Live data from Hacker News

Web Bot Auth

developers.cloudflare.com

51–60 of 77 posts

Re: Web Bot Auth

#51

I disagree with the other top-level comments at the moment: I believe Web Bot Auth is a useful and non-centralized emerging standard for self-identifying bots and agents. This press release today is a better statement of _why_ this feature exists (as opposed to the submission link, which is nuts-and-bolts of implementing): https://blog.cloudflare.com/signed-agents/ Web Bot Auth is a way for bots to self-identify cryp…

Isn't this somewhat equilivent to ensuring cookies are required?

Obviously this technology is different but the same sort of result.

What's the end game here? All humans end up having to use a unique encryption key to prove their humanness also?

Re: Web Bot Auth

#52
post #49

Earlier quoted context omitted.

That’s not shady, that’s awesome customer value! Bot blocking as Default option is a great choice for all of us.

It's discriminatory against robots and helps make the web even more locked down. DRM never works; the analog hole is always the nuclear option. In the end, only people with non-mainstream browsers (or using VPN to escape country-level blocks, or Tor, or noJS) suffer. It's like how anti-piracy measures only affect paying customers, while pirates ironically get a better experience. The best way to get around endless CA…

> It's discriminatory against robots

You would... lead your response with that argument? This has nothing to do with DRM. When people talk about how bots suck, the focus is on billion or trillion dollar businesses making everyone on the web pay.

There's also a reason why the bot conversation flared up; we've always had bots, but before the conversation centered on Google and SEO. Now the conversation centers on companies like OpenAI.

Re: Web Bot Auth

#53

Earlier quoted context omitted.

What's now at the top has links to IETF drafts in the first paragraph. What am I missing? A way to authenticate identity for crawlers so I can allow-list ones I want to get in, exempt them from turnstile/captcha, etc -- is something I need. I'm not following what makes this controversial. Cryptographic verification of identity for web requests, sounds right.

I think about failure modes. What happens if cloudflare decides you are a bot and you’re not. What recourse do you have? What are the formal mechanisms to ensure a person is not blocked from the majority of the web because cloudflare is a middleman and you are a false positive?

This is not a spec sbout false positives, ir is about self identification as a bot.

Re: Web Bot Auth

#54

Earlier quoted context omitted.

What's now at the top has links to IETF drafts in the first paragraph. What am I missing? A way to authenticate identity for crawlers so I can allow-list ones I want to get in, exempt them from turnstile/captcha, etc -- is something I need. I'm not following what makes this controversial. Cryptographic verification of identity for web requests, sounds right.

I think about failure modes. What happens if cloudflare decides you are a bot and you’re not. What recourse do you have? What are the formal mechanisms to ensure a person is not blocked from the majority of the web because cloudflare is a middleman and you are a false positive?

Don't use a user agent that sends signed headers identifying you as a bot? How are any of the failure modes you mention not /improved/ by the spec proposal this comment section is about?

Re: Web Bot Auth

#55
post #49

Earlier quoted context omitted.

That’s not shady, that’s awesome customer value! Bot blocking as Default option is a great choice for all of us.

It's discriminatory against robots and helps make the web even more locked down. DRM never works; the analog hole is always the nuclear option. In the end, only people with non-mainstream browsers (or using VPN to escape country-level blocks, or Tor, or noJS) suffer. It's like how anti-piracy measures only affect paying customers, while pirates ironically get a better experience. The best way to get around endless CA…

> It's discriminatory against robots

That's the entire point.

Re: Web Bot Auth

#56

I disagree with the other top-level comments at the moment: I believe Web Bot Auth is a useful and non-centralized emerging standard for self-identifying bots and agents. This press release today is a better statement of _why_ this feature exists (as opposed to the submission link, which is nuts-and-bolts of implementing): https://blog.cloudflare.com/signed-agents/ Web Bot Auth is a way for bots to self-identify cryp…

Isn't this somewhat equilivent to ensuring cookies are required? Obviously this technology is different but the same sort of result. What's the end game here? All humans end up having to use a unique encryption key to prove their humanness also?

I understand your concern and we are probably headed into that direction, but that does not prove humanness any more than the subject of this post proves botness. They prove the knowledge of the value of a key.

Re: Web Bot Auth

#58

I disagree with the other top-level comments at the moment: I believe Web Bot Auth is a useful and non-centralized emerging standard for self-identifying bots and agents. This press release today is a better statement of _why_ this feature exists (as opposed to the submission link, which is nuts-and-bolts of implementing): https://blog.cloudflare.com/signed-agents/ Web Bot Auth is a way for bots to self-identify cryp…

I generally agree it's a good thing. It stacks the incentives so that bots can meaningfully build a good reputation, and be rewarded for behaving well.

That said, I do think it's the whole procedure is more than a bit overcomplicated to the degree where I doubt it will be widely implemented. You could likely achieve almost the full effect with a request signing alone.

Re: Web Bot Auth

#59

I disagree with the other top-level comments at the moment: I believe Web Bot Auth is a useful and non-centralized emerging standard for self-identifying bots and agents. This press release today is a better statement of _why_ this feature exists (as opposed to the submission link, which is nuts-and-bolts of implementing): https://blog.cloudflare.com/signed-agents/ Web Bot Auth is a way for bots to self-identify cryp…

> This is a good thing! We want bots to be able to self-identify in a way that can't be impersonated.

Who is we? I absolutely don't want that.

Re: Web Bot Auth

#60
post #50

Earlier quoted context omitted.

I will tell you that we have had bot super fight mode on for a year and since then we have not had to address abusing traffic nor deal with legitimate people blocked. There is no way we could have achieved such balance. prior to that it was me blocking every Chinese AS under the sun as they shifted and bombarded us with traffic

> nor deal with legitimate people blocked How are you so sure of that? Their marketing?

Simple: If you ignore people who get blocked or just also make sure they get blocked the same way in all ways they could reach you, then you don't have to deal with them and can just ignore the issue. Fun times ahead for us.
Post reply on HN