I’m sorry but hyperbole like that distracts from the point you’re making.
It's bad enough on mobile - try banking apps, Netflix, Google Pay, Samsung's Watch companion app or pretty much any game on a rooted Android, you'll have to bytecode patch your way around. I do not want that crap on desktop as well.
> their push for PAT will lead to users effectively being locked out of a lot of online services if they do not pass the Blessed Test
The blog post you linked to specifically explains that Cloudflare are using PATs to replace CAPTCHAs. Do you find yourself filling out Cloudflare CAPTCHAs on a regular basis when accessing 80% of web services? I personally do not, nor have I heard anyone complain about such a thing.
If you're not filling out a CAPTCHA today you're not going to be required to provide a PAT tomorrow. Even if you _are_ required to provide a PAT to access a service your inability to do so means it'll fall back to what happens today: you fill out a CAPTCHA.
I'm not saying this is amazing or even anything positive at all but I think it does a disservice to exaggerate the situation. It leads to people dismissing the issue out of hand.
I regularly see applications deny me service simply because my Android device is rooted. The RiF app, back when it was usable, led fanfiction.net to loop around Cloudflare craptchas in its in-app browser because FFN had the anti-bot settings turned to the extreme and something deemed my device to be dangerous.
I have zero reason to assume that once Cloudflare has enough market penetration they can and will switch on a rule to kill off "modified" desktop devices just as well - especially not if rightsholder alliances such as the MPAA, Netflix or whatever demand yet another piece of crap signal to judge my device worthy. Just look how rightsholders almost got Microsoft to implement Palladium for their crypto crap decades ago, and now we got the same shit on virtually all mobile devices with Widevine refusing service if you dared to install an aftermarket firmware or root it. Or how the rightsholders got HDCP embedded everywhere. Or how Secure Boot got all but mandatory.
Thanks but no thanks, everything that even begins to veer in this direction has to be stopped from the start. Cloudflare is in a too powerful (and for media rightsholders, way too tasty) position, and we have seen it in the past (as detailed above) how eventually the rightsholders get their way.
“[link to a post discussing replacing CAPTCHAs with PATs] is the greatest threat to user freedom we’ve ever seen” loses potential allies because the evidence doesn’t back up the statement.
IMO the actual threat is the centralisation of power on the internet. PATs are simply a manifestation of that power. Lots of people in this thread use Cloudflare and enjoy their products so any argument relying on “Cloudflare are evil” will likely also fall flat. “Centralised power is inherently/inevitably evil”… now we’re cooking with gas. But it’s still an uphill struggle losing people all the way.
Lots of people in this thread likely use and enjoy Google or Apple or Microsoft products, and yet the notion that said companies are evil probably wouldn't get much disagreement except from their most rabid of fanboys.
When it does happen that Windows and Linux join the sealed and signed party, what can be done to make you whole?
Until I turn SIP/AMFI off and mess with the OS as I wish, which Apple lets me do. I'm not looking forward to random websites deciding that is grounds to denying me access or giving me 10x more captchas.
Cloudflare position themselves as the internet safety police will turn the web into a monoculture and that was the argument used against MSIE and now used against Google. But this is a larger threat because the end-users don't choose to use CF so it isn't measurable how many people are being adversely affected. Site owners' metrics will only show them the permitted users and they'll be unaware that their applications are unusable to many people. How do you get a bug report from something that doesn't appear in your logs?
Sort of. On a regular basis = when I decide to visit less hacker-culture websites, which isn't often, but then I do the CAPTCHA and it stops bugging me for a long time.
So, are you telling me in the future PAT will prevent me from visiting such websites altogether? Maybe the poster isn't hyperbole then.
Our there any other nuanced opinions?
Secondly doesn't an entity have to have a certain amount of internet traffic to even consider a CDN.
My point of view is that large commercial entities need CDNs small time people can get by with the ip provided by the ISP.
The core problem is that our governments are doing nothing to keep bad actors accountable - China, Russia, North Korea, Iran, they all can run attacks as they please without any consequence. And ISPs don't do anything if you alert them about hacked routers.
In my day job, I'm responsible for running a few very high profile and high traffic targets, and the amount of bullshit we have to deal with even after CloudFront+WAF in front is absurd. Gotta be three digits worth of abuse emails I sent out to ISPs all over the world, and nothing happened.
My plan is to stop everything that isn't a valid URL in my next incarnation. Sounds like this won't be adequate at a certain volume of traffic.
Do any current rules of them exist for estimating resources vs. traffic.
I never resort to the abuse emails I figure it's all fraud. I just ban IPs indiscriminately.
I don't use Chinese services as much as possible, so everything would bother me if I had to use them.
The same situation exists in other areas as well. Trying to bootstrap a search engine? Well tough luck, because what are you trying to do with a headless version of Chromium?
This in turn creates a cartel where only few players can compete, and the members of said cartel can enter new markets without ever having to compete.