4 karma · joined September 15, 2024
juan at truesign dot ai
But it got flagged/downvoted into removal (twice!). Someone here has lots of HN accounts and doesn't tolerate free competition.
Disclaimer: I'm the founder and main researcher of the "flagged" company.
- some browsers / extensions disable webRTC by default, and certain privacy configs use a proxy to reach out to STUN. These are not "weird" browsers: Safari, Firefox, Brave, Opera do it by default or through configs.
- naive RTT calculations will cause you lots of false positives. Just as an example, some devices on low battery do slow down their network stack, randomly causing bigger RTT on some network packets and triggering your TLS > RTT*3. We discovered it the hard way, and there are many more other corner cases.
- as an independent site operator, I'd find this harder to deploy than i.e. deploying a reverse proxy or using 3rd party service. Also you'd need to always show an interstitial screen where the webRTC checks happen, instead of running your detections on the fly as each request comes in.
If you're interested on the topic, let's chat by email and/or take a look at our demos:
The PoW solutions I've seen out there just add 1-2 seconds of delay before granting access to the whole site. It could work against random unsophisticaed crawlers but I don't see how that can stop determined bots.
Residential and mobile proxies are also detected.
Where's the wait list?
No need to ask for a phone or card -- or worse, biometric data! -- which also removes friction.