CloudFlare is ruining the internet for me (2016)
https://www.slashgeek.net/2016/05/17/cloudflare-is-ruining-t...
And the ensuing Hacker News discussion a few months ago:
91–100 of 335 posts
CloudFlare is ruining the internet for me (2016)
https://www.slashgeek.net/2016/05/17/cloudflare-is-ruining-t...
And the ensuing Hacker News discussion a few months ago:
It appears that you may have made some modifications to your user agent string. If you revert your user agent to the one provided by default by your browser vendor everything will be fine.
for context this is what I had set (and, for quite some time it was working): "Mozilla/5.0 (X11; Linux x86_64; rv:57.0) Gecho/20100101 Firefox/57.0"
Ironically I set this so that I could continue logging in to google. Since I had been unable to log in to google-apps without setting this user agent string.
What did it fail on? the mis-spelling of "Gecho"?
The problem presented by services like ReCaptcha and Cloudflare is a tough nut to crack. They're silently embedded in a huge portion of modern websites, and the average user will never even know about them. But it seems to be way too easy for them to blanket-ban or serve an absurd amount of captchas to powerusers, linux gurus, privacy geeks, or anyone with the wrong combination of browser+addons. And the failures (as…
Yeah, you can't really talk about downsides of Recaptcha/Cloudflare without also acknowledging the extreme amount of malicious actors and abuse on the internet. We're in a "this is why we can't have nice things" predicament and you have malicious actors to thank for that, yet most people on HN only seem capable of attacking the few affordable solutions to that problem. I'm even down with the theory that Cloudflare is…
Cloudflare have a long history of supporting those malicious actors, so it's not like the problem is unrelated to the purported solution.
Earlier quoted context omitted.
Because their regex is crap and if you have @twitterHandle or something with a legitimate "@" you just see the obfuscated version. It's laughably adorable to think it's actually solving a problem or helping in any way, the 'bad actors' it's trying to prevent probably have a work around anyway.
> It's laughably adorable to think it's actually solving a problem or helping in any way, the 'bad actors' it's trying to prevent probably have a work around anyway. They do—changing your user agent is trivial.
Earlier quoted context omitted.
How is it ridiculous? It's called email obfuscation (it can be disabled within Cloudflare) it's to stop spam bots from ripping email addresses from websites and adding them to mailing lists.
The problem is therefore spam bots abusing the email system.
Earlier quoted context omitted.
Do you have any evidence of this? I'd take a dodgy looking blogspot URL over absolute nothing
In the past, Cloudflare were free speech absolutists. They accepted customers in a content neutral way. When people tried to get them to deplatform ISIS websites, they said this: One of the greatest strengths of the United States is a belief that speech, particularly political speech, is sacred. A website, of course, is nothing but speech... A website is speech. It is not a bomb. There is no imminent danger it create…
Earlier quoted context omitted.
How is it ridiculous? It's called email obfuscation (it can be disabled within Cloudflare) it's to stop spam bots from ripping email addresses from websites and adding them to mailing lists.
Because their regex is crap and if you have @twitterHandle or something with a legitimate "@" you just see the obfuscated version. It's laughably adorable to think it's actually solving a problem or helping in any way, the 'bad actors' it's trying to prevent probably have a work around anyway.
To the target market, who have a spam issue, cloudflares protection sounds great, and by the time they've set it up, they won't switch CDN's just because it isn't effective enough.
Earlier quoted context omitted.
Yeah, because most custom browsers are malicious. They have the data to prove it. This isn't a side feature, it's a direct feature that is 100% intentional. They maintain a backend whitelist of known "good" user-agents. Curl is on that list and there are a few others outside of the big players. Most people building custom browsers are doing it to do something Chrome would disallow. One instance would only supporting…
Any sufficiently bad actor will already modify their user agent. Who is this really stopping?
It's maddening, but it's true. I've seen tale of people having to modify resource auto-generators that created URLs with hexadecimal identifiers in them because the sequence "ad" in a URL would trip ad-blocking browser plugins. You might ask yourself "how many ad companies worth their salt have 'ad' in the URL path?" and the answer is "The ones who are worth their salt might not, but the ones who are terrible do, and they're probably terrible at other things too, like letting malware on their network."
Earlier quoted context omitted.
Yeah, you can't really talk about downsides of Recaptcha/Cloudflare without also acknowledging the extreme amount of malicious actors and abuse on the internet. We're in a "this is why we can't have nice things" predicament and you have malicious actors to thank for that, yet most people on HN only seem capable of attacking the few affordable solutions to that problem. I'm even down with the theory that Cloudflare is…
> Yeah, you can't really talk about downsides of Recaptcha/Cloudflare without also acknowledging the extreme amount of malicious actors and abuse on the internet. What percentage of traffic on the long tail of 95% of smallest websites served by CF is malicious then? So that we talk in numbers.
Earlier quoted context omitted.
So if your browser agent is not firefox, chrome, safari internet can stop working. What a great side feature.
Yeah, because most custom browsers are malicious. They have the data to prove it. This isn't a side feature, it's a direct feature that is 100% intentional. They maintain a backend whitelist of known "good" user-agents. Curl is on that list and there are a few others outside of the big players. Most people building custom browsers are doing it to do something Chrome would disallow. One instance would only supporting…