5 ms·
How exactly do you imagine bot/attach protection (cloudflare's main product) working without JS? Even to bypass a captcha using your browser to assert trust req
by endigma 4y ago
How exactly do you imagine bot/attach protection (cloudflare's main product) working without JS? Even to bypass a captcha using your browser to assert trust requires JS.
Are captchas and DDoS bot protection ruining the web?
- T3RMINATED 4y ago
- NoraCodes 4y agoThere is definitely an inherent tension between forcing legitimate users to load JS and store CloudFlare's cookies, and keeping bots off of services. As an individual, having to load random nonsense from CloudFlare does not improve my experience!
- ynbl_ 4y agothe same way it worked before cloudflare.
- endigma 4y agoworked so well cloudflare came into existence and nigh-obsoleted it
- rakoo 4y agoThere is a clear distinction between bots (which are legitimate users) and DDoS. The latter aren't even repelled at the application layer but well earlier in the stack.
- RobotToaster 4y agocaptchas don't require javascript.
- TDiblik 4y agoI thought they do? I'm not really sure, but I think that capchas also collect info about your browser etc... as well as identifiing you with some kind of "challenge", or am I wrong?
- RobotToaster 4y agoA captcha is just an image, usually generated server side, the response can be returned using a normal POST request.
- dns_snek 4y agoModern captchas like Google's Recaptcha V3, hCaptcha, etc. require a lot more than an image. They track your reputation score, fingerprint your browser, OS, hardware, window size, installed fonts, analyze your mouse movements and probably more.
- netsectoday 4y agoAnyone who monitors their web traffic would tell you the bots are ruining the web. I hate these "are you human" checks too, but when a persistent threat is poking your defenses and legitimate web traffic is only 10% - 20% of your server load... you have to do something. So the alternative here to receiving a challenge is that the site would just be blocked in your country or for your network provider. Would you prefer to be outright blocked, or is it ok to have an annoying "are you human?" challenge?
- hotpotamus 4y agohttps://major.io/2021/06/06/a-new-future-for-icanhazip/ https://major.io/2021/06/06/a-new-future-for-icanhazip/ Pretty interesting story about a tiny IP checking tool and how it sort of got out of hand sadly due to abuse. The solution? Major sold the site to Cloudflare for $1. But really kind of a shame overall.
- netsectoday 4y ago> Seeing that over 90% of my traffic load was malicious and abusive was frustrating. That story nailed it. > If you’re curious, Cloudflare did pay me for the site. We made a deal for them to pay me $8.03; the cost of the domain registration. The goal was never to make money from the site. A little more than $1, but basically the same idea.
- hotpotamus 4y agoAh yes, I remembered it as a token amount, but obviously not completely accurate lol. But I worked with the author just a bit, so I used and still use the utility, and it's a shame because he's one of the more gracious people I've come across in the industry.