webcompat / web-bugs

A place to report bugs on websites.
https://webcompat.com
Mozilla Public License 2.0
749 stars 68 forks source link

pp-attester-turnstile.research.cloudflare.com - site is not usable #139311

Closed webcompat-bot closed 4 months ago

webcompat-bot commented 4 months ago

URL: https://pp-attester-turnstile.research.cloudflare.com/challenge

Browser / Version: Firefox 128.0 Operating System: Windows 10 Tested Another Browser: Yes Chrome

Problem type: Site is not usable Description: Problems with Captcha Steps to Reproduce: Captcha is broken, have been refreshing for over 30 minutes and it keeps showing failed on Firefox. Chrome passes captcha but doesn't have my profiles

View the screenshot Screenshot
Browser Configuration
  • gfx.webrender.software: false
  • blockList: basic
  • channel: nightly
  • defaultUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
  • hasTouchScreen: false
  • frameworks: {'fastclick': False, 'mobify': False, 'marfeel': False}
  • mixed active content blocked: false
  • mixed passive content blocked: false
  • tracking content blocked: false

View console log messages

From webcompat.com with ❤️

sv-calin commented 4 months ago

We appreciate your report but I was not able to reproduce this issue.

image

Tested on: • Browser / Version: Firefox Release 128 • Operating System: Windows 10

Suggestions: • Clear cache/data/cookies, disable Ad-blocker (if available), or create a new profile (without syncing/importing data) and check again • If there are any changes made to the default settings of the browser (e.g. in about:config), please revert to the default settings

[qa_29/2024]

MasterInQuestion commented 3 months ago

= Cloudflare Turnstile Error: 600010 =

    Which I can reproduce for various Cloudflare Turnstile related sites:     https://2captcha.com/demo/cloudflare-turnstile     https://pp-attester-turnstile.research.cloudflare.com/challenge     Seemingly similar failure cause.

    Trace: [Cloudflare Turnstile] Error: 600010.     c@https://challenges.cloudflare.com/turnstile/v0/api.js:1:8236     Zt/<@https://challenges.cloudflare.com/turnstile/v0/api.js:1:8576     r@https://challenges.cloudflare.com/turnstile/v0/api.js:1:8747     v@https://challenges.cloudflare.com/turnstile/v0/api.js:1:8908     w@https://challenges.cloudflare.com/turnstile/v0/api.js:1:32782

    File: https://web.archive.org/web/20240803045214/https://challenges.cloudflare.com/turnstile/v0/api.js     (mostly identical)

    Related:     https://bugzilla.mozilla.org/show_bug.cgi?id=1887685     .     Deep-trace spotted multiple Cloudflare Captcha related issues on Bugzilla over the years.     Partly for Cloudflare's erroneous assumption on the theoretical boundaries:     https://community.cloudflare.com/t/firefox-resistfingerprinting-vs-cloudflare-challenge/306354/4     .     Proof of Work (PoW) authentication is the only means essential to leverage query flood attacks.     Else, hardly reliable; and mostly no-op.     And "security by obscurity"..?

    Also, I've noted alike work for some sites while don't for the other.     Probably relevant with the site's own configuration: but Cloudflare reported cryptic message? \ \     Would you attempt again in Private Browsing Mode?     Also, I'd like to know more about the reporter's Firefox config.

    Note:     This one doesn't appear to be related with "dom.enable_resource_timing".     And ad-block extension doesn't appear to be the cause.     My Firefox config: https://github.com/MasterInQuestion/talk/discussions/11

    Not directly related, but for reference:     https://old.reddit.com/r/CloudFlare/comments/19bmj70/turnstile_error_likely_ip_related/?sort=old