Modern Web Woes - I'm mad at the internet

Seems there is internet-wide "Cloudflare" outage, at least on my end.

Why the hell is so much of the 'net dependent on "Cloudflare" anyway?
Sure would be a shame if your little website got DDoSed off the Internet. You know, for a small fee we can take care of that for you.

Like the mob, but less honest.
 
Has anyone else seen those "verification loops" with "Cloudflare" bullshit?

Like it will do the automatic "verification" process, then repeat endlessly, without ever letting you access the site you want to see?
Yeah it means your browser isn't playing nice with whatever Cloudflare checks.
Seems there is internet-wide "Cloudflare" outage, at least on my end.

Why the hell is so much of the 'net dependent on "Cloudflare" anyway?
Because Cloudflare is evil
 
I AM NOT DOWNLOADING A GOOGLE MOBILE APP ON MY PHONE AND GIVING IT CAMERA ACCESS TO USE AF UCKING WEBSITE
This is horrifying.

Almost as horrifying is the rigamraole to log into an old account when you forgot the password and requires OTP codes and reset links. I had this happen over the weekend, and here is the approximate rundown:
> Goto site, realize I forgot the password.
> Click on forgot password.
> "We've emailed you a reset link on account 1."
> Go to log into account 1
> "We've send an OTP code to account #2."
> Log into account 2 and get the code to log into account 1.
> Log into account 1 to get the reset link.
> Reset password on original account.


Calgon take me away! *sigh*

Anything that isn't just mindless passive docile niggercattle behavior like scrolling Instagram on a mobile phone is just a hellish labryinth of Cloudflare turnstiles and reCAPTCHAs and select the ducks that are facing to the right of the beach balls or whatever the fuck that just barely works because people are too retarded to adopt things like ALTCHA and memory-hard challenges that have been around in concept for AS LONG AS THE INTERNET HAS EXISTED
I forget what mundane activity I was doing recently that required either a captcha of grainy images or an audio challenge to pass through the site. Apart for people using VPNs, there seems to be no rhyme or reason beyond when a captcha is or isn't required and it's frustrating to any end user dealing with this crap. Meanwhile, the nefarious activity this is supposed to stop continues without any sign of relenting.

They deregistered Gab's ASN for wrongthink. Why can't they deregister the ASNs that are sources of DDOS traffic?
From my past lurking on a network-related newsgroup, the TL; DR answer is that many of networks engaging in abusive tactics have their ASNs routed through providers that either don't care or facilitate their bad activities - or even engage in those bad activities themselves. ASN deregistration today is more politically motivated than it is the efforts to address legitimate acts of net abuse. This is where blocklists come into play as reps from many of these abusive providers would grovel on the newsgroup to be removed from the various blocklists only to be told by BOFH types to either boot their abusive clients from the network or FOAD.

The thing is the phishing mails are getting quite good. I had one at work that looked like a 100% legit Microsoft message.
It almost fooled me, until I double checked the email address.

Anything that can be exploited will be exploited.
Between AI and more sophisticated efforts, phishing emails are so convincing now to the unsuspecting it's scary, - especially when people instinctively react in panic and don't take time to double-check the situation.

I received an email claiming a domain name had expired. I found this odd because (1) The registrar normally sends several reminder emails within 30 days of the expiration date, and (2) A quick attempt to browse the site at that moment brought it up without issue. I eventually logged into the registrar's control panel and saw the domain wasn't expiring any time soon. I checked the email again and the embedded link went to an unfamiliar site that presumably stole victims' registrar credentials.

With how long the Internet has been around, you'd think we'd be teaching the kids at school Internet safety, like they did with stranger danger and drugs.
Sadly, today's kids have an attention span shorter than the life span of a fruit fly and they're more interested in fad trends. Even with internet safety lectures in the middle schools all around me, there's still news reports of teens engaging in internet behavior they shouldn't be and adults acting all Pikachu-faced surprised over it. It doesn't help that students are also conditioned to believe whatever they're told without question when "Trust but verify" is the minimum advice to follow when doing stuff on the internet.

Phishing emails continue to amuse me because they always come off as suspicious, my favorite ones spoof my own email address.
Not only that, but I like the spam and phish attempts that use the left hand part of the email address as the first word in the subject as if it's automatically the recipient's first name. That's one of my giveaways an email is likely not legitimate.

Like it will do the automatic "verification" process, then repeat endlessly, without ever letting you access the site you want to see?
I've had that happen at least once in the past year. Not sure if it's the result of VPN usage, too much site traffic, a random glitch, or some mix of all of the above.

Why the hell is so much of the 'net dependent on "Cloudflare" anyway?
Name/brand recognition most likely - especially if end users feel too intimidated to perform site security and DDOS mitigation on their own.
(Edited for spelling and clarity).
 
Última edición:
Fandom/Wikia is now working with Cloudflare and a few other companies to heavily push back against ad blocking. They are rolling out a system where if they detect any sort of ad or script blocking they disable the entire site. So you will need to whitelist everything on the site because if even one element will not load the site will respond by blacking out all scripts and visuals.

Has anyone else seen those "verification loops" with "Cloudflare" bullshit?
We've talked about this before. Every once in a while Cloudflare stops working on certain browsers or sites. This can last hours but sometimes it lasts for weeks. There was an issue with Firefox where Cloudflare didn't work properly for months and they took forever to fix the issue. Cloudflare has a near monopoly on DDOS protection and probably have as much control over the net infrastructure than Google and Chrome.
 
Fandom/Wikia is now working with Cloudflare and a few other companies to heavily push back against ad blocking.
It is amazing how they can keep coming up with endless new and innovative ways that were previously not even imagined to make the internet far more worse than it already is.

And of course that bullshit will likely spread to every site that runs on that "Cloudflare" bullshit. FFS.
 
Seems there is internet-wide "Cloudflare" outage, at least on my end.

Why the hell is so much of the 'net dependent on "Cloudflare" anyway?
it's not just cloudflare. It's also seen with AWS for the most part.
It both of them fails, then the net is completely fucked. Also not to mention the similar inversion circlejerk these companies have just like AI development.
 
It is amazing how they can keep coming up with endless new and innovative ways that were previously not even imagined to make the internet far more worse than it already is.

And of course that bullshit will likely spread to every site that runs on that "Cloudflare" bullshit. FFS.
It also doesn't work if you spoof your UserAgent, and occasionally have WASM disabled on any given site when it asks you to verify.
 
I haven't seen AWS yet (IIRC). How sucky is it?
You don't see it. Amazon Web Services is the big monopoly cloud host that everyone pretends is anything other than a gigantic, malevolent money sink. Sometimes it goes down and takes half the internet with it, because they're all hosted on aws or someone reselling aws.
 
Has anyone else seen those "verification loops" with "Cloudflare" bullshit?

Like it will do the automatic "verification" process, then repeat endlessly, without ever letting you access the site you want to see?
This started happening to me a lot after I started using browser extensions that spoof tracking/fingerprinting data. A lot of websites became inaccessible.

The solution: I don't visit those websites anymore.
 
This started happening to me a lot after I started using browser extensions that spoof tracking/fingerprinting data. A lot of websites became inaccessible.
It's actually extremely simple why. All you have to do is look at blogposts about it. They will literally tell you about it. They just mistake you for a bot because all bots do that.
For example, the user agent string provides some entropy but is trivial to override. In fact, changing it is often the first thing bot developers do, whether through Puppeteer, Playwright, or any HTTP client library.

In my opinion, it's much simpler to just seperate your activity into "official" and anon/pseudonymous. If you're visiting a website you want to be anonymous on, use anonymity-preserving means in doing so. If you're doing Chase Online Banking or X dot com there's no point in i.e. using a VPN, you're probably actively harming yourself rather because you're associating your name with the VPN address/privacy-enhanced-browser/whatever that you use for anonymous things. You can of course be worried about i.e. getting profiled based on your search history or whatever (i.e. reading articles from XYZ news outlet, watching ABC video on youtube etc) but realistically 99% of people are much more tracable through their credit card purchases that they literally sign with their name and address and then that data is sold to everyone, so while I agree in spirit, I'd say for 99.9999% of people there's bigger things to tackle.
 
This started happening to me a lot after I started using browser extensions that spoof tracking/fingerprinting data. A lot of websites became inaccessible.

The solution: I don't visit those websites anymore.
You can occasionally get around it by deleting cookies for the website. I've had said websites become inaccessible to me and I've narrowed it down to one of two scenarios that can happen to you: The Cloudflare verification box never appears which means Cloudflare is refusing to serve up the captcha to you and this happens when you spoof your UserAgent, or when the verification box gets stuck in an endless loop or you click on it and it just sends you back to another verification screen, which means you have to enable WASM on the website you're trying to verify for.
 
Atrás
Top Abajo