Ask HN: Anyone else frustrated with “secure connection checks”?
Many sites seem to deploy cloudflare's bot check / secure connection check. And the thing outright does not seem to work with all browsers or setups. Web seems to slowly fall in to the "just use chrome" hole.
4 comments
Yes, it can be quite frustrating. On my search engine[0] I tag sites that use captcha services and browser checks so that the user has more transparency and can choose to avoid sites that use these services if they want.
[0] https://ichi.do
[0] https://ichi.do
The funniest thing I've seen recently, is government API services that have been put behind Cloudflare. Which means, you literally cannot access them without a browser. Let me reiterate, you cannot use machine-to-machine APIs without a browser.
Do they require an interactive oauth2 flow too?
I’m sure they will now that you suggested it :)
What bothers me is the mendacity.
No, you're not checking for a "secure connection". What you're doing is taking a fingerprint, to both deanonymize me and detect if I'm a bot.
No, you're not checking for a "secure connection". What you're doing is taking a fingerprint, to both deanonymize me and detect if I'm a bot.
What browser/OS are you using? What country are you in? Are you using Tor?
It can happen on both Windows and Mac, with both Chrome/Firefox. I've seen it happen in Western Europe just fine. No Tor.
You don't need to have some "exotic" setup to see this.
https://www.google.com/search?q=cloudflare+browser+check+ann...
You don't need to have some "exotic" setup to see this.
https://www.google.com/search?q=cloudflare+browser+check+ann...
Do you get a Cloudflare Ray ID on the page when you’re being asked? You can send that to the website admin and ask them to check for you.
Forgive the dumb question, but what can a friendly website admin do with the Ray ID you send them, that can help you as a user, assuming they put Cloudflare in the middle as a CAPTCHA in the first place for a reason unrelated to you, and still want/need it there?
They can look up why you were blocked, your ISP, your local POP, the page you were requesting and if it was because of a firewall rule they’ll see that too. Basically everything unique about your request.
So if they’re accidentally blocking people because a firewall rule is misconfigured you’ll let them know.
In a previous job we used Cloudflare and found some of our remote workers were triggering a SQL injection on the website by updating our WordPress blog.
So if they’re accidentally blocking people because a firewall rule is misconfigured you’ll let them know.
In a previous job we used Cloudflare and found some of our remote workers were triggering a SQL injection on the website by updating our WordPress blog.