Cloudflare is fine with Chromium from the same residential IP address, however, but I don't want to use Chromium for those Web sites.
I also don't want to have to try to debug the obnoxious behavior of some third-party company that perhaps doesn't care whether it's blocking legit users from its customers.
The Kafkaesque Cloudflare "prove you're a human" infinite loop is hopefully not a foreshadowing of an imminent Internet dystopia, with Cloudflare the vanguard of it.
Every site you put behind Cloudflare contributes to the future where they have the singular ability to decide what networks can connect to others.
Except for the fact that you can disable Cloudflare on your site anytime you choose.
Totally frustrating that Cloudflare is basically the Internet's biggest gatekeeper with a mysterious black box behind it that punishes legitimate users.
> The Kafkaesque Cloudflare "prove you're a human" infinite loop is hopefully not a foreshadowing of an imminent Internet dystopia, with Cloudflare the vanguard of it.
The "prove you're a human" glitch, should be a really obvious fix, that lots of users have continuously complained about for a while. You would think that once proven human, that means access to the site. Somehow, Cloudflare has shown no interest in fixing it. In fact, they appear to have more interest in destroying user privacy and protections, using access to a site as the carrot. A lot of the webmasters seem to be getting overzealous or don't have a clear understanding of how they affect users. Cloudflare appears to not be helping, but rather pushing tools and settings to promote sales, so we get user nightmares like "prove you're a human" infinity glitches.
You might be interested in a plugin to toggle the fingerprint protection: https://addons.mozilla.org/de/firefox/addon/toggle-resist-fi...
> Apparently, that’s not the case for IPFS.
But it’s also not the same situation at all.
With DNS, blocking would mean making the whole site unavailable.
With their IPFS gateway they are just filtering individual items.
For IPFS vs CDN, I'm guessing relevant copyright laws give a service provider an out when it's a well-defined user/customer doing the copyright-related redistribution; no such agreement exists for content on IPFS.
EDIT: Trying to read the relevant DMCA sections and precedent makes me happy I'm not a lawyer. Cloudflare was previously sued for copyright infringement (Mon Cheri Bridals, LLC v. Cloudflare, Inc.) and found not guilty. In Cloudflare's own blog about the decision, they said the suit was meritless for several reasons including "our services are not even necessary for the content’s availability online." My guess is there is sufficient ambiguity over whether operating a inter-protocol gateway puts them at increased legal liability.
The site is still available, just not through its DNS entry.
> With their IPFS gateway they are just filtering individual items.
They can filter as broadly or as targeted as they want.
A public list of what their gateway will not retrieve for you would fuel the Streisand effect...
hxxps://libgen.is/dbdumps/
There is actually a conference of ipfs devs and users in Brussels going on (or held not long ago). https://2023.ipfs-thing.io/
Insofar as I understand IPFS, the most natural use case I've come across would be serving Nix packages.
That is, my understanding of IPFS is "protocols related to distributing content based on its content". Nix stores all its packages in a nix store, where its address there is a hash of the inputs; but, there are experiments for addressing Nix packages by the package's contents.
https://www.tweag.io/blog/2020-09-10-nix-cas/
On the Nix side of things: a cache-miss from a binary cache would just mean that a package would need to be built from source.
Speaking of which, is Freenet still alive?
I can't afford to serve the 98% that is bots. That's about 10 search requests per second, most of them are search queries aimed at poisoning the query log of my search engine, which doesn't exist. But I think they're just scraping for opensearchdescription definitions and spamming every endpoint they can find in the hopes it's wired up to Google or Bing.
Cloudflare are the only ones that seem to offer some sort of (affordable) mitigation against this. They're hiding behind a botnet so rate limiting and ASN/IP blocking does all of bupkis.
The other option is to shut down my website. I believe that world is a worse world than one where stuff gets routed through Cloudflare, although I'm fully aware that this is far from ideal.
What I do to help those who want to avoid cloudflare is offer API access, which means I give you a token so I can rate limit you. Also means less anonymous of course, but it's at least free from men in the middle.
With TLS it’s arbitrarily easy to overwhelm a target site that’s hosted on the smallest instance types at $provider due to the compute requirements of terminating TLS. Thankfully Cloudflare + LetsEncrypt makes it economical to host a personal site with good security without arbitrarily and suddenly high bills, constantly high bills, or my site arbitrarily disappearing off the web.
Bad actors poisoned the well (thanks China), and now here we are. I, for one, appreciate greatly what Cloudflare has done for the indieweb.
I can't host a website for my home internet without the risk of getting black holed.
Can't ask the website for my home internet because Comcast won't let me.
Providers will charge you out the ass for bandwidth if someone ddoses you.
The internet just isn't a sustainable place for self run websites now,
I know that Meta is doing its level best to wipe LLaMA's weights from the face of the Internet, but I also suspect (and cannot prove) that various organs of the US state (CIA, NSA, FBI) are also trying.
If they're not, I'm even more afraid, because one of their most important jobs is being alarmed so I don't have to be.
I'd wager a few dollars that Cloudflare had a visit.
And, as an aside, I'd say it's a matter of when, not if, a GPT-4-scale model is leaked, possibly GPT-4 itself. If not to the open Internet, then to China.
OpenAI is (for now) staffed by humans, and humans are vulnerable to seduction, spearphishing and spycraft.
IPFS is primarily used to store infringing content, yet few users directly interacted with IPFS. Instead, they usually rely on Cloudflare basically serving as a free proxy.
It's like the early days of mega or something, just with a layer of indirection that serves as plausible deniability.
Why Cloudflare bothers to provide this presumably costly service at all is confusing to me. I guess maybe they drank the crypto kool-aid and thought that it might some day be profitable?