60 ms·
Tell HN: Cloudflare is blocking Pale Moon and other non-mainstream browsers
Hello.
Cloudflare's Browser Intergrity Check/Verification/Challenge feature used by many websites, is denying access to users of non-mainstream browsers like Pale Moon.
Users reports began on January 31:
https://forum.palemoon.org/viewtopic.php?f=3&t=32045 https://forum.palemoon.org/viewtopic.php?f=3&t=32045
This situation occurs at least once a year, and there is no easy way to contact Cloudflare. Their "Submit feedback" tool yields no results. A Cloudflare Community topic was flagged as "spam" by members of that community and was promptly locked with no real solution, and no official response from Cloudflare:
https://community.cloudflare.com/t/access-denied-to-pale-moon-desktop-browser/764330 https://community.cloudflare.com/t/access-denied-to-pale-moo...
Partial list of other browsers that are being denied access:
Falkon, SeaMonkey, IceCat, Basilisk.
Hacker News 2022 post about the same issue, which brought attention and had Cloudflare quickly patching the issue:
https://news.ycombinator.com/item?id=31317886 https://news.ycombinator.com/item?id=31317886
A Cloudflare product manager declared back then: "...we do not want to be in the business of saying one browser is more legitimate than another."
As of now, there is no official response from Cloudflare. Internet access is still denied by their tool.
- tushar-r 2y agoBadly configured bot protection. It'll look at user agent headers and try to fingerprint the browser (some form of fpjs2 or similar,) and then decide. Very error prone.
- ycombonator 2y ago[dead]
- scblock 2y ago[flagged]
- hexagonwin 2y agoSame issue. I haven't been able to visit any websites powered by Cloudflare on my SeaMonkey browser recently.
- nonrandomstring 2y agoI use w3m which makes me about as popular as a fart in a spacesuit. No Cloudflare things for me.
- zlagen 2y agoI'm using chrome on linux and noticed that this year cloudflare is very agressive in showing the "Verify you are a human" box. Now a lot of sites that use cloudflare show it and once you solve the challenge it shows it again after 30 minutes! What are you protecting cloudflare? Also they show those captchas when going to robots.txt... unbelievable.
- viraptor 2y agoThe captcha on robots is a misconfiguration in the website. CF has lots of issues, but this one is on their costumer. Also they detect Google and other bots, so those may be going through anyway.
- deleted 2y ago[deleted]
- jasonjayr 2y agoSure; but sensible defaults ought to be in place. There are certain "well known" urls that are intended for machine consuption. CF should permit (and perhaps rate limit?) those by default, unless the user overrides them.
- JimDabell 2y agoPutting a CAPTCHA in front of robots.txt in particular is harmful. If a web crawler fetches robots.txt and receives an HTML response that isn’t a valid robots.txt file, then it will continue to crawl the website when the real robots.txt might’ve forbidden it from doing so.
- fcq 2y agoI have Firefox and Brave set to always clear cookies and everything when I close the browser... it is a nightmare when I come back the amount of captchas everywhere.... It is either that or keep sending data back to the Meta and Co. overlords despite me not being a Facebook, Instagram, Whatsapp user...
- reify 2y agoI use Librewolf and Zen Browser If I am met with the dreaded cloudflare "Verify you are a human" box, which is very rare for me, I dont bother and just close the tab.
- molticrystal 2y agoTo have cloudflare work on Librewolf I had to enable web workers. Why does it need web workers, when it worked fined without them on Waterfox Classic firefox 56 fork that hasn't been updated in water?
- ai-christianson 2y agoHow many of you all are running bare metal hooked right up to the internet? Is DDoS or any of that actually a super common problem? I know it happens, but also I've run plenty of servers hooked directly to the internet (with standard *nix security precautions and hosting provider DDoS protection) and haven't had it actually be an issue. So why run absolutely everything through Cloudflare?
- uniformlyrandom 2y agoMost exploits target the software, not the hardware. CF is a good reverse proxy.
- raffraffraff 2y agoThey make it easy to delegate a DNS zone to them and use their API to create records (eg: install external-dns on kubernetes and key it create records automatically for ingresses)
- dosdosdosdos 2y ago[flagged]
- codexon 2y agoIt is common once your website hits a certain threshold in popularity. If you are just a small startup or a blog, you'll probably never see an attack. Even if you don't host anything offensive you can be targeted by competitors, blackmailed for money, or just randomly selected by a hacker to test the power of their botnet.
- progmetaldev 2y agoWeb scraping without any kind of sleeping in between requests (usually firing many threads at once), as well as heavy exploit scanning is a near constant for most websites. With AI technology, it's only getting worse, as vendors attempt to bring in content from all over the web without regard for resource usage. Depending on the industry, DDoS can be very common from competitors that aren't afraid to rent out botnets to boost their business and tear down those they compete against.
- 2y ago
- arielcostas 2y agoA lot of people are failing to conceive the danger that poses to the open web the fact that a lot of traffic runs through/to a few bunch of providers (namely, CloudFlare, AWS, Azure, Google Cloud, and "smaller" ones like Fastly or Akamai) who can take this kind of measures without (many) website owners knowing or giving a crap about. Google itself tried to push crap like Web Environment Integrity (WEI) so websites could verify "authentic" browsers. We got them to stop it (for now) but there was already code in the Chromium sources. What makes CloudFlare MITMing and blocking/punishing genuine users from visiting websites? Why are we trusting CloudFlare to be a "good citizen" and not block unfairly/annoy certain people for whatever reason? Or even worse, serve modified content instead of what the actual origin is serving? I mean in the cases where CloudFlare re-encrypts the data, instead of only being a DNS provider. How can we trust that not third party has infiltrated their systems and compromised them? Except "just trust me bro", of course
- raffraffraff 2y agoI don't think people aren't aware that it's bad. They just don't care enough. And they think "I could keep all this money safely in my mattress or I could put it into one of those three big banks!" ... Or something like that.
- SpicyLemonZest 2y agoI can easily conceive the danger. But I can directly observe the danger that's causing traffic to be so centralized - if you don't have one of those providers on your side, any adversary with a couple hundred dollars to burn can take down your website on demand. That seems like a bigger practical problem for the open web, and I don't know what the alternative solution would be. How can I know, without incurring any nontrivial computation cost, that a weird-looking request coming from a weird browser I don't recognize is not a botnet trying to DDOS me?
- juped 2y agohow do you know a normal-looking request coming from google chrome is not a botnet trying to ddos you?
- graemep 2y agoMost of the sites mentioned in the forum work for me with PaleMoon. I do get a "your browser is unsupported" message from the forums.
- fishgoesblub 2y agoSince 2024 to now I've had to constantly verify that I'm human just to visit certain sites due to Cloudflare. Now it's even worse since (sometimes) cdnjs.cloudflare.com loads infinitely unless I turn on my VPN. Infuriating that I have to use a service known for potential spam, to get another service that blocks spam to bloody work.
- randunel 2y agoChromium on linux is also frequently blocked by cloudflare. I can't use tools such as HIBP.
- martinbaun 2y agoSame here. I just gave up on most of these websites. When I absolutely need to use a website such as for flights, I have a clean chrome browser I spin up.
- wkat4242 2y agoYeah and Firefox on Linux too. I do have the user agent set to one from Edge because otherwise Microsoft blocks many features in Office 365. Once it thinks it's Edge it suddenly does work just fine. But it doesn't completely fix all the cloudflare blocks and captchas.
- maxk42 2y ago+1 for Firefox on Linux. Several other services (like Instagram) now also accuse me of being a bot every time I legitimately log in with Firefox on Linux.
- wkat4242 2y agoYeah with Instagram I wouldn't be surprised if they just do this to annoy to into using their app. Where they can force timed ads (you have to watch an ad now for a few seconds before it continues). I noticed another platform (wallapop, a kind of ebay/craigslist here in Spain) that does the same. It never works well in a browser, even in chrome. I think they're just trying to bully their users to their app, which has 30+ trackers in it.
- juped 2y agoThings like "using Linux" or "having an adblocker at all" get you sent to captcha hell. Anything where you're in the minority of traffic. It's not going to change; why would it?
- DoctorOW 2y agoI have multiple blockers (Ublock Origin, Privacy Badger, Facebook Container) in Firefox and have not experienced this issue.
- maples37 2y agoFor what it's worth, this has been my experience as well. I've seen maybe a handful of full-page Cloudflare walls over the past year, and none have gotten me stuck in any kind of loop
- linuxftw 2y agoI have been using Fedora + Firefox for years. I sometimes get a captcha from Cloudflare, but not frequently. Works just fine. I have not tried less mainstream browsers, just FF and Chrome.
- jeroenhd 2y agoThings are going to chance. Unfortunately, things are only getting worse. CAPTCHAs are barely sufficient against bots these days. I expect the first sites to start implementing Apple/Cloudflare's remote attestation as a CAPTCHA replacement any day now, and after that it's going to get harder and harder to use the web without Official(tm) Software(tm). Using Linux isn't what's getting you blocked. I use Linux, and I'm not getting blocked. These blocks are the results of a whole range of data points, including things like IP addresses.
- flyinghamster 2y agoFor me, captcha hell is very random, and when it happens, it's things like "pick all squares with stairs" where I have to decide if that little corner of a stairway counts (and it never seems to) or "pick all squares with motorcycles" where the camera seemed to have a vision problem. What usually works for me is to close the browser, reload, and try again.
- jmbwell 2y agoI'm still in the habit of granting Cloudflare a presumption of good faith. Developers frequently make assumptions about things like browsers that can cause problems like this. Something somewhere gets over-optimized, or someone somewhere does some 80/20 calculation, or something gets copy-pasted or (these days) produced by an LLM. There are plenty of reasons why this might be entirely unintentional, or that the severity of the impacts of a change were underestimated. I agree that this exposes the risk of relying overmuch on handful of large, opaque, unaccountable companies. And as long as Cloudflare's customers are web operators (rather than users), there isn't a lot of incentive for them to be concerned about the user if their customers aren't. One idea might be to approach web site operators who use Cloudflare and whose sites trigger these captchas more than you'd like. Explain the situation to the web site operator. If the web site operator cares enough about you, they might complain to Cloudflare. And if not, well, you have your answer.
- chaoskitty 2y agoHow many times do they have to do the same thing before we modify our presumtion?
- jmclnx 2y agoI just went to a site that I think uses cloudflare via seamonkey. I was able to get to the site. This is on OpenBSD. But if someone has a site that is failing, feel free to post it and I will give it a try.
- matt_heimer 2y agoI tested palemoon on Win with one of my Cloudflare sites and didn't see any problem either. It's probably dependent on the security settings the site owner has choosen. I'm guessing bot fight mode might cause the issue.
- lofaszvanitt 2y agoCloudflare is slowly but surely turning the web into a walled garden.
- thomassmith65 2y agoPretty soon the internet will just be a vestigial thing that people use to connect to the cloudflare.
- airhangerf15 2y agoSlowly? Have you not watched the pot boil around you for the past decade? There are zero good search engines. Everything returns propaganda. This is all as it was intended.
- eitland 2y ago> There are zero good search engines. Everything returns propaganda. Kagi exists and has been production quality and better than Google for over two years already. (At this point I think it is even better than old google.)
- lofaszvanitt 2y agosince the invention of llms it's not that much of a deal that search engines are useless
- rollcat 2y agoOn one hand, this is a scummy move from CloudFlare. All this has ever done is make browsers spoof their UAs. Mozilla/4.0 anyone? On the other, Pale Moon is an ancient (pre-quantum) volunteer-supported fork of Firefox, with boatloads of known and unfixed security bugs - some fixes might be getting merged from upstream, but for real, the codebases diverged almost a decade ago. You might as well be using IE 11.
- pkkkzip 2y agoI'm not sure why people are mad at Cloudflare. They are not obligated to support browsers outside the general marketshare nor should you expect to. Cloudflare not supporting Pale Moon has no impact on the rest of us. Matter of fact today is the first time I'm hearing of this browser I will never end up using.
- rollcat 2y agoThis is not about supporting or not, this is outright blocking/gatekeeping; you can just let pass, but they chose to block. It's completely different from e.g. no longer releasing builds for PPC Macs.
- mimasama 2y ago> known and unfixed security bugs Which are..?
- out-of-ideas 2y agoat this point, im honestly surprised that all non-mainstream browsers dont emulate the same user-agent and ssl fingerprint order of a mainstream browser - or add a flag to change behavior per "tab" (or if cli per some call or other scope) - coupled with a javascript-operating-system which also aligns with those
- doctor_radium 2y agoIn concept that's a good idea, but the fingerprinting potential is VAST: user-agent, TLS, JavaScript quirks, CSS, Canvas, proprietary features like Chrome's Topics, maybe WebGL, WebUSB, etc. In practice it's very hard to do.
- tibbar 2y agoThis echoes the user agent checking that was prevalent in past times. Websites would limit features and sometimes refuse to render for the "wrong" browser, even if that browser had the ability to display the website just fine. So browsers started pretending to be other browsers in their user agents. Case in point - my Chrome browser, running on an M3 mac, has the following user agent: "'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36'" That means my browser is pretending to be Firefox AND Safari on an Intel chip. I don't know what features Cloudflare uses to determine what browser you're on, or if perhaps it's sophisticated enough to get past the user agent spoofing, but it's all rather funny and reminiscent just the same.
- ZeWaka 2y ago> if perhaps it's sophisticated enough to get past the user agent spoofing As a part of some browser fingerprinting I have access to at work, there's both commercial and free solutions to determine the actual browser being used. It's quite easy even if you're just going off of the browser-exposed properties. You just check the values against a prepopulated table. You can see some of such values here: https://amiunique.org/fingerprint https://amiunique.org/fingerprint Edit: To follow up, one of the leading fingerprinting libraries just ignores useragent and uses functionality testing as well: https://github.com/fingerprintjs/fingerprintjs/blob/master/src/utils/browser.ts https://github.com/fingerprintjs/fingerprintjs/blob/master/s...
- radlad 2y agoAs a counterpoint, I asked Claude to write a script to fetch Claude usage and expose it as a Prometheus metric. As no public API exists, Claude suggested I grab the request from the Network tab. I copied it as cURL, and attempted to run it, and was denied with a 403 from CF. I forgot the script open, polling for about 20 minutes, and suddenly it started working. So even sending all the same headers as Firefox, but with cURL, CF seemed to detect automated access, and then eventually allowed it through anyway after it saw I was only polling once a minute. I found this rather impressive. Are they using subtle timings? Does cURL have an easy-to-spot fingerprint outside of its headers? Reminded me of this attack, where they can detect when a script is running under "curl | sh" and serve alternate code versus when it is read in the browser: https://news.ycombinator.com/item?id=17636032 https://news.ycombinator.com/item?id=17636032
- stainablesteel 2y agois spoofing not a simple solution to this?
- Hold-And-Modify 2y agoUnfortunately not. Cloudflare verification goes deeper into browser 'mechanics' than that. Not to mention it could flag you as malicious if you dare attempt bypassing it.
- zb3 2y agoDo these browsers employ any additional tracking protections? "Browser integrity checks" are browser-specific and they might rely on the "entropy" those tracking vectors provide.
- zb3 2y agoSo this would only be "bad" move by cloudflare if you could get around it by recompiling the browser with spoofed UA/strings. Otherwise they'd have to support every possible engine which is infeasible. That saying, the "open web" is indeed dead.
- doctor_radium 2y ago> Otherwise they'd have to support every possible engine which is infeasible. If I understand correctly, this is why I've said on previous Cloudflare threads that they've managed to design a game they can never win. They project a certain omniscience, but then all this sh*t happens. We need to persuade them to stop playing.
- slothsarecool 2y agoCloudflare is actually pretty upfront about which browsers they support. You can find the whole list right in their developer docs. This isn't some secret they're trying to hide from website owners or users - it's right here https://developers.cloudflare.com/waf/reference/cloudflare-challenges/#supported-browsers https://developers.cloudflare.com/waf/reference/cloudflare-c... - My guess is that there is no response because not one of the browsers you listed is supported. Think about it this way: when a framework (many modern websites) or CAPTCHA/Challenge doesn't support an older or less common browser, it's not because someone's sitting there trying to keep people out. It's more likely they are trying to balance the maintenance costs and the hassle involved in allowing or working with whatever other many platforms there are (browsers in this case). At what point is a browser relevant? 1 user? 2 users? 100? Can you blame a company that accommodates for probably >99% of the traffic they usually see? I don't think so, but that's just me. At the end, site owners can always look at their specific situation and decide how they want to handle it - stick with the default security settings or open things up through firewall rules. It's really up to them to figure out what works best for their users.
- Hold-And-Modify 2y agoNot exactly. They say: "Challenges are not supported by Microsoft Internet Explorer." Nowhere is it mentioned that internet access will be denied to visitors not using "major" browsers, as defined by Cloudflare presumably. That wouldn't sound too legal, honestly. Below that: "Visitors must enable JavaScript and cookies on their browser to be able to pass any type of challenge." These conditions are met.
- slothsarecool 2y ago> * If your visitors are using an up-to-date version of a major browser * > * they will receive the challenge correctly. * I'm unsure what part of this isn't clear, major browsers, as long as they are up to date, are supported and should always pass challenges. Palemoon isn't a major browser, neither are the other browsers mentioned on the thread. > * Nowhere is it mentioned that internet access will be denied to visitors not using "major" browsers * Challenge pages is what your browser is struggling to pass, you aren't seeing a block page or a straight up denying of the connection, instead, the challenge isn't passing because whatever update CF has done, has clearly broken the compatibility with Palemoon, I seriously doubt this was on purpose. Regarding those annoying challenge pages, these aren't meant to be used 24/7 as they are genuinely annoying, if you are seeing challenge pages more often than you are on chrome, its likely that the site owner is actively is flagging your session to be challenged, they can undo this by adjusting their firewall rules. If a site owner decides to enable challenge pages for every visitor, you should shift the blame on the site owners lack of interest in properly tunning their firewall.
- Hold-And-Modify 2y agoForgot to clarify: this is not about an increased amount of captchas, or an annoyance issue. The Cloudflare tool does not complete its verifications, resulting in an endless "Verifying..." loop and thus none of the websites in question can be accessed. All you get to see is Cloudflare.
- zeroimpl 2y agoI ran into exactly this the other day trying to browse a website from a browser app on an android-powered TV. Just couldn't get to the website.
- randunel 2y agoIs this the behaviour you're observing? (my recording of HIBP) https://imgur.com/a/cloudflare-makes-have-i-been-pwned-unusable-K5z1X2R https://imgur.com/a/cloudflare-makes-have-i-been-pwned-unusa...
- PokestarFan 2y agoI was on Brave in iOS. I had to turn off Brave Shield.
- picafrost 2y agoCompanies like Google and Cloudflare make great tools. They give them away for free. They have different reasons for this, but these tools provide a lot of value to a lot of people. I’m sure that in the abstract their devs mean well and take pride in making the internet more robust, as they should. Is it worth giving the internet to them? Is something so fundamentally wrong with the architecture of the internet that we need megacorps to patch the holes?
- zamadatix 2y agoWhether something is "wrong" is often more a matter of opinion than a matter of fact for something as large and complex as the internet. The root of problems like this on the internet is connections don't have an innate user identity associated at the lower layers. By the time you get to an identity for a user session you've already driven past many attack points. There isn't really a "happy" way to remove that from the equation, at least for most people.
- kordlessagain 2y agoCloudflare's proxy model solved immediate security and reliability problems but created a lasting tension between service stability and user choice. Like old telecom networks that restricted equipment, Cloudflare's approach favors their paying customers' needs over end-user freedom, particularly in browser choice. While this ensures predictable revenue and service quality, it echoes historical patterns where infrastructure standardization both enables and constrains.
- buyucu 2y agoWelcome to the modern world. Any deviation from the average will get you flagged as a suspicious deviant. It's not just browsers. It's everything.
- windsignaling 2y agoAs a website owner and VPN user I see both sides of this. On one hand, I get the annoying "Verify" box every time I use ChatGPT (and now due its popularity, DeepSeek as well). On the other hand, without Cloudflare I'd be seeing thousands of junk requests and hacking attempts everyday, people attempting credit card fraud, etc. I honestly don't know what the solution is.
- gjsman-1000 2y agoSimple: We need to acknowledge that the vision of a decentralized internet as it was implemented was a complete failure, is dying, and will probably never return. Robots went out of control, whether malicious or the AI scrapers or the Clearview surveillance kind; users learned to not trust random websites; SEO spam ruined search, the only thing that made a decentralized internet navigable; nation state attacks became a common occurrence; people prefer a few websites that do everything (Facebook becoming an eBay competitor). Even if it were possible to set rules banning Clearview or AI training, no nation outside of your own will follow them; an issue which even becomes a national security problem (are you sure, Taiwan, that China hasn't profiled everyone on your social media platforms by now?) There is no solution. The dream itself was not sustainable. The only solution is either a global moratorium of understanding which everyone respectfully follows (wishful thinking, never happening); or splinternetting into national internets with different rules and strong firewalls (which is a deal with the devil, and still admitting the vision failed).
- stevenAthompson 2y agoI hate that you're right. To make matters worse, I suspect that not even a splinternet can save it. It needs a new foundation, preferably one that wasn't largely designed before security was a thing. Federation is probably a good start, but it should be federated well below the application layer.
- ToucanLoucan 2y agoI mean, it wasn't even that security wasn't a thing: the earliest incarnations of the Internet were defense projects, and after that, connections between university networks. Abuse was nonexistent because you knew everyone on your given network. Bob up the hall wouldn't try to steal your credit card or whatever, because you'd call the police. I think a decent idea is, we need to bring personal accountability back into the equation. That's how an open-trust network works, and we know that, because that's how society works. You don't "trust" that someone walking by your car won't take a shit in your open window: they could. But there are consequences for that. We need rock solid data security policies that apply to anyone who does business, hosts content, handles user data online, and people need to use their actual names, actual addresses, actual phone numbers, etc. etc. in order to interact with it. I get that there are many boons to be had with the anonymity the Internet offers, but it also enables all of the horseshit we all hate. A spammer can spam explicitly because their ISP doesn't care that they do, email servers don't have their actual information, and in the odd event they are caught and are penalized, it's fucking trivial to circumvent it. Buy a new AWS instance, run a script to setup your spam box, upload your database of potential victims, and boom, you're off. A lot of tech is already drifting this way. What is HTTPS at it's core if not a way to verify you are visiting the real Chase.com? How many social networking sites now demand all kinds of information, up to and including a photo of your driver's license? Why are we basically forbidden now by good practice from opening links in texts and emails? Because too many people online are anonymous, can't be trusted, and are acting maliciously. Imagine how much BETTER the Internet would be if when you fucked around, you could be banned entirely? No more ban evasion, ever. I get that this is a controversial opinion, but fundamentally, I don't think the Internet can function for much longer while being this free. It's too free, and we have too many opportunistic assholes in it for it to remain so.
- lopkeny12ko 2y agoCloudflare has been blocking "mainstream" browsers too, if you are generous enough to consider Firefox "mainstream." The "verify you are a human" sequence gets stuck in a perpetual never-ending loop where clicking the checkbox only refreshes the page and presents the same challenge. Certain websites (most notably archive.is) have been completely inaccessible for me for years for this reason.
- boomboomsubban 2y agoDo you have something that blocks some amount of scripts? I need to allow third party scripts from either Google or Cloudflare to get a lot of the web to function.
- BenjiWiebe 2y agoI think the archive.is/Cloudflare issue is a known problem separate from the rest.
- areyourllySorry 2y agoarchive.is does not use cloudflare for bot protection.
- indigodaddy 2y agoThis is totally fucked if true
- lapcat 2y agoThe worst is Cloudflare challenges on RSS feeds. I just have to unsubscribe from those feeds, because there's nothing I can do.
- ezfe 2y agoThat's misconfiguration on the web developers side.
- kevincox 2y agoYes, developers such as those that run Cloudflare's own official blog. Maybe there should be some better defaults if they can't even use their own product correctly. BTW a work around for this is to proxy the feed via https://feedburner.google.com/ https://feedburner.google.com/ which seems to be whitelisted by Cloudflare.
- garspin 2y agoI use minbrowser.org/ Some sites disallow it... min suggests changing the user-agent setting to something like - Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/121.0
- pndy 2y agoI don't have any issues so far under Librewolf, Waterfox and Ungoogled Chromium.
- jeroenhd 2y agoI just downloaded Palemoon to check and it seems the CAPTCHA straight up crashes. Once it crashes, reloading the page no longer shows the CAPTCHA so it did pass something at least. I tried another Cloudflare turnstile but the entire browser crashed on a segfault, and ever since the CAPTCHAs don't seem to come up again. ChatGPT.com is normally quite useful for generating Cloudflare prompts, but that page doesn't seem to work in Palemoon regardless of prompts. What version browser engine does it use these days? Is it still based on Firefox? For reference I grabbed the latest main branch of Ladybird and ran that, but Cloudflare isn't showing me any prompts for that either.
- Hold-And-Modify 2y agoThis crash is an even newer Cloudflare issue (as of yesterday, I believe). It is not related to the one discussed here, and will be solved in the next browser update: https://forum.palemoon.org/viewtopic.php?f=3&t=32064 https://forum.palemoon.org/viewtopic.php?f=3&t=32064
- willywanker 2y agoIt uses a hard fork of Firefox's Gecko engine called Goanna, and is independently developed other than a few security patches from upstream. It has considerably diverged from contemporary Firefox so is not comparable.
- ec109685 2y agoSeems seriously risky to be running a browser without access to mainstream security patches. Perhaps it’s secure enough for now due to its obscurity.
- mimasama 2y ago> without access to mainstream security patches They do have access to them. The lead developer and project owner has sec bug access in bugzilla. But vulnerabilities in newer Mozilla have over time become less and less relevant in Pale Moon's codebase, which led to the latter dropping the tracking of how many Mozilla security patches have been applied in the release notes (starting with 33.0.1).
- LeoPanthera 2y agoBlocking Falkon is especially egregious if they're not also blocking Gnome Web. Those are the default browsers for Plasma and Gnome respectively, and some of the few browsers left that are "just browsers", with no phoning home or any kind of cloud integration.
- chr15m 2y agoWhen one of my nodejs based sites experienced DoS, I installed & configured "express-slow-down" as middleware and it resolved the issue.
- EVa5I7bHFq9mnYK 2y agoWhat Cloudflare does that can't possibly be implemented locally by a site owner?
- areyourllySorry 2y agohandle terabytes per second of bot traffic
- deleted 2y ago[deleted]
- chaoskitty 2y ago...which happens to the average site owner how often...?
- sylware 2y agoOh, and a few weeks ago, google search started to block all new noscript/basic (x)html browsers...
- mococa 2y agoThe most ironic thing is that they can’t protect against bots; I even wrote some that bypassed their protection.
- trod1234 2y agoThis situation has been repeatedly happening multiple times a year. Its an ongoing battle where Cloudflare exploits their monopoly on the web to break the web for any unfavored browser. The fact that its regressed and repeated so many times now that clearly it indicates a trend and pattern of abuse by malicious intention. Change management isn't hard, unit tests are not hard, consistently breaking only certain browsers seems targeted. Notably there are mainstream browsers that have this problem as well. Mozilla Firefox for example. Their Challenge has broken large swathes of the web many times to the point where companies hosting apps and websites have simply said they will not support any browser other than Google Chrome/Edge. Anytime the market gets sieved and pushed to only one single solution, its because someone is doing it for their benefit to everyone elses loss. Cloudflare should be broken up in antitrust as a monopoly, as should Google.
- lurker919 2y agoShould cloudflare ever be the target of an attempted takeover by Musk and co (like Twitter or the ongoing NIH/USAID saga) you can be sure you won't be able to access any 'inclusive' websites anymore...
- selcuka 2y agoCloudFlare sometimes attempts to verify that I'm a human when requesting a JSON resource [1] on Australia Post's web site, which breaks parcel tracking feature without any visible captcha. The problem can only be diagnosed by using the browser's inspector tool. Even worse, I get the blanket "You have been blocked" message when I try to manually open the URL and solve the captcha. [1] https://digitalapi.auspost.com.au/shipments-gateway/v1/watchlist/shipments/123456 https://digitalapi.auspost.com.au/shipments-gateway/v1/watch...
- zzo38computer 2y agoI got a HTML with a error message first, but then I tried adding ".json" on the end of the URL and got a JSON with a error message (that the URL is wrong), and then I removed ".json" from the end of te URL and then I got what seems to be the proper JSON response.
- greggh 2y agoIt's blocking Qutebrowser also.
- EfficientDude 2y agoAll by design. The idea is to keep older devices, ones with perhaps no government backdoors, and unauthorized software, off the Internet completely. Same reason there's a big push to kill X11 - it runs great on computers from before hardware backdoors were common. With the Trumpenreich looming, these devices will become very useful. IF they are allowed on the Internet.
- willywanker 2y ago>With the Trumpenreich looming Weren't they useful the last time around, when 'literally Hitler' totally murdered freedom of speech until Biden the hero restored it?
- anticensor 2y agoCan be explained with fewer assumptions.
- radicaldreamer 2y agoI'm seeing this all the time recently using standard Safari on MacOS
- keepamovin 2y agoI see an opportunity for scraper-publishers - who use legitimate access corridors to obtain desired content and publish it without human gatewalls. I'm sure if this becomes more of an issue the market will provide for that.
- mattatobin 2y agoOk kids.. This is Tobin.. but without the Paradigm. First off.. Gee I wish we had all come together about a decade ago or so and found solutions for what was plainly coming and spelled out by my self and others. Second before it happens.. Pale Moon is not "old and insecure" It is being mismanaged had has no vision or prospects for future expansion.. It is just whatever XUL they can keep working while chugging away at the modern web features.. Pale Moon is often TOO security patched btw, which have been regularly disclosed and specially noted in the release notes since I convinced Moonchild he should do that for exactly the kind of old and insecure falsehood. Moonchild's issue as a developer is he will always choose the seemingly simplest path of least resistance and will blindly merge patches without actually testing them. Many security patches are only security patches and not just.. patches because Mozilla redefined the level of security they want their codebase to provide.. But all known Mozilla vulnerabilities and many that would only become vulnerable if surrounding code is changed are patched.. Pale Moon and UXP has become more secure over time and that is an objective fact when you consider the nature of privileged access within a XUL platform which has its own safegaurds as well that persist into Firefox today though less encountered. Now no one hates that furry bastard more than me (and I challenge you to try) but I will never call out good work as anything other than good work. Besides, there are a MILLION other plainly visible faults with the Pale Moon project and its personnel and my past behavior without having to make stuff up or perpetuate a false mantra like "old and insecure". Finally, isn't Cloudflare being very unfair to every project save the modern firefox rebuilds listed on thereisonlyxul.org? Like SeaMonkey? Why does seamonkey deserve any hate from anyone.. or systematic discrimination.. What have they ever done but try and have an internet application suite.. Why are they old and insecure despite being patched and progressing a patch queue for Mozilla patches just landed selectively to preserve the bulk of XUL functionality its users adore? In conclusion, what will be the final cost and how many will burn for trying to going against it.. I know my fate for trying.. how many will join me knowing that?
- Dalewyn 2y agoFor context, this is presumably the Tobin who caused significant tangible damage to the Pale Moon project on his way out. https://forum.palemoon.org/viewtopic.php?t=28265 https://forum.palemoon.org/viewtopic.php?t=28265
- RandyOrion 2y agoA very random note. I try to check the forum post and found out that I was blocked by https://forum.palemoon.org https://forum.palemoon.org , e.g., https://offline.palemoon.org/blocked/index.html https://offline.palemoon.org/blocked/index.html . Don't know and haven't visited this site before. https://www.palemoon.org https://www.palemoon.org works though.
- dvtkrlbs 2y agoI also get a 403 on the same page since they apparently block the entire Hetzner range (i had this IP for like 3 years and it is never used for abuse) (I sometimes use my machine as a shitty VPN since Turkish Goverment does site block with DPI). If they were using Cloudflare I could at least solve a Captcha and see the website
- deleted 2y ago[deleted]
- notpushkin 2y agoYeah, this is ridiculous. Even if their heuristics fail badly for Pale Moon, they could easily fall back to POW.
- nikkwong 2y agoYesterday I was attempting to buy a product on a small retailer's website—as soon as I hit the "add to cart" button I got a message from Cloudflare: "Sorry, you have been blocked". My only recourse was to message the owner of the domain asking them to unblock me. Of course, I didn't, and decided to buy the product elsewhere. I wasn't doing anything suspicious.. using Arc on a M1 MBP; normal browsing habits. Not sure if this problem is common but; I would be pretty upset if I implemented Cloudflare and it started to inadvertently hurt my sales figures. I would hope the cost to retailers is trivial in this case, I guess the upside of blocking automated traffic can be quite great. Just checked again and I'm still blocked on the website. Hopefully this kind of thing gets sorted out.
- ghxst 2y agoTry clearing your cookies and disabling all extensions, if that still results in a block you can try a mobile hotspot. You're either failing some server side check (IP, TCP fingerprint, JA3 etc.) or a client side check of your browser integrity (generally this is tampered with by privacy focused extensions, anti-fingerprint settings etc.). It's not a "fix" but can at least give you an indication of why it is happening.
- underdeserver 2y agoThat's quite a lot to ask. Not OP, but I'm not doing all that just because sometime else misconfigured their anti-DDoS, unless I really need to.
- ghxst 2y agoMy intention was to explain how to identify what could be causing the issue, not to give any indication that I think this is acceptable. Unfortunately like you point out, sometimes you _really_ do have to deal with a website behind an over sensitive WAF, in which case the steps I provided can be helpful.
- Moru 2y ago
- lightedman 2y agoYep, this bug blocked me from being able to respond to a few job postings on Indeed.com today. Needless to say I want to throttle every CF employee for screwing with my efforts to further enrich my life through legal means.
- amatecha 2y agoThis happens to me with Firefox as I run it on OpenBSD and enable Strict Privacy and the "resist fingerprinting" feature -- or at least in that config I've had inexplicable 403 Forbidden errors from CloudFlare and fired up Chromium or whatever and could load the page just fine (or Firefox on another computer).
- by9897 2y ago[dead]
- cess11 2y agoOligopolies are nasty. In lack of regulation, don't take business to actors like Cloudflare and talk to your local politicians. There's also another reason, Cloudflare is under the CLOUD Act, can't be trusted to touch the PII of EU citizens for legal reasons or anyone for moral reasons.
- switch007 2y agoThe silence from CloudFlare staff is rather deafening, especially as they commented on the (newer) outage post.
- Havoc 2y agoWorst part of this is Firefox struggling. Real risk of a monoculture that is functionally google-controlled. (Yes, yes chromium but we saw with manifest who sets direction).
- scooke 2y agoI avoid and refuse to use Cloud flare for these sorts of reasons. Join me.
- kuringganteng 2y ago[dead]
- guluarte 2y agoI had the same problem using minbrowser, changing the UA fixes the problem
- throwaway48476 2y agoIts disgusting how we've accepted 1 company MITMing the whole internet. Cloudflare hosts DDoS provides while selling DDoS mitigation. It's a mafia racket.
- bdhcuidbebe 2y agoYea, sucks. Cloudflare is also blocking my web scrapers ;-)
- randunel 2y agoBut not mine..
- gslin 2y agoThe latest deployment seems using Service Worker API, which causes broken on "old" browsers because the API is not supported on these browsers. Some people like me who block Service Worker API all the time are also affected, like https://chromewebstore.google.com/detail/no-service-worker/mbhfklemgegigbfbfmfdmijkcnabgpmf/reviews https://chromewebstore.google.com/detail/no-service-worker/m... this.
- pmdr 2y agoCloudflare has essentially broken the internet. Blocking or restricting access of even residential IPs running in a real, common browser is evil. And just like that, we handed over the internet to a handful of companies, like it was never ours to begin with.
- pc86 2y agoThe whole "browser integrity check" thing is bullshit.
- RobGR 2y agoTo add another link, I think this is the same issue: https://gitlab.com/gitlab-org/gitlab/-/issues/421396 https://gitlab.com/gitlab-org/gitlab/-/issues/421396
- johnklos 2y agoCloudflare is discriminatory. They, and their fanbois, will likely claim that they can't publicly discuss their criteria for who they block, so some mysterious magic is going on in the background, and we're supposed to just trust them because they're big. That in mind, I'd love even the most fawning of the fanbois to come up with rationalization for why for a very common browser (Safari on modern macOS), most links through Cloudflare work, but trying to get past the are-you-human checkbox on Cloudflare's abuse reporting page doesn't work half the time. Obviously that shouldn't be on an abuse reporting page at all, but Cloudflare has been making abuse reporting extremely difficult for years. Adding rate limiting (a human can easily hit it) and prove-you're-human verification on their abuse page just unambiguously proves this.
- zelon88 2y agoCan't you set your user agent to something else? Like Firefox or Chrome.
- edelbitter 2y agoThey flat out refuse to show what the origin server sent, unless you run some Javascript. Which is sufficient to no longer care about what the browser states in the request headers.
- WikiFuck 2y ago[dead]
- fsckboy 2y agoAdjacent topic: does anybody (US) use Chase Bank from linux? it won't let me use Chromium* or Brave (it used to; it doesn't tell me I can't, it just won't send me TFA confirmation codes to my phone or "recognize" when I log into the phone app. Phone app works, but doesn't have all the features of the web portal. I can use it from macbook but I prefer linux. *I have not tried downloading Google Chrome or IE or Edge if that still exists for linux
- socrateslee 2y agoMay be the case is that filtering user by browser UA is no longer a feasible solution(new browsers and alike are growing), and neither running javascript(headless chrome everywhere). For local physical store, geo-location is a naturally filter for customers as long as beaming a person from a spaceship to earth is not invented. For web, a equally effective solution is very hard to find.
- anacrolix 2y agoCloudFlare has become the problem. It's high time users banded together in their best interests: no ads, tracking, blocking, geo restrictions etc.
- RockRobotRock 2y agoDoesn't work for me at all on Firefox. Disabled all the privacy preserving extensions and still nada. Fuck off Cloudflare.
- RockRobotRock 2y agothis turned out to be related to an extension I was using please disregard
- zoezoezoezoe 2y ago> So sick of Cloudflare A sentiment I cannot agree with more.
- Hold-And-Modify 2y agoAfter almost ten days of deafening silence and broken Internet access, I guess we have to paraphrase Adam Martinetti, the Cloudflare Product Manager from 2022 and conclude that in 2025: Cloudflare DOES want to be in the business of saying one browser is more legitimate than another.
- doctor_radium 2y agoIn the past a Cloudflare representative typically appears in these threads, and if that's happened, I missed it. Not to mention the MVP's comment in the locked Cloudflare thread that "You should use an up to date major browser. Old Firefox forks are not supported and expected to have problems." It's all incredibly telling, that they've given up trying to be impartial. When "they" start picking browser winners and losers, are OS's next? In a way Cloudflare missed an opportunity, because a try()/catch() around the bit of failing JavaScript would have been perfect fingerprinting. Having said that, I don't expect it will take the Pale Moon team very long to patch the problem. But where to go from here? Is there anybody besides the ACLU and EFF with enough resources to mount a "public nuisance" lawsuit? And what would constitute winning? A court-appointed overseer to make sure Cloudflare is regularly educating its staff on the variety of browsers in use today, and providing near 24–hour turnaround times when issues like this occur? It would be a start. Personally I wonder if this whole style of security is a fool's errand and any blocking should be server-based and look at behavior, not at arbitrary support of this or that feature. I think it would also be helpful if anybody who finds themselves blocked would be given at least a sliver of why they were blocked, so they could try rectifying the problem with their ISP (bad IP), some blocklist, etc.
- samedev 2y agoIs there any cloudflare alternatives?
- r3db34rd 2y ago[dead]
- redder23 2y ago[dead]