5 ms·
I've implemented PAT on a service. A server would only want to require PAT when it wants to see if it is dealing with a human. In the context of, say a blog, yo
by jws 4y ago
I've implemented PAT on a service. A server would only want to require PAT when it wants to see if it is dealing with a human. In the context of, say a blog, you would require PAT when someone wants to make an anonymous comment or create an account.
For requests which are "reading" you just serve content, unless for some reason you only want human eyeballs to see your content.
In your proposed scenario, reading the publicly accessible contents of the web, there should be no problems. (Of course some percentage of sites will accidentally have required PAT at any time and be unscannable, but presumably they figure that out and fix it.)
Now for the good side: I, reluctantly, implemented a geolocation filter to control anonymous content additions to that service I was alluding to. I felt bad about it, but I also felt bad having to filter out content spam every day. It turned out that all my strange content spam came from one country, so I banned 143 million people from anonymous content creation for my convenience.
With PAT I can remove the national ban and let any "probably human" in.
- dceddia 4y ago> For requests which are "reading" you just serve content, unless for some reason you only want human eyeballs to see your content. I was going to cite the LinkedIn case where, last I had heard, the courts had decided that scraping was legal... Headline [0] from April: > Court rules that data scraping is legal in LinkedIn appeal > LinkedIn has lost its latest attempt to block companies from scraping information from its public pages, including member pages. ... but upon googling it, I found a more recent [1] ruling :/ > LinkedIn prevails in 6-year lawsuit against data scraper > The U.S. District Court for the Northern District of California sided with LinkedIn in its six year lawsuit against a firm that scraped data ... So that sure puts a nail into the argument I was going to make. But still, while I think your use case lines up with the spirit of this kind of system, I think the reality is that it also would be used by every single site with a signup wall to kill off the archive.ph's of the world. 0: https://www.zdnet.com/article/court-rules-that-data-scraping-is-legal-in-linkedin-appeal/ https://www.zdnet.com/article/court-rules-that-data-scraping... 1: https://iapp.org/news/a/linkedin-prevails-in-six-year-lawsuit-against-data-scraper/ https://iapp.org/news/a/linkedin-prevails-in-six-year-lawsui...
- asdfghjhgfderty 4y agosadly, you are completely wrong. just look at captcha usage. yeah, very few follow the original recommendation of showing captcha for ips that already showed signs of being bots etc. but the vast majority shows captchas for absolutely anything. I can't even book a dmv appointment today without answering a gratutious one. same will surely happen with PAT, especially because it is so easy for the implementer to shove it everywhere. people are lazy and dumb.