Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But to be fair, in Cloudflare's case they aren't "banning" access, they are putting it behind a captcha.

Still far from ideal, but it's not banning.



In fact, paying with cash sometimes requires a sort of captcha equivalent: the pens[1] that are used to detect counterfeit bills.

Depending on the area you're in, when you pay with a $20 bill (the most commonly counterfeited), the cashier will mark the note with a pen before accepting it.

The business is simply profiling the transaction - a $20 cash bill brings with it a higher risk of fraud - and behaving accordingly. I can't think of a way to argue that it's unfair to the customer that the business does this.

An astute observer will point out that the captcha presented by CloudFlare is an order of magnitude (or two) less convenient than the counterfeit detection pens, but I would argue that this doesn't support a position that CloudFlare is wrong to do what they do.

1: https://en.wikipedia.org/wiki/Counterfeit_banknote_detection...


When every .html resource requested is met with a captcha, access is effectively banned.


Well that's another problem. When you fill out the captcha you are given a cookie that can allow cloudflare to let you through next time.

If you are blocking that cookie for privacy reasons (which is not a bad thing!), then cloudflare has no way to verify you again (short of doing nefarious things). It's a bit of a self inflicted problem at that point.

That's not to say that the answer is "deal with it", but that we need to find a better way. A a way to verify that someone isn't a bad actor without having them take a pretty significant chunk of their time to answer captchas, or give up some of their privacy.

It's a tough problem, and i think the "proof of work" solution proposed in the original could work, but it would need participation and collaboration from "both sides" of the problem. And of course it won't happen overnight.


Any proof of work concept again is just a cookie – because the proof I present will be the same.


But you could possibly re-do the proof of work every page load without the cognitive load of multiple captchas.

It still isn't ideal for mobile or low-end clients, but its something.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: