Live data from Hacker News

Cloudflare Turnstile requiring fingerprintable WebGL

hacktivis.me

341–350 of 508 posts

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#341

> Plus privacy.resistfingerprinting isn't enabled even when selecting "Strict" "Enhanced Privacy Protection" in the settings, great job there Mozilla. For good reason. I've run that setting for ages but I kept having to disable it and add workarounds because websites would break in weird ways. Timezones in scheduling websites being messed up nearly made me miss a couple of appointments. There's no way to tell the use…

> Timezones in scheduling websites being messed up nearly made me miss a couple of appointments.

The reason for spoofing the time zone (to UTC) is that it is one of the many things used to fingerprint users. There is an unintended side effect however: a mismatch with the IP geolocation could out you as a VPN user even if no VPN is actually used.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#342

In other words, Cloudflare requires you to substantially increase your browser’s attack surface in order to visit websites.

You're not quite going far enough. Cloudflare requires that you allow it to attack your browser, as a sort of virtual hazing ritual, before you're allowed into the club. That this hazing makes your browser vulnerable to attacks by others too is a side effect that bothers them not at all.

Ah yes, the TSA of the internet.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#343
post #157

Earlier quoted context omitted.

I can no longer access any website that's "protected" by Cloudflare. As soon a website enables that stuff… "Shoot, another one bites the dust." I wonder if the website owners realise at all how many actual users they lose by this sort of "protection."

>I wonder if the website owners realise at all how many actual users they lose by this sort of "protection." How many people do you think are browsing with a weird enough config (eg. custom browser like OP, or some weird config like firefox with fingerprinting protection on a raspeberry pi) to trip cloudflare's protection?

Weird? I live in Thailand, use Firefox, and get half a dozen CF challenges per day.

It takes very little for CF to consider you "weird".

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#344

"Your browser appears suspicious because it looks like you are trying to hide your identity" Another case of the much predicted downfall of freedom due to "people who hide themselves must have something to hide, so they are automatically suspicious"

CF business model heavily relies on fearmongering, so what we can expect?

They send these emails you know? "CF saved you XXX Gb of data and protected your from YYY attacks". I have few high load web sites which I turned CF on for a while. Knowing my traffic pretty well, I can say these "CF saved you XXX Gb of data and protected your from YYY attacks" is absolute bullshit with numbers greatly exaggerated.

Since wwe can't catch them on this lie, they can put any number they like to make their "service" attrractive.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#345

Earlier quoted context omitted.

no "pay us to make it stop" "use Cloudflare to make it stop"

Or fastly, or akamai, or bunny, or any number of other providers. Cloudflare are merely the cheapest of the bunch.

Exactly. They (and most of all, Big G) stand to profit greatly from this browser discrimination. What better than to make more sites use them by launching DDoS attacks in the name of "AI scraping".

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#346
post #93

Cloudflare is known to use fingerprinting to detect scrapers For example, they use JA3 fingerprints and match them against the UA to block stuff like cURL while allowing OkHttp (Android clients) - but this can be easily be spoofed with packages such as CycleTLS [1]. I don't want to defend them, because they gate away a good chunk of the internet with their "bot protection", but unless you do PoW (which is also ecolog…

> but unless you do PoW (which is also ecologically a nightmare) Can you expand? I don't see a problem with some napkin math. 5W load for 2 seconds is 0.002Wh (we have to let smartphones pass and not by doing PoW for 10s of seconds). 8 billion checks a day for a year = 8GWh.

8 billion checks per day sounds on the low end. I can imagine it being ten or hundred times more. That still seem pretty fine though. On the other hand, it's hard to see that such a modest energy cost would dissuade any attacks.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#347
post #317

Earlier quoted context omitted.

That is not a good excuse for requiring overly complicated and overly specific software.

Every HN thread is full of people who think webmasters should just pay through the nose to handle bot traffic to preserve the sacred rights of turbonerds to visit their website using Lynx on their toaster.

I should think that there should be a better way (e.g. port knocking, instructions for manually correcting the URL that cannot easily be automated, additionally supporting alternative protocols, etc).

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#348
post #69

Earlier quoted context omitted.

Because it destroys the economics of scraping. It’s too expensive with proof of work, or at least not as economically viable

Depends on what type of scraping you're trying to stop. For the dumb scrapers that would try to scrape every page on a git forge (for which there are a bazillion pages for a modest project, because of how the site works), yeah it might deter them enough to stop. For anything high value (eg. reddit comments or retail prices), 10s of cpu time isn't going to stop them.

You can just download all of Reddit from torrent sites

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#349
post #164

Earlier quoted context omitted.

The problem is what is the alternative? I'm (not) defending them or this practice by any measure, but we all know what happens if you just open your site up without these, especially with AI bots which hammer servers and are in effect a legalized DDoS system. I've hated CAPTCHAs ever since I first encountered them and I can't wait for them to just finally die a permanent death, but I also don't know how we solve the…

I think there's some chance we get a "proof of purchase" system where there is some entity that takes a $10 payment to give out a unique identity token that you need to present to visit most sites. if you have a revocation process for ones used for bad actors, it seems like it would work pretty well.

Except if your country is under sanctions.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#350
post #296

Earlier quoted context omitted.

They showed up when the AI money did. The evidence is circumstantial, but… some of them are remarkably well engineered (from a “how difficult is it to identify this traffic” perspective, in a way that never existed before (I have been running a quite sizeable site for 8 years, over 200k registered users, and you don’t need to register to use 99% of it).

I run a quite large website and there are a few patterns. The usage is extremely quick, and follows easy-to-spot patterns. We noticed a spike in bounce rate. They never come from Google, and the bad programmed ones just crawl several pages at a time, faster than a user could do. Then there's the crazy spikes in visits from specific countries, pretty much scraping the entire content. Often from pools of IPs. In some c…

> They never come from Google, and the bad programmed ones just crawl several pages at a time, faster than a user could do.

I’ve triggered this kind of “bot protection” right here on Hacker News many times. I did that by having a bunch of Hacker News pages open and then closing and reopening my browser. I’ve also triggered it by opening a bunch of links in the background too quickly. I’ve also triggered it by reading the article, then clicking back and upvoting/favouriting too quickly. I’m also located in Singapore, which people have started to advocate for blocking here recently.

A single non-bot legitimate user can easily trigger these kinds of heuristics just by using the site in a way you don’t expect. This can affect some users disproportionately more than others, e.g. disabled people who need to use assistive technology.

Post reply on HN