3 ms·
If you can identify bots more accurately, you get less "GPT SEO trash".
by pptr 3y ago
If you can identify bots more accurately, you get less "GPT SEO trash".
- callalex 3y agoThere is approximately a 0% chance that people won’t figure out how to make their bots “verified” if this goes through.
- square_usual 3y agoThat's not how it works, because the GPT SEO trash is being generated by the people on the server.
- pptr 3y agoWell there is that and there are users that post GPT SEO trash to Reddit et al, which is what the attestation API could help with.
- blibble 3y agothe spammers are quite capable of buying several hundred old phones with valid attestation certificates to pump out crap
- pptr 3y agoWhich is orders of magnitude more expensive than deploying the bot to a cloud or botnet. I don't know how much bot spam pays these days. Maybe it's still worth it.
- blibble 3y agothe attestation requirement increases the cost but also increases the value of the spam as the spammers competitors are put out of business
- webstrand 3y agoThis proposal does not affect bots producing web content, only (potentially) bots browsing web content.
- pptr 3y agoIt does affect bots creating social media content.
- hellojesus 3y agoNot necessarily. Even with WEI, spammers could farm legit tokens and then set up their own api that hands one out to their bot when one is necessary.
- pptr 3y agoMy understanding is that you can't reuse tokens, because the system uses challenge response.
- hellojesus 3y agoBut can you get a token and then not send it and save it for later? That's more what I was thinking. Not replay attacks but gathering a bunch of tokens thst are valid but never submitted to the origin, and then provide them via api requests to those that need one to use unauthorized devices with that origin.