Live data from Hacker News

Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

herrjemand.medium.com

111–120 of 294 posts

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#111
post #101
post #66

Earlier quoted context omitted.

It is great that you care and I guess others are already provided some examples, but I'll add my own 2c here. Obvious problem is that centralized service like CloudFlare do create entry barrier and make large players on search and data mining markets even more entrenched than ever. Recently your company announced partnership with Internet Archive, but if CloudFlare want to continue play a role as behevolent party eve…

Making scraping harder definitely reduces scraping. Some bad actors will get through, but others will be deterred. I think you might not understand that it's site owners like me who want to stop scraping. It usually comes from specific bad incidents, like copycat sites stealing our content and work. Cloudflare wouldn't block scraping if website owners didn't want it. And website owners can easily disable this protect…

Scrapping protection is not a problem: defaults that CloudFlare promote are. Saying that website owners can disable it is akin saying website owners should go and whitelist Tor nodes. Most of website owners don't understand either of issues and they never gonna opt-out.

Also I'm talking from experience because I been on both sides of the fence: doing scrapping and implementing protection. So yeah your CloudFlare protection will deter 10% of bad actors, but will also cut off 99% of enthusiast / research efforts or users of niche software or browsers. Still anyone with $1000+ budget will scrap whatever they want.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#112

The article here ignores the view of the Web that Cloudflare has, which coupled with "something you have" (the U2F keys) makes for a compelling alternative to CAPTCHAs. Sure, bots can automate keys, but those keys could also be banned just as well. Cloudflare only needs to know which ones are the good keys and track those forever. This means, for every non-bot out there, the CAPTCHAs are as good as gone. The genius o…

Each key is associated with a batch of devices, though. If you ban a key, you risk banning a bunch of legitimate users. It's an interesting trade-off. It seems like batch keys for device attestation was designed to help protect individual privacy (good), but if you can't ban a key without potentially a lot of splash damage when you detect a bad actor, that seems like a very limiting choice.

> Each key is associated with a batch of devices, though. If you ban a key, you risk banning a bunch of legitimate users.

You're right. I meant Cloudflare could ban the generated public-key and not the device's public-key itself. Besides, they could also mark the batch as being taken over by bots and increase the level on challenges issued to the batch. Note though, a single secure module can only generate / store so many public-keys. For instance, Yubi Key 5 supports up to 25 keys, though those could be reset to generate a newer set of 25, but repeat registration of a number of keys from a single batch is bound to trigger some statistical anomalies.

From Cloudflare's blog about Cryptographic attestation of personhood https://archive.is/4EbER

> For our challenge, we leverage the WebAuthn registration process. It has been designed to perform multiple authentications, which we do not have a use for. Therefore, we do assign the same constant value to the required username field. It protects users from deanonymization.

Currently, the user-name field is constant for all users. I wanted to point out that that they could amend the registration ceremony to register any user in particular.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#113

The article here ignores the view of the Web that Cloudflare has, which coupled with "something you have" (the U2F keys) makes for a compelling alternative to CAPTCHAs. Sure, bots can automate keys, but those keys could also be banned just as well. Cloudflare only needs to know which ones are the good keys and track those forever. This means, for every non-bot out there, the CAPTCHAs are as good as gone. The genius o…

I agree, I saw the author mention for $25k you could have 1000 keys. I immediately though that is not nearly enough. Given the sheer volume they have, they would start putting a picture together very quickly of ip/key/sites. There is no where near enough uniqueness.

I also thought the idea of the key exchange being fast was a red herring. That's a bad thing. If I'm them I'm paying attention to how long from prompt to exchange it takes a human to touch the button. On my own setup my key is on my laptop, which is in a dock. I must stand up and tap it over my monitor. It's just a few seconds but it's a) consistent in timing b) not Overall they make some good points if you are teeny tiny player and ignore completely the scale cloudflare is operating at.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#114
post #12

Cloudflare is both a great thing and a terrible thing that has happened to the internet in recent years. Great in that they have a fantastic UI to add your site in, basically shielding the average user from attacks. Bad from a standpoint of that now only Google, Bing, and maybe other big search engines have the capabilities to actually crawl the internet now. I don't see us getting a massive innovation in search on t…

Maybe I'm cynical, but I don't see any innovation to be done in search. Google results have become much less useful over the past few years. If they cannot solve search with basically unlimited resources, how is a tiny company going to? 1. Filtering ever increasing trillions of spam/clickbait pages 2. Figuring out which results are useful information vs corporates trying to sell something. Those problems are not solv…

It's not clear to me that Google still gives a fuck about solving search/organizing the world's information and make it useful. The mess they've incentivized the web to become is very profitable for them.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#115
post #12

Cloudflare is both a great thing and a terrible thing that has happened to the internet in recent years. Great in that they have a fantastic UI to add your site in, basically shielding the average user from attacks. Bad from a standpoint of that now only Google, Bing, and maybe other big search engines have the capabilities to actually crawl the internet now. I don't see us getting a massive innovation in search on t…

Maybe I'm cynical, but I don't see any innovation to be done in search. Google results have become much less useful over the past few years. If they cannot solve search with basically unlimited resources, how is a tiny company going to? 1. Filtering ever increasing trillions of spam/clickbait pages 2. Figuring out which results are useful information vs corporates trying to sell something. Those problems are not solv…

> If they cannot solve search with basically unlimited resources, how is a tiny company going to?

Reminder: Google Is An Ad Company. Are you sure they actually want to solve search? Their primary interest is to be that corporation selling you something.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#116

Earlier quoted context omitted.

I don't see us getting a massive innovation in search on the internet now that Google has such a massive foothold, and companies like Cloudflare stop innovation from happening. How are we "stopping search innovation"?

Crawling a Cloudflare powered website is basically impossible without needing to do some bodges as to how to crawl it. How can you expect someone to crawl a bunch of websites if they are actively blocked from accessing it? Now, you might say users can whitelist bots in their robots.txt file but then again will the person creating the engine individually ask companies to allow them to crawl? Also, slightly unrelated b…

> Also, slightly unrelated but Cloudflare protected websites are almost impossible to access via tor, the captcha never succeeds.

Yes, I've never understood why it's seemingly so important to CAPTCHA me before serving me less than 100kb of read only plain jane HTML. What sort of "attack" is this stopping? I'm pretty sure the CAPTCHA itself is bigger than half the sites it blocks me from reading.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#117

Even if we ignore the technical reasons, for me CloudFlare's proposal fails at their "Associate a unique ID to your key" property, where they say CloudFlare could, but won't do it. If they implement this scheme they start normalising this approach. Once it gets to FB and Google implementation, their answer will be: we could, but we... look! a squirrel!

Their document says, correctly, that the means by which they could try to do this would be to shove the arbitrary random ID they get into a cookie.

You may have noticed that both Facebook and Google already use cookies. Did you know Hacker News has a cookie too?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#118

Earlier quoted context omitted.

Be a good netizen? Respect robots.txt. Don't lie in your User-Agent. Don't crawl at a ridiculous rate. All those are a good starting point.

Do you not realize the more fundamental problem with you, as a company, essentially being the one who gatekeeps crawler access to the web?

Customers pay for this as a feature. Why would they feel it's a fundamental problem? There's nothing that says admins need to let you crawl their site.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#119
post #41

Earlier quoted context omitted.

No, what scales is us making our DDoS and bot detection not disrupt the crawling of legit search engines that respect robots.txt, don't crawl at ridiculous speeds, don't do dumb stuff like pretend they are the Googlebot. We have teams who work on that. You can read more here: https://blog.cloudflare.com/tag/bots/ But let's suppose someone is building a new cool search engine and our ML stuff is blocking them. Then...…

So for my startup to crawl sites I must now adhere to Cloudflare’s Requirements of the Web(TM) or reach out to individual engineer, who may leave at any moment. Gotcha (but Google is allowed because Google was first to market)

Why would you possibly think you can do whatever you want to someone else's site?

Yes, you must adhere to the controls that site administrators put in place, like Cloudflare.... You don't get to blast my site with requests, just because you want to...

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#120
post #29

Earlier quoted context omitted.

For instance there is no way for distributed search engines to work with CloudFlare. No, "contact me and we'll help" is not always a solution.

That response is just a way to move the discussion out of the public domain without actually addressing it. It’s a scam.

Calling CTO of a big company who come to talk with us "scam" is very counter-productive. Some of CloudFlare bad sides are certainly by design and cannot be changed, but they can still change their default filtering policies in a way that will help open web greatly.
Post reply on HN