If you run with a lot of "identity fuzzers" (browsing through Tor, JavaScript off, cookies banned), Cloudflare can't build its trust heuristics and needs to challenge-response more often. I suspect there's overlap between HN readers and use of those sorts of tools, so I think there is a disproportionate number of people around here who run into this issue (whereas most "regular" folk almost never see a Cloudflare challenge / response).
(To be fair, consecutive requests don't get this treatment, just the one in which I jump there from eg. a search result.)
More importantly: no server is obligated to vend data until it falls over and dies, depriving all users access to that data if it isn't mirrored.
I think Cloudflare has honestly done an admirable job of coming up with a novel solution to the problem of loadbalancing and traffic-shedding in a world with a small-but-persistent percentage of hostile actors.
This is the era after the invention of Low Orbit Ion Cannon. Attacks that would previously have been technically sophisticated can now be done with a few GitHub downloads and either many volunteers or many compromised machines.
The wording "heuristic trust model [...] trust signals from the client", would not be out of place in the context of a sigint discussion.