←back to thread

1343 points Hold-And-Modify | 2 comments | | HN request time: 0s | source

Hello.

Cloudflare's Browser Intergrity Check/Verification/Challenge feature used by many websites, is denying access to users of non-mainstream browsers like Pale Moon.

Users reports began on January 31:

https://forum.palemoon.org/viewtopic.php?f=3&t=32045

This situation occurs at least once a year, and there is no easy way to contact Cloudflare. Their "Submit feedback" tool yields no results. A Cloudflare Community topic was flagged as "spam" by members of that community and was promptly locked with no real solution, and no official response from Cloudflare:

https://community.cloudflare.com/t/access-denied-to-pale-moo...

Partial list of other browsers that are being denied access:

Falkon, SeaMonkey, IceCat, Basilisk.

Hacker News 2022 post about the same issue, which brought attention and had Cloudflare quickly patching the issue:

https://news.ycombinator.com/item?id=31317886

A Cloudflare product manager declared back then: "...we do not want to be in the business of saying one browser is more legitimate than another."

As of now, there is no official response from Cloudflare. Internet access is still denied by their tool.

Show context
mattatobin ◴[] No.42957994[source]
Ok kids.. This is Tobin.. but without the Paradigm.

First off.. Gee I wish we had all come together about a decade ago or so and found solutions for what was plainly coming and spelled out by my self and others.

Second before it happens.. Pale Moon is not "old and insecure" It is being mismanaged had has no vision or prospects for future expansion.. It is just whatever XUL they can keep working while chugging away at the modern web features..

Pale Moon is often TOO security patched btw, which have been regularly disclosed and specially noted in the release notes since I convinced Moonchild he should do that for exactly the kind of old and insecure falsehood.

Moonchild's issue as a developer is he will always choose the seemingly simplest path of least resistance and will blindly merge patches without actually testing them. Many security patches are only security patches and not just.. patches because Mozilla redefined the level of security they want their codebase to provide.. But all known Mozilla vulnerabilities and many that would only become vulnerable if surrounding code is changed are patched.. Pale Moon and UXP has become more secure over time and that is an objective fact when you consider the nature of privileged access within a XUL platform which has its own safegaurds as well that persist into Firefox today though less encountered.

Now no one hates that furry bastard more than me (and I challenge you to try) but I will never call out good work as anything other than good work. Besides, there are a MILLION other plainly visible faults with the Pale Moon project and its personnel and my past behavior without having to make stuff up or perpetuate a false mantra like "old and insecure".

Finally, isn't Cloudflare being very unfair to every project save the modern firefox rebuilds listed on thereisonlyxul.org? Like SeaMonkey? Why does seamonkey deserve any hate from anyone.. or systematic discrimination.. What have they ever done but try and have an internet application suite.. Why are they old and insecure despite being patched and progressing a patch queue for Mozilla patches just landed selectively to preserve the bulk of XUL functionality its users adore?

In conclusion, what will be the final cost and how many will burn for trying to going against it.. I know my fate for trying.. how many will join me knowing that?

replies(1): >>42959864 #
Dalewyn ◴[] No.42959864[source]
For context, this is presumably the Tobin who caused significant tangible damage to the Pale Moon project on his way out.

https://forum.palemoon.org/viewtopic.php?t=28265

replies(2): >>42962464 #>>42962913 #
mattatobin ◴[] No.42962913[source]
For additional context it might be wise to include links that can't be edited by the author or webmaster.. While I didn't include links looking BinOC up on the IA isn't difficult to do and I am sure if you want to read the posts of events AS they happened you can look up the other thread.

This cited version is the revised version. Moonchild has revised his version of events multiple times in the nine months after. Pfft that isn't even the latest version lol. There are many now hidden threads on the Pale Moon forum that also showed events as they happened or as told when they happened.. All gone now.. Some of them contradict the later retellings.. I simply refer to events as they happened at the time and the Interlink release notes summery there of.

Can't wait to see if it changes anything...

replies(1): >>42964228 #
Dalewyn ◴[] No.42964228[source]
Honestly, I couldn't care less. It's one man shouting against another, it's pointless to try finding facts out of that.

But as a simple Pale Moon user, I can say you caused a big enough disruption to the project that even a user who doesn't really pay attention also noticed.

Now you're here again sidetracking the subject at hand with past dramallamas and seemingly getting your pantaloons moist at having stories besides your own also provided. No thanks.

replies(1): >>42966286 #
1. mattatobin ◴[] No.42966286[source]
You started this shit by bringing up the past dude. If this story is gonna rise to a broader appeal it would be fuckin bullshit for it to die because oh it's just Pale Moon and/or SeaMonkey.

Cloudflare staff have a real hateboner for non-mainstream browsers and tell yourself what you like but I still actually care about the well being of this unmitigated disaster we call the Internet and the "Open Web".. Not to mention the lives and well being of users and contributors out there in the world..

Go be small minded on the Pale Moon forum, I'm busy.

replies(1): >>42969638 #
2. Dalewyn ◴[] No.42969638[source]
You started it first, my dude:

>This is Tobin.. but without the Paradigm.

>Now no one hates that furry bastard more than me (and I challenge you to try)

>I know my fate for trying.. how many will join me knowing that?