Live data from Hacker News

Web Bot Auth

developers.cloudflare.com

41–50 of 77 posts

Re: Web Bot Auth

#41

Earlier quoted context omitted.

Disagree. Not everybody wants their sites scraped and their content used to train a model that they'll never see a penny from. Cloudflare is the only party who wants to build a system where both the models and individual sites have their interests respected.

Then put up a goddamn login wall. The internet was designed to work the way it does for good reasons. You not understanding those reasons is not an excuse for allowing a giant tech company to step in and be the gatekeeper for a huge portion of the internet. Nor to monetize, enshittify, balkanize, and fragment the web with no effective recourse or oversight. Cloudflare shouldn't be allowed to operate, in my view.

> You not understanding those reasons is not an excuse for allowing a giant tech company to step in and be the gatekeeper for a huge portion of the internet.

Are you somehow under the impression that Cloudflare is forcing their service on other companies? They’re not stepping in, the people who own those sites have decided paying them is a better deal than building their own alternatives.

Re: Web Bot Auth

#42
I like that parsable signature in the http message however I dont quite understand how the system differentiates between human users and an llm agent controlling a browser

Re: Web Bot Auth

#43

No offense, but screw CloudFlare, screw their captchas for humans, and screw their wedging themselves between web operators and web users. They can offer what they want for bots. But stop ruining the experience for humans first.

> screw their wedging themselves between web operators and web users Web operators choose to use them; hell they even pay Cloudflare to be between them. Seriously I just think you don't understand how bad it is to run a site without someone in-front of it.

I run a site that is a primary source of information. We also have customers that subscribe and are very sensitive to heavy handed controls. Before cloudflare and after "AI" we had bots from all over just destroying our endpoints with bursts of mining traffic. While we would love to have more discoverability this is not that. Cloudflare is in a tough spot trying to arbitrate good traffic vs bad. From my experience they are doing this as good as one can.

Re: Web Bot Auth

#44
post #7

Earlier quoted context omitted.

Disagree. Not everybody wants their sites scraped and their content used to train a model that they'll never see a penny from. Cloudflare is the only party who wants to build a system where both the models and individual sites have their interests respected.

Are you sure that CF can stop AI bots?

I will tell you that we have had bot super fight mode on for a year and since then we have not had to address abusing traffic nor deal with legitimate people blocked. There is no way we could have achieved such balance. prior to that it was me blocking every Chinese AS under the sun as they shifted and bombarded us with traffic

Re: Web Bot Auth

#45

Earlier quoted context omitted.

Your browser is configured to disable cookies. Anubis requires cookies for the legitimate interest of making sure you are a valid client. Please enable cookies for this domain. Thing is, my browser isn’t configured that way. So works well, I guess.

The target was better than cloudflare, which also demands cookies but with more tracking. This is still better.

I have not disabled cookies. Cloudflare works fine. Users being able to access a website is a pretty important metric when considering which is ‘better’.

Re: Web Bot Auth

#47

I disagree with the other top-level comments at the moment: I believe Web Bot Auth is a useful and non-centralized emerging standard for self-identifying bots and agents. This press release today is a better statement of _why_ this feature exists (as opposed to the submission link, which is nuts-and-bolts of implementing): https://blog.cloudflare.com/signed-agents/ Web Bot Auth is a way for bots to self-identify cryp…

The problem with this is that key generation is free, so being a well-behaved unknown bot is the same as being an unidentified bot, which means that you go in the block/captcha/throttle bucket.

It is only useful for whitelisting bots, not for banning bad ones, as bad ones can rotate keys.

Whitelisting clients by identity is the death of the open web, and means that nobody will ever be able to compete with capital on even footing.

Re: Web Bot Auth

#48

Cloudflare's verified bots program is a terrible idea. They want to be the central chokepoint for agents, and they're doing it in shady ways like auto enrolling customers into blocking agents.

That’s not shady, that’s awesome customer value! Bot blocking as Default option is a great choice for all of us.

Re: Web Bot Auth

#49

Cloudflare's verified bots program is a terrible idea. They want to be the central chokepoint for agents, and they're doing it in shady ways like auto enrolling customers into blocking agents.

That’s not shady, that’s awesome customer value! Bot blocking as Default option is a great choice for all of us.

It's discriminatory against robots and helps make the web even more locked down. DRM never works; the analog hole is always the nuclear option.

In the end, only people with non-mainstream browsers (or using VPN to escape country-level blocks, or Tor, or noJS) suffer.

It's like how anti-piracy measures only affect paying customers, while pirates ironically get a better experience. The best way to get around endless CAPTCHAs is to just use LLMs instead.

Re: Web Bot Auth

#50
post #7

Earlier quoted context omitted.

Are you sure that CF can stop AI bots?

I will tell you that we have had bot super fight mode on for a year and since then we have not had to address abusing traffic nor deal with legitimate people blocked. There is no way we could have achieved such balance. prior to that it was me blocking every Chinese AS under the sun as they shifted and bombarded us with traffic

> nor deal with legitimate people blocked

How are you so sure of that? Their marketing?

Post reply on HN