‹ BackHN Continuity

Thread

Cloudflare OHTTP gateway

203 points · 95 comments · est

  1. Joker_vD · · focus · HN ↗
    Hm. Interesting. I wonder how you would add "banning abusers by IP" functionality to it though — you first need to identify the abuse somehow and then link it to the originating IP (or any other kind of identifier)...
    1. someonebaggy · · focus · HN ↗
      You already can't do that since the abuser will just buy residential proxies.
      1. lgeek · · focus · HN ↗
        Cloudflare Warp has been more of an issue for a small webapp I run than residential proxies. Because it's a mix of legitimate users whom I guess installed the 1.1.1.1 app and have no idea they're tunnelling all their traffic through Cloudflare, and abusive users. I've never seen an actual CGNAT IP addresses from a consumer ISPs being shared by a legitimate user and a persistent abusive one.

        CF seems to end up in the business of making problems worse, and selling the fix way too often. Before this, I had someone try to DDoS a webapp by setting up their own domain to proxy to my backend and running their attack traffic through CF. But that was easy, I could just block CF's IP range entirely as I don't use their reverse proxies.

        1. jasomill · · focus · HN ↗
          Isn't the point of residential proxies to spread traffic accross a large number of IPs to avoid "persistent abusive" traffic from any single address or subnet?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.