Live data from Hacker News

ChatGPT won't let you type until Cloudflare reads your React state

buchodi.com

261–270 of 668 posts

Re: ChatGPT won't let you type until Cloudflare reads your React state

#261
post #166

Earlier quoted context omitted.

Is anyone talking about the fact that this is a fundamental design flaw of the web? Or arguably even the entire Internet?

It's hard to call something a "fundamental flaw of web" if it wasn't an issue for 30 years. Unless you mean something more general that I'm missing.

Cloudflare isn't providing Turnstile as a service in a vacuum, this is a direct response to bad actors who can trivially abuse the web.

Re: ChatGPT won't let you type until Cloudflare reads your React state

#262

Hey! I'm Nick, and I work on Integrity at OpenAI. These checks are part of how we protect our first-party products from abuse like bots, scraping, fraud, and other attempts to misuse the platform. A big reason we invest in this is because we want to keep free and logged-out access available for more users. My team’s goal is to help make sure the limited GPU resources are going to real users. We also keep a very close…

I don't trust what OpenAI says. Sam Altman gives shivers, and these kinds of blog posts make things look even worse.

Re: ChatGPT won't let you type until Cloudflare reads your React state

#263
post #109

Earlier quoted context omitted.

Brilliant! Just the thing we want: more hardware attestation, more deanonymization, less user control, all diligently orchestrated in a repository where the only contributor is Anthropic Claude [0]. Comes complete with a misaligned ASCII diagram in the README to show how much effort the humans behind it put in! Yes, even their "humanifesto" is LLM output, and is written almost exclusively in the "it's not X it's Y" s…

> Yes, even their "humanifesto" is LLM output, and is written almost exclusively in the "it's not X it's Y" style. ....no. There's not a single occurrence of that. https://keywitness.io/manifesto There are six emdashes on that page. NONE of them are "it's not X it's why". > Emails, messages, essays, code reviews, love letters — all suspect. > We believe this can be solved — not by detecting AI, but by proving humanit…

From their “how it works” page:

> The server stores an encrypted blob it can't decrypt. We couldn't read your messages even if we wanted to. That's not a policy — it's math.

If you can’t tell that this is AI slop then maybe KeyWitness does solve a real problem after all.

Re: ChatGPT won't let you type until Cloudflare reads your React state

#264

Earlier quoted context omitted.

> Yes, even their "humanifesto" is LLM output, and is written almost exclusively in the "it's not X it's Y" style. ....no. There's not a single occurrence of that. https://keywitness.io/manifesto There are six emdashes on that page. NONE of them are "it's not X it's why". > Emails, messages, essays, code reviews, love letters — all suspect. > We believe this can be solved — not by detecting AI, but by proving humanit…

It's either a bot, or someone who writes exactly like a bot. I don't care which it is, both go to the discard pile.

It’s a product for people who need help telling whether text was written by AI.

Maybe they deliberately write it like that, to filter out people who aren’t the target market?

Re: ChatGPT won't let you type until Cloudflare reads your React state

#265
post #166

Earlier quoted context omitted.

Is anyone talking about the fact that this is a fundamental design flaw of the web? Or arguably even the entire Internet?

It's hard to call something a "fundamental flaw of web" if it wasn't an issue for 30 years. Unless you mean something more general that I'm missing.

Arguably it didn’t see widespread commercial adoption for 30 years, and you wouldn’t expect fundamental design flaws regarding commercial incentives to manifest before that.

Re: ChatGPT won't let you type until Cloudflare reads your React state

#266
post #162

Earlier quoted context omitted.

Doesn’t really make sense, because any service can just say “you must paste your human-attestation JWT here to use this service” and plenty of people will.

You can just decay your trust level based on the `iat` value. That way people will need to keep buying me coffee. I can optionally chide them for giving out their token. If you're engaging with the idea seriously, I suppose we'd need to build a reputation or trust network or something. Although if you're talking about replay attacks specifically, there are other crypto based solutions for that.

My point is that there probably is no way in principle to distinguish between a human user utilizing automation on their own behalf in good faith (e.g. RSS readers) and bad faith automations.

Re: ChatGPT won't let you type until Cloudflare reads your React state

#267
post #149

Earlier quoted context omitted.

It's interesting to me that OpenAI considers scraping to be a form of abuse.

Scraping static content from a website at near-zero marginal cost to its server, vs scraping an expensive LLM service provided for free, are different things. The former relies on fairly controversial ideas about copyright and fair use to qualify as abuse, whereas the latter is direct financial damage – by your own direct competitors no less. It's fun to poke at a seeming hypocrisy of the big bad, but the similarity…

And yet I have to pay in my time and cash to handle the constant ddos'es from the constant LLM scraping

Re: ChatGPT won't let you type until Cloudflare reads your React state

#268
post #79

Earlier quoted context omitted.

Meet me in a cafe and I will sign a JWT saying you're not a bot. You can submit this to whoever will accept it.

If apple approves it, ive got a solution: A keyboardthat attests to your humanity https://typed.by/magicseth/2451#2NyGLfAQxmqRiAOTlaX7ma3G4d1o...

You’re getting a negative reaction from others but I share this feedback in good faith: I don’t understand what problem your product is supposed to solve.

Yeah I guess the cryptographic stuff sounds vaguely impressive although it’s been a long time since I had to think about cryptography in detail. But what is this _for_? I’m going to buy an expensive keyboard so that I can send messages to someone and they’ll know it’s really me – but it has to be someone who a) doesn’t trust me or any of our existing communication channels and b) cares enough to verify using this weird software? Oh and it’s important they know I sent it from a particular device out of the many I could be using?

Who is that person? What would I be sending them? What is the scenario where we would both need this?

Also the server can’t read the message but the decryption key is in the URL? So anyone with the URL can still read it? Then why even bother encrypting it?

Maybe this is one of those cases where I’m so far outside your target market that it was never supposed to make sense to me but I feel like I’m missing something here. Or maybe you need to work on your elevator pitch.

Just sharing my honest reaction.

Re: ChatGPT won't let you type until Cloudflare reads your React state

#269
post #149

Hey! I'm Nick, and I work on Integrity at OpenAI. These checks are part of how we protect our first-party products from abuse like bots, scraping, fraud, and other attempts to misuse the platform. A big reason we invest in this is because we want to keep free and logged-out access available for more users. My team’s goal is to help make sure the limited GPU resources are going to real users. We also keep a very close…

It's interesting to me that OpenAI considers scraping to be a form of abuse.

[flagged]

Re: ChatGPT won't let you type until Cloudflare reads your React state

#270

Earlier quoted context omitted.

The sooner we do the better.

I wonder what the PGP signing concept does to thwart people who want to profit and don't care about the public good. It seems like anyone who attends a signing party can sell their key to the highest bidder, leading to bots and spammers all over again.

In the flat trust model we currently use most places, it's on each person to block each spammer, bot, etc. The cost of creating a new bot account is low so it's cheap to make them come back.

On a web of trust, if you have a negative interaction with a bot, you revoke trust in one of the humans in the chain of trust that caused you to come in contact with that bot. You've now effectively blocked all bots they've ever made or ever will make... At least until they recycle their identity and come to another key signing party.

Once you have the web in place though, a series of "this key belongs to a human" attestations, then you can layer metadata on top of it like "this human is a skilled biologist" or "this human is a security expert". So if you use those attestations to determine what content your exposed to then a malicious human doesn't merely need to show up at a key signing party to bootstrap a new identity, they also have to rebuild their reputation to a point where you or somebody you trust becomes interested in their content again.

Nothing can be done to prevent bad people from burning their identities for profit, but we can collectively make it not economical to do so by practicing some trust hygiene.

Key signing establishes a graph upon which more effective trust management becomes possible. It on its own is likely insufficient.

Post reply on HN