18

It would seem that Orion has some trouble successfully completing CloudFlare's and perhaps possibly hCaptcha's challenges. Unsure if this happens on older versions of macOS; I noticed the console logs a 401 for the private access token challenge, possibly due to a CORS issue?

Steps to reproduce:

  1. Visit 4chan (the homepage itself is SFW; be careful clicking any boards, though)
  2. Perhaps, if unlucky, the CloudFlare verification challenge will appear
  3. Attempt to pass the challenge by completing the captcha
  4. Repeat until the end of time

Notes:

  • Tested with the default user-agent settings, Safari's user-agent, and Chrome's user-agent.
  • Tested with both compatibility mode enabled and disabled.
  • Tested with and without extensions (uBlock Origin, Bypass Paywalls Clean, and ViolentMonkey)
  • Does not occur on Safari (16.1 - 18614.2.9.1.12) or Thorium (Chromium 109.0.5361.0 w/ minor patches and additional codecs)
  • Unsure if 4chan's CF security settings mandate all visitors pass the check when accessing the homepage or if it is only required by 'high-risk' visitors
    • Safari does not even display the CF challenge; the 4chan homepage loads just fine (however, as I am on Ventura, it may be able to bypass the prompt all-together due to the private access token feature),
    • Thorium displays the prompt but passes the challenge once the captcha is complete.
    • I am on dual-stack IPv4/IPv6, the latter of which may also be the cause of the challenges, if the prompt cannot be reproduced.

Expected behavior:
One would expect the challenge to succeed upon the first successful captcha completion.

Orion, OS version; hardware type:

  • Orion: 0.99.121-beta (WebKit 614.1.20)
  • OS: macOS Ventura 13.0 (22A380 / Darwin Kernel Version 22.1.0: Sun Oct 9 20:15:09 PDT 2022; root:xnu-8792.41.92/RELEASE_ARM64_T6000 arm64)
  • Hardware: 16" MacBookPro18,1 w/ M1 Pro (10 cores, 16 GPU cores)

Image/Video:

    4 months later

    I'm also facing the same issue with the ChatGPT site, as well as the links for The Morning Brew newsletter (which are protected by Cloudflare).

    I'm attaching a video capture of the rendered web page

    Version 0.99.123.3-beta (WebKit 615.1.16.1)
    MacBook Pro (macOS Ventura 13.2.1 build 22D68)
    Apple M1 Max MKH53ZP/A, MacBookPro18,4

    • Vlad replied to this.
      7 months later

      Orion has had issues with turnstile for a while for me. In certain occasions, opening the dev tools to modify the viewport width worked, but not lately.

      Turnstile is mostly PoW and user analysis based. I think Cloudflare assumes Orion is Safari but realizes not everything matches up.

        4 months later
        6 days later
        9 days later

        I also experience this issue. What helped for me is: Disable Orion's Tracking Protection and Content Protection and just use uBlock Origin.

          21 days later

          I'm experiencing the same problem with https://steamdb.info, except nothing suggested here fixes the issue; I've tried switching user agents to Firefox, turning off tracking protection and content blockers, and turning on compatibility mode (for the last one, the captcha disappears after a while, but then the page refreshes and goes back to the captcha page). I've also tried clearing caches and cookies for the website to no avail.

          Somehow, it works when opening the page in incognito mode, although my use case for the site makes it inconvenient since I need to be logged in.

            Having issue as well. Have tried compatibility mode. Frequent with many websites now, I use vpn but issue persists with it off. Happens very often with chatgpt, perplexity.ai, and recently with downdetector

              Happens to me too. Might be related to these blob errors (cloudflare might not be able to load the challenge).

              Happened on Orion on other websites that I use, after some googling I always end up at "blobs don't work reliably in WebKit" https://stackoverflow.com/a/70253220.

              Compatibility mode seems to fix everything for me though.

                8 months later

                If one has CrashHandler set to developer, it shows the Orion RC Graphics and Media quit unexpectedly message any site that uses the Cloudflare bot check.

                I'll provide the log, if it's of any use. 🙂

                cloudflare-bot-orion-rc-graphics-and-media-quit-unexpectedlytxt.zip
                76kB
                  No one is typing