18 ms·
This is because Cloudflare is not happy with Firefox 'resist fingerprint' feature. Some related issues: - https://forum.gitlab.com/t/cant-open-the-signin-page
by imalerba 3y ago
This is because Cloudflare is not happy with Firefox 'resist fingerprint' feature.
Some related issues:
- https://forum.gitlab.com/t/cant-open-the-signin-page-it-keeps-showing-checking-your-browser-before-accessing-gitlab-com/45857/6 https://forum.gitlab.com/t/cant-open-the-signin-page-it-keep...
- https://gitlab.com/librewolf-community/browser/linux/-/issues/244 https://gitlab.com/librewolf-community/browser/linux/-/issue...
- https://github.com/arkenfox/user.js/issues/1253 https://github.com/arkenfox/user.js/issues/1253
- esaym 3y agoYes, I was going to mention something like this. I use a custom firefox cookie setting and get many sites that are broken. The sign that it is a security setting within firefox is the fact that chrome will work fine.
- soco 3y agoLucky me, I didn't find yet any site to regret if I just give up when I'm presented with the "verify you're human" garbage - which by the way you can get also on Windows Firefox from Google.
- statquontrarian 3y agoThe breadth of sites that have this is increasing. I've had problems from everything to a website that sells eggs to science journals to ChatGPT.
- thdc 3y agoThe most entertaining part of when I first ran into endless verification loop/Cloudflare error codes is that I couldn't access their official forums/support articles for information due to the same problems.
- statquontrarian 3y agoInteresting find but that's not the issue for me. about:config shows privacy.resistFingerprinting=false by default (maybe Fedora sets that default?). There were various sub-settings (privacy.resistFingerprinting.*), some of which default to true, so I explicitly set them to false, and refreshed, but that didn't help. I also changed layout.css.font-visibility.resistFingerprinting from 1 to 0. I also tried adding the domain I'm testing to privacy.resistFingerprinting.exemptedDomains and that didn't help.
- dijit 3y agoHad the same issue a long time ago, it was surprising how much of the internet was just "turned off": https://blog.dijit.sh/cloudflare-is-turning-off-the-internet-for-me https://blog.dijit.sh/cloudflare-is-turning-off-the-internet...
- lcnPylGDnU4H9OF 3y agoGot SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM when I went to the site and a redirect to https when I manually changed the protocol to http. I turned off https-only mode in Firefox so it appears to be a redirect that your server is sending back. When I change the protocol and get the redirect back to https there's another "/" which is added after the domain such that "domain/path" becomes "domain//path". This repeats if I continue to change the protocol and hit the redirect such that "domain//path" will become "domain///path" (I noticed this because there was like 6 of them). Apologies if this is indeed caused by my browser settings; I've been unable to find the cause if that's the case.
- dijit 3y agoThe slow march of progress I suppose, that machine is running OpenBSD6.0 which apparently is too old for modern ciphers, I had A+ a year ago on Qualys. I suppose I better update it now, sorry for the inconvenience.
- account42 3y agoIt is concerning how the recommended security practice is essentially planned obsolence.
- jeroenhd 3y agoThere's more to it than just anti-fingerprinting. There's also some other fingerprinting going on, and I think there may be some kind of IP reputation system that influences these prompts as well. I've put privacy protections up to max but never see Cloudflare prompts. I see them using some VPNs and using Tor, but that makes sense, because that's super close to the type of traffic that these filters were designed to block. I suspect people behind CGNAT and other such technologies may be flagged as bots because one of their peers is tainting their IP address' reputation, or maybe something else is going on on a network level (i.e. the ISP doesn't filter traffic properly and botnets are spoofing source IPs from within the ISPs network?).
- Ekaros 3y agoSome sites I have already visited keep popping them up. And I'm on public IP that should have been associated with my computer for a while... Maybe it is just per use case. Or they think I'm a bot as I keep looking at sites every couple hours... Which might be actually common with these sites.
- pixl97 3y agoEvery IPv6 thread we get someone saying "Oh v6 is worthless, we can stay on v4 forever, there are no downsides to CGNAT". I still have no idea how they can think that.
- jeroenhd 3y agoThose responses baffle me. I don't think most of those have ever been on the receiving end of anti-abuse features targeting shared IP addresses. I wonder if they're the same people who consider IPv4 a scarce resource that needs to be shared carefully. Try ten Google dorks for finding open Apache directory listings; your IP address gets reCAPTCHA prompts for every single search query for minutes. Share that IP address with thousands of people, and suddenly thousands of people get random Google/Cloudflare prompts.
- bragr 3y agoYeah, ever try to use Google through Tor? If you're lucky, it will let you do a captcha and get your result, but mostly it just says the IP is temporarily blocked for abuse.
- Tozen 3y agoThe purpose of CAPTCHA is supposedly to test if human or a bot, not to break or violate user privacy protections. It appears Cloudflare and others rather push the dangling of websites as "carrots", and see if they can get users to disable their ad blockers or any other privacy protections to get access. The Cloudflare verification has become a sick or sadistic joke now. It's often just used to annoy people, and no matter if they pass the tests, denies access anyway. If the test is not going to determine access, then don't provide it, and just wholesale be up front on mindlessly or frivolously blocking people and entire IP ranges.
- nine_k 3y agoThere's a natural contradiction between security and privacy. For security, an actor needs to be tested and marked as secure, or else tested again before every interaction. For privacy, an actor must not be marked, lest observers could correlate several interactions and make conclusions undesirable for the actor. It does not make the infinite loop produced by CLoudflare any more reasonable though.
- Brian_K_White 3y agoI disbelieve there is no way for a client to prove that it has been challenged and cleared in the past without disclosing a persistent unique identifier.
- davidmurdoch 3y agoI'm at a loss for how this could be implemented reliably (where it never fails to stop bots). Ideas?
- 3np 3y agoWhat do you see as the problem with this attempt? https://privacypass.github.io/ https://privacypass.github.io/
- 3y ago
- intelVISA 3y agoI wonder at what stage we can consider the damage Cloudflare is doing to the internet as naughty under anti-trust or similar?
- warrenm 3y ago> This is because Cloudflare is not happy with Firefox 'resist fingerprint' feature. "Cloudflare is not happy with anything that is not Cloudflare" ftfy :)