Live data from Hacker News

Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

herrjemand.medium.com

101–110 of 294 posts

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#101
post #66

Earlier quoted context omitted.

Please explain the problem (here or via email to me).

It is great that you care and I guess others are already provided some examples, but I'll add my own 2c here. Obvious problem is that centralized service like CloudFlare do create entry barrier and make large players on search and data mining markets even more entrenched than ever. Recently your company announced partnership with Internet Archive, but if CloudFlare want to continue play a role as behevolent party eve…

Making scraping harder definitely reduces scraping. Some bad actors will get through, but others will be deterred.

I think you might not understand that it's site owners like me who want to stop scraping. It usually comes from specific bad incidents, like copycat sites stealing our content and work.

Cloudflare wouldn't block scraping if website owners didn't want it. And website owners can easily disable this protection.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#102
post #29

Earlier quoted context omitted.

For instance there is no way for distributed search engines to work with CloudFlare. No, "contact me and we'll help" is not always a solution.

I've never been able to "reach a human" at Google, Facebook and other web giants and I'm skeptical that you can at a place like Cloudflare. In fact, I'd be really astonished it was possible, because otherwise their business isn't scalable.

Cloudflare support has been exceptional to me as a website owner.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#103

The article here ignores the view of the Web that Cloudflare has, which coupled with "something you have" (the U2F keys) makes for a compelling alternative to CAPTCHAs. Sure, bots can automate keys, but those keys could also be banned just as well. Cloudflare only needs to know which ones are the good keys and track those forever. This means, for every non-bot out there, the CAPTCHAs are as good as gone. The genius o…

Each key is associated with a batch of devices, though. If you ban a key, you risk banning a bunch of legitimate users. It's an interesting trade-off. It seems like batch keys for device attestation was designed to help protect individual privacy (good), but if you can't ban a key without potentially a lot of splash damage when you detect a bad actor, that seems like a very limiting choice.

The intent of attestation is that a business could decide, OK, we think FooCorp are doing a proper job and we trust their FIDO tokens, but we don't like all these dozens of cheap alternatives. So for our corporate site we'll require FooCorp tokens, and we'll just issue every employee a FooCorp token on our dime.

Maybe it could make sense for a bank to do this, sending account holders a special custom Security Key with the bank's branding on it. I personally think that's stupid, but I can imagine it appealing to bank executives and it's not so stupid as to be worse than SMS or TOTP 2FA that banks do today.

But it clearly isn't relevant for no-cost services like Facebook or Gmail, and so sure enough you can just tell them you don't want to give them attestation and they work anyway (I don't know if either of them ask, I just reflexively deny attestation if it's requested).

It isn't intended to be useful for trying to do stuff like Cloudflare are attempting here. Which doesn't mean Cloudflare can't succeed in their goals, but in the FIDO threat models a "bad actor" would be a whole vendor, maybe some outfit is using fixed long term secret keys inside their Security Key products and they just sell the NSA a list of those keys - you might decide to just refuse all the products from this vendor. Whereas for Cloudflare the "bad actor" they're worried about just buys a half dozen of whatever was cheapest from eBay and then plugs them into a Raspberry Pi.

Or, do they? That's the gamble I think Cloudflare is taking. Maybe the value of defeating this intervention is so low that bad guys will not, in fact, build a Raspberry Pi Security Key clicker proxy to make their thing work.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#104
post #98
post #73

Earlier quoted context omitted.

Hi! Thanks for taking the time to reply. You mentioned about "legit" crawlers, what defines a "legit" crawler in the eyes of Cloudflare, and what happens when Cloudflare suddenly decides it does not want to honour that "agreement"? What happens if/when Cloudflare is sold, or the contact who greenlit these smaller "legit" crawlers moves on and decides that it no longer agrees with said website anymore? Is a price comp…

There are a lot of hypotheticals here. I think you'll convince CloudFlare, and their customers, if you could name names and mention specific examples? If you are a price comparison site getting blocked by cloudflare, site owners may be losing sales, and that's good feedback.

Or site owners may actively want to block a price comparison site..

Depending on the industry, etc..

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#105

Earlier quoted context omitted.

No, what scales is us making our DDoS and bot detection not disrupt the crawling of legit search engines that respect robots.txt, don't crawl at ridiculous speeds, don't do dumb stuff like pretend they are the Googlebot. We have teams who work on that. You can read more here: https://blog.cloudflare.com/tag/bots/ But let's suppose someone is building a new cool search engine and our ML stuff is blocking them. Then...…

That doesn't sound unreasonable. Out of interest, what would you consider a ridiculous speed to be crawling at?

I can't speak for Cloudflare, but crawling speed should be dictated by the site owner via the robots.txt crawl-delay. [1] A site owner could also rate-limit unauthenticated requests by IP via the cloudflare header using a 429 too many requests error page.

[1] - https://en.wikipedia.org/wiki/Robots_exclusion_standard#Craw...

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#106
post #12

Cloudflare is both a great thing and a terrible thing that has happened to the internet in recent years. Great in that they have a fantastic UI to add your site in, basically shielding the average user from attacks. Bad from a standpoint of that now only Google, Bing, and maybe other big search engines have the capabilities to actually crawl the internet now. I don't see us getting a massive innovation in search on t…

Maybe I'm cynical, but I don't see any innovation to be done in search. Google results have become much less useful over the past few years. If they cannot solve search with basically unlimited resources, how is a tiny company going to?

1. Filtering ever increasing trillions of spam/clickbait pages

2. Figuring out which results are useful information vs corporates trying to sell something.

Those problems are not solveable by a couple guys in a garage

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#107
post #38

Earlier quoted context omitted.

Say I’m interested in building a small scale domain-specific search engine and only just started development. There’s no prototype yet and may never be. In this situation, how do you determine it’s a legit crawler? And what about crawlers with even more limited scopes (targeting only a handful of sites) that they can’t possibly be called search engines? Are they ever considered legit?

Be a good netizen? Respect robots.txt. Don't lie in your User-Agent. Don't crawl at a ridiculous rate. All those are a good starting point.

What is a “ridiculous rate”? Where is it documented?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#108
post #29

Earlier quoted context omitted.

I don't see us getting a massive innovation in search on the internet now that Google has such a massive foothold, and companies like Cloudflare stop innovation from happening. How are we "stopping search innovation"?

For instance there is no way for distributed search engines to work with CloudFlare. No, "contact me and we'll help" is not always a solution.

That response is just a way to move the discussion out of the public domain without actually addressing it. It’s a scam.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#109
post #12

Cloudflare is both a great thing and a terrible thing that has happened to the internet in recent years. Great in that they have a fantastic UI to add your site in, basically shielding the average user from attacks. Bad from a standpoint of that now only Google, Bing, and maybe other big search engines have the capabilities to actually crawl the internet now. I don't see us getting a massive innovation in search on t…

Maybe I'm cynical, but I don't see any innovation to be done in search. Google results have become much less useful over the past few years. If they cannot solve search with basically unlimited resources, how is a tiny company going to? 1. Filtering ever increasing trillions of spam/clickbait pages 2. Figuring out which results are useful information vs corporates trying to sell something. Those problems are not solv…

Maybe not, but the garage guys should look into becoming the best search engine in a niche and expand from there.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#110
post #104
post #98

Earlier quoted context omitted.

There are a lot of hypotheticals here. I think you'll convince CloudFlare, and their customers, if you could name names and mention specific examples? If you are a price comparison site getting blocked by cloudflare, site owners may be losing sales, and that's good feedback.

Or site owners may actively want to block a price comparison site.. Depending on the industry, etc..

Agreed on this point, and most companies who would want to do these sorts of things would restrict it even if Cloudflare didn't exist.

I really can't think of a good solution. But that's the tricky position Cloudflare is in - how does it balance everything.

Post reply on HN