Comment by csomar
1 year ago
As a user that gets the Cloudflare thingy, unless it is a website that I really need, I just close the tab as soon as I their captacha starts the loading stuff. If the site admin/masters do not care about the end user, I do not care about their site either. Users should vote with their feet (or clicks?).
If it is a site you use a lot (which is happening more and more) it's important to make sure the site owner is aware of the problem. I usually do this by email. Then they can ask cloudflare to fix it and get rebuffed and sour their opinion of cloudflare as they start having to maintain long UA-string whitelists.
Show site owners cloudflare isn't doing the job they are paid to do.
We care, we just can't spend the resources self-hosting business critical infrastructure. It'll break, get AI-DoSed, or will have an expired cert. It's a boring and risky problem to solve. Cloudflare provides a really good service for basically free.
> It'll break
If you add additional piece to chain, chain becomes weaker, not stronger
> get AI-DoSed
Thats not that common. There are specific industries prone to DDoS, like gaming, but your average site don't get DDoS-ed. Then again CF free service really don't protect your site from DDoS. I have seen several times CF becoming source of DoS (not caching or denying malicious requests) and if back-end is on shared infra, CF goes to firewall.
> will have an expired cert.
Your back-end still needs certificate
It's not free at all. You give them access to your unencrypted traffic and they give you protection from attacks they finance themselves. You're being ripped off
> attacks they finance themselves
Care to provide details or source?
1 reply →
Blocking bots can improve the user experience of the end users.
Designing a site to not be affected by bots is fixing the problem. Blocking things that are bot-like, poorly, with no technical understanding, is a kludge, not a fix.
That is not always possible, may not be affordable, or may degrade the overall user experience.
1 reply →
> with no technical understanding
WTF?
Building a WAF that has zero false positives and zero false negatives is impossible. All we can ask is that the companies that build WAFs be responsive, but they also need accurate bug reports with sufficient information to identify the variable.
3 replies →
> Blocking things that are bot-like, poorly, with no technical understanding, is a kludge, not a fix.
a kludge might be better than none. And it's an easy kludge (for the site owner - a checkbox in cloudflare).
The fault lies with cloudflare implementing a lazy bot detector.
And blocking users can make the user experience worse.
That's already been established. My point is that there exists a tradeoff. Blocking a small number of legitimate users can be worth the benefits blocking the bots.
1 reply →
Except the Cloudflare firewall is just so goddamn dumb. It considers all of Asia a "bot", anybody who uses Linux or has a tracker blocker. I've had this complaint from several regular people who don't even have an adblocker.
I just put my content behind a paywall. If the bots want to pay $50/mo I guess I don't mind. No cloudflare!