Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arbol
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
arbol
10d ago
It's to protect against scrapers that aren't running JavaScript. Makes it more costly for them.
2.
▲
by
arbol
14d ago
This is already happening and it absolutely does let llms understand the page better. Search for JSON-LD
3.
▲
by
arbol
14d ago
If you're getting hundreds of thousands of spam submissions then you probably need to pay for bot protection.
4.
▲
by
arbol
20d ago
Why do you expect a high level of abuse? Blocking CIDRs of major cloud providers will stop the genuine ChatGPT/Claude traffic. For the other scrapers masquerading as them, just block the agents' user agents. If you want the LLMs t
5.
▲
by
arbol
22d ago
UI says: "Could not connect to server." Console: https://ams.api.fastmail.com/auth/login net::ERR_ADDRESS_UNREACHABLE
6.
▲
Fastmail Down for Anyone Else?
(app.fastmail.com)
2 points
by
arbol
22d ago
|
3 comments
7.
▲
by
arbol
1mo ago
> I'd like to increase bot traffic to around 100k hits per day to help test the filters. Any suggestions on how? Start publishing content that AI crawlers want to read and you'll get absolutely hammered. Your site is pretty bar
8.
▲
by
arbol
1mo ago
It's not enough to use latency alone as the other commentor said. You need to look for repeat behaviour at scale. It's ML model time once these basic signals fail you.
9.
▲
by
arbol
2mo ago
Prosopo could cut out a lot of the residential proxy nonsense for you. We integrate with lambda@Edge / cloudfront workers / server side and perform analytics to detect residential proxy networks - at far less cost than DD or HUMAN
10.
▲
by
arbol
2mo ago
> The checks can be bypassed by hitting the <code>Escape</code> key five times.
11.
▲
by
arbol
2mo ago
If you're on a proxy network then you're detectable by TLS handshake timings, for example. You are right though that agent mouse and touch behaviour is almost inseperable from human data these days. So you need to use a combinatio
12.
▲
by
arbol
2mo ago
They talk about bringing these samples back to earth but don't mention how. Have they already planned how to get perseverance and its samples back?
13.
▲
by
arbol
3mo ago
It works both ways... We use prompts hidden in our bot detection system that are unreadable to humans but trigger additional payloads.
14.
▲
by
arbol
3mo ago
Tories were in governance from 2010 - 2024. And things didn't exactly improve.
15.
▲
by
arbol
3mo ago
> The site’s content happens to include an HTTP/2 endpoint that, when presented with an anonymous authorization token, behaves as a VPN server’s outer layer Is this not the fingerprintable aspect? Wouldn't you need to randomise
16.
▲
by
arbol
3mo ago
What about the services that rent vps/compute for crypto?
17.
▲
by
arbol
3mo ago
Adblock??
18.
▲
by
arbol
3mo ago
When they realise their social media ban for children doesn't work
19.
▲
by
arbol
3mo ago
It's just a concept, not a real test. Captcha are already expensive at scale due to escalating checks when abuse is detected. You have to orchestrate and pay for residential proxies, containers with different fingerprints, different be
20.
▲
by
arbol
3mo ago
AI generated drivel
21.
▲
by
arbol
3mo ago
> coming from normal-user IP addresses This is the standard now for astroturfing online. Build up a profile over time with varied interactions, sometimes over years, and then sell it for a few hundred dollars via blackhatworld. I've
22.
▲
by
arbol
3mo ago
So far its cost me $2.27 to submit a contact form 3 times - why is this better than a captcha solver with human solves at 1000 per $2? On your automation, your tool fed back to me as follows after 3 submissions: > The CAPTCHA is persiste
23.
▲
by
arbol
3mo ago
It's not hard to setup JA4 monitoring and I think its valid as a coarse filter. There are various plugins for nginx/node. > I've seen people waste so much time with the whack a mole JA4 block just because they like the int
24.
▲
by
arbol
3mo ago
In combination with other signals JA4s are useful. You learn to spot obviously incorrect ones because Chrome always looks different from Safari which looks different to Firefox. Captcha solvers have their own unique JA4s based on whatever s
25.
▲
by
arbol
4mo ago
Is it not just a case of most of their clients being US based?
26.
▲
by
arbol
4mo ago
At the time, reCAPTCHA was the alternative and it was effectively working as a giant ad targeting data collection tool. I'm pretty sure Google have now back tracked from this. WebGL finger printing is just one of many things you need t
27.
▲
by
arbol
4mo ago
I think we're talking about 2 different things. PoW is annoying for basic scrapers but it really doesn't affect enterprise grade bot operations with access to unlimited residential proxies.
28.
▲
by
arbol
4mo ago
It's either that or you tie tickets to government ID like in France. If the arbitrage opportunity is more than the cost of automation then someone will exploit it.
29.
▲
by
arbol
4mo ago
You literally can't get rid of it without introducing government issued ID to buy any scarce freely accessible items
30.
▲
by
arbol
4mo ago
I'm no CF advocate but those random APIs are literally what differentiates people running Chrome on their computer versus a bot operation with a load of containers. Kubertnetes clusters don't have GPUs. This is why it's used
More ›