Live data from Hacker News

Cloudflare Turnstile requiring fingerprintable WebGL

hacktivis.me

431–440 of 508 posts

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#431
post #85

Earlier quoted context omitted.

This is why I have two separate browsers. If you want to do official stuff like paying for things you need to get through cloudflare.

You can use Firefox with different profiles and configure it to launch particular profile directly, without launching default profile and using about:profiles. Firefox with a non-default profile can be created like that: ./firefox -CreateProfile "profile-name /home/user/.mozilla/firefox/profile-dir/" # For, say, cloudflare that would be: ./firefox -CreateProfile "cloudflare /home/user/.mozilla/firefox/cloudflare/" An…

What does profile-switching provide that switching containers within a single profile doesn't?

Edit: I RTFA'd, containers can't adjust `privacy.resistfingerprinting`. Boo

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#432

Earlier quoted context omitted.

I would like my browser to not pass their challenge and then flush support of services I cannot reach. This is the only way for them to stop, to really get on the nerves of their customers. Those might ignore it, but there are always alternatives.

That is delusional. Nobody is getting on anyone’s nerves, materially. The people who care about this are a rounding error of a rounding error.

It’s always amusing when someone brings up the “just tell banks that if they reduce account takeovers by 80%, it will drive off 3 customers a year (and those are the same 3 customers who call site support to complain the website doesn’t work well on their homebrew Chromium for when running on BSD”

Cloudflare only exists in its current form because banks and such already enthusiastically accepted that trade off.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#433

Earlier quoted context omitted.

I stand corrected. It's not a nightmare scenario (as for Bitcoins) - but I'm still of the idea that "useless" computations should be avoided (as we should avoid having 10MB websites). In any case, according to some napkin math done by Kimi 2.6 (which by itself is probably already consuming more than all of my PoW challenges for the upcoming 5 years) - the situation looks incredibly in favor of PoW: https://www.kimi.c…

There's a saying that if an idea is stupid, but it works, it's not stupid. If some computation is "useless" but it serves it's purpose, it's not useless. The reason why bitcoin network expends so much energy is down to tokenomics, not the system of PoW itself. At equilibrium we expect the power usage to be (blocks/hr) x (BTC/block) x ($/BTC) x (kWh/$), so it's a function of the BTC price and emission rate. PoW in oth…

I mean coal power plants work, so building new ones is not stupid by that standard.

I think we have to expand the definition of stupid to include things that work but have net negative externalities. Not sure where PoW falls in that way of looking at things, but we should at least consider it.

(Thinking about it, Captcha is PoW, just theoretically work by the human)

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#434
post #106

Earlier quoted context omitted.

Because it doesn’t solve the problem of residential botnets.

Why not? PoW challenge doesn't whitelist botnets. If the dumb scraper makes only get requests and doesn't solve the challenge, it doesn't matter how it connects, even if it's a perfectly hidden tor exit node.

Because the work would be done by the compromised residential device. No bothnet owner is going to care if their 100,000 rooted routers have to do a little more work. It’s still “free” from their perspective.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#435
post #317

Earlier quoted context omitted.

Every HN thread is full of people who think webmasters should just pay through the nose to handle bot traffic to preserve the sacred rights of turbonerds to visit their website using Lynx on their toaster.

I should think that there should be a better way (e.g. port knocking, instructions for manually correcting the URL that cannot easily be automated, additionally supporting alternative protocols, etc).

Sounds great. Link us to your project?

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#436

Earlier quoted context omitted.

Fingerprinting for "bot protection" is indistinguishable from fingerprinting for mass surveillance.

Sure, this is the age-old “knife used to cut steak is indistinguishable from knife used to stab people” thing. Tools are inherently amoral; only people can have motives we can celebrate or condemn.

Is the value provided by Cloudflare to public so great, that we are willing to pay for it by enabling mass surveillance?

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#437
post #409

Earlier quoted context omitted.

8 billion checks per day sounds on the low end. I can imagine it being ten or hundred times more. That still seem pretty fine though. On the other hand, it's hard to see that such a modest energy cost would dissuade any attacks.

> I can imagine it being ten or hundred times more I don't think I average even 2 captchas a day being terminally online, so 10 across every soul in the world sounds way too much for me. (we're ignoring bots it's meant to deter?) > it's hard to see that such a modest energy cost would dissuade any attacks. It's not against targeted attacks, but scrapping. And not about energy cost, but available compute power -- it r…

> I don't think I average even 2 captchas a day being terminally online, so 10 across every soul in the world sounds way too much for me. (we're ignoring bots it's meant to deter?)

You're mixing up checks, fingerprinting, and PoW with a captcha being triggered because those didn't pass. The less abnormal your setup is, the fewer captchas you'll get.

I agree with the rest of what you said.

Also I think you mean "scraper" and not "scrapper".

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#438
post #425

Earlier quoted context omitted.

PoW doesn't fix anything if you have an army of zombie CCTV cameras and smart fridges at your disposal. It's either proof-of-humanity (increasingly hard to get in this day and age, particularly if accessibility is a concern), proof odf identity (even worse) or proof of system integrity, which is the least bad out of all the terrible options.

Why wouldn't PoW help? If it's tuned so that each device in that army takes 10 seconds instead of 10 milliseconds to make a request, have you not slowed the army down by a factor 1000?

You just need 1000x more zombie fridges, which may be still acceptable for some bad actors.

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#439
post #438
post #425

Earlier quoted context omitted.

Why wouldn't PoW help? If it's tuned so that each device in that army takes 10 seconds instead of 10 milliseconds to make a request, have you not slowed the army down by a factor 1000?

You just need 1000x more zombie fridges, which may be still acceptable for some bad actors.

But more expensive (to get). At the same time, the PoW would require more compute power do the same device will still be capped at the same rps

Re: Cloudflare Turnstile requiring fingerprintable WebGL

#440

Earlier quoted context omitted.

Sure, this is the age-old “knife used to cut steak is indistinguishable from knife used to stab people” thing. Tools are inherently amoral; only people can have motives we can celebrate or condemn.

Is the value provided by Cloudflare to public so great, that we are willing to pay for it by enabling mass surveillance?

That’s a better question. So far the answer seems to be yes.

Large companies and banks see >95% fraud on sign in / sign up flows. It’s a constant battle and the law of large numbers says even a tiny false negative rate can be catastrophic.

A bogus GCP or AWS or Azure account costs those companies hundreds to thousands of dollars. I don’t know what the average loss is on fraudulent bank signins, but probably on that order. And there are millions, sometimes billions of attempts per day.

I worked at a tech company that used an off-brand, truly awful captcha provider. Think “drag the mammal to the habitat it lives in, avoiding the wiggly lines”. When this awful provider went down (frequently), we fell back to recaptcha. Fraud rates were 100x higher in those minutes-to-hours outages. Though of course real users were also able to get in at higher rates.

Post reply on HN