4 ms·
I am most likely misunderstanding this, but why can't you just use browser automation to then generate the turnstile token? For example, just use Playwright/Sel
by SCUSKU 3y ago
I am most likely misunderstanding this, but why can't you just use browser automation to then generate the turnstile token? For example, just use Playwright/Selenium/Phantom to generate the token and then use that in an API call?
Otherwise, great write-up! And excellent service!
- ahofmann 3y agoThis will cost you time and most likely money. And that's stopping a lot of attackers. And if you don't stop them, you at least slowed them down big time. This could also be enough to make the attack useless.
- didntcheck 3y agoAnd in addition to the implicit proof-of-resources of forcing attackers to run a bunch of Chrome slaves, there' are also explicit POW/S challenges in the code, according to the article. It's quite an old idea [1], to add a cost which is trivial for users but a significant overhead for spammers [1] https://en.wikipedia.org/wiki/Hashcash https://en.wikipedia.org/wiki/Hashcash
- michaelt 3y agoCloudflare's code attempts to detect browser automation is happening. For example, desktop computer but clicking things without moving your mouse? Suspicious. Say you're a phone, but have desktop computer fonts installed? Suspicious. And suchlike, the precise methods are the results of a cat-and-mouse game. If these heuristics identify your browser as suspicious, they either show you an interactive captcha, or they just refuse your request.
- nijave 3y agoYup, some of these are pretty invasive like opening websocket connections to localhost to try to find daemons running on the clients machine (I think eBay and maybe others were doing this)
- yjftsjthsd-h 3y ago> For example, desktop computer but clicking things without moving your mouse? Suspicious. The war on accessibility tools remains deeply irritating.