4 ms·
The amount of times Cloudflare is making me sit through their 15 to 30 second "checking your connection" page is insane. For people going through life with ADH
by krono 3y ago
The amount of times Cloudflare is making me sit through their 15 to 30 second "checking your connection" page is insane.
For people going through life with ADHD such as myself, the impact of all these delays and disruptions throughout the day can be severe. Despite being properly medicated this measure is absolutely debilitating and makes for a dreadful and very taxing online experience.
- jeroenhd 3y agoCloudflare's Privacy Pass may help here: https://privacypass.github.io/ https://privacypass.github.io/ It should significantly reduce the amount of CAPTCHAs you see in a way that's not terrible for privacy. For Safari, you can enable Private Access Tokens: https://blog.cloudflare.com/how-to-enable-private-access-tokens-in-ios-16-and-stop-seeing-captchas/ https://blog.cloudflare.com/how-to-enable-private-access-tok... Both of these mechanisms are similar to Google's web DRM proposal in that they rely on external issuers to generate tokens, but unlike Google's attempt they don't guarantee that ad blockers are disabled on pages that try to use tokens.
- tomxor 3y agoWow, that doesn't sound like a terrible idea! Which is honestly surprising in this area where it feels like privacy, anonymity and human verification are incompatible with each other. I am trying to minimise my time wasted by websites, which is hard to balance with privacy, one other one is the repetitive consent forms (if you don't retain cookies, it's a never ending process). I think consent forms and human verification are the 2 biggest human time wasters.
- jeroenhd 3y ago> Which is honestly surprising in this area where it feels like privacy, anonymity and human verification are incompatible with each other. The thing is, it still allows for some correlation between attestation provider and the websites themselves, potentially exposing part of your browsing history to these companies based on how many tokens you use and what websites consume them. That doesn't matter much for Cloudflare's implementation (now Cloudflare knows when you visit Cloudflare, oh no!) but with Apple's attestation provider the risks increase. The smaller the attestation provider gets or the fewer parties trust that particular attestation provider, the higher the risk becomes. It's better for your privacy than the current norm (de-anonimisation through fingerprinting while you fill out a CAPTCHA) but it's still not great. It also allows for attestation providers (and their algorithms) to arbitrarily deny you access to the web if other websites decide to start using them. Privacy in exchange for power, I'm not so sure about that. I imagine for someone suffering from ADHD the small risk that Cloudflare decides to screw you in particular is worth the massive improvement in browsing experience, but everyone will have to determine the pros and cons for themselves.
- krono 3y agoCloudflare is "helping" more than enough already, but thanks for the suggestions. Besides, those solutions have far too much in common with blackmail/extortion to my liking. Either you continue to suffer this structural harassment, or hand over all your bits and maybe in specific cases suffer slightly less! :)
- throwaway154 3y agoPay us with your information to make your problem go away.
- goodpoint 3y agoThis should be illegal.
- jojobas 3y agoThat's typically deployed on sites under heavy DDOS attacks. Nobody wants for their users to see that, they are forced to.
- krono 3y agoNo need to simplify so much that only false dichotomies remain. My brain might be wired up differently but its capacity for nuance and reason is fully intact :) No one is forcing the website owners to sign up with Cloudflare to enable this service with these aggressive configurations, and yet I understand why they would even just pre-emptively. It's cheap and effective, there's no denying that. It is Cloudflare Inc. (66,59USD, +23.57USD/54.79% YTD), however, that architected the solution, markets it as a service, and controls it as a core part of their (i.e. everyone's) internet architecture. As a serviceprovider they could be better at informing their customers of these unintentional side-effects and how they impact otherwise innocent visitors, but whose mental disorders/impairments cause them to be flagged for and having to undergo additional verification steps disproportionately more than others, likely due to some atypical behavioural patterns they show and their often adjusted hardsoftware setups producing an unconventional signature. Some modifications to the system could probably be made on the architectural level too. We can get people in wheelchairs to the top of the empire state building, surely we can also find a solution that allows us to enjoy the benefits of these protective measures without wrecking the web's inclusivity and accessibility this much every time the measures need to be stepped up. Am I asking for too much, what do you think?
- jojobas 3y agoI'm pretty sure anyone who deploys aggressive cloudflare DDOS protection knows the impact and believes it's the lesser evil. If there was just as effective a way to tell cheap bots from legitimate browsers without making users wait I'm pretty sure it would have been used.
- krono 3y agoBeing "pretty sure" is an opportunity and a starting off point, not a dead end. Not to forget the classic "Assumptions are the mother of all fuck ups". Things aren't set in stone either. The most effective method to communicate over long distances used to be carrier pigeons, but only because they hadn't yet invented the telegraph.
- sammy2255 3y agoCloudflare isnt making you do that. The customer using Cloudflare has configured it to do that…
- krono 3y ago"There must be some way out of here," said the joker to the thief "There’s too much confusion, I can’t get no relief"