Live data from Hacker News

Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

news.ycombinator.com

91–100 of 312 posts

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#91

Earlier quoted context omitted.

If I have a process that works for 95% of the people, why should I care about outliers who use Linux behind a VPN on a heavily customized version of Firefox?

Because they are standards compliant and you aren't, and you are legally required to provide an unsubscribe service or whatever without undue barriers around it.

It'll be interesting to see what happens if someone takes that argument to court.

One side of the argument is that Cloudflare places an undue burden. The other side of the argument is that without the CF protections, the service provider doesn't even have reason to believe the request is coming from a human being the law protects.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#92
post #40

Earlier quoted context omitted.

How does it get around captchas?

Cloudflare turnstile isn't even a captcha. The user just has to tick a box. Behind the scenes there's a javascript challenge to make sure you're vaguely a browser and not some script a bazillion requests per minute.

It's also used for proof of work as many scrapers are using thousands of IPs but only a few CPUs

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#93

I deal with this fairly commonly, presumably because I use linux, and we all know only botnets use linux. Occasionally with cloudflare I'll just get summary rejection and supposed blocking of my IP, but either it's summary rejection or a pass without challenge. Recently I had to deal with this for alibaba just to look at something, which I usually just use torbrowser with, and finally gave up as I couldn't pass the c…

My main desktop for the past year has been Steamdeck with linux. And don't get any excess Cloudflare challenges.

Nice idea! How's that working out for you? Stock OS? Bazzite?

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#94
post #13

> The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge. That's a CAN-SPAM act violation. FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an or…

"Visiting a single Internet Web page" is considerably more involved than that. In practice, it means making a request to the DNS servers and running Javascript that's injected by the CDN/proxy which "verifies" (runs some heuristics) that you're allowed to load that page.

It's like a restaurant that complies with a local food access requirement to be open at a certain time... but only by having a drive-through that requires you to not just be a human being, but also to drive a car to get to the restaurant.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#95

I can't use any of the kerbalspaceprogram.com domains because of improper discrimination against IPv6 clients triggered by CloudFlare. Error 1015 Ray ID: .... • xxxx-xx-xx xx:xx:xx UTC You are being rate limited What happened? The owner of this website (wiki.kerbalspaceprogram.com) has banned you temporarily from accessing this website. This sort of monoculture creates an Orwellian SPoF.

Cloudflare owns kerbalspaceprogram?

No, wiki.kerbalspaceprogram.com is a customer of Cloudflare, but the outcome is the same.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#96
Cloudflare's —and most similar services'— stance here comes from these VPN funnelling not just people like you, but also attackers. It's untrustworthy traffic from their perspective.

Use a VPN but use a normal network. VPN back to your home, your office. Your traffic will probably take a throughput and latency hit but it looks like real residential traffic, and that's a lot less sus.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#97

Earlier quoted context omitted.

While you hit the nail on the head, I am still surprised that so many tools targeted at people like me (web hosting, developer tools, etc.) are protected that way.

Most developers I've met were actually similarly lazy... we just use Chrome on Mac, and don't really want to deal with VPNs unless our employers force us to. The last few Firefox holdouts also switched after running into various WebGL/Canvas/etc issues. The same attitude that leads us to focus on "happy path" users and ignore edge cases often also causes us to sheeple into that same basic dev group. Long gone are the…

> spam requests, especially from China, Russia, and India.

On my small website, bot traffic is almost entirely from DigitalOcean VPSs.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#98

Earlier quoted context omitted.

Their problem. They are not entitled to make it other people's problem.

If I have a process that works for 95% of the people, why should I care about outliers who use Linux behind a VPN on a heavily customized version of Firefox?

Maybe you should try to care about something other than just your bottom line. I'm sorry if this sounds mean, but this attitude just turns the web into a giant monoculture because you can't be bothered to care. It actually ends up hurting everybody in the long run. Look how long we were trapped with IE6. Amazing how people forget history so quickly.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#99

Earlier quoted context omitted.

> If you look like a bot, how are they going to distinguish? Some non-existant system of attesting that I'm person X (possibly through an e-ID card) who has issued a client certificate Y (cert chain, using my e-ID cert to sign) to be used with my device Z (presumably with a device fingerprint or IP range attached to the cert). Of course, this would mean no privacy, but that's not that different from being signed in t…

Okay. Do that globally. And solve the ddos problem as you’re on it. If you add transparent tls termination, edge, caching, dns… maybe I’ll have a look! I had a guy like that working with me. Blocked every possible tracker, disabled javascript, used some niche browser, proton mail, and then complains that google doesn’t allow him to sign in. I get it, privacy and what not. But the guy was an outlier. Some random blogs…

> Do that globally.

We already do a simpler version of that with TLS and HTTPS, there are globally trusted root certs that ship with most OSes and browsers. It's just that we haven't extended the same approach to client certs and identity verification, instead having a bunch of walled gardens and governments running legacy methods of figuring out who someone is, as opposed to various eID mechanisms.

If I trust news.ycombinator.com because I trust ISRG Root X1, I might similarly trust John Doe's iPhone because I trust the government of France's CA, as a hypothetical, as long as the certification chain is valid there.

It's a problem that's technically solvable (say, in 20-50 years), but won't get done because good luck getting a bunch of governments to collaborate on that across the world. It's actually a surprise that we have TLS in the first place.

Re: Tell HN: Impassable Cloudflare challenges are ruining my browsing experience

#100
post #62

Earlier quoted context omitted.

>The issue is scummy companies like cloudflare which are causing these issues. If your software is blocking legitimate users then your software is shit at its job. It's not the users fault. But if you're going out of your way to look suspicious (ie. "I use a heavily customized Firefox config on Linux"), surely you'd agree at some point it goes from "your software is shit at its job" to "it's your fault for looking su…

[flagged]

>Everyone should only be allowed to use windows and a chrome browser variant with no ad blocking. Cloudflare 100% should be allowed to arbitrarily block anyone not using this set up because they are suspicious.

Seems like a slippery slope argument, but isn't reflective of reality. They still allow Tor browser to pass, of all things.

Post reply on HN