Live data from Hacker News

Cloudflare Turnstile requiring fingerprintable WebGL

hacktivis.me

301–310 of 508 posts

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#301

Earlier quoted context omitted.

it's all for nothing, because Cloudflare's scraping protection works about as well as a $5 padlock - good enough to dissuade bored teens, not good enough to dissuade even an amateur burglar. if someone wants to scrap your publicly visible data, they will. there's nothing you can do.

> Cloudflare's scraping protection works about as well as a $5 padlock It sure seems to keep me, the casual visitor, far away from just about any site they "protect". I have zero desire to alter my browsing configuration or use extra tools to get around turnstile, I'd rather not even visit the site in the first place.

>, I'd rather not even visit the site in the first place

Until your bank, airline, and tax ministry start using them.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#302
post #38

So if you need to prevent bot abuse, but also don't want an ugly captcha every time someone goes to sign up, is there a better option?

Use proof-of-work captchas, many are private by default. Look into Private Captcha or Cap captcha.

Can this be repurposed as some kind of distributed cryptocurrency mining mechanism? Pay websites by mining some monero in order to access them?

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#303
post #196

Earlier quoted context omitted.

A small, single EU country focused non-static e-commerce, with proper robots.txt instructions that worked perfectly well in the search & co bots -only "era" with rate limiting for nginx/php-fpm setup - is kinda struggling without CF to handle 15000 requests per 15 minutes, coming from Chrome "users" from IPv6. Best so far was an avg. server load in htop = 40 on an 8-core server x_x

That's 16.6rps. A single guy holding the F5 key on chrome can generate that much traffic and take down your website. That kind of performance was never acceptable.

People will always reframe their request numbers to avoid stating their pitiful requests per second numbers, it's hilarious. "This thing is handling hundreds of thousands of requests per day!" Like cool, you're barely making it double digit requests per second.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#304
post #96

Cloudflare is known to use fingerprinting to detect scrapers For example, they use JA3 fingerprints and match them against the UA to block stuff like cURL while allowing OkHttp (Android clients) - but this can be easily be spoofed with packages such as CycleTLS [1]. I don't want to defend them, because they gate away a good chunk of the internet with their "bot protection", but unless you do PoW (which is also ecolog…

> I don't want to defend them, because they gate away a good chunk of the internet with their "bot protection" They also gate away a good many people with their "bot protection". I am extremely worried about how so many seem to have outsourced the control over who can access their websites to a company, with no second thoughts whatsoever.

> with no second thoughts whatsoever

As someone responsible for mitigating card testing "attacks", account harvesting, and DDOS attacks..

It is unfortunate, but the ISP industries(from telco up to transit) and CC industries aren't providing a lot of great options. This idea that people are doing things "without a second thought" is usually false when it comes to businesses.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#305

Earlier quoted context omitted.

Yes, circumstantial is exactly the point; it's easy to use AI as a scapegoat because it's something popular to hate on.

It's circumstantial evidence, but Occam's Razor also applies. It's not a hostile DOS in the traditional sense (I've mitigated a few of those) - no "pay us to make it stop", no pattern to the requests other than "fetch every unique URL a few times". It wasn't happening until financial incentives to gather large datasets for AI training appeared. Bad actors (using residential proxies & claiming to be a real browser) mo…

no "pay us to make it stop"

"use Cloudflare to make it stop"

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#306

I always like the axiom with crime that once X% of the population are violating a statute then it should probably struck off. Recreational drugs being the obvious example. If randomized canvas stuff was cracked down upon as a bot thing but now everyone with a copy of Firefox is doing it, maybe Cloudflare should just “legalize” it?

Everyone with a copy of Firefox is about 2% of the web.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#308

Earlier quoted context omitted.

Cloudflare will just tell them that 70% traffic drop is because 70% of their traffic was bots, and everything is working fine, and hey, don't you want to upgrade to a paid plan to block 50% of the remainder? Think about how many bots will be blocked with that upgrade!

Do you really stand by these words?

[dead]
Post reply on HN