13 ms·
Tell HN: Cloudflare Is Blocking Piped
Lately I've been getting frequent "Error HTTP 451: Unavailable for Legal Reasons" thrown by Cloudflare whilst using Piped (a YouTube alternate front end used by Nitter).
However these errors are generated... in error. The page links to a DMCA complaint which lists about a half dozen unrelated YouTube (and Piped) links, none of which are being accessed when the error is generated. In fact, viewing the video on YouTube plays back fine. There appears to be a glitch in Cloudflare's URL filtering. It's been happening so frequently that Piped is often unusable.
- adspedia 4y agoHave you submitted that to https://radar.cloudflare.com/domains/feedback https://radar.cloudflare.com/domains/feedback ?
- joecool1029 4y agoI thought about submitting this a week or so ago. Here's the link to the issue and discussion on it: https://github.com/TeamPiped/Piped/issues/1704 https://github.com/TeamPiped/Piped/issues/1704 TL;DR: Apparently there's a Hong Kong dude living in Germany that didn't like his videos being on Youtube, so he sent DMCA takedown requests to Piped instead and Cloudflare did a takedown on the whole domain, which only appears if sent as a referral from outside piped.kavin.rocks (or using the redirect extension for firefox).
- LocalH 4y agoClose. Seems to me more like he didn’t realize that Piped is an alternative front end to YouTube, and assumed that someone had actually reuploaded his YouTube content elsewhere.
- joecool1029 4y agoYeah I realized it while sleeping and when I woke up it was too late to edit. I meant to say the takedown was likely sent to the abuse contact on the whois info for cloudflare's ip address. Could be his own content he's claiming or something he really didn't want public and just exhausted every potential avenue to send takedown requests to. Not going to assume either way, but that's likely how this started.
- ronnier 4y agoCloudflare is making my live very difficult right now. Spammers are hosting websites using free domains, like .ml, .tk, so an unlimited supply of random domains, hosting them behind cloud flare which prevents us from easily getting the page content or blocking the IP for a period of time since the IP is shared. Lots of spam hosted on cloudflare these days.
- Schnurpel 4y agoYou can get the originating IP via mod_remoteip, or its nginx brethren. You can block those IPs in your firewall, or via the Cloudflare firewall.
- capableweb 4y ago> or via the Cloudflare firewall. Wouldn't that be a dream world for Cloudflare? "We protect spammers and if you wanna be as well protected against said spammers, sign up for our firewall"
- Dylan16807 4y agoHow do they make it hard to get the page content? Is it easier/better to block by IP than to block unknown free domains?
- TDiblik 4y agoNo op, but I believe that once you put your website behind cloudflare it's really hard, if not imposible to get content using requests. Don't know about scraping tho. Also, I think it's better to block unknown free domains, because (public) IPs can have thousands of devices asociated with them. Once you block a domain, the "scammer" has to buy a new one.
- luckylion 4y agoWe've seen similar things where spammers scrape our sites, put them up slightly modified and use cloudflare to block access to most of the web. They're obviously letting Googlebot through, but I've tried accessing it from dozens of countries and they're always straight up denied. I don't know what they're doing exactly, maybe it's an SEO attack, or they might be running ads and allowing that traffic to pass through. If CF had a simple way to get (verified!) customer details, much of the crime using CF would go away while the pure DDOS-protection and CDN-usage wouldn't be impacted. Legitimate companies have their legal info on their websites anyhow, they don't care if you also can query CF about who they are.
- Gigachad 4y agoYou can’t rely on cloudflare for infrastructure. They have proven too many times they will just drop stuff almost as much as Google will.
- 6c737133 4y agowhat's your alternative?
- mhoad 4y agoThis is the same company that has repeatedly gone to the mat to ensure Nazi’s and targeted hate campaigns remain active online. But this is where they draw the line? They have on multiple occasions had long and public campaigns talking about how important it is to fight censorship in all its forms except a random DMCA troll in Hong Kong? I don’t think Cloudflare really love “free speech” as much as they pretend in their public messaging.
- Jamie9912 4y agoThey weren't hosting anything..
- mhoad 4y agoYou know exactly what I mean here. I’m going to update the post though.
- breakingcups 4y agoListen, the stuff is on their hard drives, being served by their servers through their public IP addresses. I don't care whatever backend method they use to update their cache from some other origin, by all accounts they are hosting and serving it.
- Jamie9912 4y agoIt's not on their hard drives. Why don't you go and complain to Telco providers, and undersea cable infra for forwarding pro-nazi bits.
- strangeattractr 4y agoThey’ve never gone to the mat to defend free speech. They make a public statement indicating the discomfort they feel blocking content and then they censor it a few days later.
- viraptor 4y agoThey have in this case https://twitter.com/stealthygeek/status/1485731108822077443 https://twitter.com/stealthygeek/status/1485731108822077443 I don't have the case docket link easily available, but it was referenced somewhere around that thread.
- comeonbrandon 4y agoSee if changing the URL from piped.kavin.rocks/watch?v= to piped.video/watch?v= will work. I've never had the "Unavailable for Legal Reasons" error when using the latter domain name. Additionally you can set up a permanent redirect with a browser addon like the Redirector to always be sent from piped.kavin.rocks to piped.video.
- sdze 4y agoWhy would anybody in the right mind centralize his/her infrastructure? I doubt that people actually need something like Cloudflare.
- ilyt 4y agoYou can use shit slow language with fat framework and just put it behind CF and run half decent, that's why people use it
- dxuh 4y agoBut you can also use a fast language with no framework, but host it on a 5€/mo VM and put it behind CF and it will run half decent.
- sgtfrankieboy 4y agoBecause they save us ~20 thousand a month in bandwidth cost.
- rurtrack 4y agoWe got 10k visits in a single day. Cost of data transfer: zero
- hakre 4y agoReally zero, like non of the visitors was hitting the original servers? That would be impressive then. And you should consider to make money with delegating the traffic, not give away the traffic for free.
- rurtrack 4y agoI mean, I did not went into the rabbit hole of checking thoroughly, but in cloudflare it says we served 8gb and aws says we served just a few megabytes. You configure to ignore everything, even the url querystring, and worst case scenario, they serve your site from an internet archive snapshot. You can literally power off your server and the page stays online
- oefrha 4y agoHonestly, if I wasn't a technical guy and I saw my channel and all my content on some piped.kavin.rocks or yewtu.be which aren't visually distinguishable from all the non-alternative-YouTube-frontend tube sites, I would assume someone's ripping all my content and impersonating me as well. I can totally see where the DMCA is coming from. And even knowing the technical differences, one may want to dissociate with a stupid domain name like yewtu.be. Edit: I showed https://yewtu.be/channel/<channel_id> https://yewtu.be/channel/<channel_id> to a content creator friend just now. Predictably, the reaction is "WTF, am I being impersonated? What should I do?"
- BlackLotus89 4y agoWhy is yewtu.be a stupid domainname? It's an "alternative" spelling of youtu.be that's easy to memorize and fast to type. I use a plugin to redirect to newpipe instances, but if I hadn't one I would probably use yewtu.be because it would suck to always type something like piped.kavin.rocks or invidious.pussthecat.org
- newsclues 4y agoI think that is a comment about alt right commentators online. YewTube sounds like an anti Semitic joke.
- bArray 4y ago
- cumshitpiss 4y ago
- Cyberdog 4y agoJesus, people see nazis behind every blade of grass nowadays. Pray tell, what is antisemitic about "YewTube?" Just that it's one letter away from "JewTube?" Sure, but if the creators intended to be antisemitic, why not just call it that then?
- 4y ago
- zelphirkalt 4y agoBy now Cloudflare is more of an obstacle to the free web than it is helping. A centralized entity, whose scripts from randomly named subdomains you must allow to run on your machine, or be stuck at their obnoxious "checking your browser" page endlessly reloading, because some web dev decided to put their website behind Cloudflare. Cloudflare is one of the most prominent reasons for me to simply close the browser tab and leave the site.
- m463 4y agoI remember working on denial-of-service protection code for an embedded device. One problem was that if the code was TOO aggressive in protecting from a denial of service attack, you could actually help an attack or be the culprit yourself by denying legitimate traffic. I think this is what cloudflare is doing. They are imprecise and they are denying legitimate traffic.
- AtNightWeCode 4y agoI don't think that ever happens. If anything they are too lenient. Our own alarms kicks in way before Cloudflares DDOS protection is activated.
- danr4 4y agoI don’t know… the so called free web is also a bot paradise, and like it or not cloudflare is actually helping mitigate it to some degree. It comes with a cost but maybe it’s worth it?
- shrimpx 4y agoCloudflare has played a major part in making VPNs suck, by providing a service that actively blacklists VPN IPs and selling companies on integrating the VPN blocker into their services. It's probably true that some VPNs are used for nefarious stuff, but it's also lame that Cloudflare is such an anti-privacy warrior.
- deleted 4y ago
- nikisweeting 4y agoI used to love Cloudflare but their argument for free speech absolutism went out the window when they started making judgement calls about which sites to block and which to keep. Now I'm just disappointed but not surprised. Will probably move off entirely once Tailscale funnels allow for custom termination CNAMEs. If this particular instance is them getting DMCA'd then it's not really their fault, but I'm confirmation biasing it with a pattern I see of them making more and more judgement calls about what to host and becoming more like a standard 100% profit-driven megacorp hosting provider.
- convery 4y agoNot to mention that their priorities when it comes to blocking decisions seems odd. DDoS-for-hire (stressers), piracy, ISIS support-forums, revenge-porn etc. are all fine because free speech. But a forum supporting nazis, an imagebord with lax moderators, and a forum archiving illegal/insane activity that people post online are all nuked because.. ... reasons..
- cmeacham98 4y ago"I know that Cloudflare is legally required by the US government to abide by the DMCA, but this supports my theory they are censoring the web more and more on purpose!" ?????
- nikisweeting 4y agoNo I'm saying this case explicitly does not support my argument, however there are enough cases of them making judgement calls that this independent pattern has formed and it's easy for me to fall into the trap of confirmation bias. My initial comment wasn't clear but it doesn't let me edit now.
- ilyt 4y agoI still dunno how people got conned that DoH aka. "tunnel your every DNS request to american entity that is required by law to spy on you on demand" to be the new "standard" for the browsers
- pas 4y agoin the US ISPs sell your DNS request data, compared to this Cloudflare seems an improvement in other parts of the world ISPs give your DNS data to the not so secret police and compared to that Cloudflare is a huge improvement in the parts where ISPs don't sell your DNS data you should switch to a different DoH provider
- josephcsible 4y agoDoH is 100% a good thing. It makes surveillance of your Internet traffic harder, not easier. If you don't trust Cloudflare, then pick a different DoH provider that you do trust.
- capableweb 4y agoNothing is 100% "a good thing", everything has tradeoffs. In this case, you're moving the trust you put in your ISP or anyone who resolves your DNS queries to Cloudflare. Depending on where you are in the world, or how your threat profile looks, this might be good or bad, or degrees of good/bad. That everyone is starting to tunnel more and more of their traffic to one single entity (Cloudflare or not) is overall not that good. But certainly not 100% bad.
- josephcsible 4y ago> In this case, you're moving the trust you put in your ISP or anyone who resolves your DNS queries to Cloudflare. Not necessarily: > If you don't trust Cloudflare, then pick a different DoH provider that you do trust.
- ThePhysicist 4y agoI mean it's Piped's decision to host their service on Cloudflare, no? No on forces them to use that service, so I don't see this as an issue with CF. They are not "the Internet", even though their marketing makes you believe that, thousands of large services run fine without routing their traffic through them.
- fulafel 4y agoIs there a service like Cloudflare outisde DMCA vulnerable jurisdictions?
- codedokode 4y agoCloudflare might end a golden era of scraping, when it was trivial to scrape data from any site. Now Cloudflare helps site owners to make sure than only humans can read their contents manually. As more site owners switch to similar services, web will become less and less machine readable. No automated data processing, no archiving.
- nine_k 4y agoBut wait, AI models will help bots looks like real humans accessing a site! They'll try hard to will fool the AI models that check if a site is browsed by a human. Ha-ha, only serious.
- vdfs 4y agoNo need for AI, browser can easily be automated and captcha can be solved using cheap services
- 6c737133 4y ago> captcha can be solved using cheap services call it what it is - you're using slave labor in a 3rd world country to solve rudimentary puzzles for you
- from 4y agoIt's probably not slave labor. It may be really poorly paid labor but if you had slave labor you'd probably use it for something profitable like construction like they do in the Persian gulf countries instead of solving captchas that people pay $3 per 1000 for.
- bjord 4y agothis won't stop the overall trend, but it can help you get around cloudflare's effective scraping blocking (copying my comment from a previous thread): If you're scraping with Python, try cloudscraper—among other things(!), it supports JS rendering (basically the bare-minimum check cloudflare does), without needing to run a full browser in the background. It's built on requests, so integration was pretty easy. https://github.com/venomous/cloudscraper https://github.com/venomous/cloudscraper
- Run_DOS_Run 4y agoCloudFlare again.. Offering their service to crime forums, credit card fraud shops and phishing websites, while making usage of Tor and VPNs nearly impossible or atleast a pain. Coupled with the hypocrisy of an open web and freedom of speech, it makes CloudFlare arguably one of the worst threats to the web as we know it. Whereas the freedom of speech ala Cloudflare stops as soon as it can generate cheap PR, because then a website is quickly blocked after a few media reports.. or in case of Piped as soon as the content mafia is complaining.
- AtNightWeCode 4y agoThere is nothing in Cloudflare that blocks anything like that by default. Site owners decides what to block. The problem with VPNs and TOR is that there is a lot of rouge traffic from these services. Also, there is no feature that blocks VPNs in CF. Some get blocked for not coming from consuming ISPs but more commonly whole ASNs are blocked if the majority of the traffic is bad.
- Terretta 4y agorogue traffic, unless you mean pink powder
- sylware 4y agoAnd cloudflare again! Those guys... not to mention their pesky "browser verification" which is does not work with noscript/basic (x)html browsers.
- nine_k 4y agoIt's the site owners who enable this; they are just not interested in users who run noscript or any other non-standard setup.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- bArray 4y agoI also get CloudFlare now blocking my access to RSS feed MP3s for some podcasts. Once the almighty CloudFlare deems you a threat, your IP is burned. These days I can use less and less of the internet. I really want to just see us get to the point where we don't have to rely on such services. I refuse to use them or any other for services I run, DDoS be damned.
- kiririn 4y agoI also refuse to use them for anything. A decade or so ago I spent 2 years barely able to access any site using cloudflare, won’t forget that It goes to show the flaws of centralised services where you are not the customer. Not only is there no one to complain to, you can’t even take your money/traffic elsewhere as the competitors probably use cloudflare too
- kevincox 4y agoCloudflare's default settings are very hostile to RSS feeds in general. They block these as part of bot blocking. Which of course is silly because these are intended to be accessed by bots. Even Cloudflare's blog RSS feed is affected by this.
- prdonahue 4y agoI agree this is a problem, and we're actively working to fix it. Specifically, there's a ticket in progress to improve how bot mitigation handles requests for certain types of static content (including RSS feeds).
- kevincox 4y agoGood to hear. It seems to me that more or less all static content should be exampt because it can be cached so serving it doesn't cost the origin anything. Of course there are ways to bypass the cache with bogus URL parameters that make this difficult and some customers that are concerned with scraping even if that content is "static".
- lvass 4y agoLibRedirect is working fine with Piped for me. I think I hit some blocked URL but it's trivial to remove it from the list, most mirrors are definitely working.
- cheri9 4y ago[dead]
- necrosyne 4y agoI’ve been running into this exact problem in recent weeks. Switching to piped.video is the workaround I’m using atm.