4 ms·
Sounds like someone made a comprehensive directory of their customers who don't have properly secured APIs. Maybe instead of suing the creator of the directory
by bink 3y ago
Sounds like someone made a comprehensive directory of their customers who don't have properly secured APIs. Maybe instead of suing the creator of the directory they should use that list to contact their customers and have them secure their APIs?
- BoorishBears 3y agoExcept they did secure their API. Take this implementation: https://github.com/xtekky/gpt4free/blob/main/gpt4free/italygpt/__init__.py https://github.com/xtekky/gpt4free/blob/main/gpt4free/italyg... The site has a rate limit, doesn't expose their API key, and it has a CSRF token. In terms of non-intrusive measures they could have taken, they did it all right. So what's left on the table is intrusive stuff: HN has a lot of people constantly whining about how they're stuck in captcha hell because their hand built Lenovo running Firefox on BSD compiled on an abacus isn't recognized as a real client... but aggressive captchas are going to become even more pervasive if every GPT based product must fight off proxy attempts.
- pseg134 3y agoYeah that’s what selenium browsers are for, they aren’t going to win this battle. They need to secure their endpoints .
- BoorishBears 3y agoThe endpoints are secured. I think you might want to pick up more context on what the library does and what the actual issue is.