Live data from Hacker News

Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

herrjemand.medium.com

131–140 of 294 posts

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#131
Is this post missing the point, or am I? I thought that the point of requiring attestation is to prove that someone actually did go out and buy a legitimate Yubikey (or whatnot) and ban that key if they're spamming.

With those two considerations, this actually seems like a really good idea to me.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#132
Cloudflare captchas in particular, and any checks and roadblocks to see something publicly available in general, are terrible, period. It doesn't matter which form they take. Every time you see one you feel like a second-class citizen and get reminded that the internet is no longer what it used to be.

I personally simply close the tab when I see a cloudflare "one more step" page.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#133

Earlier quoted context omitted.

https://yacy.net/ for example. Each interested node does indexing and serving some chunk of the results. Or in practice - each node quickly runs into a CloudFlare captcha preventing it from indexing content for a few hours/days. Since CF fronts a lot of the useful internet these days, it means it's effectively working against distributed indexing with its current captcha solution.

Thanks. I'll bring this to the attention of the bots and DDoS teams.

Yacy is 18 years old and not exactly obscure. If your bots team is unaware of it it's because they've chosen to be ignorant of it.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#134
post #10

There's always CAPTCHA bypasses if you're willing to pay, there've been sites operating for decades that will take a captcha URL and spit out the appropriate response by just feeding it to humans. This is just a different way to make you pay - and arguably to something of less ill-repute, buying more U2F keys once yours get banned. This provides effective rate limiting and you can still get every key you automate ban…

Second this. For a major sporting event, one of our sites was heavily targeted by “free TV streaming services” self promoting their stuff. No amount of Google CAPTCHA or Cloudflare could stop it while keeping it online. Never seen anything like it in my life.

That makes me so frustrated.

I HATE CAPTCHA's with a passion. They are everywhere and constantly slow me down. And you mentioned, they are likely not helpful in stopping bots.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#135

Cloudflare captchas in particular, and any checks and roadblocks to see something publicly available in general, are terrible, period. It doesn't matter which form they take. Every time you see one you feel like a second-class citizen and get reminded that the internet is no longer what it used to be. I personally simply close the tab when I see a cloudflare "one more step" page.

How do you mitigate ddos attacks and other bad actors hitting a page?

What does your cdn solution look like?

Route optimization from your (single) endpoint to clients literally half a world away?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#136

Is this post missing the point, or am I? I thought that the point of requiring attestation is to prove that someone actually did go out and buy a legitimate Yubikey (or whatnot) and ban that key if they're spamming. With those two considerations, this actually seems like a really good idea to me.

It doesn't appear to identify any specific key, just that the user has a yubikey. You could only ban a whole key manufacturer (or key batch, however large that is).

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#137

Earlier quoted context omitted.

Crawling a Cloudflare powered website is basically impossible without needing to do some bodges as to how to crawl it. How can you expect someone to crawl a bunch of websites if they are actively blocked from accessing it? Now, you might say users can whitelist bots in their robots.txt file but then again will the person creating the engine individually ask companies to allow them to crawl? Also, slightly unrelated b…

If you are building a search engine and getting blocked you can always contact me and I'll make sure that the teams that work on bot detection and DDoS are aware. We would like to know because we should not be blocking a legit crawler like this.

What's the best way to contact you?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#138
post #56

Cloudflare is the professional wall builder you hire to protect your garden. Tech monopolies have always had a vested interest in locking up user data, dictating the policies, and enforcing their own ownership rights. It used to be that only the largest and most sophisticated companies had the resources to shield that data, but Cloudflare changed all that. Walls are now trivial to set up, and virtually unbreachable,…

No offense, this framing is so dumb. I hate it. The ‘Internet 3.0’ isn’t coming because of Cloudflare. It’s coming because these monolith big tech companies have an army of engineers who have been centralizing and building it this way for years. Cloudflare didn’t build these walls, it’s more of a giant boat now navigating it because other companies have no choice. I like to think of them as giant data ferryman in thi…

Clearly Cloudflare isn't responsible for the data centralization that is corrupting the internet. They are however, a very sophisticated and efficient enforcer of those policies. They've helped ensure large portions of the web is no longer crawlable, and that serves to consolidate information and power in those tech monopolies.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#139
post #29

Earlier quoted context omitted.

For instance there is no way for distributed search engines to work with CloudFlare. No, "contact me and we'll help" is not always a solution.

I've never been able to "reach a human" at Google, Facebook and other web giants and I'm skeptical that you can at a place like Cloudflare. In fact, I'd be really astonished it was possible, because otherwise their business isn't scalable.

while I share your sentiments regarding some other companies, I was able to get in touch with an actual cloudflare technician (and not some outsourced first level support with standard boilerplate replies) in a timely manner even on their free tier when I ran into a problem with one of their system. every support case with them has do far been a real pleasure compared to what you experience with other companies. I only hope they will be able to keep this level...

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#140

Earlier quoted context omitted.

I don't see us getting a massive innovation in search on the internet now that Google has such a massive foothold, and companies like Cloudflare stop innovation from happening. How are we "stopping search innovation"?

By being gatekeepers on which website crawling is okay and which is not. No such filters should exist. Is it really that awfully bad without anything but basic filters (ban an IP for flooding)? Are there like, operations that try and spam every single Cloudflare-hosted website 24/7? Legitimately curious if your anti-bot measures come from actual bad experience with the internet or is it just a liability limitation mo…

Cloudflare's customers request and then enable those features. Cloudflare itself doesn't give a damn about that traffic; they have bandwidth to spare. They will, however, happily sell tools to people that do care.

That isn't to say that the customers are savvy and have a good understanding of different types of automated traffic and which automated traffic is harmful and which is benign. Many have a quite naive understanding that doesn't extend beyond "bots = bad, unless it's Google" and dial protection settings to the max for no good reason.

Post reply on HN