@cR0w @troyhunt @dangoodin @benjojo @Viss @matthew_d_green
Seriously, #ClownFlare are at best a #ValueRemoving #MITM and more often than not a #RogueISP who's business model is a #RacketeeringScheme that should not exist to begin with.
@0xF21D #ClownFlare is a #RogueISP and their #MITM-based approach eould've always allowed that.
@Viss #CloudFlare is a #RogueISP known to offer Services in #Russia and to #CyberCriminals...
#ClownFlare is also a #ValueRemoving #rentseeker who's core product / service is essentially a #Racketeering Scheme and should not exist as any competent hoster offers #DDoS protection free of charge...
Wow, GitLab's setup of Clownflare's "Are you a human?" widget is blocking Firefox on my work Mac today, nice work.
Really not happy with CloudFlare deciding what browser I can use for things. I'm really not a robot.
As is tradition, Chrome (well, Vivaldi in my case) works. It did get challenged *twice* though, which seems like overkill.
Oh hey, Cloudflare's bug-ridden fingerprinting captcha still fails in Firefox on EndeavourOS, I feel right at home.
I have a perverse urge to see if it works in @servo
@kotaro yes, and they circumvent #ClownFlare's "#DDoS Protection" and can only be stopped by literally blocking entire CIDR Netblocks if not complete ASNs.
Okay, obviously even #Cloudflare isn't able to interpret #DMARC policies and sends out bounce mails if someone hijacks your domain to send spam/malware.
@cr #ClownFlare on it's own is a shure way to identify #CyberCriminals and criminally incompetent people.
@kajer well, @mozillaofficial DESERVES the #hate and #heat for betraying #Firefox users!
According to this, I have Strong Bot Signals.
https://developers.cloudflare.com/turnstile/troubleshooting/challenge-solve-issues/
My strong bot-like behaviour is apparently running Firefox on OpenSUSE Linux? 'cause I've got all the same extensions in Vivaldi, and it's not a bot.
Or is it?
Why should I disable my extensions when you're the one who's broken? But I've tried this before, and it doesn't help.
Shoutout to @squidfunk for making Material for MkDocs which comes with a metric ton of #QualityOfLife improvements like being easily able to self-host all assets and thus comply with #privacy #laws whilst being as easy to setup as the regular #MkDocs.
LeetCode's got the broken Cloudflare, but their login process lets you hit "Sign in" while Cloudflare is sitting there spinning.
Task failed successfully.
@fluepke I literally cancel companies for using #ClownFlare to this day!
@sylv_a personally, I'd recommend #XMPP+#OMEMO (and #PGP/MIME - encrypted #eMail) for real #E2EE with #SelfCustody of Keys as well as actual #decentralization.
Cuz I noone's gonna risk jailtime for (non-paying!) users - it at all…
In fact I'd call U.S. MIL/INTEL as "criminally incompetent" if they didn't manage to plant multiple people inside @signalapp / #Signal or any other single-vendor / single-provider messenger.
Personally, solutions like Signal & #Threema have a stench like #CryptoAG / #MINERVA / #Rubikon and #ANØM / #OperationIronside / #OperationTrøjanShield.
By contrast: #OpenStandards like XMPP+OMEMO & PGP/MIME are independently verifyable and not dependent on on a single individual/organization for maintenance/survival/implementation/development.
Personally I'd still recommend @monocles / #monocles with #monoclesChat & #gajim...
@dee @agturcz Still, using #ClownFlare, which is a #RogueISP is a serious risk and it's up to @signalapp to actually not do that!
"[...] easy to use solutions that are at the same time private and secure. [...]"
It is easier, faster, cheaper and overall simpler to get someone setup with #XMPP + #OMEMO espechally if they don't have a #PhoneNumber and/or #ID to acquire a #SIM.
And if you go and say, "Just buy a [insert country here] [e]SIM!" and expect #TechIlliterates without a #CreditCard, #PayPal or other means of #OnlinePayment to fiddle around with some #eSIM if not having to get some #eSIMcard because they can only afford to maintain one SIM and can't spend triple-digits on a new devices then you completely missed the point!
It's not that I expect anyone to get #TechLiterate within minutes, but similar to setting up a cordless DECT phone it's something one has to do once in 5 years and just have them put the password in a safe spot to retain...
Point is that #Signal #WontFix their setup and that was evidently clear even before @Mer__edith succeeded #MoxieMarlinspike: Their entire operation has a distinct #CryptoAG stench as it's an #unsustainable #VCmoneyBurning party!
A counterexample on how this could've been done are #Tor, #eMail and other truly #OpenSource as in #MultiVendor & #MultiProvider standards.
NOTHING compells Signal to demand PII, run a #Shitcoin #Scam aka. #MobileCoin that even seasoned #TechLiterates and #CryptoBros can't setup properly, and in fact Signal using phone numbers makes it trivial to discriminate against users and easier for them to identify them!
If my reasoning didn't resonate with you, then try helping i.e. undocumented migrants aka. "#SansPapier|s" to get setup with it without violating laws and/or ToS and/or needing an imported SIM which I'm shure most folks don't have on hand!
Whereas it's trivial to get people setup on one of many XMPP servers I've personally tested!
AFAIK Signal doesn't even have an #OnionService / .onion
for their Website, much less any #API enpoints to use it with!
You're free to also provide evidence and supporting data to your arguments, rather then neighsaying against proven to be more secure and reliable [by virtue of decentralization] options like XMPP+OMEMO and/or #PGP/MIME.
The proper fix is to actually assess the situation and acknowledge the risks and limitations as well as the very nature of communications, which means upgrading later is exponentially more painful, thus getting people properly setup once is way easier.
Speaking of #monocles: That business is at least #sustainable because it's funded by users (€2 p.m.) which they can pay anonymously