Hacker News new | ask | show | jobs
by xist 1258 days ago
>JUST STOP MASS BLOCKING. You literally have no reason to. The only reason would be if you have an agenda to stop people from anonymously accessing information.

You are not entitled to access a website and the website doesn't know if you're a "good" or "bad" person automatically.

Put another way, if 9/10 of all phone calls/text messages sent to you are antagonistic at all hours of the day with NO filtering, would you accept that?

If so please post your unfiltered phone number that you will always answer, or your email address that has no spam filtering on it.

When most of the traffic on the internet is junk, some level of filtering is required.

How does a website determine if you're a "good" person, or a hacker who will destroy them otherwise?

2 comments

That's a lot of false logic and implicit assumptions there buddy.

Perhaps you want to take another go, only this time don't push a false narrative?

It was possible to reach sites without cloudflare before and view the content.

Now its primarily being used as a stopgap to block and de-anonymize people. The website doesn't need to determine if you are good or bad.

They simply need to manage their resources, and send the response to requests.

That is if they are actually in the business of providing something to someone like content or something else. Otherwise the business they are really talking about is data brokering and surveilling without really disclosing it, and that's another discussion completely.

Most of the traffic on the internet isn't junk, somewhere about 30% is protocol overhead, some small percentage is discarded during path and routing, and a large percent is the data people ask for.

There are tactics you can use as a website owner that target bad actors without blocking en-masse. Server side checks that characterize specific actors that are not related to IP or ASN. Those can then be easily targeted, and its not hard to set that kind of response up as an automated response.

> Not entitled

I'm saying what Cloudflare should do as reasonable engineers. It's not a question of entitlement. IP blocking is never valid aside from temporary DDoS mitigation. Eventually, those IPs will get reassigned or the attacker will get bored, and you have to stop blocking at that point or else you will just block legitimate users, since IP addresses do not represent individual people.

Your analogy is invalid. The captcha we're talking about here is not for filtering messages. To further nip this argument in the bud: Most sites that have a Cloudflare captcha to view anything at all will still require more captchas, email confirmation, and often phone confirmation before being able to sign up and post. Then this last idea that IP blocking stops hackers is just not even plausible (queue flood of posts arguing about the diminishing returns of repurposing firewalls/av/block lists for mitigation of low quality automated exploit attempts).