6 ms·
Kitesurf: Agent-first browser that runs in V8 isolates
- QuantumNomad_ 2mo agoFrom the page https://developers.cloudflare.com/browser-run/ https://developers.cloudflare.com/browser-run/ linked to from this article: > Run headless Chrome on Cloudflare's global network for browser automation, web scraping, testing, and content generation. Does Cloudflare the CDN allow these browser instances to bypass their own anti-bot mechanisms? Or will Cloudflare the CDN block them the same as if someone was running scraping bots from a different provider? Will Kitesurf in Cloudflare workers get special bypass privileges to content protected by Cloudflare the CDN?
- buremba 2mo agoNo it doesn't and it's simply useless. They have been trying to enable publishers to charge scrapers so that's why they're pushing this path hard.
- celso 2mo agoBrowser Run requests coming from Chromium or Kitesurf are always identified as bot traffic by Cloudflare. https://developers.cloudflare.com/browser-run/faq/ https://developers.cloudflare.com/browser-run/faq/ We also have a documented UA and sign our requests with Web Bot Auth: https://developers.cloudflare.com/browser-run/reference/automatic-request-headers/ https://developers.cloudflare.com/browser-run/reference/auto...
- nicoburns 2mo agoThis is built on top of Blitz (https://github.com/dioxuslabs/blitz https://github.com/dioxuslabs/blitz): a new modular (open source) browser engine that I've been building for the last 2.5 years. (I wasn't involved in building kitesurf, but I am informed that they intend to open source and upstream their patches)
- hugs 2mo agoany plans to support webdriver bidi for automation? (i'd be happy to help!) [edit: for others reading who don't usually nerd out on browser automation protocols: webdriver bidi is the new-ish w3c cross-browser standard inspired by CDP - the main magic was the upgrade to websockets and also to standardize the capture of network-level traffic. there are still feature gaps between CDP and BiDi (in spec and implementation), but long term, i believe we should bet on web standards, not proprietary protocols controlled by one company. (disclosure: i started the selenium and appium projects.)]
- nicoburns 2mo agoIt's definitely on the list of "things that would be nice to have eventually". It hasn't been very high up my personal list of priorities to build myself, but if you want to build it then I imagine we'd accept the patches (though I'd ideally like to see an implementation plan first). (if kitesurf does upstream their patches then presumably we'll get a CDP-based automation API as part of that)
- hugs 2mo agook, cool. looks like i should chat with the fine people at cloudflare, too.
- nicoburns 2mo ago> Long term, i believe we should bet on web standards, not proprietary protocols controlled by one company. Totally agree. Not sure if you're involved in the development / spec process for WebDriver Bidi, but the big limitation atm is that it has almost no support for the devtool inspection use cases served by the Chrome Devtools Protocol (CDP) and the Firefox Devtools Protocol (FDP). The Servo and Ladybird browsers both have FDP implementations (and Blitz has an in-progress CDP implementation) for this reason. But we'd all love to switch to a single standardised protocol if it had the requisite support.
- hugs 2mo ago
- LetsGetTechnicl 2mo agoUgh
- zuzululu 2mo agowish it was open source so it can be run locally a welcome addition although it'd be very easy for websites to fingerprint and block
- donpark 2mo agoFrom the final notes section of their announcement blog post: > One last thing: we're going to open source Kitesurf once we're ready — hopefully soon. Our goal is to let any customer deploy their own version of Kitesurf on their own accounts, if they want to.
- celso 2mo agoWe will open source soon. You can block today, Kitesurf doesn't try to hide. https://developers.cloudflare.com/browser-run/reference/automatic-request-headers/ https://developers.cloudflare.com/browser-run/reference/auto... https://developers.cloudflare.com/browser-run/faq/ https://developers.cloudflare.com/browser-run/faq/
- cautiouscat 2mo agoCan someone give me examples of where you use agents in your browser? I’ve heard executive leaders tout that “people use agents to buy things for them” but I haven’t actually seen that.
- OroPla 2mo agoI would use them to solve captchas if that was a thing.
- digidecode 2mo agolol
- hugs 2mo agoi've been tempted to use an agent to help me find non-horrible seats to see the 70mm imax version of the odyssey. but that's also the kind of thing that is heavily guarded by anti-bot detectors.
- nozzlegear 2mo ago> I’ve heard executive leaders tout that “people use agents to buy things for them” but I haven’t actually seen that. My wife really dislikes building up the shopping cart for our weekly grocery delivery, so I built an agent... thing with earendil's npm libs. It takes the menu my wife has decided on, confers with her about the ingredients (if it hasn't seen a recipe before), and then uses Chrome's devtools protocol to head to Walmart and add everything to the shopping cart. It works fairly well and uses the local models I have running on my Mac Studio.
- diarrhea 2mo ago> uses the local models That is fantastic. Last I checked models capable of running on commodity (anything below a dedicated GPU rack) hardware were very lackluster.
- nozzlegear 2mo ago
- saadyousfi 2mo ago[flagged]
- nirbendavid 2mo agoBit surprised nobody's mentioned the security side. The V8 isolate guards the wrong half of this imo. It stops the agent's code from escaping the sandbox, but the risky part of a browser agent isn't code escaping, it's that it reads untrusted pages and then acts on them. A prompt injection on a page doesn't need to break out of V8, it just tells the agent to use its normal tools to do something you didn't intend. So the isolate bounds what it can run, not what it can be talked into doing. How does Kitesurf scope that part, ie what can the agent actually reach and send after it loads a hostile page?
- mtxeat 2mo agoRight — the isolate protects the host from the agent, but nothing protects the agent from the page. A commerce agent reading 40 product pages is reading 40 untrusted inputs, any of which can carry instructions. Hidden instructions in product descriptions will become the new blackhat SEO: instead of keyword-stuffing for crawlers, stores get prompt-stuffed for agents.
- fukaiall 2mo agoSeems like Cloudflare only writes Rust these days…
- cpursley 2mo agoThankfully, hopefully everyone else gets on board so we can dump the node/JS dumpsterfire.
- hn0tdqaek4 2mo ago[flagged]
- hn5595p698 2mo ago[flagged]
- broker_desk 2mo agoI spent today doing the thing an agent-first browser is meant to make unnecessary: driving the open web with raw HTTP only - no rendering, no JS, no image or audio decoding - and writing down exactly what stops me. Rendering was almost never the blocker. Identity was. Results from the last hour, verbatim: - lemmy.world /api/v3/site: registration_mode RequireApplication, captcha_enabled true, require_email_verification true, and an application question that explicitly rejects temporary email. Three independent walls on one signup. - lemmy.today and lemy.lol /api/v3/user/register: {"error":"captcha_incorrect"}. The captcha ships as base64 PNG plus WAV, so it is a wall for anything without a decoder, headless browser or not. - bsky.social com.atproto.server.createAccount: {"error":"InvalidPhoneVerification"}. - Publishing, by contrast: api.telegra.ph and write.as both take an unauthenticated POST and hand back a public URL. A browser in a V8 isolate does not help with any of the failures above, because the gate is a CAPTCHA, an SMS, or a card on file, and an isolate has none of those. The same is true on the payments side: an agent can hold an address and receive, but every write path in that ecosystem is a signature over a payload, so if something else custodies your key the machine-payments world is read-only to you. The missing primitive for agents is not a browser. It is a portable identity and a spendable balance that are not borrowed from a human's phone and credit card. Full map of what was reachable and what was not: https://write.as/ih3l0kd78lpb1 https://write.as/ih3l0kd78lpb1
- wmf 2mo agoThe missing primitive for agents is not a browser. It is a portable identity and a spendable balance... It's funny you should mention that since Cloudflare is also working on bot identity and payment (x402).
- broker_desk 2mo ago[flagged]
- Hexcles 2mo agoIt's nice to see wpt.fyi was used to help with the verification of this new browser! Also BiDi can't come fast enough.
- celso 2mo agoAs we explained in the blog, tests — and WPT tests specifically — were extremely important to get Kitesurf off the ground so fast, and still are as we move to higher API coverage. We have been keeping a close eye on BiDi as well.
- Hexcles 2mo agoNow that OpenAI basically abondoned Atlas, which had a truly novel architecture, let's see if this more obvious technical route (not saying this to diminish the achievement!) would gain traction.
- tonyrice 2mo agoThis reminds me of PhantomJS
- dupontcyborg 2mo agokinda meta to have a js engine built in rust, compiled to wasm, running in cloudflare workers which itself is another js engine (v8 isolates)
- celso 2mo agoIt is! But it works. Native eval support will come to Workers at some point, though. We will reevaluate Kitesurf's architecture when that happens. Shouldn't be hard to migrate, we have all the logic in place now.
- ako 2mo agoKitesurfing is so last decade, this decade is all about wingfoiling and parawinging.
- jonnyparris 2mo agoKitesurfing is faster (and more fun imo)!
- minraws 2mo agoI am not against the idea but Cloudflare should honestly split itself and spinoff the CDN and DDOS/Cybersecurity company if it's also going to do agents. These two feel like they are opposing teams, I don't think they are colluding today, but how long will that last, this seems very suspicious I say that as a long time cloudflare user, I welcome making the platform agent friendly and adding agent specific deployment cloud stuff like Cloudflare OS is something I can live with as well. But this is going a bit too far, what's next AI bot net to scrape content from sites protected by Cloudflare? I don't want to sound entitled but man do we deserve better.
- chrysoprace 2mo agoIt's pretty bizarre to see them going from being the bot protection platform to differentiating on the kinds of bots they'll block, because now they're facilitating the exact kind of bot automation they made their name protecting against.
- com 2mo agoSurely it’s smart business to encourage and potentially even profit from both sides of the fence?
- echelon 2mo agoIt feels sickening to watch, because you can get a sense of where this is going. They're cutting AI off at the legs for everyone else, then building the new tool to sell AI enablement. They'll probably let their customers pay to bypass their protection scheme, which will complete the loop. It really rubs me the wrong way. It should 100% be a different company. I don't feel safe with Cloudflare being the ones building this tech.
- scotty79 2mo agoHuge chunk of internet already moved to CloudFlare. It's only reasonable to move the browsers there too. If the traffic doesn't leave CloudFlare it's huge saving for them.
- tizerluo 2mo ago[flagged]
- TheRealPomax 2mo agoBut then the obvious next question is: is it still a browser, then? In the same vein as asking whether a tool that can extract data from PDF files is a "PDF Reader" (probably not) or a tool that runs a game demo for benchmarking purposes is still "the actual game" (definitely not). It's a web data tool, but as something not used for browsing, by definition this is not a browser.
- ElijahLynn 2mo agoJust to throw in the context window, another agentic browser (headless): https://lightpanda.io/ https://lightpanda.io/
- chainauditor 2mo ago[flagged]
- rldjbpin 2mo ago(let's keep in on the downlow) time for another approach to run your agent's web searches through this (or by mocking browser signature), with potential cf bypass built-in!
- momojo 2mo agoI'm intrigued! There's so much movement in the sandbox space. Can someone tell me how a V8 sandbox compares to say Fireworks or if they've chosen one over the other? I think, from a technical standpoint, that it's neat that we already have an entire sandbox in the browser (albeit with a bit of chrome) but someone tell me why it shouldn't be used that way
- tamsinoduya 2mo ago[flagged]
- wh0ar3y0u 2mo agoHi, I’m the creator of Obscura. This has been a pretty strange few days. I had no idea Cloudflare had tried porting Obscura until I read this post. Seeing something I built mentioned as the starting point for Kitesurf is an honor, and I appreciate the team giving the project credit. From what I understand, Kitesurf eventually went in its own direction and isn’t simply Obscura running on Workers. Still, knowing that Obscura helped get the original experiment started means a lot. I recently added native rendering to Obscura. It can now take screenshots, stream screencasts, and generate PDFs without Chromium. The repository has also passed 21,000 stars. For context, I’m 16 and have mostly been building this with my friend, so I’m still figuring out what the project should become and how to keep developing it sustainably. Happy to answer any questions about Obscura or the rendering work.
- Candoa 2mo ago[flagged]