Live data from Hacker News

Precursor

blog.cloudflare.com

131–140 of 170 posts

Re: Precursor

#131

This (agent detection) is now a kind of emerging space. Obviously it'll get much more important, too. Other products in the space: - Foil ( https://usefoil.com/ ), I'm biased, a friend is building this - Kasada https://www.kasada.io/ - DataDome ( https://datadome.co/ ) - Castle ( https://castle.io/ ) - Fingerprint ( https://fingerprint.com/ ) - HUMAN ( http://humansecurity.com/ ) - Google Cloud Fraud Defense, which i…

Darwinium (darwinium.com) is another example. Approach here involves a combination of profiling and step-transition probabilities; idea is that a customer can ring-fence a particular area of a digital estate where they might want to challenge or block an agent - eg a payment, due to chargeback risks. Precursor at least for now seems more focused on site scraping multiple docs from the same site.

Re: Precursor

#132

Earlier quoted context omitted.

You also screwed up by using Firefox. That's the #1 method Google uses to prove someone is a bot. If you are't participating in the Google panopticon, you are suspect.

I haven’t used Firefox for personal browsing for maybe ten years or more now, so I’m not sure where this is coming from.

It was an assumption based on personal experience.

Re: Precursor

#133
>keyboard activity, focus changes, and visibility. These events are serialized into a compact format and buffered in memory. At regular intervals, the buffered data is sent back to the evaluation layer for analysis.

So it's a keylogger?

Re: Precursor

#134
post #69

Earlier quoted context omitted.

No, it's "jitter that mimics human cursor movements detected by Cloudflare's Precursor script". It'll just be another arms race.

Like any other detection system you will always have determined adversaries that put in the work to bypass it. But that doesn't mean you shouldn't still try to block the much larger number of less sophisticated/resourced adversaries that are using OOTB libraries and low-effort setups.

Sure, but of course since there's profit to be made defeating these systems once someone makes a program to defeat detection they'll sell it. Complicated attacks only stop simple attackers until a sophisticated attacker scripts & sells the exploit. Not that you shouldn't try, just don't expect defenses to last long-term.

Re: Precursor

#135

Earlier quoted context omitted.

I get flagged way more often on Starlink then I did on my local ISP fiber.

It's the odd latency changes. You'll see the same thing with certain streaming services.

I've seen it happen with a grocery store website, oddly enough.

Re: Precursor

#136
I think in 10/20 years from now, access to the Internet will be allowed only upon personal identification. Every website will be allowed to ask about your identity upon serving any content. Thats the only way I see this is going. The internet as it is right now does not have a future if majority of traffic will be done by agents. Thus, the cost of that traffic will have to be put on the users and since displaying ads doesnt make sense to agents, a paid access will be introduced (which is what cloudflare is slowly doing)

Re: Precursor

#137
post #45

So now instead of having the slow-axx Cloudflare turnstile slowing down your requests, you get surprised with a "You are a BOT!!!" while you are conducting your business on a website. I already quickly close any website that I do not need for business purposes when it shows me the Cloudflare spinner. Now I might have to start considering competitors who do not implement this shit.

Turnstile already does the "You are a BOT!!!" thing btw, if it thinks you're a bot, which is quite rare as it seems much more permissive than systems like reCAPTCHA.

Re: Precursor

#138

Earlier quoted context omitted.

The complaint is that the offer is a great deal with no downsides for consumers, and this is likely to result in Cloudflare having a lot of power (which they currently don't have) as a market maker. This position as market maker would grant them the power to extract economic rent from the web economy by charging both sides of the web provider and web consumer market to get access to the other.

So the complaint is that one day they have such a strong monopoly that they can freely turn evil? Just want to make sure I understand the real issue here, because that sounds like a lot of fearmongering to me.

Uhhh, they have it right now, and they are currently being evil by blocking a lot of people from accessing a lot of websites.

Re: Precursor

#139
post #12

It’s a bit alarming how cloudflare is establishing itself as arbiter of all things bots…both on blocking and allowing. Doesn’t seem healthy for the internet as a whole

Gonna zag here. If you take a step back, cloudflare has been paving the path for pay for crawl. I think it's a noble and ambitious goal. While I can understand why you would be alarmed, I can point to almost two decades of lamenting on this forum about how we need better ways of rewarding content creators than ads. Well, this is it. Moreover, these products weren't built in a vacuum. Most threads about Anthropic and…

What's incredible is that you have businesses paying CloudFlare to stop their content being ingested by AIs (OpenAI, Anthropic, Self-operated scrapers).

And at the same time, they're paying SEO experts to make that same content easier to be ingested by systems (Google and other Search Engines) which use it for their own AI offerings.

Are you going to be able to make your online content available to Google Search but unavailable for Google Gemini?

Re: Precursor

#140
post #34

control+F accessibility no results Yeah so this mouse movement astrology is going to completely lock non-sighted/keyboard only users out of large swaths of the Internet isn't it.

I'm guessing it's going to lock the non-sighted//keyboard only users out of the anonymous Internet. I'm guessing if you log in and give up your anonymity they'll consider you not a bot.

If that's true, attackers just need to run their bots under registered throwaway accounts...
Post reply on HN