← Back to context

Comment by csomar

1 year ago

As a user that gets the Cloudflare thingy, unless it is a website that I really need, I just close the tab as soon as I their captacha starts the loading stuff. If the site admin/masters do not care about the end user, I do not care about their site either. Users should vote with their feet (or clicks?).

If it is a site you use a lot (which is happening more and more) it's important to make sure the site owner is aware of the problem. I usually do this by email. Then they can ask cloudflare to fix it and get rebuffed and sour their opinion of cloudflare as they start having to maintain long UA-string whitelists.

Show site owners cloudflare isn't doing the job they are paid to do.

We care, we just can't spend the resources self-hosting business critical infrastructure. It'll break, get AI-DoSed, or will have an expired cert. It's a boring and risky problem to solve. Cloudflare provides a really good service for basically free.

  • > It'll break

    If you add additional piece to chain, chain becomes weaker, not stronger

    > get AI-DoSed

    Thats not that common. There are specific industries prone to DDoS, like gaming, but your average site don't get DDoS-ed. Then again CF free service really don't protect your site from DDoS. I have seen several times CF becoming source of DoS (not caching or denying malicious requests) and if back-end is on shared infra, CF goes to firewall.

    > will have an expired cert.

    Your back-end still needs certificate

Blocking bots can improve the user experience of the end users.

  • Designing a site to not be affected by bots is fixing the problem. Blocking things that are bot-like, poorly, with no technical understanding, is a kludge, not a fix.

    • > with no technical understanding

      WTF?

      Building a WAF that has zero false positives and zero false negatives is impossible. All we can ask is that the companies that build WAFs be responsive, but they also need accurate bug reports with sufficient information to identify the variable.

      3 replies →

    • > Blocking things that are bot-like, poorly, with no technical understanding, is a kludge, not a fix.

      a kludge might be better than none. And it's an easy kludge (for the site owner - a checkbox in cloudflare).

      The fault lies with cloudflare implementing a lazy bot detector.

  • Except the Cloudflare firewall is just so goddamn dumb. It considers all of Asia a "bot", anybody who uses Linux or has a tracker blocker. I've had this complaint from several regular people who don't even have an adblocker.

  • I just put my content behind a paywall. If the bots want to pay $50/mo I guess I don't mind. No cloudflare!