5 ms·
Not a comment on the article, but the CAPTCHA before it seems weird and kind of sketchy. > Why do I have to complete a CAPTCHA? > Completing the CAPTCHA prove
by philh 6y ago
Not a comment on the article, but the CAPTCHA before it seems weird and kind of sketchy.
> Why do I have to complete a CAPTCHA?
> Completing the CAPTCHA proves you are a human and gives you temporary access to the web property.
Okay, but... why do I have to complete a CAPTCHA?
> What can I do to prevent this in the future?
> If you are on a personal connection, like at home, you can run an anti-virus scan on your device to make sure it is not infected with malware.
> If you are at an office or shared network, you can ask the network administrator to run a scan across the network looking for misconfigured or infected devices.
> Another way to prevent getting this page in the future is to use Privacy Pass. You may need to download version 2.0 now from the Firefox Add-ons Store.
How would a virus scan help here? I certainly hope my browser doesn't go around advertising when I last did one of them. And how does Privacy Pass prove I'm human, are robots unable to pretend to be Firefox plus Privacy Pass?
- dewey 6y ago> How would a virus scan help here? Usually that means that the IP you are connecting from got somehow flagged as an originator of malicious attacks. Like if the virus on your computer does automated requests (click fraud, scraping, DoS,...) to other IPs that are monitored by them. Of course this is probably mostly useless especially if you are on a dynamic IP but that's where it's coming from.
- judge2020 6y agothis line of text was more appropriate when this text only showed up when CF had a low "trust score" for you; now website owners have much more control and can trigger a captcha for almost any reason that doesn't necessarily mean your network is infected (eg. A website owner triggering captchas on a page of their website once they have a heavy increase of traffic)
- dewey 6y agoI was only answering to the part about why they suggest virus scan, not the usage of captchas in general. Of course you are right in regards to captchas in general.
- kop316 6y agoI'm getting the same issue. I also use CDN from cloudflare for my personal sites...and this is making me reconsider using it. Giving cloudflare the benefit of the doubt, what could trip this is: 1) the site is getting higher than average visits (tripping the anti-DDoS flag for the CDN) 2) I went without javascript on, so they think I am just a bot. EDIT: after giving it the benefit of the doubt, the captha didn't work for me at least 4 times. That is unacceptable.
- snazz 6y agoI think that the site backend is having trouble keeping up with the load and the owner turned on Cloudflare’s Under Attack mode, thinking that this was a DDoS. This doesn’t look like the behavior I’ve seen when Cloudflare does it automatically. It’s smart enough to know that HN is not a DDoS.
- judge2020 6y agoA common question on the CF forum is a requests/second trigger for either enabling Under Attack mode or enabling a Firewall rule that triggers the full hCaptcha page. This is most likely what happened here. [This is usually done by counting requests/second at the origin then using the CF API to enable the firewall rule or change the security level)
- kop316 6y agoI have an add-on that removes referrer strings...but when I disabled that I get the same issue. When I checked it on my phone (Android, mobile Firefox with the same add-ons), I was able to go fine.
- cuspycode 6y agoI got the same CAPTCHA, running Firefox 68.4.1 on Linux. Normally when this kind of thing happens, I just close the tab and move on with my life. But this time I tried opening with Chromium instead (version 76.0.3809.100) and then no CAPTCHA was required. Neither browser has Privacy Pass, so why are they treated differently?
- SXX 6y ago> And how does Privacy Pass prove I'm human, are robots unable to pretend to be Firefox plus Privacy Pass? Privacy pass just like some blockchain tech require to spend some computational resources in order to get tokens. After all CloudFlare goal isn't to block bots as is, but to make DDoS attacks and mass vulneribility scan more expensive.
- gruez 6y agoThat’s not what privacy pass is. There’s no proof of work involved. Basically you solve a captcha once, and it gives you 30 tokens to skip future captchas.
- lexicality 6y ago> In preliminary tests on consumer hardware, our extension takes ~1.1 seconds to generate blinded tokens to be signed by the server and ~1.9 seconds to parse the signed tokens and verify the DLEQ proof. Creating a pass that can be used to redeem signed tokens takes <40ms. It's intentionally very slow to get and use those token though
- gruez 6y agoThat seems to be a side effect of the zero knowledge proof implementation, rather than an explicit design choice. There doesn’t seem to be a tunable “difficultly” parameter, like with all proof of work implementations.
- lexicality 6y agoIf we assume a spherical cow and say that there are no rate limits on the captcha service and capture solves are instant, then privacy pass requires you to spend 100ms of CPU time before each request, which is a sort of "work" If we then say that the captcha you solve can be dynamically adjusted based on how suspicious the request is, then that is a sort of difficulty tuning. Sure this isn't exactly blockchains or whatever, but it's basically the same idea. Why would CloudFlare endorse this system if it was just "business as normal but you solve 1/30th of the captchas"?