HNHacker News
TopNewBestAskShowJobs

cport1

13 karma · joined November 20, 2008

submissionscomments
cport1··on [dead]
-Detects only new/changed strings and translates them (no redundant API calls)

-Supports XLIFF 1.2, XLIFF 2.0, and JSON (flat + nested)

-Handles ICU MessageFormat plurals with CLDR rules for 20+ languages

-Commits translated files back to your repo automatically

-Works with Anthropic Claude, OpenAI, or self-hosted Ollama

cport1··on FCaptcha – A modern CAPTCHA system designed to detect everything
You're right that most of these signals are spoofable in isolation. FCaptcha doesn't make pass/fail decisions on any single signal. It's weighted ensemble scoring across ~50 signals, where the cost of spoofing all of them simultaneously is the actual defense.

Addressing a few specific ones:

PoW CPU cost: Difficulty is adaptive — 4 for residential IPs, 6+ for datacenter. On modern hardware that's ~200-800ms. For 1M users/day that's ~55-220 CPU-hours total, distributed across clients. It's comparable to what Cloudflare Turnstile does.

Keyboard-only users: Already handled. If keyEvents >= 2 and totalPoints === 0 (tabbed + Enter/Space), all mouse-based detections are skipped. No false positives on keyboard users.

  "Can be recorded/replayed": signals are SHA-256 hashed and bound into the PoW input before solving. You can't solve PoW first then attach recorded signals... the hash won't match. Replaying old signal sets also fails because each challenge has a unique nonce.
Micro-tremor at 125Hz: Fair point... low polling rate mice produce less granular data. It's weighted low and only contributes when data is available. Not a gatekeeper.

CDP userGesture: true: Good catch. We detect CDP-specific artifacts (Runtime.evaluate residue, protocol binding flags), but you're right that a custom Chromium build sidesteps this entirely.

The honest answer: a sufficiently motivated attacker with a custom Chromium build can beat this. The goal is to make that cost high enough that it's cheaper to just solve the CAPTCHA legitimately or move to an easier target. Same tradeoff Cloudflare makes, but open source and privacy first.

Where I think the real gap is: server-side signals (IP reputation, TLS fingerprinting, rate patterns) and that's really what our paid bot detection is for. https://webdecoy.com

cport1··on [dead]
Browser-as-a-Service platforms like Browserbase, Hyperbrowser, and the growing ecosystem of LLM-powered browsers can spoof nearly every JavaScript API, rotate residential IPs, and generate convincing user agents. What they cannot easily fake is the TLS handshake.
cport1··on How Websites Can Detect Claude Computer Use and OpenAI Operator
Traditional bot detection doesn’t account for them. There’s no navigator.webdriver flag. No automation framework injecting globals. No suspicious HTTP headers. Just a browser, controlled by an AI that sees the screen exactly like you do. But vision agents have a fundamental weakness: they’re blind between screenshots. And that creates detection opportunities that behavioral analysis can exploit.
cport1··on Blocking AI web-scraping bots on personal sites using Nginx on low-power servers
You can also checkout https://webdecoy.com if you want to catch them behaviorally and with honeypots.
cport1··on Due to relentless AI scrapers notabug.org is currently down
Check out https://webdecoy.com if you want to start tracking which AI bots are hitting your site
cport1··on Show HN: Stop AI scrapers from hammering your self-hosted blog (using porn)
That's a pretty hilarious idea, but in all serious you could use something like https://webdecoy.com/
cport1··on Ask HN: Cloudflare WAF Alternatives?
I have been using https://webdecoy.com and integrating it with Cloudflare WAF.
cport1··on Website unresponsive: diagnostic steps and blocking the AI crawlers
might want to try something like https://webdecoy.com
cport1··on Ask HN: I need ideas to impress fifth graders with technology
I would recommend things like https://littlebits.com/
cport1··on Resolutions for programmers (2012)
"Switch to Dvorak" .. ha :(
cport1··on Why 451?
Link isn't working for me anymore?
cport1··on Ask HN: Ok you've built a rudimentary prototype – how would you proceed next?
I used to see these guys at every bar in Austin. I used it once and then never used it again. It was almost more of a hassle using the app than just simply using my credit card.