9 ms·
A great opportunity right now for CloudFlare to win some goodwill and PR by helping out EasyList for free right now. But what about simply enable a firewall an
by JimWestergren 4y ago
A great opportunity right now for CloudFlare to win some goodwill and PR by helping out EasyList for free right now.
But what about simply enable a firewall and show captcha or similar if the origin IP is from India and requesting that URL until the situation is under control? I did that with the free plan recently in CloudFlare in a similar situation and it worked perfectly (of course on a much smaller scale).
- metalliqaz 4y agothat would break everyone in India not using one of those broken browsers
- iforgotpassword 4y agoThey are already serving access denied replies, so I assume they can identify the browsers via user agent or similar? If so, returning a bogus file that blocks everything and adding a comment in that list asking the developers to use caching or mirroring the file should be fine. I wonder if those browsers honor the list when fetching the update though. Would be awesome if you could just add easylist and lock out further requests right on the device.
- democra 4y agoBrowser developers can choose to fake user-agents. Brave uses a generic chrome user agent so it cannot be differentiated from regular Chrome.
- acdha 4y agoEveryone in the world is impacted if the site goes down under load. Changing that to everyone in a particular country (perhaps with a given user agent if the free plan allows expressions) would still be an improvement even if other work is needed.
- bluehatbrit 4y agoMost requests will be in the background or in Cron jobs. Captcha wouldn't be possible in those situations as it would never be seen by anyone.
- Nextgrid 4y agoI’m not sure a captcha would help though. These aren’t intentional attack requests, they’re “legitimate” requests by a clueless developer’s app that happened to get popular. They just need to serve either an empty response or an intentionally broken rule to break the misbehaving browser and force its developers to fix it.
- bluehatbrit 4y agoYes there is of course that as well!
- rvnx 4y agoThese apps behind cannot render the captcha, as the fetch is happening in the background. However what you can do is match the user-agents, and return a global/catch-all adblocking rule that blocks all the content of all the pages (by blocking the body element). The app developers are going to notice the issue very fast (because users are reporting the problem), and mirroring the lists or adding a cache is immediately going to be their priority. Bonus: I think some browsers and extensions can execute JavaScript in adblocking rules; https://help.eyeo.com/adblockplus/snippet-filters-tutorial https://help.eyeo.com/adblockplus/snippet-filters-tutorial (which is essentially re-using a gigantic XSS in order to notify the user)
- jannyfer 4y agoBlocking all page content to knowingly cause unintended behavior… I wonder if this can be considered criminal. I read that poisoning your own lunch to catch a workplace fridge thief could be considered assault. EDIT: here’s what I read. https://law.stackexchange.com/questions/966/can-one-be-liable-for-poisoning-food-one-expects-to-be-stolen https://law.stackexchange.com/questions/966/can-one-be-liabl... Imagine, say, you update the list to block all URLs, and it impacts some municipal government worker’s ability to update some emergency alert service and causes hundreds of people to be permanently injured.
- Volundr 4y agoIf an application can't handle failed web requests that application is already broken. Web requests can and will fail at any time.
- rvnx 4y agoI don't think so. Google often knowingly and intentionally breaks apps (through API deprecation) because it's more convenient for them or that it is costly to maintain. Nothing criminal there. Same for Easylist, if they decide that a quota of 100000 requests per IP+UA per day is the maximum, that's their choice. They owe nothing to the consumers of the lists. That being said; Easylist actually benefits from being distributed in many apps; it is really valuable to influence / control adblocking lists, so the more flexible they are to the browser developers, the better (I guess).
- anigbrowl 4y agoI can't understand their argument that a text file 'isn't a web content'; seems like a bullshit excuse.
- cvwright 4y agoDoes not inspire confidence in Cloudflare, that’s for sure.
- kalleboo 4y agoI think CloudFlare pretty explicitly do not want people to be confident that they can serve 2 petabytes a month of API data on the free tier
- cvwright 4y agoThat’s part of the problem though, isn’t it? Because they certainly want to serve some huge amount of traffic for free while they attempt to become the next abusive monopoly platform. They’re trying to have their cake and eat it too.
- jacooper 4y agoMaybe if they created a web page for easylist and then hosted that + the lists directly on CF pages, maybe that would considered as web content?
- r3trohack3r 4y agoThis doesn’t sound like bullshit to me. Serving a static text file that is primarily used by applications is not in line with their terms of service. Cloudflare provides a significant service to the free and open web by subsidizing the hosting costs of static content for websites. They give that away for free under what appears to be reasonable terms.
- yellowapple 4y agoI can think of few things more static than a .txt file.
- bergenty 4y agoA captcha for all 600 million internet users seems like overkill. Maybe a smaller subnet range.
- GekkePrutser 4y agoTrue but I bet 99% of CloudFlare's income comes from companies that wish to see EasyList die in a fire. I'm pretty sure this would factor into their strict enforcement of the 'rules'. I mean, this is something between github and CloudFlare right? And github sure hosts a ton of other .txt files and other stuff that's not 'web content'. They don't enforce it so strictly with other sites. Still, I'm sure the 'community' can figure out how to keep something like this online. I'd be happy to pony up some cash for decent hosting and I'm sure many would be. If that doesn't work out, something like ipfs, a torrent or whatever.
- winstonprivacy 4y agoCorrect. And let's not forget that the company which owns them would also like to see EasyList die in a fire.
- jgrahamc 4y agoLooks like it's fast to download now.
- corobo 4y agoWouldn't their R2 service tick all the boxes for this one? https://developers.cloudflare.com/r2/platform/pricing/ https://developers.cloudflare.com/r2/platform/pricing/
- 22c 4y agoSounds like they'd probably be in for at least $500/mo on this which doesn't seem like a lot if you're serving the amount of data EasyList is doing, but is a lot if your previous hosting costs were "free".
- tatpacc 4y agoPwned Passwords project by Troy Hunt is served by CloudFlare cache. I don't know scale of bandwidth usage by Pwned Passwords. But CloudFlare can definitely make the similar arrangement here too.
- chemmail 4y agoThis is a bit different though. You are basically taking away a main revenue stream from websites, your main clients. That sounds like bad optics for them.
- tatpacc 4y agoI can understand but my reply was with reference in parent comment > A great opportunity right now for CloudFlare to win some goodwill and PR by helping out EasyList for free right now.
- jgrahamc 4y agoI am following up internally. Looks like there's a combination of this data not being cached, our systems thinking a DDoS was happening (which it sort of was). But getting the full story now.
- deleted 4y ago[deleted]
- Yeri 4y agoSeems like MP says it’s fixed: https://twitter.com/tuinslak/status/1583016022491435009?s=61&t=N9WX0bnYDZTkDrEbKWfxMw https://twitter.com/tuinslak/status/1583016022491435009?s=61...
- solardev 4y agoI'm glad they sorted it out, but I wish there was a proper support route other than "create a sufficient media storm so that an employee tweets the CEO"
- AnonC 4y ago> EasyList is hosted on Github and proxied with CloudFlare. Unfortunately, CloudFlare does not allow non-enterprise users use that much traffic, and now all requests to the EasyList file are getting throttled. > EasyList tried to reach out to CloudFlare support, but the latter said they could not help. Moreover, serving EasyList actually may violate the CloudFlare ToS. Seeing the comments from Cloudflare here, looks like the HN machine has yet again worked its magic to get appropriate attention!