3 ms·
The captchas serve to stop bot nets and DDoS attackers who are all over the world. It is why many sites throw those up. It is not a miss configuration. It is a
by fowlerpower 10y ago
The captchas serve to stop bot nets and DDoS attackers who are all over the world. It is why many sites throw those up. It is not a miss configuration. It is a smart move.
- MichaelGG 10y agoIt is 100% the wrong thing to do. On a static page like Trump's website, it is absolutely unacceptable that it ever shows a captcha to obtain readonly information. They are already handling the TCP connection, they are sending back the static assets (custom error page). They just don't send the main content. Unless it's under a current attack, and even then it should go by IP or something. Visiting from an IP never used before should now throw up a captcha. Nor should it continue to do so on repeated visits. It's broken, full stop. Edit: I mention Trump's site because it's a reasonably high profile, static, site that I've seen CF blocking on. Also, FWIW, after I sent several emails to Jet, they seemed to reverse course and their app and site are available. Seems like an oversight/not knowing to me. CF's defaults are not very good so they probably didn't change them. CF should review their customers and suggest better defaults, at least to high end clients.