14 ms·
Turnstile: privacy-preserving alternative to CAPTCHA by Cloudflare
- bwb 4y agoGod, I hope this works; I do tire of the silly CAPTCHA test. I def get hit with it a lot more from outside the USA than within.
- homero 4y agoThat's awesome and it's free, about to swap out my recaptchas
- zagrebian 4y agoCan’t CAPTCHA be integrated into the browser? Can’t the browser vouch for the user?
- worenga 4y agoThis already being worked on as part of Private Attestation Tokens and the best thing is Turnstile is using this already, read https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/ https://blog.cloudflare.com/eliminating-captchas-on-iphones-...
- miohtama 4y agoIf you read the article you realise you need a valid, unique, device > In June, we announced an effort with Apple to use Private Access Tokens. Visitors using operating systems that support these tokens, including the upcoming versions of macOS or iOS, can now prove they’re human without completing a CAPTCHA or giving up personal data. > By collaborating with third parties like device manufacturers, who already have the data that would help us validate a device, we are able to abstract portions of the validation process, and confirm data without actually collecting, touching, or storing that data ourselves. Rather than interrogating a device directly, we ask the device vendor to do it for us. The trick is that bot farms do not have access to correctly provisioned mobile phones (for now). Thus anyone with a valid mobile device gets a pass.
- contravariant 4y agoSomething about my browser trying to figure out if I'm not 'abusing' a website feels off to me. Perhaps because it's the user-agent acting in the interest of the website.
- kube-system 4y agoThat depends on whether you can trust the browser. For example, browsers have long had flags to indicate whether they’re being driven by webdriver, but you can simply recompile the browser without those flags.
- boltzmann-brain 4y agois it really just "simply recompile"? I would assume some intensive patching and learning would be necessary, especially for someone who isn't familiar with the source or the build process.
- duskwuff 4y agoIf you're automating a browser, you're probably technical enough to compile a patched web browser -- or, at least, to use someone's script to compile one, or to download one that someone else has built.
- kube-system 4y agoSometimes even more simple -- there are some methods people use that are as simple as "copy and paste this javascript that overwrites some properties". There's a lot of people scraping the web, so there's somebody out there that has done the work for you already. My point is, you don't really know what software is connecting to your web server.
- boltzmann-brain 4y agoThat's true, you never really know what's on the other end, but even the simplest hurdle is a full stop for most people.
- stevewatson301 4y agoThat would just DRMize the web with a few select browsers being allowed to access content and the rest being left to dust.
- endisneigh 4y agoNot really - how could it be worse than the status quo? Worse case you could use turnstile, no?
- r1ch 4y agoCompanies will realize the majority of abuse comes from humans completing CAPTCHAs and little to none from TPM attestations. It's then a small leap to only trust TPMs and lock everyone else out. After all, every genuine user has an OS that requires a TPM.
- stevewatson301 4y agoCloudflare’s scheme with PATs is essentially a form of attestation, which, realistically, will only be implemented by Microsoft, Apple and Google, and if you’re a Linux or BSD user which isn’t integrated with a device manufacturer, you’d just have no other choice. This is an unpopular opinion, but Recaptcha has never had this problem. I might face a few more captcha image screens to solve, but what’s being proposed with PATs is dangerous.
- mwcampbell 4y agoAsk a deaf-blind person which solution they think is less bad.
- jasonjayr 4y ago"Remote Attestation" is the tech for this. and trust me, this technology is not in the interest of the user, especially if the user wants free (as in freedom) and open internet.
- boltzmann-brain 4y agoyou're being downvoted, but while the question you pose proposes a bad idea, it is a good question that resulted in a lot of interesting conversation, so you get my upvote.
- 1f60c 4y agoI think changing the comma to a colon and adding "a" before "privacy-preserving" would make the title clearer.
- eastdakota 4y agoThis is yet another example of Cloudflare centralizing the web. I’m tired of this. Sure the only previously viable solution was ReCAPTCHA from Google. But it’s Google. I depend on them for search. And, sure, their business model depends on them being able to track me online. But I know them. And it’s hard for me to live without them. So I’m ok with depending on them, but I worry about further centralization of the Internet if there’s an alternative. At the end of the day, I like the Internet how it is and how I’ve gotten used to it. Facebook is clearly evil, but I still check them from time to time to keep up with my friends, but a lot less than I used to. I, of course, need to use Google so even though their business is inherently about tracking me, what’s the alternative. But Cloudflare, they’re new. They disrupt what I’m used to. They add another player to the mix. So how dare they centralize the Internet?? This is total BS. I’ll stick with ReCAPTCHA.
- 2Gkashmiri 4y agoWait till captcha farm companies bypass this and sell solutions for a profit. I use one and its ~95% accurate which is fine for me I guess.
- EFruit 4y agoAs much as I _despise_ modern ReCAPTCHA, I have always been able to pass the challenge eventually; it has never flatly rejected me with no recourse. If I made a mistake or was insufficiently human for it, I got a new challenge and tried again. There are apocryphal stories of Google tar-pitting users with it, but I have never seen it in action. If this judges the browser more than the user, what do I do when the browser fails? Do I refresh the page hoping for a different batch of invisible challenges? Do I submit a ticket to CF customer support... despite not being a customer?
- shiomiru 4y ago> There are apocryphal stories of Google tar-pitting users with it, but I have never seen it in action. That used to be the case when using Tor; I remember having to rotate exit nodes to get recaptcha to load at all. These days the situation is a lot better, I've been able to pass Google captchas through Tor every time I tried this month. Seems like they even fixed audio-based captchas, so you no longer get instant-blocked if you try to use them. Of course, all this could be reverted tomorrow, and there would be absolutely nothing we could do about it...
- deathanatos 4y agoI've had to go a few rounds with the photo match. Where I usually get tarpitted is by Cloudflare. I'll pass the (automated) CAPTCHA, the page will reload (still as if I had passed), and … it'll be another CAPTCHA. I'm pretty sure these usually amount to a passive-aggressive demand for cookies/storage, but I just vote with my browser & go back/somewhere else.
- bombcar 4y agoCloudflare deep down greatly discriminates against shared IPs. If you have a real honest-to-goodness IPv4 address that doesn't change, you'll hardly ever encounter anything. But if you are behind any sort of carrier-grade NAT or otherwise sharing IPs, you're a second-class netizen, sucks to be you.
- 4y ago
- frankjr 4y agoJust a heads up for CF folks: Once you create a Turnstile, the link below the generated secret ("Server side integration code") leads to 404.
- Ocha 4y agoNo mention of hcaptcha. Is this still worth it if you are hcaptcha user?
- stevewatson301 4y agoWhat is the failure case for the Cloudflare captcha? In case browser fingerprinting fails to identify me as a human, do they fallback to a challenge that humans can solve, such as audio or image challenges? Say what you will about Recaptcha, but they do have a way to eventually pass through the challenge.
- vnkr 4y agoDepending on the mode you choose there can be an interactive element
- fariszr 4y agoThis looks great, Cloudflare will always be Better Privacy wise than Google. > without having to be a Cloudflare customer or sending traffic through the Cloudflare global network And you don't even need to use CF as a proxy.
- plibither8 4y agoFor Cloudflare employees going through this thread, the linked "Turnstile Developer Documentation" link [1] in the Turnstile dashboard is returning a 404. [1]: https://developers.cloudflare.com/turnstile/ https://developers.cloudflare.com/turnstile/
- adspedia 4y agoFixed, should work now.
- Cryma 4y agoFYI: The docs link in the Dashboard [1] points to a 404. [1]: https://developers.cloudflare.com/turnstile/get-started/client-side-validation/ https://developers.cloudflare.com/turnstile/get-started/clie...
- worenga 4y agofixed.
- deleted 4y ago[deleted]
- V__ 4y agoCan anyone shine a light on this solution and GDPR compliance?
- yjftsjthsd-h 4y agoCloudflare: "Cloudflare has a long track record of investing in user privacy, which we will continue with Turnstile." Also Cloudflare: Tracks and fingerprints everyone, and blocks anyone who hardens their browser ("First we run a series of small non-interactive JavaScript challenges gathering more signals about the visitor/browser environment. Those challenges include proof-of-work, proof-of-space, probing for web APIs, and various other challenges for detecting browser-quirks and human behavior. As a result, we can fine-tune the difficulty of the challenge to the specific request.").
- mwcampbell 4y agoThere are no perfect solutions. In the arms race to protect against abuse, I'll take the solution that's more accessible, particularly to people that are discriminated against by CAPTCHAs, such as deafblind people.
- mdaniel 4y ago> to protect against abuse I would actually be on-board with such things if this were against abuse but it's not -- it's preemptively assigning blame, since my copy of Firefox is not modified in any way except uBO but CF loves to captcha it. The other stories in every one of these captcha threads, and the majority of the CloudFlare announcements at all, demonstrate this isn't isolated to "oops, our bad" but a systemic problem If I were DDoS-ing some site, I deserve every ban I get, but just browsing via the provided navigation links on the site shouldn't "pardon our interruption" or gatekeep
- byteduck 4y agoInteresting. I wonder what other factors you might have going against you causing CF to captcha you - I have my Firefox loaded up with almost every ad-blocking, privacy, and anti-fingerprinting extension I could think of, but I rarely get CAPTCHAs.
- yjftsjthsd-h 4y ago
- deleted 4y ago[deleted]
- beefee 4y agoWill any of this be available on Linux or owner controlled systems?
- ChrisArchitect 4y agoMy problem with this is I want to use the CAPTCHA to deter humans from continuing. Letting them thru automatically allows spammers/attackers to just continue on, but many will actually skip pages/sites where they have to do the CAPTCHA etc. This helps the bot problem, but doesn't solve the SPAM problem.