15 ms·
Cloudflare Turnstile requiring fingerprintable WebGL
- deleted 4mo ago[deleted]
- nulledy 4mo agoAs turnstile users on several of our sites, I think we need to revisit that decision.
- sammy2255 4mo agoOut of curiosity, why did you have it on in the first place?
- nulledy 4mo agoBot rejection for contact forms. Better UX than reCaptcha.
- nlitened 4mo agoDid you think it rejects bots by using some kind of magic?
- nulledy 4mo agoWell, of course not, don't be silly. But if it blocks visitors of our site from using non-standard browsers, perhaps its worth exploring alternatives. Nearly all of our sites are visiting by extremely tech literate folks, the exact type that may not be using Google Chrome or Firefox.
- kykat 4mo agoWhat? Big tech company is evil? No way! I thought cloudflare were good guys...
- aboardRat4 4mo agoBig tech companies are always visited first by the G-men who need something done.
- aleksandrm 4mo agoWhat gave you the impression that Cloudflare were the good guys?
- tardedmeme 4mo agoProbably everyone on HN singing their praises for the past 10 years.
- kykat 4mo agoAnd my og comment getting downvoted on this very intellectual forum that definitely isn't an echo chamber
- Petersipoi 4mo agoYour very sarcastic, uninteresting comment getting downvoted is not an indication that forum isn't intellectual. It's an indication that you aren't behaving intellectually.
- bflesch 4mo agoCognitive dissonance in tech millionaires is quite strong, still worth it to trigger them from time to time on a factual basis.
- tick_tock_tick 4mo agoPretty sure every thread has a massive chain about them being a NSA honey pot.
- 348752389 4mo ago[dead]
- Fokamul 4mo agoPlease, anyone from EU (US is doomed rofl) create a petition to ban browser-fingerprinting in EU, across all existing browsers. I'm not good at creating petitions but can happily sign it. Also with stop killing games and anti-chat control. I can imagine this can get a traction, if it's explained in youtube video to "normal" people.
- koolala 4mo agoa. Accept All b. Accept Only Necessary Fingerprinting
- fidotron 4mo agoA better solution would be to make webgl, webgpu and (especially) webrtc have some sort of prompt before they can be in any way used in that fashion, but this will absolutely destroy web ux Windows Vista style.
- richwater 4mo agoYou mean the "Accept Cookies" banner that has become a complete joke? Pass
- MyMemoryfails 4mo agoI think he means browser permissions, for example when browsers want notify or record your mic theres a permission check something similar for webgl.
- J-Kuhn 4mo agoFun Fact: When Cookies were introduced into Netscape, you got a browser permission prompt. Then browser vendors set it to allow by default. And then legislation required those consent boxes back, so everyone built their own, instead of demanding that the default should be changed back.
- bflesch 4mo agoIt's about explicitly deciding to allow certain capabilities on a per-website basis. No major browser allows defense-in-depth via fine-grained website permissions. Even simply changing the user agent was sabotaged at Firefox, and choosing one user agent per domain is wishful thinking.
- anonym29 4mo agoSay no to malware - say no to Cloudflare
- corstian 4mo agoFor real -- that stuff is obfuscated in a way most malware could learn from.
- malka1986 4mo agoThanks, i did not know about `privacy.resistfingerprinting` I'll make sure to fail all cloudflare turnshit in the future.
- Wowfunhappy 4mo ago...in the age of AI, does anyone have an actual solution for keeping out bots while preserving the privacy of humans? Obviously this is terrible, but I think there's a possibility it's the least terrible option? Another option is IP reputation, which I think is worse. Or scanning a code with a non-rooted phone, which I think is even worse than that!
- spacedoutman 4mo agoPrivate invite only internets
- arbol 4mo agoLAN parties?!
- fidotron 4mo ago> ...in the age of AI, does anyone have an actual solution for keeping out bots while preserving the privacy of humans? There isn't one, and pretending otherwise is nonsense because humans will always provide their credentials to something to act on their behalf. In the limit you end up with Chinese phone farms.
- tardedmeme 4mo agoRight. Botnet operators love cloudflare because they make so much money renting out compromised machines to pass their tests.
- malka1986 4mo ago> keeping out bot You can forget about it. It is not possible. Simple as that.
- Wowfunhappy 4mo agoLet's say I'm selling concert tickets. How do I prevent bots from buying up all the tickets and scalping them?
- denysvitali 4mo agoCloudflare is known to use fingerprinting to detect scrapers For example, they use JA3 fingerprints and match them against the UA to block stuff like cURL while allowing OkHttp (Android clients) - but this can be easily be spoofed with packages such as CycleTLS [1]. I don't want to defend them, because they gate away a good chunk of the internet with their "bot protection", but unless you do PoW (which is also ecologically a nightmare), probably fingerprinting is the way to go - completely destroying the privacy of everyone involved. Cromite, a privacy conscious fork of Chromium for Android, has constantly issues with CloudFlare Turnstile [2] because they (Cloudflare) try to fingerprint it in multiple ways in order to pass the challenge. The only way to get it to work would be to join the CloudFlare Browser Developer program - which requires signing an NDA. Rightfully so, the project maintainer didn't want to do it. If you want to see the extent of what CloudFlare does to fingerprint the browsers, just have a look in the issue [2] and see which flags need to be disabled in order to allow CloudFlare to pass the challenge. I understand both sides, but at least CloudFlare could be flexible enough to fall back to PoW instead of just blocking people from sending forms or accessing websites... [1]: https://github.com/Danny-Dasilva/CycleTLS https://github.com/Danny-Dasilva/CycleTLS [2]: https://github.com/uazo/cromite/issues/2365 https://github.com/uazo/cromite/issues/2365
- PearlRiver 4mo agoThis is why I have two separate browsers. If you want to do official stuff like paying for things you need to get through cloudflare.
- helterskelter 4mo agoFirefox added profile switching recently. Works good. (That said, I still keep separate machines. One for doing "official" things, the other for everything else)
- b65e8bee43c2ed0 4mo ago>Works good. does it? same binary, same machine, same display, same 781 other heuristics.
- adamtaylor_13 4mo agoSo if you need to prevent bot abuse, but also don't want an ugly captcha every time someone goes to sign up, is there a better option?
- ribtoks 4mo agoUse proof-of-work captchas, many are private by default. Look into Private Captcha or Cap captcha.
- phoronixrly 4mo agoHow does proof of work stop bots?
- stephantul 4mo agoBecause it destroys the economics of scraping. It’s too expensive with proof of work, or at least not as economically viable
- gruez 4mo agoDepends on what type of scraping you're trying to stop. For the dumb scrapers that would try to scrape every page on a git forge (for which there are a bazillion pages for a modest project, because of how the site works), yeah it might deter them enough to stop. For anything high value (eg. reddit comments or retail prices), 10s of cpu time isn't going to stop them.
- pmontra 4mo agoIt will not scare away bots but 10 seconds of wait (CPU or only a sleep) will turn away many real users. "This site is so slow, I'll use something else." A kind of reverse captcha.
- deleted 4mo ago[deleted]
- avallach 4mo agoDoesn't this mean we just need to make the webgl fingerprint resistance implementation smarter? Instead of explicitly rejecting webgl access or responding with dummy data, respond with data that is random within space of N common and reproducible patterns. E.g. emulate webgl implementation of some low spec but actually popular devices.
- bflesch 4mo agoAll of those advanced features should be enabled on a per-website basis but unfortunately even browsers whose marketing focuses on privacy don't allow you to do that. Same with TLS root CA certificates, there is no way to configure that a certain CA can only create certificates for certain domains.
- btown 4mo agoThe last screenshot in the OP article mentions that "a browser extension... adding random noise to canvas data" can be detected. Which isn't to say this perfectly detects all such randomization, but it's certainly an active part of the arms race.
- ranger_danger 4mo agoYes but the idea is that the protection should be part of the browser itself, then it becomes the expected norm AND isn't really "detectable" since there's no extension to redefine javascript variables. Scraper-friendly solutions like Camoufox or CloakBrowser make such changes to avoid having the same fingerprint every time while still appearing normal.
- gruez 4mo agoThis blog post is filled with false assumptions. >Turns out it's because Cloudflare wants to have a fingerprint of your device via WebGL, the only reason for doing this would be tracking. > So Cloudflare just banned all WebKitGTK browsers as I guess they put an exception for Safari. This is false. I ran firefox with: * hardware acceleration disabled (so software renderer, nothing to fingerprint) * resistfingerprinting enabled, including letterboxing with default window size * webgl disabled * VPN enabled * In a Windows VM By all accounts this should be the most suspicious fingerprint ever, but turnstile happily lets me through. If they want to track people, they're doing a pretty bad job. My guess is that OP's browser is getting banned because his WebKitGTK has a weird fingerprint, not because of webgl or whatever. > Such things are blocked in WebKit, and have been for years. Meaning it's tracking so awful that even Apple would block it, and as far as I can tell it's not the kind of privacy protection you can easily disable in it. This is also false. Webgl fingerprinting works just fine on Safari. They might try to mitigate it by adding some noise, but that's not so different than what firefox does, and is certainly not "blocked".
- superkuh 4mo agoYep. Cloudflare and cloudflare's customers don't care about blocking people that use non-standard browsers (or accessible browsers, or feed readers, or whatever). Using cloudflare defaults is basically saying, "Only major corporate browsers released in the last year or two can access this site."
- shiomiru 4mo ago> My guess is that OP's browser is getting banned because his WebKitGTK has a weird fingerprint, not because of webgl or whatever. So why is Cloudflare saying the author got blocked because of WebGL? > > Such things are blocked in WebKit, and have been for years. Meaning it's tracking so awful that even Apple would block it, and as far as I can tell it's not the kind of privacy protection you can easily disable in it. > This is also false. Webgl fingerprinting works just fine on Safari. They might try to mitigate it by adding some noise, but that's not so different than what firefox does, and is certainly not "blocked". While I don't have an iDevice to try, the assumption that they are special cased is fair... because they are: https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/ https://blog.cloudflare.com/eliminating-captchas-on-iphones-... (Yes, this is basically WEI in a shinier package.)
- JoshTriplett 4mo ago"This makes your browser appear suspicious because it looks like you're trying to hide your identity." Yeah, this needs to be burned to the ground.
- gruez 4mo agoBad optics aside, it doesn't actually reflect reality. See my other comment. You can enable basically all the privacy settings and still pass turnstile. Tor browser in a VM passes it, of all things. https://litter.catbox.moe/gaizpk692bhhs6b7.png https://litter.catbox.moe/gaizpk692bhhs6b7.png
- JoshTriplett 4mo agoAny idea what the difference is between your setup and the one in the article that failed with fingerprint-resistance enabled?
- gruez 4mo agoHe's using a custom browser, apparently: https://hacktivis.me/projects/badwolf https://hacktivis.me/projects/badwolf
- JoshTriplett 4mo agoI'm talking about the screenshot from Firefox.
- gruez 4mo agoIt didn't fail for him in firefox, even with privacy settings enabled.
- JoshTriplett 4mo agoIt tripped "Canvas Randomization Detected". See the last screenshot. Cloudflare's demo page still treats that as a pass, but complains about it. As is often the case with Cloudflare, I expect that they'll then take no responsibility for sites that use more aggressive settings.
- shevy-java 4mo agoI wondered about that too. So they allege that bots require that everyone now has to ID to the big service providers. Very dystopian situation. Skynet is currently winning the war.
- bflesch 4mo agoFirefox has so much built-in tracking it seems they want to push me to build my own browser. For example every time you open the settings there are several ways they are sending out pings to certain extensions. Also by default addons.mozilla.org is a privileged site so of course they include google tracking in it and they get the proper fingerprint no matter what you have configured.
- konform 4mo agoIf you are this motivated (I am!), how about joining forces on Konform Browser? Radio silence and remote third-party integrations disabled by default and generally sane and conservative defaults respecting old-fashioned notions like individual consent and data-protection regulations. Aside from general dev, could use a hand in bringing it to more platforms (mobile and flatpak are frequently asked) and taking a closer look at fingerprinting protections and what's currently tripping up the turnstile. https://codeberg.org/konform-browser/source https://codeberg.org/konform-browser/source
- deleted 4mo ago[deleted]
- tomrittervg 4mo ago> Also by default addons.mozilla.org is a privileged site so of course they include google tracking in it and they get the proper fingerprint no matter what you have configured AMOs privileges are limited to (A) installing extensions with only one prompt (instead of two) (b) launching some sort of "UI Tour" feature that highlights some features of the UI and (c) extensions cannot, by default, operate on the site. That last one is an unfortunate trade-off we've made because of the massive waves of malicious extensions. You can re-enable extensions access to AMO on a case by case basis: https://support.mozilla.org/en-US/kb/quarantined-domains https://support.mozilla.org/en-US/kb/quarantined-domains but I recognize this is an opt-in, non-default configuration. I am saddened to hear we use Google Analytics on the site, but I can tell you with certainty that it is not bypassing any of Firefox's built-in fingerprinting protections or getting any privileged access that way.
- kordlessagain 4mo agoI did warmups in Grub Crawler to fight this: https://deepbluedynamics.com/grub https://deepbluedynamics.com/grub
- 4oo4 4mo agoI tested this extension that I've been using for a long time on the turnstile page and it got through, fwiw. I think it's a bit more subtle than how resistfingerprinting works but not sure what the privacy tradeoff is. https://github.com/kkapsner/CanvasBlocker https://github.com/kkapsner/CanvasBlocker
- tosti 4mo agoLooks cool. And I wonder why I'd run this over JSshelter. It appears to do the same thing, no?
- 4oo4 4mo agoJSshelter looks cool, I'm not familiar but this makes it seem like it operates more like resistfingerprinting by blocking outright instead of noise injection, at the expense of more broken sites? https://jshelter.org/fpd/ https://jshelter.org/fpd/ What all security extensions do you run? After running into issues over the years, with extensions doing multiple things that fight each other, I switched to trying to block via ublock origin as much as possible, then prefer other extensions to just do one thing to extend coverage, like this one. Makes it much easier to troubleshoot/exclude/disable when it breaks something vs. fiddling in settings.
- BoingBoomTschak 4mo agoThanks for the report, I've been running this for a long time.
- Dwedit 4mo agoAdding noise to a canvas element is a mistake anyway. It means you can't develop a proper paint program using web technologies because your browser will mess with the image.
- tosti 4mo agoYou can still do that, but it may not be rendered correctly in a screenshot.
- boywitharupee 4mo agoYou can denoise it: https://github.com/google/security-research/security/advisories/GHSA-24cm-69m9-fpw3 https://github.com/google/security-research/security/advisor...
- deleted 4mo ago[deleted]
- dblohm7 4mo ago> Plus privacy.resistfingerprinting isn't enabled even when selecting "Strict" "Enhanced Privacy Protection" in the settings, great job there Mozilla. That pref is there for the Tor Browser.
- konform 4mo agoIt's enabled by default in Tor Browser and I'm not sure it can even be disabled? Also enabled by default for Konform Browser and Mullvad Browser, which borrow many of the privacy- and security-related patches from Tor Browser.
- jeroenhd 4mo ago> Plus privacy.resistfingerprinting isn't enabled even when selecting "Strict" "Enhanced Privacy Protection" in the settings, great job there Mozilla. For good reason. I've run that setting for ages but I kept having to disable it and add workarounds because websites would break in weird ways. Timezones in scheduling websites being messed up nearly made me miss a couple of appointments. There's no way to tell the user Firefox isn't broken without displaying a permanent banner like "if websites are broken in any way or you see weird glitches or your computer's time is wrong or fonts look weird or videos don't always work right, click here to disable fingerprinting protection". Interestingly, Turnstile breaks with resistfingerprinting but works with fingerprintingProtection, I guess the latter takes this crap into account.
- croes 4mo agoMaybe a good reason for not enabling it by default but a bad reason to not enabling it for strict settings. I somewhat expect breaking sites with strict settings, I don’t expect an still wide open tracking path. That’s deceiving.
- jeroenhd 4mo agoEven with resistFingerprinting, websites will be able to fingerprint you. There is no full immunity against fingerprinting. Websites already break often with the strictest protections enabled, adding a "super duper strict protections" mode will just lead to bug reports. Even more-than-bare-basic tracking prevention has HN threads full of comments like "doesn't work on <Firefox fork>" because they don't see the connection between fingerprinting protection, WebRTC/WebGL/WebGPU, and websites not working. People who are willing to take that bet can enable it in about:config.
- croes 4mo ago> Websites already break often with the strictest protections enabled, adding a "super duper strict protections" mode will just lead to bug reports. That’s what I‘m saying. They already break because of other effects of the strict settings, so what is the benefit of leaving resistFingerprinting turn off? > There is no full immunity against fingerprinting. There is 0 immunity if you don’t even try. Strict means, do what you can, not do somethings strict other not so strict and others ignore completely. Don’t call it strict if it isn’t strict
- Kiboneu 4mo agoIn other words, Cloudflare requires you to substantially increase your browser’s attack surface in order to visit websites.
- NoMoreNicksLeft 4mo agoYou're not quite going far enough. Cloudflare requires that you allow it to attack your browser, as a sort of virtual hazing ritual, before you're allowed into the club. That this hazing makes your browser vulnerable to attacks by others too is a side effect that bothers them not at all.
- Kiboneu 4mo agoAh yes, the TSA of the internet.
- neop1x 4mo agoIt is very similar to kernel modules for game anti-cheats. Soon, websites will work on unmodified Windows and Mac computers only, with a signed cloudflare kernel driver installed. :/ They are completrly destroying the web.
- Animats 4mo agoIs there a deal between Google and Cloudflare to make non-Chrome browsers harder to use? The pressure to use Chrome keeps increasing, and the amount of ad filtering you can do in Chrome keeps decreasing.
- wnevets 4mo agoI would wager to guess its one of the nature consequences of Chrome being the most popular browser on the web. Most legit traffic will be from Chrome.
- tardedmeme 4mo agoYes
- bigyabai 4mo agoIt doesn't stop there: https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/ https://blog.cloudflare.com/eliminating-captchas-on-iphones-...
- hack1312 4mo agoonly chrome was approved for use internally at cf 5 years ago when i left
- denismi 4mo agoAs someone who runs Firefox on both Linux and Android, with Enhanced Tracking Protection enabled, and tries to use web over native mobile apps wherever possible ... I really don't feel this at all?
- jjice 4mo agoI assume it's business people finding it to be a better "bang for their buck" implementation time-wise or lazy developers who don't use Firefox for their testing phase. I've seen it so many times. At a previous company, I was the only person using Firefox daily and I would catch bugs a few times a year during PRs for things that worked fine in Chrome, but not in Firefox. Oftentimes the suggestion was just to leave it because "who uses Firefox?"
- SilverElfin 4mo agoThis company makes the internet unusable if you value privacy and use VPNs or whatever. Evil.
- pmdr 4mo agoCan't directly outlaw VPNs? No problem, we'll have the the few corporations powering the internet block anyone who even thinks about anonymity!
- zuzululu 4mo agoDont like it but is a reality due to bots
- megous 4mo agoThey use all kinds of obscure APIs, which you'll learn if you're privacy/security conscious and disable random web APIs that are of no use to YOU as a web user, but only can ever serve the people who serve you stuff or want to hack you or track you. Normally websites feature test and just skip using obscure disabled APIs, or more likely, websites don't use those APIs at all or only tracking scripts use it, which are already optional usually. Problem with CF is that if you want increased security they'll prevent you from gaining it everywhere, even on sites they don't protect, or prevent you from accessing services even the ones you paid for. Browsers don't allow disabling APIs per domain, so you're either at risk everywhere or you're blocked from accessing a lot of things for no particular reason. CF can't be bothered to feature test.
- arbol 4mo agoI'm no CF advocate but those random APIs are literally what differentiates people running Chrome on their computer versus a bot operation with a load of containers. Kubertnetes clusters don't have GPUs. This is why it's used in bot detection (I use brave with no hardware acceleration and I'm captcha everywhere)
- konform 4mo agoI'm maintaining a minority browser[0] and as of a couple of weeks this is affecting several of our users[1]. While I'm currently not considering this a browser bug (one could be involved, of course), more eyes are better and any help or ideas on improving or mitigating the situation would be appreciated. [0]: https://konform-browser.codeberg.page/ https://konform-browser.codeberg.page/ [1]: Most? All? Without any telemetry, relying on user reports and our own testing here.
- gorgoiler 4mo agoI always like the axiom with crime that once X% of the population are violating a statute then it should probably struck off. Recreational drugs being the obvious example. If randomized canvas stuff was cracked down upon as a bot thing but now everyone with a copy of Firefox is doing it, maybe Cloudflare should just “legalize” it?
- aboardRat4 4mo agoEveryone with a copy of Firefox is about 2% of the web.
- boywitharupee 4mo ago> has been looping indefinitely this can mean WebContent process is crashing
- jameson 4mo agoI use LibreWolf which disables creating WebGL API by default and I don't have this issue. Why could be the reasons I'm passing CF turnstile?
- goda90 4mo agoAlready fingerprinted, perhaps?
- majorchord 4mo agoCF uses more than just WebGL to fingerprint users... LibreWolf isn't helping you as much as you think it is. https://abrahamjuliot.github.io/creepjs/ https://abrahamjuliot.github.io/creepjs/
- mixologic 4mo agoPrivacy and Bot defense are opposite ends of the same fulcrum. If you permit privacy, the site/service has to trust users to behave and follow the rules. If you track users, then the users have to trust the site/service owners not to abuse that trust. There isn't really an in between. So if you want privacy, you have to accept poor and sometimes insecure services.
- userbinator 4mo ago"If they know you're spoofing, you're not spoofing hard enough." This stupid "war against bots" is going to lead to the downfall of the Internet and effectively turn it into another walled garden where only "approved" (anti-)user agents are allowed. Don't fall for the nonsense about "AI scrapers" --- it's just a way to manufacture consent.
- 0x59 4mo agoIdk, if bots ate hammering your server then setup rate limits. If you have content that you don't want others to have access to, don't serve it with a webserver.
- TkTech 4mo agoI used to just start giving any IP downloading way too much a redirect to multi-tb NASA images. This was a long time ago but it was surprisingly how many would follow redirects and never time out. Wouldn't see a request again for hours and then its right back to downloading a new part of the sky. Those images also used to crash all the early GUI irc and chat clients that showed inline images without size checks...
- dotancohen 4mo agoHow were you tracking each IP address's data usage? Did you parse the logs every request? Store usage in a database? At the application or webserver level?
- TkTech 4mo agoWebalayzer! I'm not sure there were really any other options at the time other than writing your own. Parsed the apache logs and gave you pretty detailed results and you could see the usage (in kb, which tells you how long ago this was!) broken down by date and IP. Once you added a redirect rule for the IP to apache you'd just check your log and see the IP that was hitting you every couple of minutes poofed for a good few hours.
- baq 4mo agoThe logical next step would be for them to allow to pay you to pass the check and become the ultimate Internet tool booth.
- rfl890 4mo ago>It looks like you're trying to hide your identity. You were never entitled to it in the first place
- J37T3R 4mo agoWeb3.0 and beyond was a mistake
- morpheuskafka 4mo agoI'm getting this error on Safari 26.3.1 even without an adblocker extension, and advanced tracking prevention is set to private tabs online.
- gausswho 4mo agoBrazenly requiring the abuse of a browser feature's intended use against the user. What an age. I'd like to hear from someone who worked on WebGL and how they feel about their ambitions being utterly subverted. Remember when the dream was playing games i. the browser?
- X-Istence 4mo agoThis is an issue I am running up against on Safari (Version 26.5 (21624.2.5.11.4)) on MacOS 26.5. I keep getting the turnstile and having to click the "I a human" button.
- whatwhyisthis 4mo agoYou hiding things from them automatically lots automatically bins you with agents having a reason to hide things from them. Which, to be clear, is the entire problem: given how much of the internet goes through them, they should have enough alternative signals as to wether you’re not a bad actor that are stronger than this specific one. However, this also presents the problem that there’s barely any users in their base with your exact configuration, so getting any actual solutions might just take forever.
- elivoncoder 4mo agointeresting topic. 3 of my browsers failed that test page. konqueror. and on android, vanadium and cromite. https://browser-compat.turnstile.workers.dev/ https://browser-compat.turnstile.workers.dev/
- aussieguy1234 4mo agoFor the malicious bot authors, if WebGL is a "free pass" so that their browser is not detected as a bot, they'll simply switch to a chrome based browser such as CloakBrowser, which already passes CloudFlare Turnstile. So no real benefit for bot detection here. Just a privacy nightmare for everyone else.
- 1vuio0pswjnm7 4mo agohttps://web.archive.org/web/20260531173328/https://browser-compat.turnstile.workers.dev/ https://web.archive.org/web/20260531173328/https://browser-c... Internet Archive passed?
- fulafel 4mo agoWebGL fingerprinting is of course an attack and a unintended use of the WebGL API. Browser vendors should respond to this misuse somehow (reputation based blacklist?).
- account42 4mo agoWebGL should just require a permission prompt, JS too really. No reason that every page you visits should be free to run stuff on your CPU and GPU.
- akimbostrawman 4mo agoWebGL does on Tor browser, LibreWolf and Mullvad Browser.
- hanzeweiasa 4mo ago[flagged]
- ryanshrott 4mo ago[dead]
- JensenTorp 4mo agoI want to point out that Cloudflare Turnstyle is a separate and more strict product than their usual "are you a bot" protection. I use Cloudflare protection on all my website but only the account creation page uses Turnstyle.
- hbwang2076 4mo ago[flagged]
- petterroea 4mo ago"Your browser appears suspicious because it looks like you are trying to hide your identity" Another case of the much predicted downfall of freedom due to "people who hide themselves must have something to hide, so they are automatically suspicious"
- jesterson 4mo agoCF business model heavily relies on fearmongering, so what we can expect? They send these emails you know? "CF saved you XXX Gb of data and protected your from YYY attacks". I have few high load web sites which I turned CF on for a while. Knowing my traffic pretty well, I can say these "CF saved you XXX Gb of data and protected your from YYY attacks" is absolute bullshit with numbers greatly exaggerated. Since wwe can't catch them on this lie, they can put any number they like to make their "service" attrractive.
- kevincox 4mo agoI can only assume that every time I back out of these sites because I don't want to check the box or just don't want to wait a few seconds that is marketed to the site owner as a GREAT VICTORY as I am clearly a EVIL BOT that they have defended the site from.
- jesterson 4mo agoBe sure they multiply your number by 100 at least. I was getting numbers for "evil bots" way exceeding possible good and malicious traffic.
- petterroea 4mo agoThey are probably counting every single http request rejection as an evil bot
- jesterson 4mo agoI did some math, and even if they would count every http pass through together with rejection traffic, their numbers would still be greatly exaggerated.
- m463 4mo agocloudflare is becoming more and more of a gatekeeper of the public internet.
- ai_fry_ur_brain 4mo agoIve been concerned about Cloudflare turnstile fingerprinting ever since I started being forced to "prove I was human" on my anonymous X/Twitter accounts anytime I'd say something anti police/government/military. I would get locked out of the account on all devices after saying these things until I compeleted their turnstile. For many accounts I just never used them again. I could go more into this, but im highly suspicious of Cloudflare and of course X/Twitter in this regard. Ive been reccomend people to follow on anonymous twitter accounts for people I went to elementary school with and havent spoken to in years and have no digital connection to. Its very weird.
- rg2004 4mo agoQuestion, can we spoof a fingerprint to be random and valid each time?
- Ruslan1095 4mo ago[flagged]
- boesboes 4mo agoCloudflare is just a fucking protection racket. Next we'll need to pay to use services too
- DR_MING 4mo agoIt feels like we're moving toward a web where proving you're a human becomes a larger part of the browsing experience.
- account42 4mo agoYou mean proving that you are using an approved browser. The "proving you're a human" part is already owellian doublespeak.
- AgentReinAi 4mo agoThis is a concerning trend. Turnstile was marketed as a privacy-respecting CAPTCHA alternative, but requiring WebGL fingerprinting undermines that entirely. At this point what's the actual difference between this and the tracking they claimed to replace?
- arbol 4mo agoAt the time, reCAPTCHA was the alternative and it was effectively working as a giant ad targeting data collection tool. I'm pretty sure Google have now back tracked from this. WebGL finger printing is just one of many things you need to do if you actually want to stop automation. There is no way round it other than requiring ID of some sort.
- toastal 4mo agoSo wild thinking folks would actually believe a massive, US-based, publicly-traded company when they say something is “privacy-respecting”.
- meszmate 4mo agoI don't really understand why verifying I'm human would require fingerprinting my device in the first place. The whole framing feels backwards.
- gspr 4mo agoThis makes me think we need something like https://www.ietf.org/archive/id/draft-venhoek-tls-client-puzzles-00.html https://www.ietf.org/archive/id/draft-venhoek-tls-client-puz... sooner rather than later. It seems pretty absurd that everyone is running around with bespoke application layer solutions for this.
- cdolan 4mo agoThe battle against the bots is becoming tiring. Stop trying to be a middleman broker of the entire Web, CF
- jeroenhd 4mo agoBlocking bots is how Cloudflare makes money. There are cheaper CDNs out there but Cloudflare doesn't waste as much of your paid CDN bandwidth on bots.
- flintenmuschi 4mo ago[flagged]
- mring33621 4mo agoWhy does Cloudflare get to decide that it's wrong/bad to hide your identity?
- tomrittervg 4mo agoThe Bugzilla bug is at https://bugzilla.mozilla.org/show_bug.cgi?id=2036440 https://bugzilla.mozilla.org/show_bug.cgi?id=2036440 The breadth of responses here about people who can't reproduce this (or can) is one of the most frustrating things about working on fingerprinting protection. I also cannot reproduce this behavior, and have to assume that there is some complicated, behind-the-scenes risk assessment that is being done and some people trigger it and some don't. If any Cloudflare devs want to chat, I would love to. While not a normal way to contact us (support requests will be ignored), I can be reached at security@mozilla.com
- tomrittervg 4mo agoAnd to the point about Mozilla's protections lacking, I've corrected the record: https://ritter.vg/blog-webgl_renderer.html https://ritter.vg/blog-webgl_renderer.html