3 ms·
What is the point of making the user click the box? Can't that be skipped altogether?
by ss1996 3y ago
What is the point of making the user click the box? Can't that be skipped altogether?
- david_draco 3y agoIt checks lots of browser APIs and makes a proof-of-work calculation in the background. I guess we are getting close to paying for entry with computation.
- KirillPanov 3y agoMoving the mouse causes the browser to enable fingerprintable APIs. You aren't paying with computation, you're paying with your data. https://community.cloudflare.com/t/near-infinite-loop-of-human-verification/483217?page=2 https://community.cloudflare.com/t/near-infinite-loop-of-hum...
- david_draco 3y agoI took it from the article: "We find and stop bots by running a series of in-browser tests, checking browser characteristics, native browser APIs, and asking the browser to pass lightweight tests (ex: proof-of-work tests, proof-of-space tests) to prove that it’s an actual browser." but yes, not yet.
- isoprophlex 3y agoThe way you move your mouse, the timing of the click button down/button up events, all those things go into some algo to determine if you're a bot or not Edit: actually not, I'm full of shit, ignore me
- tritiy 3y agoThe article stated that this has nothing to do with it and the click would technically not even be necessary. It is just a way to start the procedure where Turnstile verifies your browser.
- isoprophlex 3y agoWell, so much for my reading comprehension skills...
- vntok 3y agoNo, not at all. The click is not important / needed, what matters is that by moving the mouse you're granting Cloudflare's JS permission to execute functions in the background that can't run without user interaction.
- est 3y agoI guess it could be merged with the "login" or "checkout" button with few lines of JS.
- omneity 3y agoHaven’t dug in their code, but my best guess is to get the user to trigger a “trusted” event which is needed for access to certain browser APIs such as clipboard or audio. Probably some fingerprinting trick. The same is done by shady news websites which load a single sentence and ask you nonsensically to “Click to expand Article”.
- danShumway 3y agoMy hot take for a while has been that trusted events are bad UX design. Highlighting text on a page can be treated as a trusted event to trigger things like audio autoplay. It's a tricky problem to solve, and I guess it's technically better than nothing, but we really should be focusing on surfacing these permissions in a more user-understandable way. There's friction there -- we want to be able to go to Youtube and click a single button and have a video play. But stuff like video autoplay does not make sense to hide behind a user click that can be anywhere on the page or a keypress that can be basically anything at all. It's too easy of a bar to cross imo; it breaks certain applications and makes them less reliable, but also makes it far too easy to just have a popup banner with an X, and poof, now you have all the permissions you need.