Cloudflare is working with the makers of Chrome, Edge, and Firefox on a new way for websites to tell whether incoming traffic is legitimate – without resorting to the usual mix of CAPTCHAs, logins, and extra tracking.

The system is called Private Access Control Tokens, or PACT, and it arrives at a time when bots have surpassed human traffic online.

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    26
    ·
    1 month ago

    Clearly, they haven’t heard of proof of work.

    Ask tor, it helps tremendously.

    Hidden services went from being absolutely horribly unreliable to being very reliable.

    • FG_3479@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      It only slows down bots. If a bot is willing to do the PoW then it can get right through.

      • shortwavesurfer@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 month ago

        That’s true, but I don’t really truly think bots need to be entirely stopped. I think they need to be more limited so that they can’t just overwhelm a website. And proof of work will do that.

        • FG_3479@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          It depends on the site. For a blog PoW is perfect, however if someone like Facebook or YouTube switched to only PoW then the spam would entirely dominate and make the site unusable.

          • shortwavesurfer@lemmy.zip
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 month ago

            I think that would depend a lot on the amount of servers serving that service.

            If you’ve only got one server, then the proof of work is going to ramp up quite quickly because of the fact that it can only serve so many requests at a time. If you have 10,000 servers serving the same website, then the proof of work would ramp up pretty slowly because then you can serve a ton more requests at once before needing to kick the proof of work up. Tor currently has a zero proof of work if the service is not under load at all, and then ramps the proof of work up as the service comes under more requests. My thought would be to not have any point where there’s a zero proof of work and have a minimum proof of work required of one.

  • plz1@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    25
    ·
    1 month ago

    This sounds a lot like fingerprinting under the false flag of making user experience better.

  • gapa@feddit.nu
    link
    fedilink
    English
    arrow-up
    21
    ·
    1 month ago

    I had to solve two captchas last time I tried ordering groceries online.

    • pinball_wizard@lemmy.zip
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 month ago

      I’m just going back to cash.

      All of this “artificial intelligence security” just gets in the way of basic legal transactions, but all the yes men running it are too spineless to tell their bosses and shareholders how much money they’re losing.

    • Zarobi@aussie.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      I keep getting fraud alerts and having to sooth my bank account into permitting my groceries. You’d think after the 20th time on the same day with the same price they’d stop flagging my groceries.

    • neclimdul@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      Why would a grocery… wait… people are having agents order groceries and its causing problems aren’t they?

      • gapa@feddit.nu
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 month ago

        I think it was ddos protection. I have bookmarks for stuff I order regularly and I open a bunch at the same time.

  • Feyd@programming.dev
    link
    fedilink
    English
    arrow-up
    19
    ·
    1 month ago

    I don’t see any details here that make me understand how sites couldn’t just save the PACT and collude to build profiles.

    • pinball_wizard@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      Yes. I would be quite surprised if that detail were present, since these folks seem to just want another way to track people and sell a higher quality profile.

    • floquant@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      I assume it would be something like a key that gets used to generate disposable signatures, not transmitted directly. But I’ve also been unable to find actual technical details, the article mentions a “GitHub proposal” without linking to it but i couldn’t find anything in their repos. Their blog has nothing either

      • Feyd@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Yeah I’m assuming the goal is some kind of cryptographic process that meets the stated goals. Publishing this news before actually having anything is obviously going to lead to nothing but skepticism though.

  • pHr34kY@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 month ago

    This sounds a bit like a passport-stamping scheme. But the passport doesn’t have your name and photo on it. Hopefully it only stores verifiable stamps, but not who stamped it.

    I hope they use this to tackle age verification. I’d like to just have a token to prove my age without handing over an actual ID to questionable companies.

    • coolmojo@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 month ago

      I hope they use this to tackle age verification. I’d like to just have a token to prove my age without handing over an actual ID to questionable companies.

      Nope, because what they want is not age verification. They want identity verification.