Live data from Hacker News

Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

herrjemand.medium.com

201–210 of 294 posts

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#201
post #171

Earlier quoted context omitted.

Why is every and any TOR and sometimes VPN user deemed a DoS attack... it discriminates against users who value privacy by forcing hCaptcha on them by default. Worst of all... it could be a de-anonymization attack as well, hence why I as a regular TOR user, just exit the page immediately when that happens. For any of my pages that do happen to use Cloudflare, I am luckily able to disable this discrimination in the CP…

From experience, traffic via Tor was always 99%+ fraud.

You can conduct fraud by accessing public, read-only web pages? You can conduct fraud by searching on Google?

Those are the two I find repeatedly blocked when accessing via Tor. The former by Cloudflare, the latter by Google.

I use Tor to lookup phone numbers that have just called me, to decide whether it's a good idea to answer. Since I don't want to be personally associated with such numbers I prefer to search anonymously. But often it's impossible to get a result.

Sometimes even spending 5 minutes solving captchas isn't enough. (I'd only spend that long to see if it's just an outlier. No, it's quite common.)

This creates an immense pressure to tell various services exactly who is phoning me, which is a terrible attitude to privacy.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#202
post #199

Earlier quoted context omitted.

> You're missing a zero in that RTT for users in places like Asia if your server is anywhere in the west. Well, it does say 130 ms in here: https://www.quora.com/How-long-would-it-take-for-light-to-fl... And that's around the planet, to go around and end up at the same spot. In practice, with sanely-configured routes, your packets should never need to traverse more than half that distance. So, divide it by 2, then th…

There's no need to guess based on the speed of light. Test it yourself: https://www.cloudping.info For me, the highest was 310ms round trip to Singapore, so higher than your estimate but not too bad. But this is completely beside the point. As far as I know, if you're using a CDN effectively (i.e. a large proportion of requests are hitting cache), it should be cheaper than having all requests hit your server, not mor…

338 ms to Sydney is my worst. 234 ms to Singapore.

AWS does offer a CDN, right? Somehow they do it without captchas and without me ever noticing. So I'm somewhat right at cursing at cloudflare because it's the only one actually announcing its presence by actively disrupting your browsing.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#203
post #169

Earlier quoted context omitted.

> Yes, there will be 200 ms RTT in some cases. So what? Get over it. You're missing a zero in that RTT for users in places like Asia if your server is anywhere in the west. (It's actually somewhat revealing when someone throws out a number like this without any qualification; what exactly made you conclude 200ms is the magic number?) > Optimize your website to load in fewer round-trips. TCP congestion control adapts…

> You're missing a zero in that RTT for users in places like Asia if your server is anywhere in the west. Well, it does say 130 ms in here: https://www.quora.com/How-long-would-it-take-for-light-to-fl... And that's around the planet, to go around and end up at the same spot. In practice, with sanely-configured routes, your packets should never need to traverse more than half that distance. So, divide it by 2, then th…

I live in New Zealand, definitely a first world country with first world infrastructure. Ping times to US East or Europe are over 300ms right now from my home[1].

My old business had users in countries around the world, and the assets were highly optimised for speed. However adding CloudFlare (a) significantly sped up our service to clients, especially those in Asian countries, and (b) significantly improved reliability of connections because CloudFlare have their own dedicated network links between countries and/or optimised for reliability.

[1] https://www.cloudping.info/

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#204
post #185

Cloudflare captchas in particular, and any checks and roadblocks to see something publicly available in general, are terrible, period. It doesn't matter which form they take. Every time you see one you feel like a second-class citizen and get reminded that the internet is no longer what it used to be. I personally simply close the tab when I see a cloudflare "one more step" page.

what? Have you ever dealt with a DDoS attack and the consequences on your availability and infra health?

Are ddos attacks a common enough occurrence to warrant putting half the internet behind ddos protection? In my impression you need to do something really wrong to deserve one.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#205
post #153

The way I'd put it is that Cloudflare's suggested implementation may have its issues, but the general idea of trying to verify that someone is a human and then providing this verification to services in a way that is 1) anonymous and 2) cross-compatible with other services, is the correct way to go about things (or at least has some very appealing features). I hope that we have something in the future that does this…

Alternatively, if services demand a fee then there is no need for human verification. Instead of trying to solve anonymous human verification we can as well make micro-payment an option.

A small micropayment makes for a great way for bad actors to test stolen credit card numbers.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#206

Is CAPTCHA a necessity only in ad-sponsored web? Is there other compelling use-case for it? Can we make CAPTCHA obsolete with decent micropayments solution, when you pay for every transaction with every website, just like we pay for every drop of water we use? Perhaps ISPs could handle it for us?

I can't see that being very popular. Even if it doesn't actually cost you much in absolute terms, billing per page will make people a lot more reluctant to explore new content.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#208
post #185

Earlier quoted context omitted.

what? Have you ever dealt with a DDoS attack and the consequences on your availability and infra health?

Are ddos attacks a common enough occurrence to warrant putting half the internet behind ddos protection? In my impression you need to do something really wrong to deserve one.

That's unfortunately not true at all in my experience. Maybe if you're an anodyne SAAS, but if you host any user-generated content, especially if it's adjacent to gaming (my personal experience was mostly with gaming-related forums and IRC networks), politics or any other charged topic, expect to get hammered on a pretty frequent basis. IoT botnets are pretty easy to rent at this point, so the attack is accessible to every skid known to mankind.

I actually agree with your overall point as I try to use Tor for a lot of "normal" browsing, but I'm not sure what the correct solution to accommodate both is. It's a hard problem, and having been in that position myself I have a hard time faulting small website operators who have no alternative defenses.

e: just to add to this, I see the existence of ddosing as a significant driver towards centralized monolithic services. If your blog on Palestinian rights or whatever is getting hit, that's an incentive to move it to a platform that takes care of networking for you. It's a little absurd to go all-in on decentralized self-hosting without at least an acknowledgement that with current tech and typical personal-computing budgets, doing so is giving a heckler's veto to literally everyone. Cloudflare isn't the only dimension things can be centralized along.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#210

Once they have your ID info, they'll later change the terms to sell it to advertisers. Are they contractually committing to never doing that? No. So they will.

Even if they are contractually committed not to sell your info, that still might not save you:

“Yesterday, the bankruptcy court approved the sale over the objections of several parties, including the Federal Trade Commission (FTC) and third party manufacturers Apple and AT&T who sold products to the bankrupt retailers.

...

The FTC’s objection was made to the court-appointed consumer privacy ombudsman in the RadioShack bankruptcy. Specifically, the FTC’s letter alleged the sale of personal information constitutes a deceptive practice because in its privacy policy, RadioShack promised never to share the customer’s personal information with third parties.”

https://www.jdsupra.com/legalnews/radioshack-bankruptcy-cour...

In that case the judge allowed the sale of the information in contradiction to its commitments.

Post reply on HN