5 ms·
Telling computers and humans apart is a wrong goal. Every request comes from a computer that is commanded by some human. And why shouldn't users be allowed to u
by Fice 3y ago
Telling computers and humans apart is a wrong goal. Every request comes from a computer that is commanded by some human. And why shouldn't users be allowed to use automated user agents when they don't do it for spamming or anything malicious?
CAPTCHA is essentially a proof-of-work variant where challenges are designed to be solved by humans rather than computers, and same as any PoW it works by means of consuming some limited resource (human time, processor time, energy).
- teacpde 3y agoA lot of times the purpose is more on rate limiting than disallowing bot access. The goal to tell apart is on the premise that humans are a lot slower than bots.
- weird-eye-issue 3y agoIn our SaaS we have usage limits and rate limits. Have never needed to implement "bot detection" for this reason
- kalleboo 3y agoHow do you rate limit a botnet coming from tens of thousands of different IP addresses?
- weird-eye-issue 3y agoFor anonymous/free users we have very strict usage limits and the functionality is more limited to only operations that cost us less money. So a very targeted attack would do damage but that is true of basically any system and we could flip on bot blocking in Cloudflare if needed and if that would help
- remram 3y agoCloudflare's bot blocking uses CAPTCHA... By your own admission, the only reason you don't have a CAPTCHA is that you haven't needed one yet.
- weird-eye-issue 3y agoAgain, we have rate limits and usage limits in place. You know that you can pay to have Captchas automatically solved, right? It's not the solution to all problems. Obviously if a targeted DDOS happens then some changes would be required. Also, that is no longer the case that Cloudflare uses Captchas for bot blocking. That's the legacy mode
- remram 3y agoThe fact that you can pay for both doesn't make them equivalent. To have a similar cost for spammers, you would need to request a challenge that takes many minutes to solve, which you just can't do. There is a strict limit on how long a user will wait for your security check and you can't pretend otherwise. Let's stop pretending that all things are in the same bucket because "you can pay to have it solved". That's such a weird claim. For the right price you can have someone rob a bank for you, that doesn't mean it's as safe as your $2 padlock.
- weird-eye-issue 3y agoWay to completely miss the point At this point you are just arguing for the sake of it. What is it you are even trying to debate at this point?
- remram 3y agoThe point is way upthread, it's literally the top comment on this submission. I don't know where you got lost on the way.
- weird-eye-issue 3y ago
- ozim 3y agoI see you don’t understand why people make websites or systems. Or why people make bread. I don’t make application so that users benefit or to make them happy. I make applications so that I can earn money. Earning money requires having human on the other side. Just like you are not making bread to make bread and throw it into a shredder. If someone has scheme where automation is beneficial they will create API for their system. You should use API if I provide one. But when I create UI then I create it for people to use it.
- xigoi 3y ago> I don’t make application so that users benefit or to make them happy. I make applications so that I can earn money. This is why most commercial software is so bad.
- ozim 3y agoAnd open source maintainers are burning out or writing rants how no one wants to pay. There is no “non commercial software” that is better even if commercial is bad it is still better than non existing one.
- figassis 3y agoWhy not both, make money and benefit people. I think that’s what earning money means. Otherwise you’re just making money at someone else’s cost.
- ozim 3y agoYou always have to do software in a way that people will benefit because otherwise they will not pay. Read again my down voted post and think about the sentence in context of post where "Fice" wrote: "Telling computers and humans apart is a wrong goal.". Then add to that topic of CAPTCHA and that CAPTCHA is annoying for users so adding CAPTCHA is not beneficial for users so it specific case and discussed in context.
- j16sdiz 3y agoThe main goal usually like anti-spam or anti-scraping. Some shop (for example, concert ticket-selling) have very limited supply and high demand, and don’t want automation in buying.
- kalleboo 3y agoI always figured that CAPTCHAs worked because they limited on a resource that was harder to steal - human attention. Rate limit by IP, and you get attacked by a botnet that "steals" IP addresses with malware. Rate limit by PoW and you get people stealing AWS accounts, or using aforementioned botnet. See bitcoin mining. Rate limit by CAPTCHA and you have to get a lot more clever (see things like setting up porn sites and proxying CAPTCHAs there) So while you can pay to have CAPTCHAs solved, you actually DO have to pay and can't just steal your way in, so it means your target has to be more valuable.
- runeks 3y ago> So while you can pay to have CAPTCHAs solved, you actually DO have to pay and can't just steal your way in, so it means your target has to be more valuable. None of these things you listed above are available for free. They all require either effort to obtain or paying someone to do the work.
- remram 3y agoSomeone did the math down thread: https://news.ycombinator.com/item?id=37056504 https://news.ycombinator.com/item?id=37056504 Unless you set your challenge to many minutes of work, you are not competitive with the human-centric solutions.
- rmbyrro 3y agoCan you steal AWS accounts with no effort? And keep stealing them after you get blocked on the first ones?