Hacker News new | ask | show | jobs
by alightsoul 18 days ago
From my understanding this is also how cloudflare bot protection has worked for a long time, and then they look for entropy in user input to confirm the user is human. Also how recaptcha without images works.
4 comments

Google and Cloudflare both are not just looking at entropy of mouse movements, that was cracked years ago, they are fingerprinting you and correlating your session with all your activity cross domains to score your botlike behavior.
I doubt they are doing it. You just have to get on a VPN to and see yourself being flooded with captchas despite browsing the web like a normal human and solving dozens of captchas along the way.
I guess that raises the bot score given that the vpn IP is a data Center IP and thus in a lot of ban lists
Also some of the free VPN apps support themselves by proxying this kind of traffic:

https://www.kaspersky.com/blog/what-is-wrong-with-free-vpn-s...

Which also involves detecting entropy across sites I guess
How is that not a massive GDPR violation?
You can just break the law, if you don't get caught, especially if you're rich.
They can just not do it in Europe and keep doing it everywhere else
Profiling visitor traffic to protect against abuse is a legitimate use case, even for GDPR. It's only a violation if that usage is not disclosed in the ToS.
Supposedly, but not really. I regularly encounter sites where cloudflare serves me with an ambiguous ban notice rather than a proof of work. What's worse is that these apparent IP bans take effect even if I already had a valid active session (ie previously passed the check).

Yes, a VPN involved. That doesn't make it okay and notice that anubis by default works without issue (though possibly with a more difficult challenge) in the exact same scenario.

There's lists of data center IPs. You're probably in them and That's why you're getting banned
Regardless of the precise logic it's no excuse for the policy. Simply hand out a sufficiently difficult PoW to prevent widespread abuse.

I'm quite certain it isn't a generic "datacenter" list though because a given VPN exit that was working will suddenly stop. Meanwhile I have a valid cookie yet that is disregarded.

Wikipedia maintains a quite exhaustive list of them to prevent spam and they also block vpn IPs as soon as they're found.
That is an entirely different matter. They only block (AFAIK) editing which is a scenario where PoW would not be expected to solve the problem. What I was talking about here is IP banning as a (boneheaded) mitigation against high volume scrapers.
Cloudflare often just straight up blocks me or makes me do a captcha. IMO those are both much worse than Anubis
Sounds like it's because your IP is on a data Center IP list
That's lame of them, I'm on a residential plan. Maybe because I host my personal website from home?
Also by doing network traffic analysis