Live data from Hacker News

Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

herrjemand.medium.com

81–90 of 294 posts

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#81

Complete aside, but I'm still not certain I understand the technical details of why Cloudflare can't uniquely identify users. I thought I knew how hardware keys worked, but apparently I don't. If the key being shared is embedded in the device, even in a secure enclave or something, then my understanding was that would open the door for key extraction. If the key is unique per-device, then that's not a problem. But if…

https://fidoalliance.org/fido-technotes-the-truth-about-atte... explains this pretty well.

Basically:

* Attestation keys are not unique per authenticator; they're shared among batches of authenticators.

* If you extract the batch's attestation key, you can imitate authenticators from that batch. That doesn't mean you can authenticate as a registered authenticator, of course; it just means you can pretend to be a "Yubico XYZ" device.

* Yes, I think Cloudflare is assuming it's hard to extract the attestation key. I think this is basically a safe assumption, but if it isn't, they can always choose to distrust batches known to be compromised.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#82
post #26

I’d rather take these tradeoffs than doing 5 steps of Recaptcha because I’m using a VPN to work, which as Cloudflares announcement said, is very localized to North America and likely extra complicated for those outside the region. In theory, couldn’t Yubikey begin reducing batch sizes to 1,000 and Cloudflare mark specific batch numbers as requiring one extra step to verify? The vast majority of Yubikey sales will be…

Wouldn't reducing batch sizes make privacy even more of a problem? Now instead of a 1/100000 chance of the user being the same person on another website there would be a 1/1000 chance.

Yeah, except that because the other 999 users probably wouldn't be using Tor to access the same websites, in practice this would be pretty much guaranteed to give a highly accurate, persistent tracking identifier.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#83

The article here ignores the view of the Web that Cloudflare has, which coupled with "something you have" (the U2F keys) makes for a compelling alternative to CAPTCHAs. Sure, bots can automate keys, but those keys could also be banned just as well. Cloudflare only needs to know which ones are the good keys and track those forever. This means, for every non-bot out there, the CAPTCHAs are as good as gone. The genius o…

They already have that but it's just for internal teams. I used it recently to lockdown Wordpress installations

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#84
post #35

Earlier quoted context omitted.

This will scale wonderfully!

No, what scales is us making our DDoS and bot detection not disrupt the crawling of legit search engines that respect robots.txt, don't crawl at ridiculous speeds, don't do dumb stuff like pretend they are the Googlebot. We have teams who work on that. You can read more here: https://blog.cloudflare.com/tag/bots/ But let's suppose someone is building a new cool search engine and our ML stuff is blocking them. Then...…

That doesn't sound unreasonable. Out of interest, what would you consider a ridiculous speed to be crawling at?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#85

Is CAPTCHA a necessity only in ad-sponsored web? Is there other compelling use-case for it? Can we make CAPTCHA obsolete with decent micropayments solution, when you pay for every transaction with every website, just like we pay for every drop of water we use? Perhaps ISPs could handle it for us?

How do you know who to pay to?

Sure, you are paying for the every drop of water, but what if you really wanted to pay for water from a specific region, doesn't want water from another region, and trust that the water company does not keep a cut or rip off either of you?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#86
post #56

Cloudflare is the professional wall builder you hire to protect your garden. Tech monopolies have always had a vested interest in locking up user data, dictating the policies, and enforcing their own ownership rights. It used to be that only the largest and most sophisticated companies had the resources to shield that data, but Cloudflare changed all that. Walls are now trivial to set up, and virtually unbreachable,…

No offense, this framing is so dumb. I hate it.

The ‘Internet 3.0’ isn’t coming because of Cloudflare. It’s coming because these monolith big tech companies have an army of engineers who have been centralizing and building it this way for years.

Cloudflare didn’t build these walls, it’s more of a giant boat now navigating it because other companies have no choice.

I like to think of them as giant data ferryman in this regard versus “a wall builder”.

I’m not saying frustrations aren’t warranted but — like come on — have a little perspective of what’s really happening with the Internet and who is actually driving it.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#87
post #64

Earlier quoted context omitted.

Be a good netizen? Respect robots.txt. Don't lie in your User-Agent. Don't crawl at a ridiculous rate. All those are a good starting point.

I think the problem is some IPs just straight-up always get CAPTCHAs from Cloudflare even if one’s a good netizen, respect robots.txt, not crawl at ridiculous rate, and not lie in the user agent. One reason is shared IP, which disproportionally affects people from third world countries as their ISPs don’t have enough IPv4 for everyone; but it also happened mysteriously to at least one dedicated IP I used in the past.…

Then the problem has nothing to do with your crawling.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#88

I’d rather take these tradeoffs than doing 5 steps of Recaptcha because I’m using a VPN to work, which as Cloudflares announcement said, is very localized to North America and likely extra complicated for those outside the region. In theory, couldn’t Yubikey begin reducing batch sizes to 1,000 and Cloudflare mark specific batch numbers as requiring one extra step to verify? The vast majority of Yubikey sales will be…

And if Yubikey could reduce batch sizes - could they require bulk non-wholesale orders to retain the same batch ID to reduce likelihood of abuse?

This won't work because guess what? Bad actors have money and means to buy as many devices as needed through individuals.

Most of the abuse that CloudFlare protects from is also usually illegal. And those taking risk of doing something illegal usually do it because it's highly profitable so making some authentification devices a bit more expensive won't make any difference.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#89
post #72
post #33

Earlier quoted context omitted.

Is it pretty much dead? Yeah, if you’re moving FAANG level traffic you need something more fancy than LAMP + an internet connection, but I’ve seen dozens and dozens of sites with a plain old no-cdn, no-pdn, LAMP tech stack. Working with startups might bias your view - lots of companies are running extremely boring setups and they work just great.

Respectfully, I think you miss the point. The fact that 98% of traffic goes trough this new infrastructure, allows some still plug their server to the net raw and their traffic still gets trough.

>The fact that 98% of traffic goes trough this new infrastructure

Doesn't mean that 98% of the value of the Internet results from this traffic.

Even if you discount all of the web, there still lots of applications using the federated model (e.g. SMTP) or peer-to-peer (e.g. Crypto, VOIP), that require end-to-end connectivity.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#90

Complete aside, but I'm still not certain I understand the technical details of why Cloudflare can't uniquely identify users. I thought I knew how hardware keys worked, but apparently I don't. If the key being shared is embedded in the device, even in a secure enclave or something, then my understanding was that would open the door for key extraction. If the key is unique per-device, then that's not a problem. But if…

> Are we assuming that it's impossible to extract a private key from one of these devices?

Nope, it's just "expensive" to extract keys from secure hardware like this. The problem with an approach like this is that when the secret keys are identical for a large number of devices then the cost of revoking a compromised key goes up significantly which, for a spammer, would increase the value of obtaining said key because of the likelyhood that the key would be usable for a much longer time than if the key was unique to each device (and could be very easily blacklisted).

Techniques to extract data from these sorts of secure devices include various forms of side-channel analysis, decapping and microprobing the IC, using SEM, etc. to physically damage parts of the circuit to try to force it to disclose the key and various forms of power and clock glitching.

Most decent hardware-based cryptosystems are designed to ensure that each device has a unique key so that the cost of extracting one key (lets say around $100k) is too high for a potential attacker if the key can just be blacklisted, but if the key is expensive/impossible to blacklist then that cost might be worthwhile to an attacker.

Post reply on HN