Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Mathwiz

Member
  • Joined

  • Last visited

  • Country

    United States

Everything posted by Mathwiz

  1. A lot of these bots are probably using folks' smart TVs to evade blocking: https://www.feistyduck.com/newsletter/issue_138_the_threat_of_residential_proxies?utm_source=fd&utm_medium=email&utm_campaign=newsletter-2026-06
  2. And in the US, R3dfox brings back memories of a beloved comedian: https://en.wikipedia.org/wiki/Redd_Foxx
  3. Does make me wonder though.... Does MSFN have any remaining defense against the onslaught of AI scrapers?
  4. I was wondering why R3dFox started letting me sign in!
  5. In the case of R3dFox, the 3 is just a backwards E: "Red Fox." But e3k-blah appears to be just a random string of characters. I don't think there's anything special about the digit 3. If there's a commonality between those two, I think they both came out of (IMO silly) "password complexity" requirements that made everyone come up with mixes of letters and numbers for their passwords. It became common to either use 0 for O, 1 for I, 2 for Z, 3 for E, 4 for A, 5 for S, 6 for G, and 7 for T; or just use a random password generator and let the browser remember it. Later these usages spread beyond passwords.
  6. Not sure why but I'm now able to sign onto MSFN in R3dFox 142.0.1. The Cloudflare loop that stopped me before is no longer occurring. I haven't had the guts to sign out and try signing back in in Serpent yet. I guess I could try it in a clean profile....
  7. I just use shortcuts, or type "msfn" and rely on auto-complete. So I'd forgotten that it's .org. Not a big deal, I suppose; I'm sure everyone knew I meant this forum. I have the same experience with R3dFox 142.0.1 as @VistaLover had with 140; I have to use the shortcut, which includes the /board part. Even FireFox 150 requires the /board part. This might be something @xper can fix with a redirect. Of course I know, but other readers may not, so just for clarity: Serpent 55 was abandoned by "upstream" long ago, when "upstream" was Moonchild Productions. And unlike Serpent 52, 55 doesn't use the "official" UXP engine. (UXP's upstream is still MCP.) However, luckily for us St 55 users (the few, the proud), @roytam1 has been quite successful in porting UXP changes into St 55's engine, so I still consider UXP to be "upstream" of St 55. Completely unofficially of course ;) Surely MSFN isn't the only board on the Web using Invision Community software, so the trick, I think, would be for someone to ask MCP on behalf of another board using Invision (for support in Pale Moon, of course, which almost certainly has the same "ugliness"). But even lacking a specific ask, it appears MCP has been (slowly) adding support for newer CSS "thingies" to UXP, so msfn's appearance is likely to improve with time.
  8. I'm trying out msfn.com with the latest version of Serpent 55. Still ugly, but not quite as ugly as it was with the 5/15 version. I suspect a lot of the ugliness is new CSS thingies that Serpent and its upstream equivalent don't yet support, so I guess upstream is making progress. Maybe someday msfn will look correct in Serpent again. I still keep the 5/15 Serpent version around because it renders one site (avsforum.com) better than the latest version does. I suspect the latest version's rendering is "correct" because more modern browsers render it the same way, so what the 5/15 version does is a "feature" (a bug that I happen to find useful).
  9. It just changed! Let's Encrypt issued a new 60-day certificate Thursday, 9/3. I forgot how often certificates get changed these days. So it's no longer possible to check the previous certificate, leaving the possibility slightly open that it was being sent by a MITM attacker. Probably not - I'm still not worried - but because of the timing, I can't prove it was safe. Oh, well; on to other things....
  10. Regarding the recent issues with Cloud-flare, it looks like these Firefox builds are passing all Cloud-flare challenges perfectly. I haven't been hit with a "verify you are human" page, let alone a loop, yet while using Firefox 150. (It's possible that even v.115 for XP users will work, but I'm not going to try that myself.) v.150 has some annoying issues with highlighting the drop-down menu item the mouse pointer is on in Win 7, but I can live with that. Still, this is the second browser change being forced on me this year, first from Serpent to R3dFox, then to these Firefox builds, and I'm getting a little tired of having to waste my time manually migrating to yet another browser. 🙄 (The only automatic upgrade path is from Edge, which I haven't used in years.)
  11. That's called a "man-in-the-middle" attack. Companies sometimes do that with their workers' PCs. It's also how ProxHTTPSProxy works. But it can't be pulled off unless your browser trusts the MITM's certificate authority (CA). You are implicitly accusing a browser-trusted CA of issuing a false MSFN certificate to CF, so that CF can pretend to be MSFN and carry out the attack. Any CA caught issuing false certificates, even to CF, would immediately be distrusted by both Google and Mozilla, which would pretty much put them out of business. OK, in theory I guess there could be some grand conspiracy between CF, Google, and Mozilla to steal MSFN users' passwords, but it seems pretty unlikely to me. But if you're still not convinced, we can just ask @xper to settle the matter: Which CA issued MSFN's current TLS certificate? What is the certificate's fingerprint? If his answers match the certificate your browser is seeing, then your browser is seeing MSFN's actual certificate, and you are safe. If not, then you are right and have my sincere apologies.
  12. I don't think so. HTTPS: is end-to-end encrypted. Only MSFN's server can see what you entered for your password. Middlemen like Cloudflare can't eavesdrop. That said, Cloudflare is causing lots of issues for users of older browsers, and has been even before MSFN's latest update.
  13. I'm lucky; I'm on Win 7 so I have access to newer browser versions. Site looks much better in R3dfox 142. But I can't sign in! As soon as I try I get stuck in a Cloudflare "verify you are human" loop. I tried the SSUAO @AstroSkipper gave above but had no luck, even with uBO completely disabled. At least with St 55 I can sign in and post. I don't totally blame MSFN for that. Cloudflare has been making life miserable for users of browsers over 2 months old for months now.
  14. Oh, wow. When I got the email, I figured there would likely be an "extreme makeover," but this is ridiculous. Almost everything is now black on white, which I don't like but can live with. But many clickable buttons are now dark blue on black and nearly unreadable. (I found I can highlight the text to make them readable though.) The main topic pages have ballooned in size, with each topic often taking a full page now. The new site is ugly as hell, but at least it works. Well, for the most part. I've been using @roytam1 's Serpent 55 (and an older version dated 5/15). Clicking the "*" to go to the first unread post brings up Cloudflare's challenge, which St 55 cannot pass. I just have to go to the last page and try to figure out which post I read last. Trying to click the arrow in a quoted post to go to the original post is blocked too.
  15. Well, it was a matter of the purest optimism to have posed the query in the first place.... Perhaps @roytam1 could implement the pref and use it to temporarily shut off :has() support, in the hope that an upstream fix will soon be available.
  16. Does UXP's new :has() support honor that same about:config pref? If so, disabling the pref might be a workaround for the serious performance issues with it.
  17. I realize I'm just an old fart now, but I still don't think it's crazy for me to stick to my ancient 2023 ways, and watch only one video at a time. That said, I suppose it's reasonable for someone to want to "keep an eye on" a live (not prerecorded) video or two other than the one they're actually watching. An example might be watching the local sports team play, while keeping an eye on rival teams' games. At least as long as you can back up and replay the last several seconds if something interesting happens. I even suppose it's possible that some folks are trying to do that sort of thing with their Web browser on an older OS like Windows XP. However, I suspect that's quite rare nowadays.
  18. I have AT&T fiber. My router is built into the fiber interface provided by AT&T. It is rather "locked down." I can't even block unwanted DNS lookups at the router, nor can I reroute DNS requests to another device, such as my Raspberry Pi (for, say, Pi-Hole). That sort of thing has to be done by configuring each connected device individually. You're welcome to prove me wrong but I doubt there's a way to force this router to obtain a new external IP address by running a script on a connected device.
  19. @roytam1: Weird that it works for you and @Skorpios but not me. Serpent 55 always brings up the captcha for me, left-click or right-click, and then doesn't pass the challenge. Maybe it is the user agent that Cloudflare is balking at, as @AstroSkipper suggested earlier. R3dfox also brought up the captcha, but I just pasted the URL, so there wouldn't have been a referer. That's probably why. (I know "referer" isn't the correct spelling, but it's how Mozilla spells it.) Bringing up MSFN in R3dfox, signing in, browsing to this thread, and then clicking one of the links might have worked, but I just wanted to get the file. R3dfox passed the challenge of course. Since my wget batch file is working again, it doesn't really matter to me now.
  20. @VistaLover's suggestion worked My .bat file has been repaired! @AstroSkipper, I didn't say I had a static IP address. I said "I don't really have an option to change my IP address though." Well, that wasn't entirely correct. I do have such an option: power-cycle the router, so it negotiates a new IP address with my ISP. This, of course, would disconnect all devices in the home, so it's not really practical unless I do it in the middle of the night. The IP address Cloudflare sees is, of course, my home network's external IP address, negotiated between the router and ISP. Changing the internal address my PC is using with the router would make no difference to Cloudflare whatsoever. Luckily it's now clear that such a thing isn't necessary anyhow.
  21. @Skorpios, no; I didn't think that a right-click followed by "Save Link As" would lead to different results than a left-click, which invokes the captcha. I guess XP users have a way to download the latest version after all. Edit: Just tried it. Right-click and "Save Link As" didn't work for me. I got a 6 kB file. Maybe it's that "referer" Roytam mentioned, but.... @roytam1, all my "referer" prefs in Serpent 55 are at their defaults. A standard left-click on the link brought up the captcha. I haven't yet tried the right-click and "Save Link As." @AstroSkipper, perhaps telling wget to use a Firefox UA along with Roytam's "referer" suggestion might do the trick. I don't really have an option to change my IP address though. I just couldn't imagine Cloudflare leaving such a gaping security hole! @VistaLover, check this out: https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/ Sneaky devils! I don't (and as long as I can get away with it, won't) own a "smart" TV, but I do own a Roku streaming box. I wonder if any of its "apps" are letting folks use my Internet bandwidth without my knowledge.
  22. I just got bitten by this thing. Normally, when you log in the site sets a cookie that will keep you logged in. As long as you connect often enough, you never have to log back in again. But I guess I went too long, so I had to log in again. Problem is, my browser remembered my user name, not my email address. (That's how long it had been since I logged in last.) And I couldn't remember which email address I had used when I originally signed up! So I was forced to just guess. Luckily, I guessed right (or you wouldn't be seeing this post). But that's a problem. I've had several email addresses over the years and some of them aren't even valid any more. Mutemail.com went belly-up and clear.com got bought out and shut down by Sprint (before Sprint themselves got bought out and shut down by T-Mobile). From the above, I take it the change was made to deal with spam (although I'm not clear how it helps with that, but evidently it does). But there needs to be a way to deal with forgotten email addresses. Perhaps a page where you can enter your user ID, password, and your current email address (maybe with a captcha), and get your old email address emailed back to you, or a link to reset it to the current one. Otherwise you're stuck creating a brand-new account and losing all your settings.
  23. I'm back. R3dfox worked, but good grief. I had to click the stupid "I am human" box. No more automated downloads. What really bites is that I had a nice .bat file that would automatically download the list of files from the appropriate directory at o.rthost.win, find the newest, automatically download that file, back up the old version, extract the new one, and apply all my browser customizations, all with just a few keystrokes. Now that's all been thrown out the window!
  24. Ultimate irony: the Cloudflare security checks block me from downloading Serpent with wget any more. I just get "403 Forbidden." Nor can I even use an old Serpent version to download the newest version! Apparently I'll have to use R3dfox to download Serpent now...? At least I'm on Win 7 and can use R3dfox, but what's an XP user to do now? Have I mentioned lately how much I hate AI? Not because I don't find it useful, but because everybody and their God damned dog is trying to scrape the entire World Wide Web to train their damned AI, necessitating all these damned security checks.
  25. Re: Forcibly reinstalling uBO, I agree with NHTPG. Unfortunately the author appears to have missed the point: Re: the first point, I would too! On today's Internet, I'd never browse without an ad blocker, and uBO is the best IMO. But there's a difference between installing uBO by default, and reinstalling it if the user intentionally uninstalls it, effectively making it an unavoidable part of the browser! I don't think the author fully appreciates the gravity of forcibly installing a third-party's add-on, no matter how good that third party may currently be. What if some hypothetical company (which I'll call "Poogle") makes gorhill an offer he can't refuse to exempt Poogle ads from being blocked by uBO? Or what if gorhill gets hit by a truck, and his heirs aren't software developers, have no interest in continuing uBO development, and just sell it to Poogle outright? (As for having uBO always available when testing, the author could add it to his own policies.json; that doesn't mean it has to be in the distribution for everyone.) As to the second point, editing a .json file is a bit beyond the ability of the average user. There needs to be a way for non-techies to do this. But in any case, it appears the author has no intention of addressing this issue.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.