Hacker News new | ask | show | jobs
by hbrid 3697 days ago
Please turn JavaScript on and reload the page.

DDoS protection by CloudFlare

...um, no!

1 comments

I don't see why Cloudflare would require JS to be on
It's what they use to try and detect if your browser is a real browser, not a fake one. Which is very hard to determine without Javascript.
It looks like an important goal

Maybe they can do it better and not turn people without JS away (at least while accesses are at a regular level)

Something like hashcash?
To fingerprint the visitors.
EDIT: Why did someone flag this? This is literally what CloudFlare said they do – they fingerprint your browser, to track you, and find out if you are a bot DDoSing them – or if you have a normal browsing behaviour.

For that to work they need to fingerprint and track you. Which is why they said they block users with NoScript or on TOR.

Cloudflare surreptitiously injects its own Javascript into pages it serves, including NSA malware.
Something tells me Matt Prince would sooner shut down CF than bow to NSA demands.
If that were true, he wouldn't have built something so perfect for abuse.
What if shutting down was not an option?