Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Cloudflare breaks CAPTCHA again for the 3rd time this year for nonmajor browsers (palemoon.org)
10 points by mimasama on July 10, 2024 | hide | past | favorite | 5 comments


Why does there always have to be a captcha? I see the proof-of-work system many deplatformed sites use, and it seems to be a much better solution for quenching bot activity than making the user perform a humiliation ritual or deny them simply because they use a certain browser.

It's true that big market players like Google tend towards monopoly in the browser market, but it's the shadow players like Cloudflare that enforce their unwritten rules.


I suspect the problem might be some people at Cloudflare writing code for the checks who are not aware of how to make it work for most browsers, and e.g. demand/expect some header behaviour that's only seen in a small number of browsers (say, Origin:, which has been involved in the past). So the issue would manifest itself no matter the kind of approach involved. At one point, the issue was even that such a header behaviour was requested in the fallback code intended for other browsers, causing a redirect to step zero and a DDoS against Cloudflare.

I haven't tried to debug the issue yet this time, and I'm not sure I want to, because that'd be the (at least) third time I'd get deep into the network inspector to try to compare headers and identify the issue in the middle of obfuscated and/or minified JS, and a chain of requests that are probably intended to defeat this kind of analysis (making it more difficult to identify what is causing the issue). If this was one occurrence every two years or so and Cloudflare were willing to help, and receptive to comments about it breaking in some configurations, the matter would be different (one of the times, their support kept dismissing reports as "unsupported!" and it might have been solved only because someone from Cloudflare saw it here on HN).

On top of that, I'm dealing with a hardware issue that means I don't have enough memory to do the debugging comfortably now...


Also see https://news.ycombinator.com/item?id=39705936 for a few links on this that I put here last time I saw this happening.


I see, thanks.


Honestly Cloudflare Turnstile is constantly breaking for me on Firefox, so it's not even just Palemoon and more uncommon browsers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: