3 ms·
When every .html resource requested is met with a captcha, access is effectively banned.
by CodeWriter23 11y ago
When every .html resource requested is met with a captcha, access is effectively banned.
- Klathmon 11y agoWell that's another problem. When you fill out the captcha you are given a cookie that can allow cloudflare to let you through next time. If you are blocking that cookie for privacy reasons (which is not a bad thing!), then cloudflare has no way to verify you again (short of doing nefarious things). It's a bit of a self inflicted problem at that point. That's not to say that the answer is "deal with it", but that we need to find a better way. A a way to verify that someone isn't a bad actor without having them take a pretty significant chunk of their time to answer captchas, or give up some of their privacy. It's a tough problem, and i think the "proof of work" solution proposed in the original could work, but it would need participation and collaboration from "both sides" of the problem. And of course it won't happen overnight.
- kuschku 11y agoAny proof of work concept again is just a cookie – because the proof I present will be the same.
- Klathmon 11y agoBut you could possibly re-do the proof of work every page load without the cognitive load of multiple captchas. It still isn't ideal for mobile or low-end clients, but its something.