←back to thread

1343 points Hold-And-Modify | 1 comments | | HN request time: 0.237s | source

Hello.

Cloudflare's Browser Intergrity Check/Verification/Challenge feature used by many websites, is denying access to users of non-mainstream browsers like Pale Moon.

Users reports began on January 31:

https://forum.palemoon.org/viewtopic.php?f=3&t=32045

This situation occurs at least once a year, and there is no easy way to contact Cloudflare. Their "Submit feedback" tool yields no results. A Cloudflare Community topic was flagged as "spam" by members of that community and was promptly locked with no real solution, and no official response from Cloudflare:

https://community.cloudflare.com/t/access-denied-to-pale-moo...

Partial list of other browsers that are being denied access:

Falkon, SeaMonkey, IceCat, Basilisk.

Hacker News 2022 post about the same issue, which brought attention and had Cloudflare quickly patching the issue:

https://news.ycombinator.com/item?id=31317886

A Cloudflare product manager declared back then: "...we do not want to be in the business of saying one browser is more legitimate than another."

As of now, there is no official response from Cloudflare. Internet access is still denied by their tool.

Show context
mattatobin ◴[] No.42957994[source]
Ok kids.. This is Tobin.. but without the Paradigm.

First off.. Gee I wish we had all come together about a decade ago or so and found solutions for what was plainly coming and spelled out by my self and others.

Second before it happens.. Pale Moon is not "old and insecure" It is being mismanaged had has no vision or prospects for future expansion.. It is just whatever XUL they can keep working while chugging away at the modern web features..

Pale Moon is often TOO security patched btw, which have been regularly disclosed and specially noted in the release notes since I convinced Moonchild he should do that for exactly the kind of old and insecure falsehood.

Moonchild's issue as a developer is he will always choose the seemingly simplest path of least resistance and will blindly merge patches without actually testing them. Many security patches are only security patches and not just.. patches because Mozilla redefined the level of security they want their codebase to provide.. But all known Mozilla vulnerabilities and many that would only become vulnerable if surrounding code is changed are patched.. Pale Moon and UXP has become more secure over time and that is an objective fact when you consider the nature of privileged access within a XUL platform which has its own safegaurds as well that persist into Firefox today though less encountered.

Now no one hates that furry bastard more than me (and I challenge you to try) but I will never call out good work as anything other than good work. Besides, there are a MILLION other plainly visible faults with the Pale Moon project and its personnel and my past behavior without having to make stuff up or perpetuate a false mantra like "old and insecure".

Finally, isn't Cloudflare being very unfair to every project save the modern firefox rebuilds listed on thereisonlyxul.org? Like SeaMonkey? Why does seamonkey deserve any hate from anyone.. or systematic discrimination.. What have they ever done but try and have an internet application suite.. Why are they old and insecure despite being patched and progressing a patch queue for Mozilla patches just landed selectively to preserve the bulk of XUL functionality its users adore?

In conclusion, what will be the final cost and how many will burn for trying to going against it.. I know my fate for trying.. how many will join me knowing that?

replies(1): >>42959864 #
Dalewyn ◴[] No.42959864[source]
For context, this is presumably the Tobin who caused significant tangible damage to the Pale Moon project on his way out.

https://forum.palemoon.org/viewtopic.php?t=28265

replies(2): >>42962464 #>>42962913 #
1. mattatobin ◴[] No.42962464[source]
Yeah except that's not the way it happened. My crimes are taking my ball and going home after being all but forced out for the second time just weeks after my father passed away from cancer and 2 months after I moved across the country.

It isn't like half the Pale Moon userbase ever wanted me there to begin with despite giving them not just an Add-ons Site and a developer wiki/doc site, the Pale Moon for Linux website, but a fully functional XUL platform that survives my involvement and a Pale Moon that is STILL Pale Moon when Moonchild as early as Pale Moon 27 was going to go the cyberfox route of Australis with CTR. So context of a decade of selfless unpaid work of 10-16 hour days every day, forum drama, bad decisions and behavior on my part in response to the response of my selfless work, and relentless attacks such as these no matter if I pop my head out or not?

If you want the full story of the end look it up on Kiwifarms (This was all before them being removed from clearnet so before the stuff you are thinking of) where I was maneuvered towards by 4chan anon people because that was the ONLY venue I had afterwards. For some reason they engaged then moved on.. Left me intact. I don't know why. But it is all there.. A cleaner version is codified in Interlink release notes on the internet archive. I encourage you to learn what actually happened and when and then make your judgement.. If you do that I will accept it even if I disagree with it because I disagree with a lot about my self these days.

Doesn't matter anyway. There are much larger issues now in the world than years old drama that still in the end.. Created the Unified XUL Platform (Take 2, the one that worked) and helps give hope to those otherwise subsumbed by the monoculture. Not that Pale Moon culture is much better but the fact it persists means more than one thing can. I can do better.. and so can we all.. Let's do that while we still can.

-nsITobin