Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cloudflare, you have my login token cookie but you are still asking me to prove I'm not a robot. Please make using a VPN not to be a punishment since all the sites that use your SSL show me the "I'm not a robot", no matter how often I verify it. I am most times under an insecure WIFI so no VPN is not an option for security. Possible steps:

1. Make me solve it only once every X minutes/hours.

2. Make the defaults to be one step down in security, probably most webmasters don't want to block legitimate people using VPN.

3. Make it dynamic, so only those under suspicion have to do it. And consider being using a VPN NOT to be enough suspicion for it.

Right now I have to choose either to:

- Compromise my security: don't like it now, cannot do it when I start working with the new company I'm going to work

- Solve hundreds of "I'm not a robot" per day



> I am most times under an insecure WIFI so no VPN is not an option for security.

Maybe apply some netfilter or proxy magic to push traffic to port 443 over the wifi and everything else through the vpn?


These settings are available but it is currently up to each given site to enable it.


That was exactly my point 2: Make the defaults to be one step down in security, probably most webmasters don't want to block legitimate people using VPN.


That seems like it might be a difficult sell for a company that considers itself a security company for the benefit of a relatively niche use case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: