zlacker

Tell HN: Cloudflare is locking out Linux users

submitted by supriy+(OP) on 2023-06-05 15:15:40 | 76 points 21 comments
[source] [go to bottom]

It appears that Cloudflare's Turnstile captcha product has decided Linux users are no longer considered "human" and therefore locked out of websites using this product.

While the usual explanation is that there may be a compromised device on the network, I can pass these challenges myself using my Mac, but not on Linux on the very same network. This is from a residential ISP in India, and as you can see in the screen recording, I'm using an incognito window with all extensions disabled, so it's unlikely that the IP address or the browser configuration are at fault here.

* Mac: https://drive.google.com/file/d/1glfS_9OkV5mw5ysU3ASZCwR5c5eCeRT3/view?usp=sharing

* Linux: https://drive.google.com/file/d/1WnNRUlikqfmqdELfcohu7SBfjJr9aNzZ/view?usp=sharing

At a societal level, it is scary how things seem to resemble RMS' "Right To Read" with one corporation deciding to unilaterally deciding what browser should have access, as I've said elsewhere.

At a technical level, I speculate the issues are because Cloudflare is unable to properly distinguish between headless and regular Chrome because of changes in Chromium[1] as well as because of TLS ClientHello permutations[2].

[1] https://antoinevastel.com/bot%20detection/2023/02/19/new-headless-chrome.html

[2] https://www.fastly.com/blog/a-first-look-at-chromes-tls-clienthello-permutation-in-the-wild


NOTE: showing posts with links only show all posts
2. wmf+Xa[view] [source] 2023-06-05 15:50:28
>>supriy+(OP)
Linux users basically have to install Privacy Pass. https://developers.cloudflare.com/support/firewall/settings/...
9. freerk+Mc[view] [source] 2023-06-05 15:55:56
>>supriy+(OP)
The captcha on https://app.ahrefs.com/user/forgot-password from your video works fine for me with both Firefox and Chrome on Ubuntu. Do you use any fancy JavaScript blocking plugins?
◧◩
16. supriy+4l[view] [source] [discussion] 2023-06-05 16:26:17
>>woreng+Ca
It seems like someone flagged the topic so I didn't notice your response earlier, but I must say that care should be taken to not flag legitimate users as bots.

Regardless, it's very hit and miss, I got the infinite spinning circle once, followed by a failure next, and then a success.

https://drive.google.com/file/d/1YZARkZ9Dp7xiwVx5hGbN-4ilq5q...

https://drive.google.com/file/d/1HD52R69QT4vvtWSuCLVT1o2gEea...

I tried capturing a HAR but it's returning success now -- if this is fixed, thank you for your efforts.

[go to top]