28 ms·
You don’t want to be on Cloudflare’s naughty list
- PaulHoule 4y agoThe rise of Cloudflare is the first real threat I've seen to ordinary people running webcrawlers.
- lorey 4y agoWhich is in turn a threat to the open web in general. Could not agree more.
- mschuster91 4y agoTragedy of the commons, unfortunately. There were a bunch of cases where web crawlers and scrapers built competitive services on the back of the services they scraped, some of these ending up in courts [1]. [1] https://www.derstandard.at/story/1389860104020/eu-gerichtshof-bremst-parasitaere-suchmaschinen https://www.derstandard.at/story/1389860104020/eu-gerichtsho...
- elwebmaster 4y agoMaybe there are but the specific example you linked is about real-time API use and unrelated to scraping/crawling.
- jgrahamc 4y agoWell into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare. It might have received the reputation data from a partner, and it just propagated through the Bandwidth Alliance network. That's not what Bandwidth Alliance is at all. It's about reducing or eliminating egress fees between a cloud provider and Cloudflare. Not sure where the idea that it's about sharing IP reputation data comes from. https://www.cloudflare.com/bandwidth-alliance/ https://www.cloudflare.com/bandwidth-alliance/ So, if Google Search started showing a CAPTCHA that's not Cloudflare.
- pilif 4y agoYep. That paragraph made me pause and consider that maybe OP is the victim of some compromised device running on their network. If two independent sites believe you are a bot, you or something at your address just might be.
- O__________O 4y agoThey do have a threat score https://developers.cloudflare.com/firewall/recipes/block-ip-reputation/ https://developers.cloudflare.com/firewall/recipes/block-ip-... I was surprised to learn Cloudflare was born out of Project Honeypot, so I am guessing Cloudflare does share data with them: https://www.projecthoneypot.org/cloudflare_beta.html https://www.projecthoneypot.org/cloudflare_beta.html
- deleted 4y ago[deleted]
- elcomet 4y agoFYI you're responding to the cloudflare CTO
- trasz 4y agoIt’s naive to assume Cloudflare CTO would not be lying if beneficial to him or Cloudflare.
- Veen 4y agoIt's even more naive to assume Cloudflare's CTO would tell lies that can be trivially shown to be untrue.
- pessimizer 4y ago
- trasz 4y ago
- leonfs 4y agoIf you haven't done anything, someone else might have. Check your router logs for strange devices and activity in your network, also check your machine/s for malware.
- superkuh 4y agoDaniel Aleksandersen of ctrl.blog has absolutely no foot to stand on here. He is a proponent of this kind of algorithmic blocking for weird browsers and even implemented it on his own site and argued for it. https://www.ctrl.blog/entry/detect-non-browser-form-submission.html https://www.ctrl.blog/entry/detect-non-browser-form-submissi... It's only after it happened to him that now he's suddenly against it. Until he removes the same type of blocks from his own website I have absolutely no sympathy for him.
- phreack 4y agoEven if that were the case (which we can debate), him being wrong before does not prevent him from being right now. Being de facto banned from the common internet due to centralization is absolutely scary.
- ranger_danger 4y ago
- superkuh 4y agoI completely agree. I am against Cloudflare and the centralization it implies 100%. I never use it for sites I develop. I just have no sympathy for Daniel since up until just now he was trying to get everyone to do this.
- scarface74 4y agoCloudFlare allows website host to have much finer grain control that would have solved many of these problems - if they pay for it. I see no problem with this.
- dmix 4y agoThe hosts aren't blocking him though, it's Cloudflare. > Just about every website I visited from my home internet connection would result in a challenge page.
- socialismisok 4y agoIs it plausible some ISP shared some IP address that was on Cloudflare's list of suspicious IPs, or that some IoT device on this person's network created a burst of suspicious traffic? I get that this sucks for the end user, but I wonder how much we should blame Cloudflare vs the wider systemic challenges of managing DDOS protection on the web.
- laxis96 4y agoI believe that might happen, but then I also believe it's the ISP's responsibility to ensure that its IP addresses are kept clean
- socialismisok 4y agoFor sure, the point I'm making is that there's a multi party transaction here, with systemic complexity. Makes it hard to pin responsibility on just Cloudflare (or just the user or just the ISP, etc).
- yjftsjthsd-h 4y agoCloudflare is the one blocking a user based on things that aren't their fault; I'm happy to blame them.
- socialismisok 4y agoThat's fine, but you are ignoring the broader picture if you do. You've correctly identified a detail, but haven't placed that detail in context.
- yjftsjthsd-h 4y agoI'm not ignoring the context, I'm saying that it's irrelevant. Cloudflare made the choice to block real people based on factors outside of their control, and then to market that product as a panacea; they don't get to pass the buck, doubly so when they don't expose enough information to let other people fix the things they broke.
- DethNinja 4y agoThere is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router. 2. Use 30 character long random password on the router. 3. Disable UPnP. 4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well, especially IOT ones.
- malfist 4y agoWhy would you disable UPnP? You're gonna break most collaboration tools/video games/etc.
- kunwon1 4y agoDisabling UPnP doesn't break much. I've used enterprise firewalls at home for years, none of them have UPnP, I've never noticed a problem arising from that lack. I don't have a problem with video games or collaboration tools UPnP allows devices inside your network to open ports to the outside world without your knowledge. I think everyone should avoid it if they can get by without it
- d2wa 4y agoIt’s absolutely required for most multiplayer games. Many need random ports and some even refuse to work if UPnP is blocked even if you manually open a port for them.
- aaronmdjones 4y agoI've never had UPnP enabled and I don't have any problems doing online gaming / flight sim / video chatting / etc.
- emikulic 4y agoSame. I've found the biggest problem was SNAT rewriting the (source) port number. netfilter, by default, doesn't do this. pf does but you can configure it not to.
- scarface74 4y agoNotice that he suspects that some of the problems with podcast rss feeds and assets that can’t be captcha confirmed may be caused by websites who are on the free tier and that don’t have the ability to specify that some subdomains shouldn’t be blocked by captchas. I have absolutely no sympathy for website owners who are depending on a free service.
- mikessoft_gmail 4y ago
- therealmarv 4y agoIf you surf on desktop sites from Philippines on a mobile phone plan (which is often the best Internet connection in that country) you also get Cloudflare's captchas everywhere. I told it before and tell it now again: Cloudflare is dividing the World between first and second/third World countries with their captchas. I call it discrimination of second/third World countries! If you are from US and Europe you will never notice it but if you travel a little bit more you see these blocking captchas everywhere.
- ReptileMan 4y agoI am from Europe and I notice if I use some non residential ip. The captchas are extremely annoying especially when trying to access a site I have already been logged into with 2fa. Who is protected in this case.
- aendruk 4y agoThe other side of this story is that PLDT stands out from other residential networks as a persistent source of web form spam. I’d love to learn what’s going on differently there.
- chrismorgan 4y agoI’ve had a similar experience in India with wired internet from a local ISP: CGNAT is used so there are who knows how many customers on the same IPv4 address, https://iknowwhatyoudownload.com/ https://iknowwhatyoudownload.com/ shows at least forty hours of movies being downloaded every day, the IP address is on half the blacklists out there because someone is part of an email-sending botnet, and yeah, Cloudflare hates you.
- MichaelZuo 4y agoIs there even any way to reliably identify individual users behind a CGNAT without invasive fingerprinting?
- Dma54rhs 4y agoI get these a lot and I'm from EU. But it's "seasonal".
- kevingadd 4y agoI'm used to getting assaulted by Cloudflare's browser check interstitials along with random Cloudflare and Google CAPTCHAs because (presumably) I run Firefox and an ad-blocker instead of vanilla Google Chrome. It's already tremendously inconvenient to wait multiple seconds on many page loads and click 20 bicycles, I can only imagine how infuriating it would be if every page load started taking 60 seconds because your IP ended up on some random algorithmic blacklist....
- 20after4 4y agoI use firefox and an ad blocker and I don't see these CAPTCHAs ( except for a few rare instances that I can recall). Something else must be going on to get you flagged.
- _yb2s 4y agoI'm also on firefox w/ adblockers and had similar issues... the 'privacy pass' plugin solved this for me.
- bastardoperator 4y agoHas he tried unplugging the router for 15 minutes and plugging it back in? I jest but I know Comcast and Spectrum will both issue a new IP address in that timeframe.
- dmix 4y agoIP bans by modern services like CF can't be solved that easily in my experience.
- bastardoperator 4y agoClearly CF has a crystal ball /s. Once the IP address I don't own is released and assigned to some other router how do you think CF determines the new IP address for the individual/home? Unless this person is running the CF Dynamic DNS service which gives CF the IP address, I'm not sure CF would have any reasonable validation techniques to determine who is what given the size of residential networks.
- aendruk 4y agoCookie on their validation page? Browser fingerprint hopping IPs in the same block?
- dmix 4y agoBingo
- bastardoperator 4y agoSo i've turned cookies off and switched to my ipad to browse the internet for the evening, they have no fingerprint, and no cookie... now what?
- dmix 4y agoAre you on a different IP block? ISPs sometimes just switch the last number. I had to use a VPN (a whole new IP) and clean chrome install to bypass one those "IP blocks" which was combined with fingerprinting.
- jasonlotito 4y agoYeah, this just continues to reinforce my opinion Cloudflare. It's not something I would ever recommend, and there are numerous other superior options out there. I see Cloudflare failing frequently enough that if it were something I was responsible for, I'd be embarrassed at the very least.
- tire-fire 4y agoWhat superior options would you recommend that are privacy focused and free?
- dedward 4y agoI'm curious if you've had experience with their enterprise package? I can understand people's gripes about things on the free/cheap packages, where Cloudflare makes decisions for you, sometimes ones you don't like. But as an enterprise customer, I've never found it to be anything short of fantastic - I can tailor it to behave exactly how I want, and not interfere with my customers.
- johnklos 4y agoYour response seems to ignore the very article being discussed. Or are you suggesting that if you're having trouble visiting sites because of Cloudflare, you should become an enterprise customer? (slightly sarcastic, but not completely)
- simple-thoughts 4y agoThere’s a real lack of education I’ve seen in developers for small projects who go directly to cloudflare for anything and everything. They don’t understand that they are immediately losing a large chunk of their user base who is either from the third world or is privacy literate. Devs working on projects that are targeting those groups need to understand the tradeoffs from using cloudflare.
- kevincox 4y agoObviously they don't. Clourdflare's markets itself as a super easy set-it-and-forget-it solution. The problem is that it isn't. The defaults are broken and it requires careful configuration and monitoring. Of course this isn't good marketing so the only way a user can know is posts like these or to accidently block their users and hear the reports. (Obviously Cloudflare's UI will only tell you how evil bots it blocked were.)
- sampa 4y agoIf an ordinary user would have to deal with google/CF bs everyday as I do, they'd burn their computer. PS Proud user of Firefox + resistFingerprinting=true PPS Ain't nothing better than CF guard page constantly-reloading on 20% of sites if you open some url :( No, fella, you first have to open the root '/' page so that guard page finally can either pass me through or show the cloudflare captcha. Ugh. Progress, they say.
- JCWasmx86 4y agoCouldn't you use e.g. the DSGVO/GDPR in the EU to get all the information about your IP, everything cloudflare has stored about it until you find the root cause?
- jabroni_salad 4y agoDo you have an ISP-provided email account that you never check? You might want to check it to see if you have any botnet notifications.
- NelsonMinar 4y agoCloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That was a straight block with HTTP errors and I had to use a proxy to access the Web. It cleared up after a few days. The lack of any user feedback or support for this situation is really annoying. Reminds you how much power the CDNs have. It'd be really bad if loading websites got as difficult as sending email through all the layers of spam filtering.
- ThatPlayer 4y agoI feel like Starlink could at least partially mitigate this by supporting IPv6. T-mobile US supports IPv6, and I hardly notice this as an issue on my phone. Or the time my work ran the business over a 4G mobile while waiting for ISP install.
- tomjakubowski 4y agoA genuine question from an ignoramus: how on earth did Starlink launch a brand new ISP in 2020 which doesn't support IPv6? Is IPv6 really so difficult? Does actually nobody care about IPv6 still, after all these years?
- jeremyvisser 4y agoNot an answer to your question, but an indicator of shared culture: Tesla vehicles also don’t support IPv6 whatsoever. Things you might use an internet connection for in your Tesla include triggering air con remotely, live traffic and satellite maps, streaming music or online radio, web browsing, or YouTube/Netflix/Disney+ clients. It completely refuses to use IPv6 over mobile or wi-fi. Also it refuses to access anything over IPv4 (apart from DNS) which resolves to an RFC1918 address, even if it's connected to said RFC1918 network. So yes, Starlink and Tesla are different companies, but I see cultural parallels which I'm sure surprises nobody.
- shiomiru 4y agoIf you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser. Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF. And the most infuriating part, you get CF marketing messages right in your face while your browser is calculating hashcash (I guess?)... At this point I can recognize every single one of them: something about bots making up 40% of all internet traffic, something about their web scraper protection racket, something about small businesses (???), etc etc... To be fair, Tor exit nodes have an awful reputation for sure. Nevertheless, I have a hard time forgiving how CF makes browsing the Internet hell for those who actually need Tor.
- yjftsjthsd-h 4y ago> And the most infuriating part, you get CF marketing messages right in your face while your browser is calculating hashcash (I guess?)... At this point I can recognize every single one of them: something about bots making up 40% of all internet traffic, Yeah, there's something amazingly aggravating about CF telling you how much traffic is bots while showing that they can't distinguish you from a bot.
- robocat 4y agoCloudFlare are creating a new devision for advertising to bots. They have projected that in the near future, bots will be 90% of spending, so the bot demographic is the most important to target, marketingwise. The fact that humans are seeing the traffic meant for bots is an unfortunate side-effect. I personally welcome our future bot overlords (not only because being unwelcome might be unhealthy for me — why would I publicly disagree with an overlord or not want to be their friend?).
- rvdca 4y agoSomeone has seen a basilisk...
- 4y ago
- robjan 4y agoI have two dedicated home internet IPs (one iCable fibre and a China Mobile 5G fallback/quarantine WiFi) and get these "checking if your internet connection is secure" interstitials all the time now. Also see them on my HKBN work connection. I'm from Hong Kong and suspect the whole territory is on the naughty list.
- yamtaddle 4y agoHarsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and the geo-blocking: it's tying some form of personal ID to your browsing activity, so that bears the reputation instead of the address. Sorry. Said it was bad news.
- Waterluvian 4y agoI think this is true. It also reminds me of one possible purpose of regulation and government, given the majority will usually be happy to throw any sort of minority under the bus for the "greater good." This also reminds me of the anxiety of Google deciding to just ban my account for some reason. They can't be bothered to commit resources to making sure mistakes can be resolved. They don't care to lose a fleetingly small percentage of customers. Not sure I have an answer. Just a thought.
- akira2501 4y ago> Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. I'm not understanding the generalized sentiment here. How would, for example, a retailer benefit from this strategy? How does it protect their bottom line? I can see how a particular kind of "facilitated user economy," such as games, gambling and promotional companies could benefit, but it doesn't seem that broadly applicable to what most people would consider a "mainstream" business. > so we can lay off the IP-based reputation stuff and the geo-blocking: it's tying some form of personal ID to your browsing activity And a new market for identity theft is born. Also, as someone who serves content and geo blocks it, that's not up to me, that's up to the owner of the content or whoever happens to be licensing it for them. So, even if you sent me a picture of your government ID, it changes nothing.
- les_diabolique 4y ago> a retailer benefit from this strategy? How does it protect their bottom line? A couple of examples I can think of is blocking bots from scraping their site for pricing and details and from resellers from buying up all of the stock (see sneakers, electronics, etc). The last example doesn't directly impact their bottom line, but it will make customers go elsewhere.
- adamsb6 4y agoDoes the author have a fixed IP? If not, figure out how to get a new one and see if the blocking recurs. If it does, the bad activity is probably coming from inside the house -- or CloudFlare has a way to identify you across an IP change.
- d2wa 4y agoThe author, me, does have a dynamic IP, but it only changes once every two years or so.
- cft 4y agoI actually think that Cloudflare is setting up the foundation of Chinese style (but privately outsourced in the US case) censorship machinery in the US. Between their AI erroneously flexing its power, Kiwifarms scandal and similar, they are emerging as a rival to Google in its censorship effort. One of the most dangerous companies in the internet.
- johnklos 4y agoImagine all the people in countries deemed less desirable by Cloudflare that go through this all the time. Cloudflare, whether it's their stated goal or not, is re-stratifying and re-centralizing the Internet because of their desire to be a monopoly, and we'll all suffer as a result.
- andrewnyr 4y agothere are multiple other large CDNs out there... its a lot more like 5 market leaders tbh
- johnklos 4y agoBut how many of them: 1) refuse to take responsibility for content they host by claiming they don't host 2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination 3) make the abuse reporting process intentionally difficult and time-consuming 4) want to aggregate all the DNS data they can by making a deal with Firefox to turn on DNS-over-https by default without asking or even informing end users 5) want to re-centralize the Internet, in part so they can mix bad actors with good, in ways that make blocking next to impossible How many of them do the discrimination we're all writing about here?
- easrng 4y agotbh I think one of the very few positives of having so many sites going through a few CDNs is that you can make it impossible to block a protocol or site without significant collateral damage, which can be a good thing, things like Tor's meek bridge rely on that.
- andrewnyr 4y ago1) refuse to take responsibility for content they host by claiming they don't host >CDNs don't host content, they proxy it 2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination >Not large parts of the internet, scammy and attacky parts of the internet. If the rules were public they wouldn't be effective. 3) make the abuse reporting process intentionally difficult and time-consuming >simply untrue, every abuse report i have filed has had an answer back within 24hrs 4) want to aggregate all the DNS data they can by making a deal with Firefox to turn on DNS-over-https by default without asking or even informing end users >this is a good thing as they are audited as having not keeping logs of dns queries 5) want to re-centralize the Internet, in part so they can mix bad actors with good, in ways that make blocking next to impossible >again every cdn centralizes the internet, and many sites need this protection
- neurostimulant 4y agoIf your ISP is using CGNAT, sooner or later you'll going to experience this problem. When this happen, I had to use a VPN (I use mullvad) to reduce the amount of cloudflare challenges I get. Pretty funny because usually I got more challenges when using a VPN instead of the other way around. The Privacy Pass extension also seems to help a bit.
- grishka 4y agoHere's a handy list of correct uses for IP addresses: 1. Packet routing In other words, I wish services like Cloudflare were made illegal.
- nuc1e0n 4y agoThis story shows Cloudflare is now harming legitimate users, is an effective monopoly and as such should be broken up.
- unity1001 4y agoIts amazing how Cloudflare became another tech monopoly that can decide the lives of ordinary people in a totally unregulated, private fashion.
- smsm42 4y agoSo this gets me thinking. We know Cloudflare will boot a site if they really don't like them. Now, what happens if Cloudflare doesn't like you? I mean, really really doesn't like. Maybe, you said something wrong online or participated in a wrong group activity, or something like that. Is it the case that they have the power to essentially deny you (provided you have a static IP and don't use VPN, say) access to a major part of the Internet? And you can do absolutely nothing about it? I know they haven't done anything like that yet. But the technical capability is there, and we all know how short is the distance between technical capability and doing it, when the appropriate pressure is applied. So I wonder, how long before activists start demanding for CF to boot people from the internet, and how long before CF caves in to that...
- deleted 4y ago[deleted]
- thephyber 4y ago> and we all know how short is the distance between technical capability and doing it Fact-less conspiranoia. The CIA has the operators, equipment, and info to be able to kill almost any US citizen in a couple of hours for arbitrary reasons. How many times have they done it? You are overweighing how much technical capability factors in and very much underweighing the costs of doing something like that. Opportunity costs, collateral damage, unintended consequences, reputation costs, brand harm. Hell even ethics and morals of those involved. Who do you know would want to work for a company that did that? Who do you know would program that feature and not say anything about it? Why do you believe that CloudFlare would have so many of those kinds of people working there, but you know so few? Why not make the same complaint about your ISP, your hardware manufacturer, your OS manufacturer? You have exactly the same amount of evidence they are doing this or could do this. Remember that US criminal system attributes 3 elements to a crime: {means, motive, and opportunity} and even then we use evidence and an assumption of innocence. You just threw out every part except “means”. I’m not defending CloudFlare here so much as tired of conspiracy theories and paranoia and social panics. We have enough of those things right now.
- deleted 4y ago
- joshfraser 4y agoIf this happened to me, the first thing I would do is switch to using a VPN. In my experience, Google is far more likely to throw up CAPTCHA challenges to VPN users. I wonder if this is what happened to the OP.
- d2wa 4y ago(Author here.) I don't use a VPN from my home connection.
- thayne 4y agoI haven't experienced it as badly as the author. But I find the cloudflare page checking that I am using a "secure browser" very frustrating. I seem to get it the most for gitlab pages for some reason.
- digitailor 4y agoNot saying that this is the case here, but this may be possible due to having a bad tab open. Especially over cellular. Haven’t looked into it with any depth, but I’ve had correlations on a much shorter timeframe. Suddenly, CloudFlare and/or Google start questioning my humanity, so I close all tabs. Then okay. Sloppy hypothesis with no evidence: JS gone haywire
- bbu 4y agoI think cloudflare updated their bot detection algorithms because we had multiple customers who complained that they get challenged. I verified that they got a bot score of 1. As usual, CF support is not that helpful…
- Melatonic 4y agoAs much as I like Cloudflare now this is why long term monopolies (not saying they are now) are bad
- btdmaster 4y ago"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her." However, this does not apply if: "is necessary for entering into, or performance of, a contract between the data subject and a data controller;" Cloudflare would therefore perhaps claim that this is "necessary".
- ritcgab 4y agoWhat is Cloudflare? The answer is simple - the biggest MITM on your Internet traffic.
- synthetigram 4y agoReputation systems should be based on /abuse/, not on automation. I also ended up on the naughty list for running an archival scraping program. Trying to preserve part of the Internet is apparently against the rules. It's really a shame because my code honors rate limits, doesn't spam, and is completely docile.
- d2wa 4y ago> Trying to preserve part of the Internet is apparently against the rules. It’s against copyright laws too, unless you get the right holders’ go-ahead first. Some regional differences, but it’s mostly not allowed with a few exceptions for some institutions.
- rubyist5eva 4y agoCloudflare is on my naughty list. I actively advocate against people using them.
- kazinator 4y ago> For whatever reason, I must have done something that angered Cloudflare I'm guessing: having an IP address close to (or outright reused from and thus identical to) someone malicious, whom you know nothing about.
- d2wa 4y agoThat’s one of the theories discussed in the article, yes.
- kazinator 4y agoSince it cleared up on its own, it was probably that. Another cause could be that you have some malware on your network that is attacking sites. The author could be infected with something that wakes up sporadically (perhaps on external command) to participate in an attack, and then returns to dormancy. So the Cloudfare block being lifted isn't necessarily evidence that all is well.
- marcus_holmes 4y agoI use a VPN, for perfectly legitimate reasons (I travel a lot, and most internet services assume that your IP address also indicates your nationality, citizenship, language, bank account country, etc. Being able to change IP source country is vital). Some VPN exit addresses have obviously been flagged as "bad" by Cloudflare and I get challenged with CAPTCHAs from some countries. It's an interesting experience, but luckily my VPN provider has enough exits that I can usually switch to one that has better reputation with Cloudflare. Obviously, none of this is helping the internet be a better place from my point of view. I get that it's part of the ongoing fight against bots and spam, but it always feels so arbitrary. IP addresses are interchangeable, folks - they say nothing about the nature of the request. Or rather, for a large majority they do, but there's us minority that don't obey those rules and resent getting caught up in it.
- throwaway742 4y agoMeanwhile actual bots can just purchase "clean" residential IPs from shady sources. Cloudflare is the worst thing that has happened to the internet.
- deleted 4y ago[deleted]
- 1vuio0pswjnm7 4y ago"I don't know what I did wrong, but I've angered one of the titans of the internet!" Why would anyone need to know what they did "wrong"?^1 That would mean they could correct their choice of software and usage patterns to conform with what Cloudflare believes is "right". IMO, anti-"bot" (anti-automation measures) can effectively identify (a) computer users with something of value to offer to website operators (usually, that means personal data/metadata at no cost), as distinct from (b) computer users who (i) do not send personal data to and/or generate metadata for website operators that indicates the user has something of value, and/or (ii) are not using the software preferred by website operators (usually, that means software that requires interactive use that generates behavioural metadata for website operators).^2 The measures taken by Cloudflare presume any automation by computer users is "wrong".^3 Meanwhile, websites and CDNs are free to use automation however they wish. Of course automation can be used in a way that poses threats to websites. It can also be used in ways that do not pose any threats. The "protection" measures used by Cloudflare cannot distinguish between the two. IMO, these measures are deemed acceptable by website operators (Cloudflare's customers) because computer users blocked accidentally are more likely to be in catogory (b) not (a). A more egalitarian approach IMO would be to publicise detailed rules for website usage. That is, provide an explanation of what the website operator/CDN considers "wrong". For example, a list of permitted software, the maximum allowable number of requests in a given time period, etc. IMO, the rules would likely be incriminating. For example, they might be discriminatory and/or anti-competitive and subject to legal challenge. 1. Another interesting question is why the website operator/CDN believes it is "wrong". It appears the OP's www usage is not posing any "threat" to Cloudflare's customers or partners. As such, there is no justifcation for blocking the OP. 2. For example, software that sends personal data to website operators, software that prominently displays advertising, software that provides "payment handlers", and so on. 3. Forcing computer users to choose "interactive" software that is generally unsuitable for automation, such as popular web browsers or mobile apps.
- SergeAx 4y agoOn OP's place I would try Cloudflare Warp. It will connect me right into CF's guts, where limits may be just cancelled. It helped me once or twice when some CF protected sites gave me bad time.
- protomyth 4y agoUsing a group's service so you don't suffer from the actions of that group? I've heard that pitch before. Francis Ford Coppola made some movies about one of those groups.
- userbinator 4y agoThe usual response from me when I get a "needs to review the security of your connection" blockade from CF is "fuck off" along with a click of the Back button. Your content is likely not unique, especially if I'm coming from a search result, and I'll just go somewhere else more friendly instead.
- Sophistifunk 4y agoThis is not an acceptable situation, but I have NFI what individual nobodies can do about it :(
- d2wa 4y ago(Author here.) Complain about in a blog post and hope it gets picked up on Hacker News?
- _8j50 4y agoSounds like the guy's network was being used as part of a ddos attack. That explains the slow loading of sites as well, CF wouldn't throttle you.
- d2wa 4y ago(Author here.) This is possible, but implausible. I log network traffic and haven’t noticed anything out of the ordinary. The point of the article was mostly to complain about the lack of information from Cloudflare, though. I don’t know what caused the blockade, and they’re not telling. How am I — as an end-user — supposed to do anything about the situation? I don’t even know what the situation is.
- uwagar 4y agono wonder all the bad karma accumulated got the founder of cloudflare.
- zaptheimpaler 4y agoAs much as it sucks, DDoS attacks seem to keep ramping up. Google recently blocked one doing 46M requests/sec [1]. It seems like the problem with credit card fraud or spam all over again. People hate being lumped in with malicious actors, but false positives are a thing and a few bad actors can and will demolish the entire system if its not secured. [1] https://cloud.google.com/blog/products/identity-security/how-google-cloud-blocked-largest-layer-7-ddos-attack-at-46-million-rps https://cloud.google.com/blog/products/identity-security/how...
- akagusu 4y agoThis kind of behavior from such companies that have the market dominance should be illegal. They have the unsupervised power to destroy people's life. But for me, the biggest problem is not companies from this size doing this, nowadays it is completely expected; the biggest problem are people, including developers, that think they are right and have the right to do it.
- d2wa 4y agoAnti-discrimination laws should be updated to include personal software preferences. “You can’t tell my gay-ass not to use Firefox on Linux!”
- ghusto 4y agoI've been having this in the last couple of days too. Wanted to +1, because there's an awful lot of "you've probably been hacked", "must be your fault" comments here.