Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>It is already painful to browse web sometimes using the non-"standard" tools (that is, not a Chrome with Google account signed in, not an EU/US residential IP). What if tomorrow Cloudflare checks will require attested and signed browser binaries?

If it's painful, that's not because of cloudflare. You can get past turnstile challenges using tor browser in a VM. You still might be blocked because of policies set by site owners, but that can hardly be blamed on cloudflare.



> but that can hardly be blamed on cloudflare

They are installing the gates with configurable locks that the site owners use. They are absolutely to blame.


Should nginx be blamed too, because that also allows site owners to ban tor/VPN users?


Never had the issue of nginx gatekeeping, but Cloudflare's shitty captchas constantly block the access, since my browser settings don't adhere to their MitM-mandated rules.


>in a VM

Are you saying it's possible to detect VMs in the browser without using the WebGL vendor? Mind sharing some resources?


Besides the vendor, you can fingerprint the extensions list, as well as various limits https://browserleaks.com/webgl. Also webgl isn't fully deterministic across vendors (similar to audiocontext, which is affected by compiler/FPU implementations), so you'll get minor differences in output due to differences in rendering pipeline/implementation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: