frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Is Cloudflair Reasonable?

3•coderatlarge•8mo ago
as someone who has to live behind a great firewall, I find myself using Expressvpn and other VPN products by necessity - as a result I end up staring at cloudflair pages much more often than I would expect. i can’t help but feel that cloudflair is making vpn users’ lives miserable for their own gain. is there any evidence either way?

Comments

Bender•8mo ago
I believe this is a losing battle. Miscreants hide behind VPNs to abuse sites. Many sites are behind CF. CF must then find a balance between anti-bot and not harming legit users. Such a balance does not really exist and that results in the phrase, "And this is why we can not have nice things..."

To answer your question I suppose they are as reasonable as they can get considering many sites can use CF free accounts and people can choose whether or not to enable the anti-bot capabilities. The alternative would be for more sites to build their own anti-bot measures but that can get expensive very fast. I do not see how they would gain by blocking VPN users unless one could pay to get around the anti-bot measures which would defeat the purpose of blocking bots in the first place as some botters would pay-to-play using stolen credit cards.

Another alternative would be for sites to find a way to create a group of "trusted users" and provide said users a way to bypass CF. i.e. each site having their own paid VPN gateway or the trusted users put up a paid bond to access a dynamically scaled HAProxy Anycast mesh. However by paying using a traceable source that defeats the purpose of a VPN and so I return to the phrase, "And this is why we can not have nice things". Short of finding all the miscreants and dropping them into an ancient style Roman Colosseum Pay-Per-View Gladiator Tournament with no rules this problem will likely always exist.

coderatlarge•8mo ago
thank you for the context. It feels like in the last year or two the focus on Geo detection and Geo blocking has grown substantially. For example, many websites seem like they won’t take any traffic at all from certain countries. and they will go to some lengths to try to detect the source country of the connection even when a VPN is in the path. I don’t really know how they do this, but it’s evident from various language features in browsers that get triggered.
Bender•8mo ago
I don’t really know how they do this, but it’s evident from various language features in browsers that get triggered

One clue comes from accept-language. If a person sets the primary language to en-US or en-GB they might also have additional languages that were automatically set based on their OS preferences. Another clue comes from cookies. Many sites use CF so there will be session cookies from CF that were set by other sites but are shared by their insight domain and others and this is even before we talk about javascript. To use sites that use CF usually requires enabling javascript and that gives mountains of data away. There are others here that know much more about this than I.

coderatlarge•8mo ago
thanks for the note. i don’t speak the local language so maybe it’s gotten enabled in some indirect way. and js there isn’t much anyone can do about it seems when interacting with a “modern” web page.

i have this day-dream that i’ll learn enough about linux networking to setup one of my boxes as a filter for all my traffic and properly encrypt and observe and properly filter out stray traffic that may be giving me away, but that’s probably a fool’s errand too on some level. also i suspect macos leaks info in various hard to secure ways.

Show HN: Verifiable server roundtrip demo for a decision interruption system

https://github.com/veeduzyl-hue/decision-assistant-roundtrip-demo
1•veeduzyl•42s ago•0 comments

Impl Rust – Avro IDL Tool in Rust via Antlr

https://www.youtube.com/watch?v=vmKvw73V394
1•todsacerdoti•46s ago•0 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
1•vinhnx•1m ago•0 comments

minikeyvalue

https://github.com/commaai/minikeyvalue/tree/prod
2•tosh•6m ago•0 comments

Neomacs: GPU-accelerated Emacs with inline video, WebKit, and terminal via wgpu

https://github.com/eval-exec/neomacs
1•evalexec•11m ago•0 comments

Show HN: Moli P2P – An ephemeral, serverless image gallery (Rust and WebRTC)

https://moli-green.is/
2•ShinyaKoyano•15m ago•1 comments

How I grow my X presence?

https://www.reddit.com/r/GrowthHacking/s/UEc8pAl61b
2•m00dy•16m ago•0 comments

What's the cost of the most expensive Super Bowl ad slot?

https://ballparkguess.com/?id=5b98b1d3-5887-47b9-8a92-43be2ced674b
1•bkls•17m ago•0 comments

What if you just did a startup instead?

https://alexaraki.substack.com/p/what-if-you-just-did-a-startup
3•okaywriting•24m ago•0 comments

Hacking up your own shell completion (2020)

https://www.feltrac.co/environment/2020/01/18/build-your-own-shell-completion.html
2•todsacerdoti•26m ago•0 comments

Show HN: Gorse 0.5 – Open-source recommender system with visual workflow editor

https://github.com/gorse-io/gorse
1•zhenghaoz•27m ago•0 comments

GLM-OCR: Accurate × Fast × Comprehensive

https://github.com/zai-org/GLM-OCR
1•ms7892•28m ago•0 comments

Local Agent Bench: Test 11 small LLMs on tool-calling judgment, on CPU, no GPU

https://github.com/MikeVeerman/tool-calling-benchmark
1•MikeVeerman•29m ago•0 comments

Show HN: AboutMyProject – A public log for developer proof-of-work

https://aboutmyproject.com/
1•Raiplus•29m ago•0 comments

Expertise, AI and Work of Future [video]

https://www.youtube.com/watch?v=wsxWl9iT1XU
1•indiantinker•30m ago•0 comments

So Long to Cheap Books You Could Fit in Your Pocket

https://www.nytimes.com/2026/02/06/books/mass-market-paperback-books.html
3•pseudolus•30m ago•1 comments

PID Controller

https://en.wikipedia.org/wiki/Proportional%E2%80%93integral%E2%80%93derivative_controller
1•tosh•34m ago•0 comments

SpaceX Rocket Generates 100GW of Power, or 20% of US Electricity

https://twitter.com/AlecStapp/status/2019932764515234159
2•bkls•34m ago•0 comments

Kubernetes MCP Server

https://github.com/yindia/rootcause
1•yindia•35m ago•0 comments

I Built a Movie Recommendation Agent to Solve Movie Nights with My Wife

https://rokn.io/posts/building-movie-recommendation-agent
4•roknovosel•35m ago•0 comments

What were the first animals? The fierce sponge–jelly battle that just won't end

https://www.nature.com/articles/d41586-026-00238-z
2•beardyw•44m ago•0 comments

Sidestepping Evaluation Awareness and Anticipating Misalignment

https://alignment.openai.com/prod-evals/
1•taubek•44m ago•0 comments

OldMapsOnline

https://www.oldmapsonline.org/en
2•surprisetalk•46m ago•0 comments

What It's Like to Be a Worm

https://www.asimov.press/p/sentience
2•surprisetalk•46m ago•0 comments

Don't go to physics grad school and other cautionary tales

https://scottlocklin.wordpress.com/2025/12/19/dont-go-to-physics-grad-school-and-other-cautionary...
2•surprisetalk•46m ago•0 comments

Lawyer sets new standard for abuse of AI; judge tosses case

https://arstechnica.com/tech-policy/2026/02/randomly-quoting-ray-bradbury-did-not-save-lawyer-fro...
5•pseudolus•47m ago•0 comments

AI anxiety batters software execs, costing them combined $62B: report

https://nypost.com/2026/02/04/business/ai-anxiety-batters-software-execs-costing-them-62b-report/
1•1vuio0pswjnm7•47m ago•0 comments

Bogus Pipeline

https://en.wikipedia.org/wiki/Bogus_pipeline
1•doener•48m ago•0 comments

Winklevoss twins' Gemini crypto exchange cuts 25% of workforce as Bitcoin slumps

https://nypost.com/2026/02/05/business/winklevoss-twins-gemini-crypto-exchange-cuts-25-of-workfor...
2•1vuio0pswjnm7•49m ago•0 comments

How AI Is Reshaping Human Reasoning and the Rise of Cognitive Surrender

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6097646
3•obscurette•49m ago•0 comments