← Back to context

Comment by everdrive

5 months ago

It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and another browser to attempt to prevent tracking users across the web.

Nick, I understand the practical realities regarding why you'd need to try to tamp down on some bot traffic, but do you see a world where users are not forced to choose between privacy and functionality?

Local models for privacy.

You want to go to the world's best hotel? You are gonna be on their CCTV. Staying at home is crappier but private.

Unfortunately for the first time moores law isn't helping (e.g. give a poor person an old laptop and install linux they will be fine). They can do that and all good except no LLM.

  • > You want to go to the world's best hotel? You are gonna be on their CCTV.

    ironically, in high end hotels, there's often a lot less cctv. not none. just less. rich people enjoy privacy

    • So they’re not just hidden better? Does make sense.

      Well, I can use the world‘s best safety deposit box without being on CCTV while I pass secrets in and out of it, right? Just not for free.

      Bummer, this sounds like it is about to turn into a Monero ad (“let us pay privately”)

      1 reply →

    • In hotels of all tax brackets, you usually get a room key.

      And the salient difference is that CCTV is simply defense-in-depth, not a primary means for authentication.

Meet me in a cafe and I will sign a JWT saying you're not a bot. You can submit this to whoever will accept it.

  • If apple approves it, ive got a solution: A keyboardthat attests to your humanity https://typed.by/magicseth/2451#2NyGLfAQxmqRiAOTlaX7ma3G4d1o...

    • Brilliant! Just the thing we want: more hardware attestation, more deanonymization, less user control, all diligently orchestrated in a repository where the only contributor is Anthropic Claude [0]. Comes complete with a misaligned ASCII diagram in the README to show how much effort the humans behind it put in!

      Yes, even their "humanifesto" is LLM output, and is written almost exclusively in the "it's not X <emdash> it's Y" style.

      [0]: https://github.com/magicseth/keywitness/graphs/contributors

      14 replies →

    • Oh Gawd, not this idea again!

      This idea of capturing the timing of people's keystrokes to identify them, ensure it is them typing their passwords, or even using the timing itself as a password has been recurring every few years for at least three decades.

      It is always just as bad. Because there are so many cases where it completely fails.

      The first case is a minor injury to either hand — just put a fat bandage on one finger from a minor kitchen accident, and you'll be typing completely differently for a few days.

      Or, because I just walked into my office eating a juicy apple with one hand and I'm in a hurry typing my PW with my other hand because someone just called with an urgent issue I've got to fix, aaaaannnd, your software balks because I'm typing with a completely different cadence.

      The list of valid reasons for failure is endless wherein a person's usual solid patterns are good 90%+ of the time, but will hard fail the other 10% of the time. And the acceptable error rate would be 2-4 orders of magnitude less.

      It's a mystery how people go all the way to building software based on an idea that seems good but is actually bad, without thinking it through, or even checking how often it has been done before and failed?

      8 replies →

    • The first widely distributed and open source version of this typist timing validation idea I saw (and incorporated into my own software at the time) was released by Michael Crichton as part of a password 2nd-factor checker (1st factor a known phrase or even your name, the 2nd factor being your idiosyncratic typing pattern) in Creative Computing magazine that printed the code.

      Original here: https://archive.org/details/sim_creative-computing_1984-06_1...

    • You’re getting a negative reaction from others but I share this feedback in good faith: I don’t understand what problem your product is supposed to solve.

      Yeah I guess the cryptographic stuff sounds vaguely impressive although it’s been a long time since I had to think about cryptography in detail. But what is this _for_? I’m going to buy an expensive keyboard so that I can send messages to someone and they’ll know it’s really me – but it has to be someone who a) doesn’t trust me or any of our existing communication channels and b) cares enough to verify using this weird software? Oh and it’s important they know I sent it from a particular device out of the many I could be using?

      Who is that person? What would I be sending them? What is the scenario where we would both need this?

      Also the server can’t read the message but the decryption key is in the URL? So anyone with the URL can still read it? Then why even bother encrypting it?

      Maybe this is one of those cases where I’m so far outside your target market that it was never supposed to make sense to me but I feel like I’m missing something here. Or maybe you need to work on your elevator pitch.

      Just sharing my honest reaction.

  • Doesn’t really make sense, because any service can just say “you must paste your human-attestation JWT here to use this service” and plenty of people will.

    • You can just decay your trust level based on the `iat` value. That way people will need to keep buying me coffee. I can optionally chide them for giving out their token.

      If you're engaging with the idea seriously, I suppose we'd need to build a reputation or trust network or something.

      Although if you're talking about replay attacks specifically, there are other crypto based solutions for that.

      4 replies →

What if I run a website and OpenAI produces bot traffic? Do they also consider it abuse when they do it?

This is indeed what I do. And you also should. Separate browser for banking, trusted shipping sites etc, and the normal one.

Make sure not to browse the Internet without adblock and/or similar.

Firefox multicontainers are pretty cool. But it’s an advanced process that most people wouldn’t do or do correctly.

  • I love the containers too. My current use case is to keep my YouTube account separate from my Google one. Google doesn't need all that behavioural data in one place.

    It's a pity Firefox doesn't get the praise it deserves half as much as it cops criticism.

  • It is absolutely not an advanced process. It's clicking a gui. It's not advanced thinking to understand profiles. It's a basic ability to hold multiple things in your mind at once. Telling people that's difficult only increases the societal problem that being ignorant is ok.

    • “Difficult” is a relative term. They were saying it was a difficult concept for them, not you. In order to save their ego, people often phrase those events to be inclusive of the reader; it doesn’t feel as bad if you imagine everyone else would struggle too. Pay attention and you’ll notice yourself doing it too.

      “Ignorant” is also infinite - you’re ignorant of MANY things as well, and I’m sure you would struggle with things I can do with ease. For example, understanding the meaning behind what’s being said so I know not to brow-beat someone over it.

      1 reply →

    • Mostof the people I met outside work wouldn't understand this concept.

      I think you're lucky to hang around people whose heads don't hurt when they think.

  • The possibilities with Firefox multi containers and automation scripts as well are truly endless.

    It's also possible to make Firefox route each container through a different proxy which could be running locally even which then can connect to multiple different VPN's. I haven't tried doing that but its certainly possible.

    It's sort of possible to run different browsers with completely new identities and sometimes IP within the convenience of one. It's really underrated. I don't use the IP part of this that I have mentioned but I use multi containers quite a lot on zen and they are kind of core part of how I browse the web and there are many cool things which can be done/have been done with them.

I am not Nick, but there's a few ways that world happens: the free tier goes away and what people pay for more correctly reflects what they use, this all becomes cheap enough that it doesn't matter, or we come up with an end to end method of determining usage is triggered by a person.

Another way is to just do better isolation as a user. That's probably your best shot without hoping these companies change policies.

> It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and another browser to attempt to prevent tracking users across the web.

Every time I try this, I end up crossing wires (ie using the browser that 'works' for most things, more than the one that is 'broken')

i am increasingly moving towards a model of 'no browser'.

search for me is now a proprietary index (like exa) that filters rubbish, with a zero data retention sla. so we don't need google profiling.

the content is distilled into markdown pulled from cloudflare's browser rendering api.

i let cloudflare absorb the torrent of trackers and robot checks, i just get md from the api with nothing else. cloudflare is poacher and gamekeeper.

an alternative is groq compound which can call browsers in parallel.

for interactive sites, or local ai browsing, i sometimes run a browser in a photon os docker with vnc, which gives you the same browser window but it runs code not on your pc.

that said little of my use is now interacting with websites, its all agentic search and websets so i don't have to spend mental energy on it myself

>It's getting to the point where a user needs at minimum two browsers. One to allow all this horrendous client checking so that crucial services work, and another browser to attempt to prevent tracking users across the web.

What are you talking about? It works fine with firefox with RFP and VPN enabled, which is already more paranoid than the average configuration. There are definitely sites where this configuration would get blocked, but chatgpt isn't one of them, so you're barking up the wrong tree here.

  • Is your interlocutor barking up the wrong tree, or are you missing the forest for the trees?

    According to the OP:

    > The program checks 55 properties spanning three layers: your browser (GPU, screen, fonts), the Cloudflare network (your city, your IP, your region from edge headers), and the ChatGPT React application itself (__reactRouterContext, loaderData, clientBootstrap).

    I guess Firefox VPN will hide the IP at least. But what about the other data, is it faked by RFP? Because if not, the so-called privacy offered by this configuration is outdated.

    You might be fingerprinted by OpenAI right now, as “that guy with all the Firefox anti-fingerprinting stuff enabled, even though it breaks other sites”.

    • >But what about the other data, is it faked by RFP?

      Yes, RFP spoofs or at least somewhat obfuscates/normalizes GPU/screen/font info. The rest are integrity validations of the server/app, and not really identifying in any way.

      >You might be fingerprinted by OpenAI right now, as “that guy with all the Firefox anti-fingerprinting stuff enabled, even though it breaks other sites”.

      I'm not sure what the broader point you're trying to make here is. Is fingerprinting bad? Yes. All things being equal, I'd rather not have it than have it, but at the same time it's not realistic to expect openai to serve anonymous requests from anyone. Back when chatgpt was first launched you had to sign up and verify your phone number. Compared to mandatory logins, fingerprinting is definitely the lesser evil here.

      1 reply →