Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm a product manager at Cloudflare. Thanks very much for posting this here.

This looks like a bug with our "Managed Challenge" security action that's causing the loop. This feature attempts to determine browser versus non-browser traffic and block non-browsers. The fact that the challenge is currently not working for Waterfox Classic and Pale Moon is not by intent, and we do not want to be in the business of saying one browser is more legitimate than another.

I see that the name of our Browser Integrity Check feature (which is not causing the block here) is drawing some attention. This is a feature that blocks malformed HTTP request headers, and user-agents commonly used by abusive bots (like user-agents with Java and Python in them). This is a pretty simple set of rules that also does not attempt to differentiate between browsers. Here's our KB article on the feature: https://support.cloudflare.com/hc/en-us/articles/200170086-U...

I'm sorry that this has caused a serious issue for quite a large number of users, and that we were not more reachable in our community forum. I'll provide a follow-up here when we have an update on the bug. Thank you again for taking the time to write this up!




Thank you very much for your response.

I'm sorry if my post came off as accusing Cloudflare of malice, it was never my intention. I was rather worried about negligence on supporting these older codebases, and I'm relieved to hear Cloudflare is on top of this bug.


No apologies necessary! It did not, and I appreciate you bringing it up.


Same issue in FF v56, which is old, but from which WF and PM share code. Please, keep a method for old browsers to pass Managed Challenge.


Genuine question, why would you still use firefox v56 in 2022? isn't that a massive security issue?


Because it’s last that runs on WindowsXP if I remember correctly.


Why would you use Windows XP on an Internet connected PC?


Hardware firewalls provide some protection against the kinds of threats XP faces. More to answer your question; I'm running the latest available versions of Windows 10. I sometimes use FF 56 for its consistency in behavior, XPI addon support (NoScript and uBlock still function), customizable UI, and for critical tasks (banking (affected by the Cloudflare problem)). I use FF 90+ for daily driving, and I despise it.


Because machine is connected but didn't use internet.

It's for accounting purposes only - making invoices. Probably for one month it's used for hour or two max.


How is Cloudflare DDOS protection in your internal networks that them not supporting that version of XP is a problem?


For me - isn't problem. Because as i said machine isn't used for browsing.

To be honest i have friend of mine that have small furniture manufacturing. They have CNC machine with Windows98.


it's only a security issue if you don't know what you're doing.


I am using firefox 52 , I can't upgrade to newer browser without upgrading the OS and the computer system. I can't afford to upgrade my system. I am totally not a bot and have been trying to visit a site getting stuck in the "checking your browser" loop, any chance Cloudflare can accomodate this older browser.


Don't know what you and your team did but the problem is resolved for me , I am able to visit the site that I got stuck at "checking your browser" loop previously. I thank anyone still support older browsers.


> we do not want to be in the business of saying one browser is more legitimate than another

This is essentially what you do by necessity when attempting to block bots through browser checks, as bots are just unmanned browsers. This is bound to keep happening, especially with regards to more obscure browsers few people report on.


this is your community forum

no but really, this is a good post, doesn't mean there aren't consequences


We are beginning to roll out a fix now to a small portion of traffic. I will update when the fix is 100% applied for all Cloudflare traffic.


Thanks, I've tried 2 web sites with Waterfox Classic and they redirection works OK now (it wasn't earlier today)


This fix is now live to all Cloudflare locations.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: