refalo

joined 2 years ago
[–] refalo@programming.dev 1 points 9 months ago

Yet there is still no PoE hat for the 5...

[–] refalo@programming.dev 2 points 10 months ago (5 children)

What you’re doing is filtering out bots that can’t be bothered to execute JavaScript. You don’t need to do a computational heavy PoW task to do that.

Most bots and scrapers from what I've seen already are using (headless) full browsers, and hence are executing javascript, so I think anything that slows them down or increases their cost can reduce the traffic they bring.

Canvas fingerprinting filters out bots better than PoW

Source? I strongly disagree, and it's not hard to change your browser characteristics to get a new canvas fingerprint every time, some browsers like firefox even have built-in options for it.

[–] refalo@programming.dev 1 points 10 months ago

I've seen this from people too and I have no idea why they have such a problem with using more than one app.

[–] refalo@programming.dev 22 points 10 months ago

Imagine what their home life is like.

[–] refalo@programming.dev 4 points 10 months ago (7 children)

Proof of Work is a terrible solution

Hard disagree, because:

it assumes computational costs are significant expense for scrapers compared to proxy costs

The assumption is correct. PoW has been proven to significantly reduce bot traffic... meanwhile the mere existence of residential proxies has exploded the availability of easy bot campaigns.

Canvas fingerprinting would work.

Demonstrably false... people already do this with abysmal results. Need to visit a clownflare site? Endless captcha loops. No thanks

[–] refalo@programming.dev 4 points 10 months ago (1 children)

Definitely don't visit the toxic comment thread there... wow

[–] refalo@programming.dev 4 points 10 months ago* (last edited 10 months ago) (11 children)

I don't like the approach of banning nonresidential IPs. I think it's discriminatory and unfairly blocks out corporate/VPN users and others we might not even be thinking about. I realize there is a bot problem but I wish there was a better solution. Maybe purely proof-of-work solutions will get more popular or something.

[–] refalo@programming.dev 1 points 10 months ago

All you need in order to do this is for the client to encrypt their password before sending it to the server. Often services that advertise "zero knowledge" platforms that use end-to-end encryption will authenticate their users in this way. If this were a website for example, there could be a javascript/wasm library used within the client page that encrypts their password before a login request is sent to the server.

[–] refalo@programming.dev 2 points 10 months ago* (last edited 10 months ago)

Proof? And by what metric? That has not been my experience whatsoever, nor have I heard any complaints about either of them.

[–] refalo@programming.dev 4 points 10 months ago* (last edited 10 months ago) (6 children)

xrdp and x11vnc is rootless

[–] refalo@programming.dev 23 points 10 months ago* (last edited 10 months ago) (1 children)

I would bet it's more likely emotional breakdown from cyberbullying.

[–] refalo@programming.dev 3 points 10 months ago (1 children)

See Freenet/Hyphanet

Please don't, because it is literally the largest place online that openly trades CSAM. Law enforcement even run their own nodes there to try to catch people.

view more: ‹ prev next ›