11 ms·
Precursor
- jawns 2mo ago[flagged]
- jgrahamc 2mo agoHuh?
- PessimalDecimal 2mo agoIs this equivalent to Google Cloud Fraud Defense? https://cloud.google.com/security/products/fraud-defense https://cloud.google.com/security/products/fraud-defense
- eth0up 2mo agoNot sure, but I struggle with skepticism for anyone who blocks archive.today, which cloudflare does, along with nextdns and others. Being blocked by such a large... apologies in advance for 'lack of better word' vernacular, cartel, is a near death sentence. Not a fan
- pests 2mo agoarchive.today was running a DDOS through their CAPTCHA page
- eth0up 2mo agoAlthough the blocking of archive.today goes back years, as can be verified through forum searches and archives with nextdns and others, I was not aware of this and have no excuse to dispute it. But for the record, the blocking predates 2026 by many years -- and my own records also verify this. That said, I think I need to learn more.
- nerdsniper 2mo agoCF doesn’t block archive. Archive poisons CF. Explanation direct from the CEO of CloudFlare: https://news.ycombinator.com/item?id=19828702 https://news.ycombinator.com/item?id=19828702
- Chu4eeno 2mo agoYes, this is something almost all other anti-bot/fraud prevention solutions already does, and there are already bypasses developed simulating human mouse movement. I expect this will be effective for maybe a day.
- sudb 2mo agoCool product launch, though it feels a little weird to me that Cloudflare sells agentic products alongside this new service that seems designed to block agentic usage of the web? I expect there's much more going on than just mouse path detection but I can imagine that this is already tricky for touchscreens and for people using non-traditional mouse inputs (the thinkpad nub comes to mind - but it would also be bad optics to accidentally block people using accessibility mouse tools as bot users, though then this becomes a loophole for agentic browsing!) In general though I think this is almost definitely a good thing to reduce agentic bot abuse & spam.
- deleted 2mo ago[deleted]
- skybrian 2mo agoIt’s less weird if you think there’s a difference between good bots and bad bots. They can provide services for good bots to use while helping people keep out the bad ones. If a bot is simulating mouse movement but doing it badly then that’s a strong signal of shenanigans. A good bot will obey robots.txt and do nothing to hide that it’s a bot.
- pryelluw 2mo agoWho gets to decide what is a good bot?
- tccole 2mo agoMe… obviously
- nullpoint420 2mo agoCloudflare, apparently.
- mark212 2mo agono, their customers. Why do you assume that people who run websites are clueless and lack agency in this?
- nullc 2mo agoplease drink verification can to continue
- arm32 2mo agoYour children are now in custody of Carl's Jr.!
- reluctant_dev 2mo agoWhat prevents bots/agents from just adding "jitter" to their movements that mimics how humans move their cursor? I know there are other signals being used but this one in particular seems like it wouldn't be hard to beat with a small amount of sophistication from the bot.
- stogot 2mo agoIn 2027 how many tokens will we spend to create the jitter, pre-jitter planning, post-jitter verification, and then cloudflare’s inevtiable counter-jitter
- zdc1 2mo agoSomeone needs to vibecode a "virtual mouse" tool for the agents to steer instead (semi /s)
- teravor 2mo agothat's actually how you do it. adversarial systems like those are prime candidates. one agent develops detection mechanisms and the other agent defeats them. progression signal is easy to get. and you bootstrap with existing javascript detection engines. the challenge is usually the human input data, your objective is to be clustered among the humans and for that you need to know what humans look like. this is not an open ended arms race, it will end once the bots approximate humans to a sufficient degree - false positive rate for detection will become unacceptable even if the detection system is slightly ahead.
- RedRocketFlash 2mo agoNot even. If this is being detected by client-side JS, someone can just reverse-engineer that code, and push a stream of signals into CF to emulate what a human user would generate.
- RedRocketFlash 2mo ago"We got this Trace-Buster-Buster-Buster that's gonna bust the Trace-Buster-Buster and bust their .... uh, uh, uh ... Trace!!"
- kurtoid 2mo agohow does this interact with keyboard navigation & accessibility tools?
- Havoc 2mo agoIt’s a bit alarming how cloudflare is establishing itself as arbiter of all things bots…both on blocking and allowing. Doesn’t seem healthy for the internet as a whole
- dzonga 2mo agohave you considered the alternative ? where bots run rampant ? trust me as an operator - I'm grateful Cloudflare exists.
- jppope 2mo agoAgreed, but we should be honest, the internet today is far from healthy
- ianm218 2mo agoFor any one of their product there is a good opportunity to build an open source alternative or something like it! Can be hard to work around they have the benefit of being able to have negative unit economics on lots of infra products... But people succesfully built tons of alternatives to google analytics and similar.
- esseph 2mo agoWhat they are doing requires both physical and digital infrastructure spread throughout the globe. It's not a cheap task.
- pocksuppet 2mo agoDo you actually have customers spread throughout the globe, or just in North America and some in Europe?
- ralegh 2mo agoOpen source for bot protection specifically would be difficult. If I as a bot developer can see the tests you run I can just modify my bot to pass them (either trivially or by brute force).
- 2mo ago
- nearlyepic 2mo agoI can’t wait for cloudflare to sell data on how well my wrist is working to my insurance company. What a wonderful hell we’ve created for ourselves.
- timcobb 2mo agoGosh, this is all pretty nauseating.
- freedomben 2mo agoAs a real user who uses an Ultimate Hacking Keyboard with the mouse layer, this frustrates me immensely. Yes I'm a corner case, but this is likely to make certain website not work for me because my lines are perfectly straight and my arcs zig-zag much like a bot might. Considering the keyboard/mouse layer feels like an advancement to me, this feels like tech that will lock in the "old" way of doing things. I really detest how adversarial the web is getting. I'm not a cloudflare hater but please, please consider people like me when rolling out stuff that affects millions or maybe even hundreds of millions or billions of people.
- bigbuppo 2mo agoAssistive technology is not a corner case.
- akersten 2mo agocontrol+F accessibility no results Yeah so this mouse movement astrology is going to completely lock non-sighted/keyboard only users out of large swaths of the Internet isn't it.
- sudb 2mo agoI'd imagine that mouse movement is just one signal among many that's weighted appropriately, but I hope we get feedback from these users
- abirch 2mo agoI'm guessing it's going to lock the non-sighted//keyboard only users out of the anonymous Internet. I'm guessing if you log in and give up your anonymity they'll consider you not a bot.
- thomastjeffery 2mo agoThat's even worse
- bogdan 2mo agoWhy worry? Just send them a photo of your ID and you'll be fine. /s
- RedRocketFlash 2mo agoIf that's true, attackers just need to run their bots under registered throwaway accounts...
- abirch 2mo agoThe account will require a phone number and the US is trying to move away from burner phones. As long as we don't commit thought crimes and we love Big Brother all will be well. https://www.wired.com/story/security-news-this-week-the-fcc-wants-to-kill-burner-phones/ https://www.wired.com/story/security-news-this-week-the-fcc-...
- pllbnk 2mo agoI have been noticing a lot of Cloudflare false positives where it keeps spinning on my sessions never actually redirecting me to the underlying page. If they keep just vibe coding and releasing a new solution every day, I am afraid it will be reflected in their services quality.
- mial 2mo agoSometimes it might be your user agent, or your IP, or some browser extension…
- dubcanada 2mo agoI get flagged way more often on Starlink then I did on my local ISP fiber.
- bigbuppo 2mo agoIt's the odd latency changes. You'll see the same thing with certain streaming services.
- kube-system 2mo agoI've seen it happen with a grocery store website, oddly enough.
- deleted 2mo ago[deleted]
- khurs 2mo agoCloudflare has a lot of enterprise customers. Selling bot check to companies wanting to protect their content & also taking a cut out of payments for access by bots could be a good earner for them.
- csomar 2mo agoSo now instead of having the slow-axx Cloudflare turnstile slowing down your requests, you get surprised with a "You are a BOT!!!" while you are conducting your business on a website. I already quickly close any website that I do not need for business purposes when it shows me the Cloudflare spinner. Now I might have to start considering competitors who do not implement this shit.
- pocksuppet 2mo agoTurnstile already does the "You are a BOT!!!" thing btw, if it thinks you're a bot, which is quite rare as it seems much more permissive than systems like reCAPTCHA.
- carterschonwald 2mo agoeven before the llm era sites would flag me as a bot for opening 15 links to read later. its fucking infuriating now
- TrackerFF 2mo agoOne interesting aspect is of course that the movement from the same user can be different depending on what type of mouse they use. I use a mouse at work on my PC, touchpad on my private laptop, and thinkpad nipple on work laptop. Three different profiles for one user. Obviously different movements from a AI, but if we come to the day where mouse movement fingerprinting becomes another gatekeeper, there could be some interesting outliers.
- dinkleberg 2mo agoI wonder how it'll handle those of us who try and use the mouse as infrequently as possible. I imagine the cognitive delay part would be largely telling. But it'll be interesting to see if I start getting blocked because I use vimium.
- SoftTalker 2mo agoI think it doesn't really matter, the bots will adapt with much more human-like mouse movement very quickly.
- dubcanada 2mo agoThere is nothing stopping a bot from moving their cursor like a human. This is basically just putting up a door with zero walls and telling people to stay out of your house. All of these things are completely abusable/bypass-able and just annoying for actual humans who trigger flags.
- deleted 2mo ago[deleted]
- swiftcoder 2mo ago> There is nothing stopping a bot from moving their cursor like a human. Sure, we could write a library that slows the bot down and makes it move the cursor in procedurally-generated curves with a certain degree of noise added... but its all extra work, and it all slows the bots down. Presumably they wouldn't reveal that part of the secret sauce if it was all of the secret sauce
- dubcanada 2mo agoActing like a human is something scapers already do. Using residential proxies, using latest Chrome user agents, not moving/typing as fast, etc. This is just 1 more layer, moving mouse naturally.
- Chu4eeno 2mo agothere are already stuff to trick mouse movement profiling, since its used by other bot protection stuff.
- bigbuppo 2mo agoAnd at some point they'll just use slave labor in some country with lax laws around all that. I'm not sure if I'm talking about the scrapers or Cloudflare at this point. Probably both. Probably the same pool of forced laborers.
- RedRocketFlash 2mo ago
- tavavex 2mo agoIt's a bleak world in terms of bots flooding the web, but out of all possible solutions, this seems to be preferable over invasive and identifying fingerprinting that everyone wants to roll out. Here's hoping that mouse movements aren't sufficiently unique as to be fingerprintable too.
- whimsicalism 2mo agoas a heavy user of computer use, i hope enterprises realize that people like me will switch to competitors that support native computer use & APIs
- amirhirsch 2mo agoI implemented all of this in hCaptcha 6 years ago, not just to distinguish bot from human but also to recognize the keyboard/mouse behavior of the same person signing up for many accounts or testing multiple credit cards. This kind of abuse detection was a part of Cloudflare when they switched to hCaptcha in 2020 and I had thought they already implemented all this themselves four years ago when they transitioned away from hCaptcha in 2022.
- Chu4eeno 2mo agoDidn't recaptcha v3 also do this? iirc the "silently monitor in the background" was part of the selling point.
- amirhirsch 2mo agoYea this is the premise behind all the invisible captchas, combined with browser fingerprinting. Same tech is used now to detect distillation rings.
- trunnell 2mo agoI dislike bots as much as anyone else... when weird inquiries come through my company's lead form, it costs some time and attention to sort them. But what makes Cloudflare so confident that automation always equates to "fraud and abuse?" If I send my agent to go retrieve some information, do they consider that fraud? If I block various ad trackers does that trigger their "bot detection" incorrectly? Do I have any recourse? Or is Cloudflare appointing themselves judge, jury and executioner? And let's not forget this little chestnut: > 4. Privacy by design. Precursor was designed to collect signals that help to distinguish human patterns from automated and abusive patterns. Ahh, so to "protect" against bots they're standing up a whole new regime of user surveillance and session-level monitoring. And they definitely won't be selling that, they promise. Got it. This crap should be illegal. In the real world, I can authorize others to act on my behalf. The same should be true with software agents.
- bellowsgulch 2mo agoYawn. Train a domain-specific model on human inputs and then run inference against that. At integration, you change what, one line of code with another? You at best raise the expense to bot, but in today's world, this isn't much compute expense. You can do it on 10-year-old Xenon processors, the same ones used by companies promoted on LowEndBox. Skids already fall into the trap of using open source automation like playwright-extra-stealth.
- erikvanoosten 2mo agoYour keyboard and mouse rhythm and timings are probably so unique that they can be considered PII. Wonder how that works out legally.
- zuzululu 2mo agohmmm i think this is the first time i've seen a genuinely decent approach to blocking scraper/agents that mouse cursor movement is very hard to replicate a real human with the amount of data that cloudflare has you could reproduce something close but cloudflare has seen probably trillions of movements that will be tough to beat watching this carefully but i think this is the right approach
- cjbarber 2mo agoThis (agent detection) is now a kind of emerging space. Obviously it'll get much more important, too. Other products in the space: - Foil (https://usefoil.com/ https://usefoil.com/), I'm biased, a friend is building this - Kasada https://www.kasada.io/ https://www.kasada.io/ - DataDome (https://datadome.co/ https://datadome.co/) - Castle (https://castle.io/ https://castle.io/) - Fingerprint (https://fingerprint.com/ https://fingerprint.com/) - HUMAN (http://humansecurity.com/ http://humansecurity.com/) - Google Cloud Fraud Defense, which is basically the updated reCaptcha (https://cloud.google.com/security/products/fraud-defense?hl=en https://cloud.google.com/security/products/fraud-defense?hl=...) - this, Cloudflare Precursor It seems like some of the main reasons people care so far are: - Preventing automated credential stuffing - Preventing bots from creating a bunch of fake accounts (eg free trial abuse, which can also lead to high twilio SMS bills!) - Reducing payment fraud - Blocking LLM scraping - Blocking automated scalpers (!) eg for tickers or sneakers I'm curious to see which use cases end up dominating as the reason companies care about this. And I'm hopeful that my agents will still have good ways for me to browse and do things on the web on my behalf - eg detect agents and route them to an agent path, rather than blocking them. (I'm interested in tools for detecting AI agents and seeing how this shifts as bot traffic goes way up.)
- harrylepotter 2mo agoDarwinium (darwinium.com) is another example. Approach here involves a combination of profiling and step-transition probabilities; idea is that a customer can ring-fence a particular area of a digital estate where they might want to challenge or block an agent - eg a payment, due to chargeback risks. Precursor at least for now seems more focused on site scraping multiple docs from the same site.
- lukewarm707 2mo agohappy to offer a counter of some great products for anti-bot defeat: https://brightdata.com/ https://brightdata.com/ https://www.zenrows.com/ https://www.zenrows.com/ https://www.capsolver.com/ https://www.capsolver.com/ https://scrapfly.io/ https://scrapfly.io/ hundreds of millions of residential ips, human browser fingerprints, custom browser binaries, auto solve of turnstyle, recaptcha v3, kasada, datadome, AWS WAF, etc if they come up.
- linksbro 2mo agoThe examples of mouse movement, really reminds me what bot scripts looked like for Runescape back in 00s-10s. Early scripts were color-based and jumped the mouse around, and those were quickly caught. But over time, bot scripts developed into complex orchestrations; taking breaks, doing random actions spontaneously, moving the mouse naturally, logging sessions on different platforms (mobile, PC), even responding in chat. There's been plenty of effort put into mimicking realistic / "human" behavior in writing video game bots, and every video game still has tons of bots despite the best efforts of the game devs. You definitely can't win against bots - but you can definitely make the entire "game" (web at large, in this case) worse off for everyone else through this "always-online DRM" parallel.
- thenthenthen 2mo agoThere is a cool video on Runescape bot development and detection methods here: https://youtu.be/B8i26g45WeY?si=MrnM8b5T7L5rpWjp https://youtu.be/B8i26g45WeY?si=MrnM8b5T7L5rpWjp
- cdrnsf 2mo agoGreat. More surveillance, slow browsing and turnstile-style false positives to blanket the web.
- thomastjeffery 2mo agoSo we're just going to let tech monopolists make accessibility impossible, are we? Fuck that!
- altairprime 2mo agoI can’t wait for Cloudflare to decide my musical-rhythm enhanced typing and extraordinarily rapid and repeatable-pattern captcha clicking are somehow machine signifiers just like Google does: If I complete Google captchas at full speed it decides I’m a robot and challenges me endlessly, once 29 times in a row in two minutes or something. That’s what I get for having excellent spatial reflexes and mouse-clicker practice from Q3A sniping. So exhausted of the reversion to mediocre tendency of anti-bot systems, sigh.
- bigbuppo 2mo agoYou also screwed up by using Firefox. That's the #1 method Google uses to prove someone is a bot. If you are't participating in the Google panopticon, you are suspect.
- altairprime 2mo agoI haven’t used Firefox for personal browsing for maybe ten years or more now, so I’m not sure where this is coming from.
- bigbuppo 2mo agoIt was an assumption based on personal experience.
- bigbuppo 2mo agoI can 1000% guarantee this will adversely impact assistive technology. You can tell it will because they don't mention any testing with regards to assistive technology.
- Insimwytim 2mo agoPrecursor is a client-side, session-based verification system, built with privacy in mind, that uses dynamically injected JavaScript to continuously collect behavioral signals as visitors interact with your application. ... I can't even ...
- charcircuit 2mo ago>keyboard activity, focus changes, and visibility. These events are serialized into a compact format and buffered in memory. At regular intervals, the buffered data is sent back to the evaluation layer for analysis. So it's a keylogger?
- piterrro 2mo agoI think in 10/20 years from now, access to the Internet will be allowed only upon personal identification. Every website will be allowed to ask about your identity upon serving any content. Thats the only way I see this is going. The internet as it is right now does not have a future if majority of traffic will be done by agents. Thus, the cost of that traffic will have to be put on the users and since displaying ads doesnt make sense to agents, a paid access will be introduced (which is what cloudflare is slowly doing)
- yencabulator 2mo agoHow about we make browsers not report mouse movement to the page? This is getting way too creepy.
- stanfordkid 2mo agoI'm sure they are doing more than looking at mouse movements, but I don't think this is a compelling approach -- I think human movements could be faked pretty easily using a large corpus of real world behavioral data. It's an adversarial game but the level of intelligence we are approaching with AI this can be solved IMO.
- nikolay 2mo agoHonestly, you need to be completely out of your mind to use Cloudflare for anything. These guys don't offer any support. They seem like a lucrative option until they start blackmailing you into paying for Enterprise, since anything else is a joke.
- hirbyturby 2mo agoUltimately, I think a lot of this is for naught. As models get better and smaller and move from the data center to the PC and the phone, end-user agentics are going to become more prevalent. Bots and agents will be the standard way that people interact with your products. Products that can't or won't allow it will die.
- mchusma 2mo agoI would say that overall there are pros and cons to this, I really want to be allowed to use agents on my behalf, and don't want to see sites prevent me from doing this. On the other hand, I do recognize there are cases when its good/ok to have only humans allowed to take some action. In my opinion, the line is likely when you are representing you are a human, its ok to prevent bots. otherwise, you can't.
- boesboes 2mo agoI guess I should blame the fucking AI bro's, but man, do I fucking hate cloudflare. Feels like a protection racket to me. Also, I'd like to note my home IP triggers A LOT more blocks and checks then when browsing from non-residental IPs, (i.e the office, VPN). I find that sus.
- cute_boi 2mo agoCloudflare should stop acting as if it is protecting the internet. https://developers.cloudflare.com/browser-run/quick-actions/scrape-endpoint/ https://developers.cloudflare.com/browser-run/quick-actions/... This company is like a tobacco seller building a hospital at the same time.
- egiboy 2mo ago“Move your mouse without rhythm to avoid the worm”
- TinyOslo 2mo agoMy 2 cents - have anyone bothered to account for disabilities? Anyone using a given site with tech that moves a cursor? Not using a mouse or trackpad?
- JJvb89 2mo agoThis is frankly just ridiculous. Tracking mouse movements has been a basic bot-detection signal for 15 years. Cloudflare just added it as a signal and is making a huge deal out of it. A firewall company knows very little about browser internals so don't expect much from this.