5 ms·
I think their work is fantastic, but I really don't like that every site I visit meets me with CF's captcha page. It's not only annoying per se, but the privacy
by supergreg 10y ago
I think their work is fantastic, but I really don't like that every site I visit meets me with CF's captcha page. It's not only annoying per se, but the privacy implications are unsettling. I welcome the competition.
- majke 10y agoThis was never the intention. Part of the problem is inertion - cf operates large and complex application that was designed back when we had only a handful of customers. Part of the problem is technical - the privacy-centric anti-abuse technologies don't exist yet. Please do help us fix this. Report issues, help us understand when we have incorrect IP reputation. Help us find captcha accessibility problems. And maybe - join the team to actually code the fix.
- jwr 10y agoProblem is, your "incorrect IP reputation" concept is fundamentally flawed. As an example, I noticed that most VPN exit nodes have "incorrect IP reputation", which means if I want to browse the internet without my government spying on me, I have to wade through all your CAPTCHAs.
- IntelMiner 10y agoKeep in mind, unless you're using your own personal VPN off a self-hosted machine, you're likely to be sharing your IP address with other (potentially) malicious actors trying to hide their tracks
- acdha 10y ago“fundamentally flawed” is not synonymous with “not supporting the style of anonymity which I prefer”. There's no evidence supporting the assumption that those VPN exit nodes’ IP reputation is actually incorrect rather than earned by the behaviour of other customers. We went through this in the 90s where a few people were upset that they couldn't send email directly from their dialup connection, because they were still thinking of the world as it was in 1993 before spam became so prevalent and anyone who ran a mail server was constantly trying to deal with thousands of dialup IPs trying to deliver spam. What actually worked was that people changed the way they worked to use things like authenticated SMTP relays so you could simply block entire dialup ranges rather than try to come up with a spam-blocking AI. The browsing system could be improved by something like a CloudFlare login system or long-term persistent authentication storage so you'd only see a CAPTCHA once a week. Unfortunately, most of the complaints come from very pro-anonymity users – which is a legitimate position but also means that it's a community which is going to be significantly more likely than average to have things like cookie & JavaScript blocking, so the complaints would simply shift to “I shouldn't have to create an account!” or “Why can't I disable JavaScript and cookies for your site!?!”
- jwr 10y agoI stand by my assertion — the idea that an IP address can have "reputation" is fundamentally flawed. The SMTP example that you cite is actually a good one: the whole reason why we started assigning "reputation" to IP addresses is because we could not be bothered to improve SMTP over the last 40 years or so and it still assumes we live in a world of trust. CloudFlare (and everyone else for that matter) should stop assigning "reputation" to IP addresses. An IP address is a network location, think of it as a temporary storage box which could be occupied by anyone and anything. We should move beyond coloring boxes.
- acdha 10y agoSo what's your alternative? People use addresses because they're a strong signal with relatively low false-positives (not many people are tor/VPN users with cookie blocking). How do we do better short of deploying a login system or a unique client identifier which cannot be disabled?
- eeeeeeeeeeeee 10y agoThis is an inherent problem with numerous different people using the same IP addresses (VPN, Tor, etc). And might be a bigger problem than Cloudflare can resolve on their own. Cloudflare has to protect its network and its customers like a normal business, so VPN and Tor IP addresses will naturally be viewed with suspicion. Also, I think the captcha solution is better than what most administrators do, which is to block those IPs outright.
- meowface 10y agoThere is probably no solution to this problem. Criminals regularly use those same services you're using. Cloudflare's job is to block potential attacks, and blocking or CAPTCHA-restricting a subnet tied to a large number of attacks against their infrastructure seems reasonable. Either switch VPN providers, or deal with the CAPTCHAs.