BleepingComputer Forum also follows WildersSecurity Forum and adopts CloudFlare protection against malicious bots.

Sampei.Nihira

Level 24
Verified
Well-known

1.png
 
I encountered this earlier when my router dropped the IPv6 connection, and I was connecting via IPv4. Once I rebooted the router to fix the IPv6 problem, it didn't come up again. I guess generally IPv6 is more trustworthy because even the prefixes given by the ISPs may not be shared, and the IP itself is device-specific.
 
When a site adopts Cloudflare's advanced bot protection or Turnstile, that interstitial "security check" isn't just looking at IP reputation. It drops a heavily obfuscated JavaScript payload designed to silently collect a massive amount of telemetry to verify if the client is a genuine human operating a standard browser.

To Cloudflare's machine learning models, an "average" setup, standard Chrome or Edge with a basic ad blocker like uBlock Origin running default lists, looks normal. When that user hits the site, Cloudflare's invisible JavaScript challenges run in the background, the browser provides the expected telemetry, and the system easily verifies it's dealing with a standard human environment. Cloudflare then drops a clearance token (the cf_clearance cookie) in the browser. For the next week or month, depending on the forum's settings, that user isn't challenged again because that token proves they already passed the gauntlet.

By trying to be completely invisible, heavily hardened browsers end up waving a massive red flag. The system doesn't know who they are, but it knows they are actively hiding their environment, which forces Cloudflare to treat them as a high-risk bot and throw them into a perpetual challenge loop.
 
Last edited by a moderator:
I have visited BleepingComputer minutes ago; did not face the security check message; it is quite annoying in Wilders Security.
I used to get this message when visiting NeoWin, but it stopped to appear days ago.
The difference between BleepingComputer, Wilders, and NeoWin comes down to each site's individual Cloudflare Zone settings. NeoWin issued your browser a clearance cookie, so you are bypassing the check automatically now. Wilders likely has a stricter security threshold or shorter cookie lifespan.
 
This one

No, this is the link:


Cloudflare is active on this forum link, not their main site.
But for the last week or so, I'm having issues with sites that have adopted this. Sometimes clicking on such sites (from the bookmark bar) doesn't load for me on the first try; I have to click again to make it load. Otherwise, the browser keeps loading. Don't know whose side the issue is on. MS Edge/adblocker/some other extension/DNS/ISP/Cloudflare itself, or what?
 
No, this is the link:


Cloudflare is active on this forum link, not their main site.
But for the last week or so, I'm having issues with sites that have adopted this. Sometimes clicking on such sites (from the bookmark bar) doesn't load for me on the first try; I have to click again to make it load. Otherwise, the browser keeps loading. Don't know whose side the issue is on. MS Edge/adblocker/some other extension/DNS/ISP/Cloudflare itself, or what?
Yep, Brave Shields + Cloudflare WARP produced a security verification page for me.
 
The verification page is a third-party frame which, in the absence of an exception rule, is blocked in my case by my uBoL in Enhanced Easy mode.
This is almost certainly the fate of “less advanced” bots:

1.png

From my point of view, the fact that a verification page is not always obtained (when closing/reopening the browser) is NOT very positive.;)

P.S.

But for those who love comfort, it's very comfortable.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top