13 ms·
Firefox appears to be flagged as suspicious by Cloudflare
- SkeuomorphicBee 4y agoFor me it was even worse, I got a straight "Access denied" with no captcha or recourse. (Firefox, Linux)
- trog 4y agoFirefox user - have seen this many times. Always assumed it's either NoScript or Firefox's built-in tracking protection meaning there's some pre-existing cooking not set that Cloudflare places from other site visits, or because some script is getting blocked somewhere else.
- rezonant 4y agoSeeing the cloudflare challenge as a user can happen in any browser depending on the site and it's configuration. A site can choose a security level that requires all visitors to receive a JS/captcha challenge, and sites can make custom firewall rules to require JS/captcha challenges on any of hundreds of different attributes of a particular request using CF's web application firewall tools. One of those attributes is user agent, for instance.
- Aachen 4y agoI mean, with that market share, popularity among open source fans... it's an easy group to target and filter oddballs. I'm a Firefox user and I'm used to this treatment at every step of the way, no matter if it's about software, airports, opening a bank account so I can receive a salary, etc. Fundamental things everyone wants to do are being made hard to do the right way. It's always anti privacy, anti self repair, anti longevity/sustainability, anti user freedoms, anti whatever we ideally want in this world. Of course using Firefox is now suspicious.
- detritus 4y agoReally? I'm a firefox user too and whilst I occasionally bump into some situation as you describe where I need to hop onto Chrome, I genuinely can't remember the last time this happened. Nope, actually - sometime last year, with some poorly-coded gig ticket purchase thing, if I remember right. I was able to check the code and amend some stupid niggle in WebDev tools to get around it. Not saying I should have to accept that, but that's what it was. Certainly not 'regularly'.
- cleandreams 4y agoFirefox use, same.
- SoftTalker 4y agoOften, just changing the user agent string so that Firefox appears to be Chrome will let those sites work. I.e. they work fine in Firefox, but are restricted by user agent string checks to reject that browser and/or OS. There are several plugins for Firefox that make this easy.
- adra 4y agoI've used Firefox and Mozilla for what, 20 years? And I've never bumped into a situation like this. Some very clearly shit internal IT systems had pathetic IE requirements, but never one that said sorry go get chrome
- SoftTalker 4y agoThey don't always say "go get chrome" but one example that still happens to me is logging in to Outlook email at work, if I use Firefox I get a hobbled "basic HTML" interface, if I masquerade as Chrome on Windows I get the full UI and it all works perfectly. Google drive is another one, where some things stop working depending on the user agent I'm presenting.
- EdwardDiego 4y agoMy health insurer won't let me login using Opera, a Chromium based browser, and suggests I install Firefox or... Chrome. UA sniffing is soooo 2008.
- lfkdev 4y agoCool Username
- Aachen 4y agoAppreciated :). I see you're from nearby, might you happen to be looking for dev or security work? (For anyone else reading this, remote is also possible. Contact in profile, to not spam the thread.) I'm not actually from Aachen myself, but nearby in NL and I work in Aachen nowadays and wasn't sure what username to choose. If someone else would want it, I'm also fine passing it on. Dunno if there are guidelines on that actually but I'd consider an HN username like a domain name: finite, first-come-first-serve in principle, and hoarding is not cool.
- throwlllllllll 4y agoDon't get me started on banks and accounts! It's like they WANT me to take the simple, easy, forbidden paths.
- phh 4y agoMy personal experience is that I do fallback some sites to testing in Chrome quite often, maybe once a week. But the number of times where using Chrome actually fixed the issue is maybe once a year? Really, it's just that I stumble on quite a number of broken websites.
- kordlessagain 4y agoFirefox is fast, so maybe it's getting flagged because people are using it with webdriver to crawl sites. Just a hypothesis.
- GekkePrutser 4y agoI don't even have chrome installed and never need it to be honest. Except for some boneheaded sites that refuse FF entirely ( https://business.apple.com https://business.apple.com is such an offender) I don't have issues with sites not working. Edit: it looks like even Apple has got their act together now, it seems to support Firefox now too. Finally
- CamperBob2 4y agoI just followed your link and it says, "Your browser is not supported. We recommend using the latest version of Safari, Microsoft Edge, or Chrome." So apparently Firefox is subversive and scary enough to make Apple refer me to Microsoft or Google to avoid it. I guess that's what passes for "Think Different" at Apple these days.
- cpeterso 4y agoI tried spoofing Safari's and Chrome's User-Agent string in Firefox and business.apple.com still blocks me because I'm not using a real Safari or Chrome. So they appear to be using feature detection of some API that's not available in Firefox. I see that the site also blocks Apple's own Safari browser on iOS. Looks like this site was been blocking Firefox users since at least 2018, according to the bug report on Mozilla's webcompat.com issue tracker: https://webcompat.com/issues/18964 https://webcompat.com/issues/18964
- zhfliz 4y agoUA spofing used to work some time ago, as I was definitely using it that way. it seems they recently changed something, because now I can't even load the login page properly anymore due to X-Frame-Options disallowing the embed of the auth iframe.
- deleted 4y ago[deleted]
- gfs 4y agoI'd be curious to see if this is the case for other sites that use Cloudflare bot protection as well. There are a bunch of ways to tune the service so maybe they are just extra cautious?
- rezonant 4y agoIt is definitely this. My websites on Cloudflare are not exhibiting this behavior with Firefox...
- realusername 4y agoI can confim the behavior on mobile
- gzer0 4y agoIncredible. I just changed my user-agent whilst on the Google Chrome browser. * Changing to Firefox immediately displayed the Cloudflare error message * Edge had no errors * Chrome had no errors * Safari had no errors Edit: Even internet explorer 9, android kitkat, and the opera browser had no errors. Edit 2: as another user has pointed out, this is most likely a firewall rule put in place by the website operator themselves.
- jefftk 4y agoDo you see the error when testing with Firefox, though? Receiving a "you look like a bot" message when using Chrome configured to pretend to be Firefox isn't very surprising.
- existencebox 4y agoI can confirm this on pure (native) FF as well. As someone who has run multiple large web properties this hurts to see. I've observed firsthand the impact of what adding friction to certain browser segments does to utilization, if large corps decide that FF is a "risk" it will do a number on their already struggling traction, and we already live in far too much of a browser monoculture. (Disclaimer, MSFtie, all opinions are my own)
- leereeves 4y agoI can also confirm this on Firefox. With JS enabled I get the challenge from Cloudflare, and with JS disabled for g2.com, I get: > Please turn JavaScript on and reload the page. > DDoS protection by Cloudflare
- deleted 4y ago[deleted]
- baisq 4y agoCloudflare uses a lots of heuristics to determine whether to show their challenge. In fact getting served a challenge says more about the amount of bot traffic that the website is getting than about how bot-like you look.
- Dylan16807 4y agoIt might say "more" about how much bot traffic the site is getting, but it is also making some very clear statements about user agent. Those don't contradict at all.
- Operyl 4y agoI can’t reproduce what this article is claiming, even using a completely new profile. I’m only a size of one for this perspective though.
- 13415 4y agoSame for me, my Firefox with all kinds of adblockers is not flagged.
- shaicoleman 4y agoA workaround is to install the Privacy Pass extension to bypass the captchas [1] [2] It's an open source extension available for Chrome and Firefox. It allows to privately identify you're human, and is the process of going through IETF standardisation, so hopefully someday you won't need to install an extension for it. After you complete a captcha once, you won't need to do it again for a long time. I'm not happy about installing extensions just to view some websites, but it'll make things less painful 1. https://privacypass.github.io/ https://privacypass.github.io/ 2. https://support.cloudflare.com/hc/en-us/articles/115001992652-Using-Privacy-Pass-with-Cloudflare https://support.cloudflare.com/hc/en-us/articles/11500199265...
- dingleberry420 4y agoDeanonymizing yourself just to appease cloudflare is not a valid solution. Any website should work in any browser out of the box. If they don't, the website is broken.
- shaicoleman 4y ago"The blind signing procedure ensures that passes that are redeemed in the future are not feasibly linkable to those that are signed. We use a privacy-preserving cryptographic protocol based on ‘Verifiable, Oblivious Pseudorandom Functions’ (VOPRFs) built from elliptic curves to enforce unlinkability. The protocol is exceptionally fast and guarantees privacy for the user. As such, Privacy Pass is safe to use for those with strict anonymity restrictions." 1. https://privacypass.github.io/ https://privacypass.github.io/ > Deanonymizing yourself just to appease cloudflare is not a valid solution I'm not claiming it is a valid solution, I'm just sharing a possible workaround.
- Wowfunhappy 4y agoSorry, can I get a layman's translation? What prevents websites from using Privacy Pass to track user behavior? (Beyond determining who is and is not a bot.)
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- zinekeller 4y agoI think it's two-fold: rise of tools like curl-impersonate (https://github.com/lwthiker/curl-impersonate https://github.com/lwthiker/curl-impersonate) and the very consistent Firefox TLS fingerprint across platforms. Unlike Chromium (where you could differentiate a Linux, Mac or Windows computer from its chiphers, and so for example challenge only Linux clients), Firefox has NSS and NSS is used everywhere the Gecko engine is used while Chromium, although has BoringSSL for modern chiphers, also uses the underlying TLS stack of the operating system (whether it's Microsoft's SChannel, Apple's SecureTransport or Linux's... NSS). The only time Chromium uses a pure BoringSSL implementation is on Android (Conscrypt).
- dingleberry420 4y ago
- kd913 4y agoI don't imagine it's deliberate. A bunch of cloudflare engineers are long-term ex-servo, ex-mozilla given their experience on Rust.
- dingleberry420 4y ago
- saagarjha 4y agoJumping to conclusions without much evidence to back it isn't either.
- dingleberry420 4y ago
- mynameisvlad 4y ago
- 6d6b73 4y ago
- deleted 4y ago[deleted]
- shadowgovt 4y agoBecause it works super great at throttling malicious traffic and solves a hard problem real site admins have.
- betaby 4y agoAmount and severity of malicious traffic is greatly overestimated by many.
- meibo 4y agoIt might be, but I know that I had 200TB of real traffic via Cloudflare this month, while I paid for 8TB on my upstream. Running services of that scale would be utterly impossible for me and probably a lot of other people without their help, so it's definitely empowering.
- betaby 4y agoAre you saying that 95% of traffic is malicious or 95% can be cached? In either case 200TB is a 1Gpbs link with 70% utilization. Something what a cheap (<100eur) server from Hetzner can sustain, for static content of course. 8TB is also not that much at all. As an example our household uses about 2TB per month, both working from home + watching netflix sometimes.
- ddispaltro 4y agoFedora Chrome (not chromium) user here, I get the full challenge too.
- robonerd 4y agoWe're regressing to a state reminiscent of the dark IE years. Except back then when you suggested alternative browsers, people were generally receptive once they saw the practical utility of features like tabs. Now when you suggest alternative browsers, people complain about tens of milliseconds more latency and insist on using Chrome for the speed. It's hard to blame them though, since the practical advantages of Firefox are slipping away as Mozilla focuses on more abstract advantages, like privacy, freedom, etc. Noble causes to be sure, reason enough for me to continue using Firefox even if it were a hundred times slower. But I think most people are looking for practical advantages; Firefox usage continues to decline and I don't have much hope for these trends turning around anytime soon.
- deleted 4y ago[deleted]
- pjmlp 4y agoEven if FOSS fans don't like it, it is iOS/Safari that is the last block preventing the Web platform to be finally renamed to Chrome OS.
- robonerd 4y agoLiking it is beyond the point, it isn't available for me to use unless I replace my phone and computers. But yes I think you're right, Firefox has become so thoroughly marginalized that Safari seems like the last meaningful resistance to the Chrome monoculture.
- ocdtrekkie 4y agoUnfortunately there are literally activists promoted to ending that final stand protecting the open web.
- simion314 4y agoThe reality is people want freedom to use Firefox or Chrome in iOs, they don't want a monopoly , imagine if Microsoft would not have allowed you to install a third pary browser unless it uses their engine and it accepts their rules, then we would all still use IE6 but with different themes and superficial features. Safari needs to implement the standards and offer decent performance, adding on top of that very good integration with the OS and it should win on Apple OSes. Also Apple users please demand Apple to sacrifice a bit of their profit and offer web developers some way to test their websites/code on Safari(including Betas for free) , either by providing test virtual machines images or some Web Based service. Safari Beta not only requiers you have Apple hardware and OS it requires you update to latest version (you maybe don't want to be forced to latest version).
- rezonant 4y agoThis is almost certainly a firewall rule put in place by the operators of that site. My own sites which are protected with Cloudflare do not exhibit this behavior when using Firefox.
- lwthiker 4y agoI think they have different plans and configurations for their anti-bot service [1]. I'm not sure though because I'm not using their services. [1] https://developers.cloudflare.com/bots/get-started/ https://developers.cloudflare.com/bots/get-started/
- buro9 4y agoThis. I used to work there, and there wasn't a global "do this for this browser" (except for a little bit to reduce annoyance specifically for the Tor browser). It is almost 99% certain to be a site operator firewall rule based on the browser user agent. This may even be accidental, they may have been hit by an aggressive bot using a UA string that matches Firefox and the site operator may not even realise they've done this (if they use Chrome, which is likely).
- webmobdev 4y agoPrivacy preserving extensions like uBlock Origin, Canvas Blocker, Decentraleyes etc. used in Firefox also trigger the CloudFlare wall of harassment. Some of the actions of these extensions prevent browser fingerprinting and CloudFlare gets easily confused when this happens and unnecessarily triggers a lot of challenges for a user. You can easily get sucked into the blackhole of captchas - sometimes even solving 5+ captchas isn't enough to convince them that you are a real human.
- schappim 4y ago>> CloudFlare wall of harassment You’re right, this is a form of harassment, and it needs to be recognised as such.
- dylan604 4y agoIs there a meme like name along the lines of "self-own" when you go online and have a tantrum about someone doing something to you only to find out it's your own doing that caused the issue?
- dingleberry420 4y ago
- iamdual 4y agoThe challenge screen has appeared on Google Chrome on a Linux distro.
- shadowgovt 4y ago> Open-source browsers are an important part of the web and should not be treated differently than their closed-source counterparts. One way to interpret that is they should all have the same suspicion rules for lack of popularity applied to them. One way Cloudflare's rules could be causing this is if there's some threshold for fingerprints-per-second under which any UA is considered sus, and Firefox's market share is so low that it tends to fall under that threshold. In which case, what lwt hiker is asking for is special treatment for the browser because they believe the Mozilla project's browser has special value to the web ecosystem. Which they are allowed to believe, but let's be clear about when we're seeking special treatment vs. being treated like any other user agent.
- itvision 4y agoI'm using VPN 99.9% of the time, so it's all the same for me. The perks of living in a authoritarian state which tries to limit your access to the Internet.
- StanislavPetrov 4y ago>The perks of living in a authoritarian state which tries to limit your access to the Internet. Unfortunately these days this could be virtually anywhere.
- deleted 4y ago[deleted]
- dchest 4y agoTested in Safari, got the captcha challenge. I doubt it's due to some specific Firefox block.
- dan1234 4y agoFor me, it was fine in Safari and Chrome, but got the 'checking your browser' message in Firefox
- dowath 4y agoCould it have anything to do with the Tor browser being based on Firefox?
- jtbayly 4y agoThis is absolutely my thought.
- LegitShady 4y agoI've been de-googling all of my services and software over the last couple years including a switch to firefox. I have noticed cloudflare challenging me more and more often. I assumed it was related to privacy extensions like noscript, ublock, and privacy badger.
- klepto69 4y agoTried it, didn't stop me viewing the page, no delay either
- klepto69 4y agoMaybe it's your IP. I tried it in Firefox and Edge. No problem
- t_mann 4y agoCan confirm that I got that exact challenge only on Firefox at least a week ago, although only on one site. Still getting it now.
- tomerv 4y agoI use Firefox Focus on my phone (opens links from apps in a private session - generally a great idea!) and always get this 5 second delay (which is often actually 10 or more seconds). I never considered that it's a Firefox-only thing!
- cpeterso 4y agoAre you using Firefox Focus on Android or iOS? Does the 5-10 second delay happen on all websites or a specific one?
- midislack 4y agoI just close the tab if Cloudflare pops up and I don’t visit the site again. I don’t trust or like Cloudflare and I suspect they themselves initiate DDOS’s even though I have no actual proof.
- NelsonMinar 4y agoCloudflare provides service both for Firefox VPN and Firefox DNS over HTTP. Or at least did recently, I don't think anything's changed. https://developers.cloudflare.com/1.1.1.1/privacy/cloudflare-resolver-firefox/ https://developers.cloudflare.com/1.1.1.1/privacy/cloudflare... https://www.mozilla.org/en-US/privacy/firefox-private-network/ https://www.mozilla.org/en-US/privacy/firefox-private-networ...
- Erlangen 4y agoDoes it have to do with the main browser you use? I am running Debian, Firefox is main browser, while chromium is used occasionally. I got captcha for Chromium, but not Firefox.
- santamex 4y agoEvery time I login to gitlab.com with Firefox I get this screen. I thought that was normal. Because it is like this for months or maybe years already.
- prdonahue 4y ago(I’m responsible for Cloudflare’s L7 security products) While we can’t comment on the specifics of any customer configuration, we do not block or challenge Firefox by default—either with our Bot Management products or with any other L7 security controls. You can confirm this by signing up a free zone and making a request from Firefox.
- judge2020 4y agoTo add, without knowing the homepage firewall rule g2 has set up, we won't know exactly what sort of rules is triggering this, although the most likely signals they're using are either bot scores[0] or threat scores[0]. 0: https://developers.cloudflare.com/bots/concepts/bot-score/ https://developers.cloudflare.com/bots/concepts/bot-score/ 1: https://support.cloudflare.com/hc/en-us/articles/200170056-Understanding-the-Cloudflare-Security-Level https://support.cloudflare.com/hc/en-us/articles/200170056-U...
- prdonahue 4y agoAppreciate the speculation, but using Firefox does not increase your likelihood of being flagged as a bot nor does it increase your threat score.
- alaricus 4y agoCare to back that up with data? The link above is demonstrating the opposite.
- _HMCB_ 4y ago
- kevin_thibedeau 4y ago> The JavaScript Detections (JSD) engine identifies headless browsers and other malicious fingerprints. Blocking JS is not malicious.
- eastdakota 4y agoNope. Individual customer setting, not a Cloudflare policy. We work closely with the Firefox team on many projects.
- my69thaccount 4y agoAren't you not supposed to comment on individual customers?
- tomcatfish 4y agoThey aren't, they're commenting on company general policy and making the obvious deduction from that. It's (literally) basic logic 1. Some site flags Firefox. 2. Not all sites flag Firefox. 3. Either every site flags Firefox or individual sites flag Firefox. 4. It is not true that every site flags Firefox (obverse of 2) C. Individual sites flag Firefox (disjunction with 3, 4)
- vanous 4y agoTested on Android with Fennec (Firefox without telemetry), FOSS browser and Midori. Only Fennec gets the challenge. Even such obscure browser like Midori is OK.
- jmclnx 4y agoI have been seeing this issues also, very odd, workarounds I tried do not get around the issue. >If this behavior gets adapted on more sites, we can expect even more users leaving Firefox But I will just not go to the sites instead of using something other than Firefox.
- CamperBob2 4y agoThis business of flagging legitimate downloads as "suspicious" is getting way out of hand. Here's what I'm dealing with lately: https://i.imgur.com/ZzExHt2.png https://i.imgur.com/ZzExHt2.png This setup program is signed with an EV certificate from DigiCert and hosted on an https site. No other hoops left to jump through except this awesome Catch-22 implementation, which leaves no actionable solution.
- lobocinza 4y agoI use Chromium and was served the challenge.
- usr1106 4y agoI have got this on gitlab.com every morning when I log in for at least a year. (We are a paying customer.) I use Firefox with Coookie Auto Delete. I know that the internet is full of idiots and criminals. If they protect their service it's my benefit. It costs me maybe 2-3 seconds every morning, but then there will be 1000s of requests during the workday. If each of them were 0.1 seconds slower because their servers deal with nonsense my user experience would be much worse. (I have no idea whether keeping cookies or using a different browser would avoid the visible challenge. I just don't care.) Edit: I would really hate it if I had to do free Google captcha labor. Or fill the AWS one which always takes me 3 attempts to get it right.
- Terry_Roll 4y agoConsidering CDN's are duplicates of websites located around the world to remove lag, has anyone every flagged up how CDN's can be used for nefarious means, or do people just trust CDN's blindly? When is a sock puppet not an avatar on a web forum but an entire website radicalising individuals in secret?
- ummonk 4y agoI hit the “checking your browser” quite often, as well as hitting captchas. I assume this means my adblocker / tracking blocker (in Safari) is doing a good job.
- megous 4y agoI also got perma blocked by cloudflare (no option to override to get access, not even their captcha), because I dared to disable web timing APIs in Firefox at some point in the distant past. (I felt those have no legitimate uses, and I still do) dom.enable_event_timing / dom.enable_performance_navigation_timing I only figured what was wrong after a month of no access to gitlab and other websites.
- tuankiet65 4y agoI got HCaptcha-ed while using Chromium + uBlock Origin (no other privacy extensions / settings as far as I think). Happens both in normal and incognito mode.
- rbut 4y agoSame HCaptcha in Brave. I then tried in Firefox and only got the delay mentioned in the article. Note that I am also browsing via a VPN.
- erung88 4y agoI don't think one can conclude anything with just 1 site being blocked by www.g2.com using Firefox. More tests will show a clearer picture: What about using another OS? What about using another IP address? What about other websites? Is the issue only repeatable with www.g2.com? What about using mobile phone browser instead?
- forgotmypw17 4y agoI'm not sure what the cause was, but many sites failed to resolve for me in Firefox (and derivatives) for a month or two straight recently. archive.is was one of them. I think it may still happen with default settings, but I solved it by turning off DNS-over-HTTPS (which I think is a stupid feature anyway)
- russelg 4y agoRelated: https://news.ycombinator.com/item?id=28495204 https://news.ycombinator.com/item?id=28495204 Basically archive.is has an issue with the way Cloudflare DNS does things. This will also affect DNS over HTTPS as Cloudflare is the default DoH provider in Firefox.