Live data from Hacker News

Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

herrjemand.medium.com

241–250 of 294 posts

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#241

Earlier quoted context omitted.

If you're on 3G I would expect sites to load in a similarly bad way with or without an extra most of 200ms of RTT.

The throttling in dev tools is meant to represent that latency...

If setting it to 3G is supposed to represent just 200ms latency, that's going to give you a very exaggerated and misleading impression of how bad it is. It's a meaningless test.

I thought you were giving an example of how bad connections can get, and saying that the extra latency would make it worse, but in that situation it's a drop in the bucket.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#242

Earlier quoted context omitted.

> Each key is associated with a batch of devices, though. If you ban a key, you risk banning a bunch of legitimate users. You're right. I meant Cloudflare could ban the generated public-key and not the device's public-key itself. Besides, they could also mark the batch as being taken over by bots and increase the level on challenges issued to the batch. Note though, a single secure module can only generate / store so…

> For instance, Yubi Key 5 supports up to 25 keys This is for resident keys. A YubiKey 5 supports an infinite number of non-resident WebAuthn keys, because the returned key handle will simply be the private key encrypted with a master key stored on the YubiKey. For authentication the service will send the stored key handle back to the YubiKey which then can decrypt it and use the decrypted private key to sign the cha…

TIL.

Envelope encryption. Neat. Can WebAuthn keys be (made) a resident key? If so, is that preferred instead?

Conversely, what use case is there for resident keys in context of WebAuthn? For example, if there are multiple master keys, can I switch between them per browser / website (assuming the master key itself is a resident key and not burnt into the element)? Thanks.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#243
post #229
post #119

Earlier quoted context omitted.

Why would you possibly think you can do whatever you want to someone else's site? Yes, you must adhere to the controls that site administrators put in place, like Cloudflare.... You don't get to blast my site with requests, just because you want to...

(a) Who said I was blasting your site with requests? Cloudflare stops much more than just blasts (b) But you’re a-ok with Google doing this. Gated communities aren’t really good for anybody but I see what you are saying.

Gated communities are great. They lower the risk of crime significantly: https://www.sciencedaily.com/releases/2013/03/130320115113.h...

The same is true online. Apple's walled garden has kept hundreds of millions of people safe on their device. It's why iOS malware isn't a thing.

> Cloudflare stops much more than just blasts

Exactly. There's even more benefit to Cloudflare than just DDoS. Captcha's for stopping credential stuffing, for example.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#244
post #181

Earlier quoted context omitted.

Then what does the 200ms have do with "writing an app"?

Apologies, your username looks like the one that tossed that number out as a what they assumed was a high number. 200ms latency isn't that bad, but I'm seeing more 800-2000ms latencies with some users depending on physical location. at some point latency kills usability. Especially when trying to get through a complicated QA or inventory process.

That latency is literally impossible unless they’re up in space somewhere, beyond satellite orbit. Your latency is most likely caused by CPU on low-end devices. A CDN won’t help you with that (and probably be harmful having to manage another TCP connection).

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#245

Could this be solved (in large part) if key makers like YubiKey did I.D. verification on purchase? Then, to do the type of "farming" that's mentioned in this article, you'd need to organize a large group of people to all buy the keys rather than just submit a bulk order to Alibaba. Of course this idea raises privacy and authority concerns, similar to certificate authorities.

> key makers like YubiKey did I.D. verification on purchase?

I think that would require that every key maker would have staff in every city in the world who were trained to inspect your identity documents, check for forgeries, and not be susceptible to bribes or coercion.

Or at the very least every city would have to contain at least one location where someone from some organisation (possibly the government) could carry out this process.

The "authority" concern would require that the verifying organisation could be blacklisted if they started giving out too many IDs to the wrong people, or refusing to give IDs to the right people. (Perhaps you've played the game "Papers, Please".)

It's the "privacy" concern that worries me more. What happens if someone tries to buy a second key? Presumably there is a limit to how many each person can buy, so if someone says they lost their previous key, the issuer needs a way of revoking it. But how do they do that without creating a valuable list somewhere of which key belongs to which real world ID?

To make matters worse, because people can move between cities and jurisdictions, this database of online IDs would need to be globally shared between all verifiers, otherwise you could just buy multiple IDs from multiple vendors. That means the database that ties your browsing history to your legal identity will be accessible to basically everyone in the world, because the access to that database will only be as secure as its weakest link.

If we're going down this route, we might as well put everyone's identity onto a blockchain and let people vouch for each other in order to establish trust/reputation. In fact, that sort of system has actually been implemented; it's called BrightID, and it "requires no personal information, letting you prove your humanness without risking your privacy".

https://www.brightid.org/

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#246

Reading CF's blog announcement [1], this is really horrifying. It trains users to insert security keys and accept biometric identification requests when visiting random web pages, on random untrusted domains. This cannot possibly end well. [1]: https://blog.cloudflare.com/introducing-cryptographic-attest...

Do you think it won't become normal for people to present a fingerprint or a face scan in order to buy and sell things online? We already have a similar process for people visiting businesses during a pandemic.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#247
post #171

Earlier quoted context omitted.

Why is every and any TOR and sometimes VPN user deemed a DoS attack... it discriminates against users who value privacy by forcing hCaptcha on them by default. Worst of all... it could be a de-anonymization attack as well, hence why I as a regular TOR user, just exit the page immediately when that happens. For any of my pages that do happen to use Cloudflare, I am luckily able to disable this discrimination in the CP…

Because that's a not insignificant portion of traffic they see from tor and vpns? tor has some absolutely valid and import use cases, but what percent of tor exit traffic is actually someone trying to keep their traffic anonymous from the eyes of an oppressive regime, and what percent are script kiddies, or someone hiding torrenting from their isp?

Are you one of those people that answers the door with a gun, even when you’re expecting a friend?

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#248

Even if we ignore the technical reasons, for me CloudFlare's proposal fails at their "Associate a unique ID to your key" property, where they say CloudFlare could, but won't do it. If they implement this scheme they start normalising this approach. Once it gets to FB and Google implementation, their answer will be: we could, but we... look! a squirrel!

Their document says, correctly, that the means by which they could try to do this would be to shove the arbitrary random ID they get into a cookie. You may have noticed that both Facebook and Google already use cookies. Did you know Hacker News has a cookie too?

Did you know Hacker News has a cookie too?

There's a difference between being logged in to an account on a single site, and letting Big Tech track you across most of the Internet.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#249

Earlier quoted context omitted.

Are ddos attacks a common enough occurrence to warrant putting half the internet behind ddos protection? In my impression you need to do something really wrong to deserve one.

Yes, they absolutely are. Hell just getting a few random bots scraping stuck in a loop or being overly aggressive on your site is enough to double your bill. So yeah it's 100% required.

> to double your bill

Do you pay a variable amount for your hosting? How and why? All VDS and dedicated server offerings I've ever seen are fixed amount per month. And more often than not the network is limited by speed, not by data transfer.

Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea

#250

Earlier quoted context omitted.

Yes, they absolutely are. Hell just getting a few random bots scraping stuck in a loop or being overly aggressive on your site is enough to double your bill. So yeah it's 100% required.

> to double your bill Do you pay a variable amount for your hosting? How and why? All VDS and dedicated server offerings I've ever seen are fixed amount per month. And more often than not the network is limited by speed, not by data transfer.

In that case then the service will just hang as it won't handle the requests caused by even a simple malfunction (not even an actual attack) like the one mentioned by GP.

Mind you, I see your point and I generally don't like the captchas either, but it is definitely a trade-off and I won't blame webmasters that use the DDoS protection.

Post reply on HN