7 ms·
Show HN: Replace CAPTCHAs with WebAuthn passkeys for bot prevention
I built Nocaptcha after getting frustrated with traditional CAPTCHAs both as a user and developer. WebAuthn passkeys offered a promising alternative that's both more secure and user-friendly.
What makes Nocaptcha different:
- Uses WebAuthn standard instead of puzzle-solving
- No need for users to remember passwords or solve puzzles
- Open source
Current limitation:
Working with W3C WebAuthn Community Group on true passkey disposal for this use case.
Looking for feedback particularly on:
1. Integration experience
2. User experience compared to traditional CAPTCHAs
- itake 2y agoI'm confused how this works. I tried the demo and Bitwarden asked me if I wanted to save the passkey. From a UX experience, this felt weird.. Why do I need to create an account, and save that account? Why is passkey storage prevent bots? Just that bots haven't added that automation yet?
- herghost 2y agoTotally agree with this - when it popped up asking me if I wanted to use my fingerprint to do ..._something_... I felt like I was at risk and noped out.
- dboreham 2y agoPasskey can be thought of as software emulation of a smartcard (aka hard token aka Yubikey). When it asks you to save it, that's when it creates the virtual smartcard in some reasonably secure local storage (possibly TPM-secured or at least kernel-secured). The benefit of this approach is that a bot doesn't have the private key. Of course you want to be sure that webauthn on boarding can't be botted.
- itake 2y agoI'm still confused... Why can't headless Chrome with Bitwarden easily by-pass this? What private key?
- Oras 2y agoIt worked fine on Mac, curious how does it work on Windows?
- jeroenhd 2y agoWindows has had TPM-backed authentication mechanisms baked in for a while now. For devices lacking biometrics, you authenticate with your Windows PIN/password, use a phone, or use a yubikey or similar device. Or, on any OS, you can use addons like Bitwarden to take over WebAuthn for you. I do wonder what the macOS workflow looks like, especially if you don't have a fingerprint reader on your keyboard.
- deleted 2y ago[deleted]
- politelemon 2y agoIt does nothing on Linux.
- suprfsat 2y agoIn Chrome devtools, use WebAuthn > Enable virtual authenticator environment to see the result.
- Aachen 2y agoWhat part of webauthn can a computer not do? I understand if you say bots are currently not programmed to, but is that why this will temporarily work or is there something more fundamental?
- n144q 2y agoYeah, the notably missing part in README is "how this works".
- Aachen 2y agoWhat I'm scared of is some sort of cryptography becoming the death of the open web. Baking keys into your hardware and doing remote attestation. It doesn't tie you to a real-world identity except that you're locked into using an unrooted (DRM'd) device for using online services like a normal person If I had to choose between two evils, I'd rather upload my passport to cloudflare and be able to get anonymous tokens from their API (RSA blind signatures or whatever) to prove I'm a real person and browse the web with Firefox and no closed source components, than be forced into hardware attestation and a locked-down device. But uploading government IDs to a (few) central point(s) of trust will create outcry about privacy whereas hidden cryptography baked into normal people's devices with Google Play Services and Apple Something and just working in the background goes unnoticed until everyone (the 99% who aren't on a custom ROM) already experienced the benefits For webauthn I know it can be all software, I've used virtual devices for testing a server implementation's security, but I vaguely remember there also being a mode that requires having keys signed by a hardware vendor. Just not sure anymore if that was webauthn or something else related to authentication
- jeroenhd 2y agoApple has already shipped remote attestation with Safari and Cloudflare has been working to standardise their test release of this scheme as a web standard. It's only a matter of time before remote attestation starts replacing CAPTCHA thanks to the advances in AI. The worst part will probably be that any hardware backed attestation mechanism will need to blacklist entire ranges of devices once scrapers and other bots find a mechanism to mass produce attestation results, the same way a dumped key from a bluray player carries the risk of killing all future bluray player functionality from devices with that model. WebAuthn is pretty useless for this purpose as far as my understanding of it goes (as you can pretty much emulate all of it, except if the website has a hardware whitelist that'll eventually block a lot of legitimate users as well). It's harder to bypass remote attestation mechanisms, though, as they're actually meant to provide security against bots.
- jsnell 2y agoThis is neither a new idea or a good one. Cloudflare did a PR launch of pretty much the same thing a few years back, and that you haven't actually seen it in the wild probably tells you all you need to know about how useful it is. Webauthn is not an integrity attestation; it doesn't tell you anything about how trustworthy the client is. Nor is it a uniqueness attestation; an attacker can mint an arbitrary number of different identities at basically no cost. It's a primitive for building account security systems, not one for building abuse prevention ones. Some relevant HN threads: https://news.ycombinator.com/item?id=27141593 https://news.ycombinator.com/item?id=27141593 https://news.ycombinator.com/item?id=27153254 https://news.ycombinator.com/item?id=27153254 https://news.ycombinator.com/item?id=27500326 https://news.ycombinator.com/item?id=27500326
- blibble 2y agothere is attestation of the registration device in webauthn so you can tell that a token was signed by an official yubikey, apple secure enclave, tpm, etc for yubikeys the attestation signing certificate is shared between devices, but this number is limited so you could rate limit... just it would be a horrible experience when you are limited
- doctorpangloss 2y agoI don’t see that in the code. But you’re right that there is something heuristic you can do.
- yonixw 2y agoHere is a relevant discussion about it in S/O: https://stackoverflow.com/questions/67797804/how-to-distinguish-fido2-devices https://stackoverflow.com/questions/67797804/how-to-distingu...
- blibble 2y agothe cynic in me thinks this will become mandatory on major websites at some future point so you won't be able to log into youtube unless you have a TPM approved by Google
- Pxtl 2y agoHonestly I just want government backed digital ID for this stuff. I know the concerns. I no longer care. The benefits outweight the costs, imho. I want to be able to tell a site "yes I'm Martin here's proof either ban me or let me in but stop making me jump through hoops to prove ID. And so that social sites I use will no longer have to deal with undesired non-unique accounts for bot swarms and sockpuppets and the like. The political usefulness of swarms of bots and sockpuppets is why I have conspiracy theories about the conspiracy theories about digital ID.
- hombre_fatal 2y agoProps for sharing what's probably a ubiquitously hated opinion on HN. Here are two of my own, just to join in: 1. Social credit score system. We should all be able to point our phone at antisocial behavior and damage their score. Until then there's pretty much zero recourse against people who have hostile social behaviors that don't commit a crime (like arguing with the McDonalds employee or causing a scene when someone asks them to turn down their music on the bus). People hate on "Karens" but they're actually our last remaining line of defense against these people. 2. As soon as you get on a public road, the government should have dystopian-level control over your car. You can't speed. You can't run a red light (or it will be video recorded and you'll be insta-billed). When there's a wreck, the camera feed in all nearby vehicles is auto-uploaded to the net so all parties can see what happened, no fuss. Break the rules a few times? That's fine, you get your government issued tiny zip car for a year and we'll see if you can respect the shared roads after that. And, of course, alcohol breath analysis to drive.
- iou 2y agoAs other commenters have said, a better solution needs to be something that is prohibitively difficult for bots to mint. I’m sure there are a few contenders in the space but one I’m aware of is [worldcoin](https://world.org/ https://world.org/)
- qingcharles 2y agoWorldcoin has always creeped me out since this: https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/04/29155417/worldcoin-orb-indonesia-1024x548.png https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/202...
- solardev 2y agoSaruman's vacation pics?
- latexr 2y agoGiving biometric data to Sam Altman has to be one of the worst ideas we could pursue. Not only is Worldcoin a know scam, rightfully being banned in several countries, Sam and OpenAI are one of the major reasons realistic-looking misinformation became easier to proliferate. He’s done enough damage, let’s not make the creator of the problem in charge of the “solution” that benefits him too. https://www.buzzfeednews.com/article/richardnieva/worldcoin-crypto-eyeball-scanning-orb-problems https://www.buzzfeednews.com/article/richardnieva/worldcoin-... https://www.technologyreview.com/2022/04/06/1048981/worldcoin-cryptocurrency-biometrics-web3/ https://www.technologyreview.com/2022/04/06/1048981/worldcoi...
- throwawayian 2y agoI don’t think you understand the problem space. Although, this is a great alternative for SMB’s who aren’t being targeted by attackers who are writing tools specifically for their business. But, also.. A hardcoded “what’s 7\1=“ would also achieve the same outcome. Barrier to beat is “can the attacker put together a webauthn emulator”. Low, but will work for many organisations for a long time.
- lofaszvanitt 2y agoNo need for passkeys, just a back and forth between your physical secure key and the browser.