Live data from Hacker News

The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

positiveblue.substack.com

311–320 of 520 posts

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#311

> The same is true online. A cryptographic signature that claims “I am acting on behalf of X” means nothing unless it is tied to something real, like a verifiable infrastructure or a range of IPs. Without that, I can simply hand the passport to another agent, and they can act as if they were me. The passport becomes nothing more than a token anyone can pass around. how does this person think jwt’s work?

Hi, "this person here" Cloudflare will block that request that has a jwt because "it does not come from a person".

What I was trying to say is that even the discussion "is this a bot 100% sure or not" makes no sense.

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#312
post #268

Earlier quoted context omitted.

Why was it OK for Google to incorporate their words into a for-profit search index which has increasingly sucked all the profit out of the system? My Ithaca friends on Facebook complain incessantly about the very existence of AI to the extent that I would not want to say I ask Copilot how to use Windows Narrator or Junie where the CSS that makes this text bold or sometimes have Photoshop draw an extra row of bricks i…

[flagged]

[flagged]

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#313

While I concur with the effective tech, I don't think this is something that's a net win for society. Just because you can, doesn't mean you should and I don't feel any one entity (private or public) should be an arbiter on these matters. This is something that can, and should, be negotiated at the "last virtual mile".

100% needs to be done at the last mile.

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#314
post #20

Everyone loves the dream of a free for all and open web. But the reality is how can someone small protect their blog or content from AI training bots? E.g.: They just blindly trust someone is sending Agent vs Training bots and super duper respecting robots.txt? Get real... Or, fine what if they do respect robots.txt, but they buy the data that may or may not have been shielded through liability layers via "licensed d…

Don't publish things if you don't want them published.

Get real yourself.

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#315
post #205
post #4

Earlier quoted context omitted.

AWS is an alternative no?

We were supposed to pentest a website on AWS WAF last week. We encountered three types of blocks: 1) hard block without having done any requests yet. No clue why. Same browser (Burp's built-in Chromium), same clean state, same IP address, but one person got a captcha and the other one didn't. It would just say "reload the page to try again" forever. This person simply couldn't use the site at all; not sure if that wo…

Shouldn't this be seen as success? You weren't a normal user, you were trying to penetrate the site, and you got a bunch of friction?

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#316

[flagged]

I could not give less of a shit between whitelist/allowlist. I use them indistinctly.

You can sleep peacefully today but you should try to don't over stress from how other people write on the internet

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#317
post #269

Earlier quoted context omitted.

Not everybody wants to manage some commercial grade packet filter that can handle some DDoSing script kiddie, it’s a strong argument. But another argument against using the easiest choice, the near monopoly, is that we need a diverse, thriving ecosystem. We don’t want to end up in a situation where suddenly Cloudflare gets to dictate what is allowed on the web. We have already lost email to the tech giants, try runni…

Please do try running your own mail some time. It's not nearly as hard as doomers would have you think. And if you only receive, you don't have any problems at all. At first, you can use it for less serious stuff until you see how much it works.

I do, I host my own mail server.

Technically it's not very challenging. The problem is the total dominance of a few actors and a lot of spammers.

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#318
post #217

The web doesn't need attestation. It doesn't need signed agents. It doesn't need Cloudflare deciding who's a "real" user agent. It needs people to remember that "public" means PUBLIC and implement basic damn rate limiting if they can't handle the traffic. The web doesn't need to know if you're a human, a bot, or a dog. It just needs to serve bytes to whoever asks, within reasonable resource constraints. That's it. Th…

"It needs people to remember that "public" means PUBLIC and implement basic damn rate limiting if they can't handle the traffic."

And publish the acceptable rate.

But anyone who has ever been blocked for sending a _single_ HTTP request with the "wrong" user-agent string knows that the issue website operators are worried about is not necessarily rate (behaviour). Website operators routinely believe there is no such thing as a well-behaved bot. Thus they disregard behaviour and only focus on identity. If their crude heuristics with high probability of false positives suggest "bot" as the identity then their decision is to block, irrespective of behaviour, and ignore any possibility the heuristics may have failed. Operators routinely make (incorrect) assumptions about intent based on identity not behaviour.

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#319

Earlier quoted context omitted.

> Everyone loves the dream of a free for all and open web. But the reality is how can someone small protect their blog or content from AI training bots? I'm old enough to remember when people asked the same questions of Hotbot, Lycos, Altavista, Ask Jeeves, and -- eventually -- Google. Then, as now, it never felt like the right way to frame the question. If you want your content freely available, make it freely avail…

Google (and the others) crawl from a published IP range, with "Google" in the user agent. They read robots.txt. They are very easy to block The AI scum companies crawl from infected botnet IPs, with the user agent the same as the latest Chrome or Safari.

Okay. Which, specifically, are the "AI scum" companies you're speaking of?

There are plenty of non-AI companies that also use dubiously sourced IPs and hide behind fake User-Agents.

Re: The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch

#320

Earlier quoted context omitted.

> Everyone loves the dream of a free for all and open web. But the reality is how can someone small protect their blog or content from AI training bots? I'm old enough to remember when people asked the same questions of Hotbot, Lycos, Altavista, Ask Jeeves, and -- eventually -- Google. Then, as now, it never felt like the right way to frame the question. If you want your content freely available, make it freely avail…

What if I want my content freely available to humans, and not to bots? Why is that such an insane, unworkable ask? All I want is a copyleft protection that specifically allows humans to access my work to their heart's content, but disallows AI use of it in any form. Is that truly so unreasonable?

It's not unreasonable to ask but I think it probably is unreasonable to expect a strictly technical solution. It feels like we're in the realm of politics, policy, and law.
Post reply on HN