So how would this work with financial websites like Stripe? Should they let bots open ready to use their service?
Headless Chromium with some tweaks is already good enough that it's practically impossible to distinguish from regular Chromium, and Google knows it. That's why they were pushing for WEI (even though they were claiming it wouldn't impact browser extensions or debugging protocols). Google knows that environment browser/fingerprinting isn't an effective solution to stop automated requests, because normal user browsers out of the box allow sending automated requests.
Basically the only reason why botters don't already run full browsers is because of computer power, and botnets get around that problem. When attacks aren't limited by IP or compute power, attackers can just run regular browsers and bypass all of these checks. Even that isn't always necessary, a Raspberry Pi 5 is going to be perfectly capable of running a full Chrome instance to send automated requests through.
At least IP rate limits require actual work to circumvent, you need to acquire a botnet or a lot of IPs. Browser capability testing is comparatively easier to get around, you just run a full browser.
----
People have a tendency to lean into whatever outcome they want as if it's the default outcome that everyone else needs to disprove. But the reality is, Turnstile is a new system that is being newly developed as a response to changing conditions around traditional CAPTCHA methods, and it's not any privacy advocate's fault that robots now know how to do OCR.
And "I don't need to figure out how to preserve your privacy" should give you some clarity into why privacy advocates are not very sympathetic when you say "well, we have to start doing fingerprinting now because the robots broke everything, what is the alternative?"
Nah, we don't have to find you an alternative if you have no interest in actually working with us to meet everyone's needs equally. It stinks that robots broke your audio CAPTCHAs, but that's not Firefox's fault and it's not a privacy advocate's job to fix. Particularly not in the situation where you're unwilling to advocate for our needs alongside your own.
So you are complaining that the existing solutions aren't good?
I mean, I'm perfectly fine sticking with existing CAPTCHA audio systems or proof of work. They're problematic but workable; over time we can push for systems like privacy pass that improve them for everyone. But if you want to propose that we go all-in on fingerprinting and capability testing, then what's your plan to mitigate the new privacy risks from that?
Cloudflare: Hey guys, we have a solution for telling humans and bots apart!
Commenter: Your solution sucks!
Me: What would you recommend?
Commenter: Why don't you recommend something?
etc etc.
Right, and what I'm saying is that when a solution is proposed that stinks, it doesn't just magically get the default seal of approval, it doesn't suddenly become everyone else's problem to find an alternative.
Clouflare is proposing a solution with a negative impact on privacy rights and user autonomy. And you're kind of jumping right to, "well, unless you can perfectly solve the problem then we'll go with what they propose." That's not really how solutions or negotiations or anything works.
If your solution to "how do we distinguish bots" is that we'll stop caring about privacy, then I don't see why it's any less of a solution to say, "the way we'll preserve privacy is to stop caring about bots" -- other than that you've arbitrarily decided that the solution to this problem has to prioritize bot filtering over privacy.
The situation we're in is that CAPTCHAs are easier to defeat now than they used to be. Cloudflare is proposing that we get rid of privacy rights and user autonomy to solve that problem. The rest of us are saying, "sorry, it's a nice idea but privacy rights are non-negotiable."
It is not our responsibility to solve Cloudflare's problem, it is Cloudflare's responsibility to come up with a solution that isn't terrible. They're the ones who are saying that existing CAPTCHAs aren't good enough anymore, privacy advocates are fine sticking with status quo.
It's not Cloudflare's responsibility to do anything, really. They could just as well not have released this. As a service owner, I want to be able to distinguish legitimate users from bots. If I can't do that, there's a real possibility that I will stop offering a subset of my service. If someone can find a privacy-preserving solution to distinguishing legitimate users and bots, amazing, but, until then, users will have to choose between the existing solutions and not accessing my service at all.
I don't see how this could be any other way, and complaining about Cloudflare's implementation of a CAPTCHA doesn't do anything constructive, as far as I can see. The problem still remains, and no amount of "your solution isn't good, do better" is helping.
I don't think privacy advocates are trying to be constructive, we're trying to tell Cloudflare that their solution is bad. We're not offering them advice about how to write a novel and this isn't a support group for their developers; we're telling people who are refusing to prioritize privacy that we're not going to prioritize their needs either if they're not willing to care about ours.
> It's not Cloudflare's responsibility to do anything, really. They could just as well not have released this.
Great, I'm on board, let's do it :D
> If someone can find a privacy-preserving solution to distinguishing legitimate users and bots, amazing, but, until then, users will have to choose between the existing solutions and not accessing my service at all.
I don't see what this has to do with Cloudflare independently offering an attestation service. Again, you're jumping right to the assumption that it's our responsibility to solve your problem. It's not.
If you can come up with a privacy-preserving solution to distinguish legitimate users and bots, fantastic. But until then, you'll have to choose between not releasing your service or dealing with bots. We don't want to change the nature of the Internet to accommodate you. If that means you can't launch your service, I do have sympathy but... what are the alternatives? Privacy advocates aren't just going to be OK with having their privacy violated just because it makes it easier for business owners. We built a system around user agency and autonomy, and if you want to make changes to that system, if that existing system as it is today doesn't work for you then it's your job to figure out how to make the changes you need without breaking everything.
> and complaining about Cloudflare's implementation of a CAPTCHA doesn't do anything constructive, as far as I can see
It discourages Cloudflare from launching the service.
> The problem still remains, and no amount of "your solution isn't good, do better" is helping.
Again, I would flip this back on you. Complaining that existing CAPTCHAs aren't effective enough doesn't change anything about the privacy problems and restrictive nature of attestation, and no amount of "but how will we block bots otherwise" is going to help move that conversation forward. It's not any more constructive than telling business owners that they'll have to tolerate bots.
I feel a bit like: I'm sorry, but I don't know what you want me to say. I'm sorry that existing CAPTCHA methods today aren't good enough for you, but it doesn't sound like you have a suggestion about how to improve them without putting people's privacy at risk, and that's kind of a nonstarter. Let us know if you come up with an idea, but I don't know what to tell you in the meantime; you're the one who's saying that audio/image CAPTCHAs that exist today aren't suitable for businesses.