The end of the road for Cloudflare CAPTCHAs
blog.cloudflare.com
blog.cloudflare.com
I have a silly anecdote. So, my wife wanted a Louis Vuitton purse - one of the more modest ones, which is relevant.
Being more affordable, the demand for it is amongst the highest of their offerings presumably. But, they artificially create a scarcity scenario so it's more desirable.
This then leads to bots farming the page endlessly and invididuals struggling to get them. So, the bots win anyway.
Why don't they just accept a waitlist if they're going to be so silly about it? Or verify you are a human being using some kind of private identity service when you attempt to purchase your cart? How does throwing up blocks on the page solve anything?
Edit: Added anecdote
I would challenge that there is no such thing as unwanted traffic if it's publicly accessible - If you want it to be stricter, you should be requiring accounts with strict purchasing limits matching that of a normal person by default. No "anonymous" purchases, and a more appropriate identity vetting on account creation.
It serves a much larger purpose - mitigating bot load in aggregate across an entire domain or network. Maybe you’re assuming that DDOS/bot attacks are rare? Because they’re not (1). If you let all of them continue willy-nilly, obviously it’ll get overwhelmed at some point? Plus, why waste so much server energy/time serving malicious load…
(1) https://blog.cloudflare.com/network-layer-ddos-attack-trends...
If you are logged in to an account with a company, they can use your entire user interaction history with that company to decide if you're human or not. That means they won't have to make me click trains.
With my permission, they can also share that info with third parties. I'd be completely happy to trust the right company to tell the world that I'm human. They would only be attesting that I am human, not which human I am, so there isn't any substantial loss of privacy.
“All connections that use Private Relay validate that the client is an iPhone, iPad, or Mac and that the customer has a valid iCloud+ subscription. Private Relay enforces several anti-abuse and anti-fraud techniques, such as single-use authentication tokens and rate-limiting. This is designed to ensure only valid Apple devices and accounts in good standing are allowed to use Private Relay.”
https://developer.apple.com/support/prepare-your-network-for...
Depending on the characteristics of a request, Cloudflare will dynamically choose the appropriate type of challenge from one of the following rotating actions:
* Show a non-interactive challenge page (similar to the current JS Challenge).
* Present an invisible proof of work challenge to the browser.
* Show a custom interactive challenge (such as click a button).
* Show a CAPTCHA challenge.
This doesn't seem like the end of the road. Is this still gonna suck behind my corporate firewall?> Present an invisible proof of work challenge to the browser.
Obviously they're not going to be mining bitcoin, but what could they possibly be doing for "proof of work" that proves you're human?
Forcing sites to require JavaScript is even worse.
Together, captchas and the new replacement from the article mostly just undermine client side security, which opens sites to much jucier attacks than unauthenticated bots reading from CDN cache!
On top of that, I regularly fail Captchas. I'd happily pay for a browser plugin or something that would have my computer complete them for me. It's probably better at it then me!
And no one will ever succeed at bringing them to zero.
Perennial favorite explainer on the topic: https://www.hcaptcha.com/post/why-captchas-will-be-with-us-a... Why CAPTCHAs Will Be With Us Always
(disclaimer: work on this stuff)
I might not want to pay slave wages to people to mindlessly click buttons, but I'm not a bad actor. (Also, these services have serious security / usability issues for pretty much everyone except bad actors.)
The captcha war was lost long ago.
I see in the article reference to specifying what kind of challenge in the context of Firewall Rules.
But what happens if I’m a new Pro customer, are Challenges on by default? Said differently, if I sign up example.com on a Pro plan and make no changes to my settings - would potential users who visit example.com be Challenged?