by EFruit on 9/28/22, 2:02 PM
As much as I _despise_ modern ReCAPTCHA, I have always been able to pass the challenge eventually; it has never flatly rejected me with no recourse. If I made a mistake or was insufficiently human for it, I got a new challenge and tried again. There are apocryphal stories of Google tar-pitting users with it, but I have never seen it in action.
If this judges the browser more than the user, what do I do when the browser fails? Do I refresh the page hoping for a different batch of invisible challenges? Do I submit a ticket to CF customer support... despite not being a customer?
by eastdakota on 9/28/22, 1:52 PM
This is yet another example of Cloudflare centralizing the web. I’m tired of this. Sure the only previously viable solution was ReCAPTCHA from Google. But it’s Google. I depend on them for search. And, sure, their business model depends on them being able to track me online. But I know them. And it’s hard for me to live without them. So I’m ok with depending on them, but I worry about further centralization of the Internet if there’s an alternative. At the end of the day, I like the Internet how it is and how I’ve gotten used to it. Facebook is clearly evil, but I still check them from time to time to keep up with my friends, but a lot less than I used to. I, of course, need to use Google so even though their business is inherently about tracking me, what’s the alternative. But Cloudflare, they’re new. They disrupt what I’m used to. They add another player to the mix. So how dare they centralize the Internet?? This is total BS. I’ll stick with ReCAPTCHA.
by yjftsjthsd-h on 9/28/22, 3:38 PM
Cloudflare: "Cloudflare has a long track record of investing in user privacy, which we will continue with Turnstile."
Also Cloudflare: Tracks and fingerprints everyone, and blocks anyone who hardens their browser ("First we run a series of small non-interactive JavaScript challenges gathering more signals about the visitor/browser environment. Those challenges include proof-of-work, proof-of-space, probing for web APIs, and various other challenges for detecting browser-quirks and human behavior. As a result, we can fine-tune the difficulty of the challenge to the specific request.").
by stevewatson301 on 9/28/22, 2:26 PM
What is the failure case for the Cloudflare captcha? In case browser fingerprinting fails to identify me as a human, do they fallback to a challenge that humans can solve, such as audio or image challenges?
Say what you will about Recaptcha, but they do have a way to eventually pass through the challenge.
by plibither8 on 9/28/22, 2:54 PM
by bwb on 9/28/22, 1:35 PM
God, I hope this works; I do tire of the silly CAPTCHA test. I def get hit with it a lot more from outside the USA than within.
by 1f60c on 9/28/22, 1:46 PM
I think changing the comma to a colon and adding "a" before "privacy-preserving" would make the title clearer.
by Cryma on 9/28/22, 2:55 PM
by fariszr on 9/28/22, 2:37 PM
This looks great, Cloudflare will always be Better Privacy wise than Google.
> without having to be a Cloudflare customer or sending traffic through the Cloudflare global network
And you don't even need to use CF as a proxy.
by frankjr on 9/28/22, 2:03 PM
Just a heads up for CF folks: Once you create a Turnstile, the link below the generated secret ("Server side integration code") leads to 404.
by 2Gkashmiri on 9/28/22, 1:54 PM
Wait till captcha farm companies bypass this and sell solutions for a profit. I use one and its ~95% accurate which is fine for me I guess.
by ChrisArchitect on 9/28/22, 9:03 PM
My problem with this is I want to use the CAPTCHA to deter
humans from continuing. Letting them thru automatically allows spammers/attackers to just continue on, but many will actually skip pages/sites where they have to do the CAPTCHA etc.
This helps the bot problem, but doesn't solve the SPAM problem.
by zagrebian on 9/28/22, 1:43 PM
Can’t CAPTCHA be integrated into the browser? Can’t the browser vouch for the user?
by Ocha on 9/28/22, 2:21 PM
No mention of hcaptcha. Is this still worth it if you are hcaptcha user?
by homero on 9/28/22, 1:36 PM
That's awesome and it's free, about to swap out my recaptchas
by beefee on 9/28/22, 5:40 PM
Will any of this be available on Linux or owner controlled systems?
by V__ on 9/28/22, 3:28 PM
Can anyone shine a light on this solution and GDPR compliance?