of my privacy,…

The article is complaining that CloudFlare (as a result of them refusing to track you) requires people to solve captchas over and over again. How is this hurting your privacy exactly?

Correct me if I’m wrong but isn’t one of the strongest signals recaptcha uses to prove “I am not a robot” the fact that you’re currently logged into a google account, have the associated cookies, etc? This “phoning home” from all these sites is a clear privacy challenge.

The good news is Safari and Firefox are making this harder and harder. The bad news is that you’ll be solving a lot more captchas.

Re: CloudFlare is ruining the internet for me (2016)

#94
post #87

Companies like CloudFlare are contributing to the erosion of user privacy in the name of security. I experience the same kind of issues that the author of the article highlights, just because I take some privacy measures. It's my view that so-called security on the Internet, which implies confidentiality, integrity, and availability, is getting increasingly worse for end users. If I want to give up all of my privacy,…

The article is complaining that CloudFlare (as a result of them refusing to track you) requires people to solve captchas over and over again. How is this hurting your privacy exactly?

They don’t make you solve captchas if they have enough information about you to think you’re unlikely to be abusive.

Re: CloudFlare is ruining the internet for me (2016)

#95

Earlier quoted context omitted.

It's discrimination by country/region. It's like saying: oh, you are from Africa or Asia. The chance is higher you are a criminal, so do this test first.

Which is completely legal and encouraged. Here's an example: if you've ever shipped an ad-monetized free app, you've probably disabled regions like Russia, Iran, North Korea, etc. You know why? Because the ad-revenue is worthless (and often malicious) and the users will be more trouble than they are worth. Same thing is happening with net traffic from other low value regions. One star reviews because users from $bann…

I believe selling your products in some of those counties can get you in legal hot water as well.

Re: CloudFlare is ruining the internet for me (2016)

#97
post #48

Earlier quoted context omitted.

It's discrimination by country/region. It's like saying: oh, you are from Africa or Asia. The chance is higher you are a criminal, so do this test first.

And the problem is worse because, apparently, even solving the captchas repeatedly from a given IP address doesn't make it whitelisted, either. So, it fits the very definition of discrimination against a whole wider group, where the individual actions of any individual actors don't matter.

I’ve lived in Vietnam for the past 5 years and experienced these issues first hand. I’m also part of the team responsible for maintaining a relatively aggressive set of Cloudflare WAF rules at my current employer.

In these developing countries, great swathes of users are accessing the internet behind carrier-grade NAT.

This makes it increasingly likely that any individual user is sharing a public-facing IP with one or more bad actors.

In my experience, I’ve never had to solve more than one CAPTCHA per domain, and frankly clicking a checkbox isn’t that hard.

As far as discrimination goes, this is a much friendlier solution than just immediately rejecting connection requests from certain CIDRs, which is what would otherwise be happening.

Re: CloudFlare is ruining the internet for me (2016)

#98
post #93
post #87

Earlier quoted context omitted.

The article is complaining that CloudFlare (as a result of them refusing to track you) requires people to solve captchas over and over again. How is this hurting your privacy exactly?

Correct me if I’m wrong but isn’t one of the strongest signals recaptcha uses to prove “I am not a robot” the fact that you’re currently logged into a google account, have the associated cookies, etc? This “phoning home” from all these sites is a clear privacy challenge. The good news is Safari and Firefox are making this harder and harder. The bad news is that you’ll be solving a lot more captchas.

I wonder if privacy conscious browsers making their users have to solve more captchas will lead to more people disabling the privacy features... or there will be a time when captchas may become micro transaction based, so for a fee you might be able to skip them. A browser with support for an anonymous cryptocurrency to make the payments should be private and easy to use enough, but it might become an interesting world where you need to pay to remain anonymous.

Re: CloudFlare is ruining the internet for me (2016)

#99
post #79
post #35

Earlier quoted context omitted.

The problem is that it's often uninformed choice. Some people at LAX, for example, decided that my whole AS has no business accessing their website. (Yes, an international airport blocking international visitors — how cute.) And Cloudflare is the enabler. Notice that you never see Akamai presenting these messages that you've been blocked. Most of these pages where you get blocked are something that looks entirely sta…

I don't use cf, I'm running some mail services but i do block entire AS's after 5 brute force attacks from different IP addresses from same AS regardless of country of origin. This are always modem / routers left with default password, IP cameras with default password, various IoT devices with default password or all of the above with vulnerable firmware with CVE's dating way back. I think that if you are unable or c…

An AS with an /8 is decidedly different from an AS with a /24. There could easily be millions of complete strangers behind a single ISP AS. Not saying you can’t choose whatever criteria for your service, but trying to pass off five-different-attacker-IPs-per-AS as fair is silly.

Edit: Even the CIDR block size isn’t a good indicator of the actual network size, due to NAT.

Re: CloudFlare is ruining the internet for me (2016)

#100

Experienced the same during my Asia travels with Cloudflare 2016/2017. Actually that was the biggest reason/negative ad not to consider Cloudflare when choosing a CDN. They simply don't respect Asia and other non first class countries with their standard settings. It's like good Internet only for the rich people in the world! I'm aware on the Chrome extension (really, why should I install this sh&+t on the first plac…

Asia is the #1 attacker of all websites I work with. Since 100% of the traffic (based on our analysis) coming from Asia is not legitimate business traffic, how would you advise those responsible for these sites security to handle this? Edit: I have no interest in using Cloudflare...

Similar for me. From the 732745 login attempts last month, 52% were from China, followed by US with 13%. Here is a graph: https://i.imgur.com/YPAuTXO.png

The sheer volume of bot traffic surprised me at first, especially since my website has zero human visitors as far as I can tell, but the numbers are consistent month after month.

Nevertheless, my $1/month VPS can handle the traffic without a problem, so I see no need to ban or rate limit any IPs, especially since I hate captchas with a passion.

Post reply on HN