To be a bit more nuanced, you can do anything with your property except that which requires permission or approval. NOT that you must get permission for anything you do with your property. The specifics can vary widely from locality to locality, obviously.
Painting a wall is something that usually doesn't require a permit. Maybe some restrictions if the building is a historic landmark or something like that.
Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.
It is very challenging to distinguish individuals interested in privacy from bots acting maliciously or with reckless indifference. If you devise a way to do this more effectively than Cloudflare, you should start a business to sell this as a service.
My employer is a small business that has an e-commerce website that is attacked by fraudsters trying to validate stolen credit cards or obtain customer information hundreds of times per day. Operations like CloudFlare are the only way to foil these actors. Just trusting you is not a viable strategy.
I had this problem too for all my clients e-commerce websites, then solved it 3 years ago with very little code changes.
Happy to share it with you. Using small businesses for credit card testing is one of the most evil things on the Internet, so anything to stop it is worth it.
Your rate limits on adding and removing credit cards? Your input sanitization? Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?
There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time.
t. Been there, done that, cartels used an app to try to launder money through loyalty programs. Management was deadset against doing the one single thing that would make it impossible to do that at scale.
Ulterior motives abound everywhere but especially behind people claiming X is the only answer. Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.
> Your rate limits on adding and removing credit cards?
All those requests will appear from different ip's and different browsers, made by someone who can spend months on trying to defraud you. How do you differentiate this from valid customer who happens to try to buy something between 20 tries by bots?
> Your input sanitization?
All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.
> Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?
They can register as normal buyers.
> It just requires thinking and a bit of dev time.
And they can spend months trying to outthink you, then will drain your service in 4 hours when you are asleep.
> Management was deadset against doing the one single thing that would make it impossible to do that at scale.
So, did you actually ever implemented and checked a good solution? Cloudflare isn't perfect, but not everyone has resources to implement their own solution that is better than cloudflare.
> Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.
The fraudsters will appear as completely new users each time, adding only one card and making one purchase.
> All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.
How are they getting pass 3D-S?
If they are able to get past it, then your liability drops off.
Yes it could be designed better, but that is a separate discussion.
It doesn’t matter that they can’t get past 3D-S, because the whole point of what they’re doing is checking what security features are enabled for a card, and whether their address and other validation data will pass. The fact that the scammers are testing so many cards that fail gets you banned from those payments providers, whether or not any payments go through. And this is ignoring all the attackers using bots for other purposes such as taking control of the website to obtain user or client data.
The technique is simple: don't publicly serve expensive (CPU/RAM-wise) pages. A simple blog like the linked article can be 100% cached and served to anyone without needing CloudFlare.
Performance optimization for website already is a business. It's just that product managers mostly don't care and optimize for other metrics (eyeball retention, SEO, etc).
Don't listen to these hecklers, you have every right to your privacy, and should demand it. Anonymity is paramount if people want to be able to talk without repercussions. Gaslighting, heckling and other forms of harassment are to convince you to self censor. Don't take the bait. Ignore them.
> Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.
Bots and scrapers and hackers also try and avoid being tracked, which is by far a bigger problem for them and most websites than the 15 of us using tons of antifingerprinting techniques. Evil? No, that's silly.
Hanlon's Razor is especially effective at getting Good people to put out their own eyes to keep them nice and soft targets for the malicious. I'll take being a harder to find likable by people I have no desire to be liked by to make myself a harder mark. The honest ones will understand. The malicious were never worth being close with, and I'm doing the world a service by getting the borderline enlightened.
Sufficiently advanced stupidity being indistinguishable from malice is also something to keep in mind.
From what I remember from my NASA friend, a few companies, hired a few fluid flow engineers, during the defense bust, and designed fan blades that remarkably increased air flow. ( think profiles like air plane wing ). Something happened and in a few years, there were good fans, and there were great fans.
I happen to own a pair of Noctura fans, and wow! They are great, so I would assume that some heavy lifting was done in fluid flow.
This sounds great. I would've loved to have set my phone to charge up to only 60% or 80% of its design capacity to reduce wear. I do this on my laptop.
It has been on iPhones for quite some while, but on androids even longer. Before that it was in the form of some smart charging scheme that it would only finish charging until the moment it thought you would unplug it.
Anecdata, but I did this on my iPhone, and it did absolutely nothing for battery longevity compared to charging to 100% with "optimized charging" (which keeps it at 80% for as long as possible when charging overnight).
Same for my s24, 80% battery limit and slow charging at night (most of my charging). It's been over 2 years and the battery seems to last just as long as day one
Dallas-Area Rapid Transit (DART) member cities all had to develop 25-year plans for denser development around station sites as a condition of their membership, if that’s what you mean by “natural”.
reply