I personally simply close the tab when I see a cloudflare "one more step" page.
I personally simply close the tab when I see a cloudflare "one more step" page.
Unless you're an original ARPANET contributor, there have always been attempts to control access and stop attacks. You're making the same mistake every conservative does. Longing for a nostalgia that never existed.
That's not what they said at all. They complained about breaking the access to things that were already chosen to be public.
I’m not sure whether this is true, but it seems like with Firefox I get these captchas much more often than with Chrome. Sometimes they’re so difficult to solve it really takes a minute or two to do so, and it’s incredibly disturbing / an unfriendly interaction.
Surely there must be a better way to deal with this? Why do I have to keep proving again and again and again to Cloudflare I am, in fact, a person?
I actually agree with your overall point as I try to use Tor for a lot of "normal" browsing, but I'm not sure what the correct solution to accommodate both is. It's a hard problem, and having been in that position myself I have a hard time faulting small website operators who have no alternative defenses.
e: just to add to this, I see the existence of ddosing as a significant driver towards centralized monolithic services. If your blog on Palestinian rights or whatever is getting hit, that's an incentive to move it to a platform that takes care of networking for you. It's a little absurd to go all-in on decentralized self-hosting without at least an acknowledgement that with current tech and typical personal-computing budgets, doing so is giving a heckler's veto to literally everyone. Cloudflare isn't the only dimension things can be centralized along.
Do you pay a variable amount for your hosting? How and why? All VDS and dedicated server offerings I've ever seen are fixed amount per month. And more often than not the network is limited by speed, not by data transfer.
Mind you, I see your point and I generally don't like the captchas either, but it is definitely a trade-off and I won't blame webmasters that use the DDoS protection.
One bot that's just stuck on a loop or being overly aggressive is going to have one IP.
What does your cdn solution look like?
Route optimization from your (single) endpoint to clients literally half a world away?
> What does your cdn solution look like?
> Route optimization from your (single) endpoint to clients literally half a world away?
And as a developer, I don't understand this newfangled obsession over CDNs either. Yes, there will be 200 ms RTT in some cases. So what? Get over it. Optimize your website to load in fewer round-trips. TCP congestion control adapts well enough to any latency. RTT only really matters in gaming and VoIP.
Cloudflare prevents a bunch of crap that site operators just don't want to deal with. Especially for smaller sites that are run by one person. Dealing with a wordpress site getting hacked because you missed an update by a day, or a bulletin bored getting swarmed with bots, or some asshat ddos'ing your site because you banned them. Suddenly that site just isn't worth running.
Complaining that about a thing that prevents that headache because it's a minor inconvenience to you is so self centered it boggles the mind.
> Dealing with a wordpress site getting hacked because you missed an update by a day
Maybe don't use something this vulnerable then and rely on a third party to protect you from exploits.
> or a bulletin bored getting swarmed with bots
Maybe require email verification and/or a captcha when signing up or posting. Don't punish people for passive actions.
Somehow, there are many forums that aren't behind cloudflare, yet there are no spam bots.
> or some asshat ddos'ing your site because you banned them
Sure ddos is such an everyday occurrence?
I just don't understand. I run a personal website. There's literally nothing to "deal" with. I set it all up once and it works. I only have to pay for the server and for the domains on time.
You're definitely overestimating the technical expertise/available time of a lot small time admins out there.
You don't see bots and spam on those forums either because they are actually using cloudflare, and you're just not seeing the captcha, or because in the backend they're feeding all their posts through akismet (in plain text). I don't think you're considering how many services see your posts, even when you don't trip a captcha.
email accounts are trivial to sign up for, especially for bots. I always recommend charging $1 (or local equivalent) for an account, that's a lot harder to fake.
My point in all this is that bitching that site is using cloudflare to not have to deal with crap, is a self centered view.
Saying "well it never happened to me, so it must never happen" is similarly self absorbed.
Maybe consider that your experience is not everyones experience
Who is serving whom here?
If a business thinks it's ok to impose cloudflare inconvenience on me, the customer, for the priviledge of giving them my money, who is self centered here?
The simple answer is I'll close the tab and go buy it from a competitor. I'm not playing captcha games to buy something.
>I don't see any alternative services with this level of ease of use.
Both of these boil down to laziness, IMHO. And for how awful they are for half the internet, that's not okay to me. Not as a user or as a developer.
When a user requests a site they expect to get the site. When you utterly disregard their utterly reasonable expectation and force them to train someone's ML algorithm for free for a minute or two you utterly destroy the user experience.
If that's my experience as a user, your entire site gets an instant 1/10 rating from me. I'll likely leave instantly and never return.
I've see much worse times for users, and a cdn absolutely help with our staff in asia dealing with our internal apps.
Of course they're not always tripping up cloudflare and being shown captchas. I almost _never_ see a cloudflare captcha either... huh...
Because this implies that.
Page load speeds by themselves can be painful. Open devtools and have your browser throttle to poor 3g speeds.
Try browsing around. even well optimized sites.
Now try uploading a couple dozen files through an api.
This is legit what some users deal with. In New York state even, you don't need to go that far to find poor connectivity.
Even if all your users have awesome home connections, think sales people taveling to a client. or on site inspections of a manufacturer in a warehouse that's mostly metal and has bad wifi.
200ms latency isn't that bad, but I'm seeing more 800-2000ms latencies with some users depending on physical location. at some point latency kills usability. Especially when trying to get through a complicated QA or inventory process.
I thought you were giving an example of how bad connections can get, and saying that the extra latency would make it worse, but in that situation it's a drop in the bucket.
You're missing a zero in that RTT for users in places like Asia if your server is anywhere in the west. (It's actually somewhat revealing when someone throws out a number like this without any qualification; what exactly made you conclude 200ms is the magic number?)
> Optimize your website to load in fewer round-trips. TCP congestion control adapts well enough to any latency. RTT only really matters in gaming and VoIP.
You don't need a very big imagination to think about cases where RTT will have significant impacts e.g. in the event you need to issue multiple sequential requests that are dependent on one another. These are unavoidable and occur often in more than just websites, but anything that e.g. uses HTTP as an API (a very simple one is something like recursively downloading dependencies.)
This comes across as a classic "I don't actually understand the problem domain very well at all, but get off my lawn" answer to the problem.
Well, it does say 130 ms in here: https://www.quora.com/How-long-would-it-take-for-light-to-fl...
And that's around the planet, to go around and end up at the same spot. In practice, with sanely-configured routes, your packets should never need to traverse more than half that distance. So, divide it by 2, then that cancels out because RTT is a measure of how long it takes for a signal to travel back and forth. You then add some time on top of that to account for buffering and processing in the various equipment along the way.
> These are unavoidable and occur often in more than just websites, but anything that e.g. uses HTTP as an API (a very simple one is something like recursively downloading dependencies.)
If you mean REST API requests, the kind that trigger some code to dynamically generate a response, how would a CDN solution like cloudflare help? The request still needs to get to the server and the response still needs to come back, all the way, because that's where that code runs. CDNs only really work for cacheable static content, don't they? I mean it's in the name.
A blog or a news website certainly doesn't need a CDN.
And switching adds significant delay, especially when you get out to the edge.
> If you mean REST API requests, the kind that trigger some code to dynamically generate a response, how would a CDN solution like cloudflare help? The request still needs to get to the server and the response still needs to come back, all the way, because that's where that code runs. CDNs only really work for cacheable static content, don't they? I mean it's in the name.
For a simple example, imagine assets that are dynamically loaded based on feature detection in JS. All of the assets (js included) can be cached on the cdn.
If you have a fiber backed, all-switched network with no routing, buffers, congestions, or detours, you may get that value, if you're lucky.
Pinging tty.sdf.org which is a direct access shell service in USA from somewhere between Europe and Asia, from an academic network backbone roundtrips in ~190ms. I'm traversing a little less than half a globe with the whole journey. In your terms, it should be around ~60ms, but it's not.
> If you mean REST API requests, the kind that trigger some code to dynamically generate a response, how would a CDN solution like cloudflare help?
By using Cloudflare workers, so your code is also distributed around the globe?
> CDNs only really work for cacheable static content, don't they? I mean it's in the name.
JS files are also static content. Unless you don't use code distribution like Cloudflare workers, using a simple CDN can cache 90% of your site if not more. CSS, images, JS, HTML, you name it.
> A blog or a news website certainly doesn't need a CDN.
Actually, CDN is the most basic optimization for distributing heavy assets like videos and images, which news websites use way more than text. Why not use a CDN?
Actually I get around 200 from Russia which is also "somewhere between Europe and Asia":
round-trip min/avg/max/stddev = 196.504/197.581/199.833/1.360 ms
> By using Cloudflare workers, so your code is also distributed around the globe?Great, let's give that company even more control. That's sure gonna end well.
> CSS, images, JS, HTML, you name it.
It all gets loaded once and then cached in the browser. The initial load takes long regardless of whether there's a CDN. Oh, and many websites also use stuff from like 10 different domains, which doesn't help this either.
And, it doesn't matter whether a JS file loads in 50 ms or 300 ms, if it then takes 5 seconds to parse and start running.
> Actually, CDN is the most basic optimization for distributing heavy assets like videos and images, which news websites use way more than text. Why not use a CDN?
So put them on a separate domain and serve that from a CDN if you really care whether that stock photo no one notices loads in 500 ms instead of 2000. That doesn't explain much why anyone would put their main domain behind cloudflare.
We have enough evil companies who invade our lives through the platform develop. Cloudflare is not one of them. Using them is voluntary (by the service providers), and I think they're one of the more useful companies around.
BTW, I'm not a web developer or Cloudflare employee. I have no skin in this stuff, however they build some cool stuff inside the Linux kernel, which is interesting from my PoV.
> It all gets loaded once and then cached in the browser.
Then cleared and/or invalidated by the user or browser's logic itself due to plethora of reasons.
> The initial load takes long regardless of whether there's a CDN.
Actually, no. A reasonably fast internet connection (>12 Mbps we can say) can load a lot of things very very fast. The biggest overhead is DNS, even with CDNs. With a good local, network-wide DNSMasq installation, if the server is close, I can load big sites almost instantly.
> And, it doesn't matter whether a JS file loads in 50 ms or 300 ms, if it then takes 5 seconds to parse and start running.
I think 5 seconds is long time for even the old Netscape Navigator's JS parser. You need to run something akin skynet to parse the JS file for straight 5 seconds. How's that even possible?
> So put them on a separate domain and serve that from a CDN if you really care whether that stock photo no one notices loads in 500 ms instead of 2000.
I don't know you, but world news generally contains live/new footage or fresh photos from the ground, not some stock photos, also we humans are visual animals. Many people want to see the images first, read the text later.
> That doesn't explain much why anyone would put their main domain behind cloudflare.
Load balancing, DDoS protection, CDN, workers, Bot/Scraping protection, cost reduction, rate limiting, you name it. Even my DSL router implements some of the protections, to my surprise.
Internet is not the same beast now when compared to 90s/00s. I miss the simpler times, but alas.
For me, the highest was 310ms round trip to Singapore, so higher than your estimate but not too bad.
But this is completely beside the point. As far as I know, if you're using a CDN effectively (i.e. a large proportion of requests are hitting cache), it should be cheaper than having all requests hit your server, not more expensive. So even if you don't "need" a CDN, you might want one. This is orthogonal to the issue of bot traffic, which exists whether or not you use a CDN. If you want to use a CDN but don't mind the costs of bot traffic, you can configure CloudFlare to not show the CAPTCHAs, or use a different CDN.
AWS does offer a CDN, right? Somehow they do it without captchas and without me ever noticing. So I'm somewhat right at cursing at cloudflare because it's the only one actually announcing its presence by actively disrupting your browsing.
My old business had users in countries around the world, and the assets were highly optimised for speed. However adding CloudFlare (a) significantly sped up our service to clients, especially those in Asian countries, and (b) significantly improved reliability of connections because CloudFlare have their own dedicated network links between countries and/or optimised for reliability.
One of the things using cloudflare gets you is all those protections without having to know how to do them yourself. Which a lot of the developers don't know how to do.
There's also something to be said for catching a lot of this at the network layer on a cluster of machines that can handle any incoming traffic that your one poor neglected vm can't.
If worried about a ddos attack cloudflare or another provider might be a good choice. But adding ddos support by default seems unncessary. In my 20 years of running 100s of sites I haven't run into a situation where I need ddos support. The vast majority will never be the target. Once in awhile google or bing will ddos you but using cloudflare to block that seems like overkill.
We might weight those tradeoffs differently. That's ok.
For any of my pages that do happen to use Cloudflare, I am luckily able to disable this discrimination in the CP so kudos for that at least, but terrible defaults imo.
Those are the two I find repeatedly blocked when accessing via Tor. The former by Cloudflare, the latter by Google.
I use Tor to lookup phone numbers that have just called me, to decide whether it's a good idea to answer. Since I don't want to be personally associated with such numbers I prefer to search anonymously. But often it's impossible to get a result.
Sometimes even spending 5 minutes solving captchas isn't enough. (I'd only spend that long to see if it's just an outlier. No, it's quite common.)
This creates an immense pressure to tell various services exactly who is phoning me, which is a terrible attitude to privacy.
It's not your choice if the site owners/admins use cloudflare. It IS your choice not to use those sites.
There is no "don't use" if I want to get my task done.
I can choose not to obtain the information, but then I still have the problem I started with.
tor has some absolutely valid and import use cases, but what percent of tor exit traffic is actually someone trying to keep their traffic anonymous from the eyes of an oppressive regime, and what percent are script kiddies, or someone hiding torrenting from their isp?
Not sure what "bad actors hitting a page" even means. I host public info so people can see it, be it good or "bad" people. Let them see it.
DDoS is different and can be devastating of course. Also, very rare. In decades hosting content (started my first hosting business in 1994) I've never experienced anything remotely like a DDos. I know it happens, but definitely very rare for most people. Driving tons of legitimate users away with relentless captcha annoyances for the once in a liftime possibility of a DDoS is not a good tradeoff.
If you're in a business that attracts DDoS like flies then deal with that, otherwise lay off the captchas.
I would refrain from commenting on this topic then.
> I host public info so people can see it, be it good or "bad" people. Let them see it.
If your site ever gets big enough, you'll understand.