4 ms·
HIBP has been rendered unusable to people in 3rd world countries because of endless CF captcha loops. https://imgur.com/a/K5z1X2R https://imgur.com/a/K5z1X2R
by randunel 1y ago
HIBP has been rendered unusable to people in 3rd world countries because of endless CF captcha loops.
https://imgur.com/a/K5z1X2R https://imgur.com/a/K5z1X2R
- nottorp 1y agoYep, Cloudflare is a great service... for the US parts of the internet. The road to hell is paved with good intentions. Incidentally I first read the title as "I have been pwned by cloudflare workers and caching".
- weird-eye-issue 1y agoI live on the opposite side of the globe and have no problems using Cloudflare. Also, my SaaS is deployed on Cloudflare and we have users in hundreds of countries who use it with no problem
- randunel 1y ago> my SaaS is deployed on Cloudflare and we have users in hundreds of countries who use it with no problem How would you know you have a problem if you outright ban non-conformant users? Is your customer support function not behind cloudflare, and accessible to users without an account?
- weird-eye-issue 1y agoIn what way do we "outright ban non-conformant users"? You are making a lot of assumptions with that statement Our security level setting is low enough that almost nobody would actually get blocked from the site. Anybody could access the contact page and email us or use the live chat We use Turnstile in a couple of places and we have gotten a couple isolated reports about users being unable to perform actions behind Turnstile but it was always that they had some sketchy extension installed. And the extra security and bot protection we are getting makes those very low false positive rates worth it (we have tens of thousands of users so a couple reports in the last couple years is fine...)
- randunel 1y ago> In what way do we "outright ban non-conformant users"? You have literally replied to a thread in which we discuss how Cloudflare bans non-conformant users (who live in 3rd world countries, use linux and possibly other non-conformant computer practises according to Cloudflare's product managers). So you outright ban them by using Cloudflare. ----- You also literally contradict yourself with the following two statements: > I live on the opposite side of the globe and have no problems using Cloudflare. Also, my SaaS is deployed on Cloudflare and we have users in hundreds of countries who use it with no problem and > We use Turnstile in a couple of places and we have gotten a couple isolated reports about users being unable to perform actions behind Turnstile but it was always that they had some sketchy extension installed. And the extra security and bot protection we are getting makes those very low false positive rates worth it (we have tens of thousands of users so a couple reports in the last couple years is fine...) Make up your mind, which is it? Do you have no problems using Cloudflare and your users in hundreds of countries use it with no problem or not? ----- These being said, what percentage of lurkers actually contact random online services to let them know that something is wrong? Almost nobody does that. Personally, I've only contacted Troy Hunt on haveibeenpwned and his blogs, letting him know on several separate occasions that his websites are inaccessible to some users, as far as I could tell, from 3rd world countries. He has deleted all of my comments, he probably deletes all comments critical of his service, since there's only praise allowed in his blog posts. To be able to contact him, I had to borrow a Macbook and use a US vpn, because all of his services are behind enless Cloudflare captchas. How many website visitors of yours, not users, would be able or willing to do go to that length to contact you about your dysfunctional Cloudflare WAF?
- weird-eye-issue 1y agoThis has nothing to do with Cloudflare WAF. Like I said our security level is very low and the Turnstile handling is done in a Worker And I'm sorry if you think that 2 users in 2 years having an issue when we have tens of thousands of paying users tips the scale of whether or not it is an overall net benefit for our company. If it wasn't for Cloudflare we simply wouldn't be able to provide the free versions of the software in the same fashion that we do now It sounds like you're upset at somebody who improperly configured Cloudflare on their sites and now you are blaming the company and everybody that uses it without having a solid understanding of the tech
- nottorp 1y agoYou mean Australia/NZ? :)
- weird-eye-issue 1y agoNo
- huijzer 1y ago> Yep, Cloudflare is a great service... for the US parts of the internet. It's fine in Europe.
- nottorp 1y agoAlmost. I don't get captcha loops but they do get all worked up and captcha me once in a while, most likely because it's Firefox + uBlock Origin. On Mac OS, if I used desktop Linux I'd probably get more.
- Arnt 1y agoI use desktop linux and don't get many. Also, my work involves hearing about internet problems in parts of the third world, and captchas aren't something I hear about often, if at all.
- g-b-r 1y agoIt depends on the brower, settings, extensions, device etc. Definitely not fine.
- weird-eye-issue 1y agoI think there is much more to it than just your location. Based on the cursor and UI, are you using Linux on Firefox? I'm not saying it shouldn't be supported, but I just think that there's definitely more factors at play here than "3rd world countries" And depending on your definition of third-world country, I'm in one as well, and I don't have this sort of issue
- decremental 1y agoHN skews heavily towards users with very unusual setups. Using one of the least popular browsers on an OS almost no one in the grand scheme of things uses makes you a statistical outlier on its own. Who knows what other obscure configuration choices could be making the problem even worse for such a user? But yeah, it's none of that just Cloudflare hates brown people or something.
- zorked 1y agoThis is not just 3rd world countries. CloudFlare has broken the Internet and made it slower with all the stupid captchas. We were better off without them.
- sharperguy 1y agoIs it really cloudflare doing this or endless bot attacks making these kind of tools necessary?
- g-b-r 1y agoIt's Cloudflare not warning their costumers of how broken their products are.
- codelion 1y agoDo other services have the same problem? Like the https://amibreached.com/ https://amibreached.com/ ?
- tick_tock_tick 1y agoThe author of this article set those settings himself.
- huijzer 1y ago> HIBP has been rendered unusable to people in 3rd world countries because of endless CF captcha loops. I don't know what the situation currently is with HIBP, but Cloudflare does allow setting the security level. Maybe at the time it was still set to high/normal instead of "low" or "essentially off".
- mmsc 1y agoSo have most websites in the world. I recently found out report-uri.com uses Cloudflare turnstile which specifically blocks the type of activity that I imagine one would actually want from a CSP-violation. I like to write about these cases in my spare time, e.g.https://joshua.hu/losing-sight-vision-mission-of-your-role-part-3 https://joshua.hu/losing-sight-vision-mission-of-your-role-p... and https://joshua.hu/losing-sight-vision-mission-of-your-role-part-3-5 https://joshua.hu/losing-sight-vision-mission-of-your-role-p.... My all time favorite was when I was in hospital and couldn't connect to my travel insurance company's website because they blocked IP addresses from the country I was in (wasn't cloudflare though, I don't think: https://joshua.hu/losing-sight-vision-mission-of-your-role https://joshua.hu/losing-sight-vision-mission-of-your-role)