It appears that Cloudflare's Turnstile captcha product has decided Linux users are no longer considered "human" and therefore locked out of websites using this product.
While the usual explanation is that there may be a compromised device on the network, I can pass these challenges myself using my Mac, but not on Linux on the very same network. This is from a residential ISP in India, and as you can see in the screen recording, I'm using an incognito window with all extensions disabled, so it's unlikely that the IP address or the browser configuration are at fault here.
* Mac: https://drive.google.com/file/d/1glfS_9OkV5mw5ysU3ASZCwR5c5eCeRT3/view?usp=sharing
* Linux: https://drive.google.com/file/d/1WnNRUlikqfmqdELfcohu7SBfjJr9aNzZ/view?usp=sharing
At a societal level, it is scary how things seem to resemble RMS' "Right To Read" with one corporation deciding to unilaterally deciding what browser should have access, as I've said elsewhere.
At a technical level, I speculate the issues are because Cloudflare is unable to properly distinguish between headless and regular Chrome because of changes in Chromium[1] as well as because of TLS ClientHello permutations[2].
[1] https://antoinevastel.com/bot%20detection/2023/02/19/new-headless-chrome.html
[2] https://www.fastly.com/blog/a-first-look-at-chromes-tls-clienthello-permutation-in-the-wild
I'm guessing it's some combination of being in India + Linux + incognito that is screwing you.
I can never pinpoint what makes these prompts and problems show up constantly for some but almost never for me.
Are you behind CGNAT by any chance? I have my suspicions that CGNAT networks are more likely to trigger these robot detection flags than others (because their users share an external IP address with many others). I can imagine a website/user with only IPv4 set up ending up getting grouped together with the countless automated Chromium installs that may also ruin your IP address' reputation with spam prevention tools.
They can never really know that you were there and change action. Just like they can never really know all those clicks are organic clicks for their ad-spend.
Its more of a we trust its this because we don't want to look behind the curtain. Unfortunately.
I'm pretty sure that prompt will hang indefinitely for user agents it doesn't recognize (because bot detection is almost impossible these days).
True, but that's the website's problem, not mine.
I figure that everyone using Cloudflare knows that they're excluding a portion of their audience by doing so, and they've made the calculation that they're OK with that. So if I'm in the excluded group, I assume that I'm one of the people they deemed as an acceptable loss.
Regardless, it's very hit and miss, I got the infinite spinning circle once, followed by a failure next, and then a success.
https://drive.google.com/file/d/1YZARkZ9Dp7xiwVx5hGbN-4ilq5q...
https://drive.google.com/file/d/1HD52R69QT4vvtWSuCLVT1o2gEea...
I tried capturing a HAR but it's returning success now -- if this is fixed, thank you for your efforts.
(Edit: I had a last paragraph here but it was in bad taste, so I removed it.)
And Install a plugin from Cloudflare ? I don't think so, who knows what it really does.