4 ms·
It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and anothe
by everdrive 7mo ago
It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and another browser to attempt to prevent tracking users across the web.
Nick, I understand the practical realities regarding why you'd need to try to tamp down on some bot traffic, but do you see a world where users are not forced to choose between privacy and functionality?
- 0x3f 7mo agoMeet me in a cafe and I will sign a JWT saying you're not a bot. You can submit this to whoever will accept it.
- jagged-chisel 7mo agoSounds like we’re bringing back the PGP key signing parties
- __MatrixMan__ 7mo agoThe sooner we do the better.
- hathawsh 7mo agoI wonder what the PGP signing concept does to thwart people who want to profit and don't care about the public good. It seems like anyone who attends a signing party can sell their key to the highest bidder, leading to bots and spammers all over again.
- 0x3f 7mo agoYou can never prevent things like this, but you can make it expensive enough to effectively solve the problem for almost all use cases.
- __MatrixMan__ 7mo agoIn the flat trust model we currently use most places, it's on each person to block each spammer, bot, etc. The cost of creating a new bot account is low so it's cheap to make them come back. On a web of trust, if you have a negative interaction with a bot, you revoke trust in one of the humans in the chain of trust that caused you to come in contact with that bot. You've now effectively blocked all bots they've ever made or ever will make... At least until they recycle their identity and come to another key signing party. Once you have the web in place though, a series of "this key belongs to a human" attestations, then you can layer metadata on top of it like "this human is a skilled biologist" or "this human is a security expert". So if you use those attestations to determine what content your exposed to then a malicious human doesn't merely need to show up at a key signing party to bootstrap a new identity, they also have to rebuild their reputation to a point where you or somebody you trust becomes interested in their content again. Nothing can be done to prevent bad people from burning their identities for profit, but we can collectively make it not economical to do so by practicing some trust hygiene. Key signing establishes a graph upon which more effective trust management becomes possible. It on its own is likely insufficient.
- zar1048576 7mo agoDefinitely miss those!
- deleted 7mo ago[deleted]
- magicseth 7mo agoIf apple approves it, ive got a solution: A keyboardthat attests to your humanity https://typed.by/magicseth/2451#2NyGLfAQxmqRiAOTlaX7ma3G4d1o4PegUpK6m-LS6ac https://typed.by/magicseth/2451#2NyGLfAQxmqRiAOTlaX7ma3G4d1o...
- mzajc 7mo agoBrilliant! Just the thing we want: more hardware attestation, more deanonymization, less user control, all diligently orchestrated in a repository where the only contributor is Anthropic Claude [0]. Comes complete with a misaligned ASCII diagram in the README to show how much effort the humans behind it put in! Yes, even their "humanifesto" is LLM output, and is written almost exclusively in the "it's not X <emdash> it's Y" style. [0]: https://github.com/magicseth/keywitness/graphs/contributors https://github.com/magicseth/keywitness/graphs/contributors
- delish 7mo agoThose are all situationally-valid criticisms, but I've long thought the ability to have smartphones' cameras cryptographically sign photos is good when available. The use case is demonstrating a photo wasn't doctored, and that it came from a device associated with e.g. a journalist, who maintains a public key. Of course, it should be optional.
- magicseth 7mo agoYes! That's what I'm getting at. This protocol optionally allows you to sign with your private key, but you don't have to for the protocol to provide utility. It could just be enough to say "if you trust magicseth's binary and apple, then this was typed one letter at a time" There's nothing stopping folks from typing a message an LLM wrote one at a time, but the idea of increasing the human cost of sending messages is an interesting one, or at least I thought :-(
- radlad 7mo agoThe problem is that it's not optional to end-users if sites enforce its use.
- tshaddox 7mo agoDoesn’t really make sense, because any service can just say “you must paste your human-attestation JWT here to use this service” and plenty of people will.
- 0x3f 7mo agoYou can just decay your trust level based on the `iat` value. That way people will need to keep buying me coffee. I can optionally chide them for giving out their token. If you're engaging with the idea seriously, I suppose we'd need to build a reputation or trust network or something. Although if you're talking about replay attacks specifically, there are other crypto based solutions for that.
- magicseth 7mo agoI am engaging with this seriously! I don't know if there will be any real solution. But I think it's worth exploring.
- tshaddox 7mo agoMy point is that there probably is no way in principle to distinguish between a human user utilizing automation on their own behalf in good faith (e.g. RSS readers) and bad faith automations.
- crote 7mo agoThat's a feature, not a bug. A human is personally responsible for a bot acting on their behalf. If your bot behaves, nothing is going to happen. If you keep handing out your personal keys to shitty misbehaving bots, then you will personally get banned - which gives you a pretty good incentive to be a bit more discerning about the bots you use.
- 0x3f 6mo agoYes, everything should just be agnostic, as long as the incentives work out it's all fine. Like if we had worked out micropayments for the web (not saying that's a good idea per se), then who cares if you're a bot or a human when you're paying a toll either way? Flipping it to be a cost rather than payment is functionally equivalent.
- SV_BubbleTime 7mo agoFirefox multicontainers are pretty cool. But it’s an advanced process that most people wouldn’t do or do correctly.
- Imustaskforhelp 7mo agoThe possibilities with Firefox multi containers and automation scripts as well are truly endless. It's also possible to make Firefox route each container through a different proxy which could be running locally even which then can connect to multiple different VPN's. I haven't tried doing that but its certainly possible. It's sort of possible to run different browsers with completely new identities and sometimes IP within the convenience of one. It's really underrated. I don't use the IP part of this that I have mentioned but I use multi containers quite a lot on zen and they are kind of core part of how I browse the web and there are many cool things which can be done/have been done with them.
- Sabinus 7mo agoI love the containers too. My current use case is to keep my YouTube account separate from my Google one. Google doesn't need all that behavioural data in one place. It's a pity Firefox doesn't get the praise it deserves half as much as it cops criticism.
- halJordan 7mo agoIt is absolutely not an advanced process. It's clicking a gui. It's not advanced thinking to understand profiles. It's a basic ability to hold multiple things in your mind at once. Telling people that's difficult only increases the societal problem that being ignorant is ok.
- docjay 7mo ago“Difficult” is a relative term. They were saying it was a difficult concept for them, not you. In order to save their ego, people often phrase those events to be inclusive of the reader; it doesn’t feel as bad if you imagine everyone else would struggle too. Pay attention and you’ll notice yourself doing it too. “Ignorant” is also infinite - you’re ignorant of MANY things as well, and I’m sure you would struggle with things I can do with ease. For example, understanding the meaning behind what’s being said so I know not to brow-beat someone over it.
- gruez 7mo ago>It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and another browser to attempt to prevent tracking users across the web. What are you talking about? It works fine with firefox with RFP and VPN enabled, which is already more paranoid than the average configuration. There are definitely sites where this configuration would get blocked, but chatgpt isn't one of them, so you're barking up the wrong tree here.
- scared_together 7mo agoIs your interlocutor barking up the wrong tree, or are you missing the forest for the trees? According to the OP: > The program checks 55 properties spanning three layers: your browser (GPU, screen, fonts), the Cloudflare network (your city, your IP, your region from edge headers), and the ChatGPT React application itself (__reactRouterContext, loaderData, clientBootstrap). I guess Firefox VPN will hide the IP at least. But what about the other data, is it faked by RFP? Because if not, the so-called privacy offered by this configuration is outdated. You might be fingerprinted by OpenAI right now, as “that guy with all the Firefox anti-fingerprinting stuff enabled, even though it breaks other sites”.
- gruez 6mo ago>But what about the other data, is it faked by RFP? Yes, RFP spoofs or at least somewhat obfuscates/normalizes GPU/screen/font info. The rest are integrity validations of the server/app, and not really identifying in any way. >You might be fingerprinted by OpenAI right now, as “that guy with all the Firefox anti-fingerprinting stuff enabled, even though it breaks other sites”. I'm not sure what the broader point you're trying to make here is. Is fingerprinting bad? Yes. All things being equal, I'd rather not have it than have it, but at the same time it's not realistic to expect openai to serve anonymous requests from anyone. Back when chatgpt was first launched you had to sign up and verify your phone number. Compared to mandatory logins, fingerprinting is definitely the lesser evil here.
- scared_together 6mo ago
- madrox 7mo agoI am not Nick, but there's a few ways that world happens: the free tier goes away and what people pay for more correctly reflects what they use, this all becomes cheap enough that it doesn't matter, or we come up with an end to end method of determining usage is triggered by a person. Another way is to just do better isolation as a user. That's probably your best shot without hoping these companies change policies.
- mememememememo 7mo agoLocal models for privacy. You want to go to the world's best hotel? You are gonna be on their CCTV. Staying at home is crappier but private. Unfortunately for the first time moores law isn't helping (e.g. give a poor person an old laptop and install linux they will be fine). They can do that and all good except no LLM.
- karlgkk 7mo ago> You want to go to the world's best hotel? You are gonna be on their CCTV. ironically, in high end hotels, there's often a lot less cctv. not none. just less. rich people enjoy privacy
- Barbing 7mo agoSo they’re not just hidden better? Does make sense. Well, I can use the world‘s best safety deposit box without being on CCTV while I pass secrets in and out of it, right? Just not for free. Bummer, this sounds like it is about to turn into a Monero ad (“let us pay privately”)
- wolvoleo 7mo agoProbably not even hidden because rich people are also catching a lot of legal winds, in which case the hotel has no choice but to provide the material. Better not to have it in the first place. You don't want your hotel cams listed as evidence in a 500M$ divorce case I guess. Also are hidden cameras even legal? I know here in EU they aren't.
- xtajv 6mo agoIn hotels of all tax brackets, you usually get a room key. And the salient difference is that CCTV is simply defense-in-depth, not a primary means for authentication.
- nozzlegear 7mo ago> Staying at home is crappier but private. Doesn't make sense, my home is much more preferable to a hotel
- kevin_thibedeau 7mo agoI've been doing that for years. Cloudflare is slowly breaking more and more of the web.
- atoav 7mo agoWhat if I run a website and OpenAI produces bot traffic? Do they also consider it abuse when they do it?
- cruffle_duffle 7mo agoThere is also the browser I use to get Claude to route around people blocking its webfetch. Both Playwright and chrome-mcp.
- gck1 7mo agoCamoufox?
- subscribed 6mo agoThis is indeed what I do. And you also should. Separate browser for banking, trusted shipping sites etc, and the normal one. Make sure not to browse the Internet without adblock and/or similar.
- lukewarm707 6mo agoi am increasingly moving towards a model of 'no browser'. search for me is now a proprietary index (like exa) that filters rubbish, with a zero data retention sla. so we don't need google profiling. the content is distilled into markdown pulled from cloudflare's browser rendering api. i let cloudflare absorb the torrent of trackers and robot checks, i just get md from the api with nothing else. cloudflare is poacher and gamekeeper. an alternative is groq compound which can call browsers in parallel. for interactive sites, or local ai browsing, i sometimes run a browser in a photon os docker with vnc, which gives you the same browser window but it runs code not on your pc. that said little of my use is now interacting with websites, its all agentic search and websets so i don't have to spend mental energy on it myself
- lukewarm707 6mo agois this bad?
- gib444 6mo ago> It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and another browser to attempt to prevent tracking users across the web. Every time I try this, I end up crossing wires (ie using the browser that 'works' for most things, more than the one that is 'broken')