So with cash, people can disagree on its benefits and drawbacks to society as a whole, but as long as it's legal, there's little reason for me, individually, to not use it, regardless of my opinion on its value to society. With IP addresses, I might conclude that I'm much better off blocking some even if I lament the consequences of this for causes that I approve of.
Really? What if it is counterfeit? What if it has some kind of poison, germ, or disease on it?
I get your general point I think, but cash can definitely harm you.
Still far from ideal, but it's not banning.
If you are blocking that cookie for privacy reasons (which is not a bad thing!), then cloudflare has no way to verify you again (short of doing nefarious things). It's a bit of a self inflicted problem at that point.
That's not to say that the answer is "deal with it", but that we need to find a better way. A a way to verify that someone isn't a bad actor without having them take a pretty significant chunk of their time to answer captchas, or give up some of their privacy.
It's a tough problem, and i think the "proof of work" solution proposed in the original could work, but it would need participation and collaboration from "both sides" of the problem. And of course it won't happen overnight.
It still isn't ideal for mobile or low-end clients, but its something.
Depending on the area you're in, when you pay with a $20 bill (the most commonly counterfeited), the cashier will mark the note with a pen before accepting it.
The business is simply profiling the transaction - a $20 cash bill brings with it a higher risk of fraud - and behaving accordingly. I can't think of a way to argue that it's unfair to the customer that the business does this.
An astute observer will point out that the captcha presented by CloudFlare is an order of magnitude (or two) less convenient than the counterfeit detection pens, but I would argue that this doesn't support a position that CloudFlare is wrong to do what they do.
1: https://en.wikipedia.org/wiki/Counterfeit_banknote_detection...
Cloudflare is doing something somewhat similar. If you are deemed "possibly a bad person" then you are asked to solve a captcha. If you want to give up some of your anonymity, you can keep the cookie they give you as a token to "prove" you are a good person.
If you don't want that though, there is nothing cloudflare can do to know you aren't a bad person.
It's much less than "heavy regulation", but i can easily see how it could be both a pain and a security issue for some.
This is a shitty problem for all involved with no good solutions...