Privacy Pass
support.cloudflare.com
support.cloudflare.com
For instance, for my mom, if instead of being subject to endless captchas due to privacy.resistFingerprinting [0], it might be okay to use Cloudflare's VPN/extension (esp since they promise to respect privacy), be able to resist fingerprinting, and not be subject to captchas. I see this as a better of two evils, since captchas aren't going away if you resist fingerprinting or use Tor, at least not anytime soon.
I'd like to think of this as OpenID-- even though it is bad privacy-wise (and single-point-of-failure security-wise), it was widely used for benefits to both the user and the service.
For me, though, the endless captchas are a price I'm willing to pay. YMMV.
[0] https://wiki.mozilla.org/Privacy/Privacy_Task_Force/firefox_...
Web service like Hacker News don't have any obligation to provide everyone equal access to their site. Cloudfare works for the web services. As a web service provider, you don't have, nor should you have, any obligation to provide equal access to anyone.
i disagree. Net neutrality to me also means that a site like HN should serve all customers coming to the site the same, and not discriminate against TOR users or VPN users, or users from a certain IP range, or users with different/non-standard user-agent headers.
I don't see how individual inserting his own meaning to well defined terms adds anything positive to the.
If you encounter term you don't understand, you look it up and don't try to make up your own definition. There is no disagreement of what the term means in a way you insist.
Actually this is the biggest reason I don't like Cloudflare. They are discriminating some second/third world countries and if you don't travel much and check websites you will never know.
Many websites owners are also not aware of this issue with Cloudflare. Discriminating traffic like this should at least be an optional opt-in in Cloudflare and not standard.
And because many website owners are just install and use Cloudflare with standard settings they don't care.
It's good that Cloudflare addresses this problem with their extension now but I had a little too much bad taste... this extension is long overdue and I still think it's not the best solution to the main problem (standard DNS settings too restricted).
If the like factories are using 3rd world IP's they are probably real human ( https://www.rt.com/viral/388169-smartphones-factory-generate... ) because bots can be run cheaper on a 1st world server because bandwidth, IP, and power usually cost less there. Captcha is an anti-bot measure and is not (or at least shouldn't be but I'm finding it hard to pass CF's captcha as human) very effective against actual humans.
I don't even think CF considers(or even aware of) the existence of a like factory on the same network for displaying the captcha and I am pretty sure they don't justify their captcha blocking with it. It's more likely that they just see a bunch of connections coming from the same IP and naively concludes that it must be a bot.
I'm sure it's easy to make "excuses"(vs justification) but given the real harm it does to actual human users and questionable effectiveness against the doubtful ill-effects of the existence of like factories against CF-hosted websites; I'd like to hear that "justification."
First world server IP ranges are treated just as poorly for this exact reason. Try browsing the web through a VPN/proxy on an OVH (French) server. I get captcha requests on Youtube videos and Google searches.
I mean, you could argue that it's not fair to discriminate entire countries because of the lax abuse policy of their ISPs, but the comment is correct: that's the reason those countries are discriminated against in this context.
When I was a sysadmin for a few admittedly-not-highly-popular websites, there were definitely more unwelcome bot traffic from US and EU IP's than there were from any 3rd world countries.
I also don't agree that social media "like-factories" should be a concern for Cloudflare at all. Even if they are truly a concern; social media "like-factories" are probably human-operated on third-world countries or bots that are likely running from developed world servers with access to cheaper bandwidth and IP's.
Browsing from a cafe, using VPN results in almost every attempt of following link from HackerNews in solving endless captchas. It is like being harrassed on the border control just because you have the wrong passport.
Saddly many of the sites "protected" by Cloudflare are interesting personal sites owned by honest people who had been scared about dangers of traffic from bad places.
Cloudflare is running internet protection racket Al Capone style.
Google does block people from accessing the audio challenge [1] in some cases, so make sure to check if you can access the audio challenge even before installing the extension by clicking on the headphone icon within the challenge widget.
Enable user input simulation from the extension's options and install the client app to reduce the chance of a temporary block while using the extension.
If you're on Chrome, there is a pending update (0.5.2) that switches to the Wit Speech API (demo) service by default, verify that you're using the correct service by visiting the extension's options to avoid any errors.
Please open an issue if you have experience with image recognition and you'd like to contribute towards a mode that would solve the visual challege, or assist users by suggesting image tiles to select.
They'll improve the captcha just like they did with the basic obscured text to now making the user do image recognition for them and people who really need the accessibility won't have it that easy any more.
I don't feel like that's a nice thing to do.
- This is not made by Cloudflare, Cloudflare is just the first to support it.
- This does not tie anything to your IP address, this introduces an alternative to tying things to your IP address.
- This does not implement more granular tracking IDs, it implements unlinkable one-time tokens.
- This does not further Tor user blocking/inconveniencing, they're who it was made for.
PrivacyPass is a third-party extension that allows a user to receive anonymous tokens that can't be tied back to them: https://privacypass.github.io/
CloudFlare supports that third-party extension so visitors can see fewer challenges.
I understand that they offer cheap solutions to very real problems, but we keep making the same mistake we made with Google and other tech giants. While they are acting in a commendable way now, I fear for how much influence they'll have when they will inevitably drop their "Don't be evil".
Also, did you see the permission list for a Firefox extension? [1] It says "Access your data for all websites".
[1] https://addons.mozilla.org/en-US/firefox/addon/privacy-pass/
In any case - privacy implications aside - having to install an extension to get around their risk assessment algorithm going wrong seems like placing the burden in very much the wrong place.
edit: was wrong about who created the extension
https://privacypass.github.io/
They run a service that shows high-risk visitors (or whom they deem high-risk) a challenge. They support a third-party extension that lets you vouch for yourself on other websites anonymously. The alternative is that they don't support it.
The other things they do are debatable, but this is a good thing.