Readit News logoReadit News
reliefcrew commented on AI search engine – How to prevent bots?    · Posted by u/chaztaubelman
timshell · 10 hours ago
reliefcrew · 5 hours ago
> Finally, our evaluation did not involve active adversarial optimization.

Good luck!

reliefcrew commented on AI search engine – How to prevent bots?    · Posted by u/chaztaubelman
timshell · 11 hours ago
Yup! It depends on your use case.

Cloudflare is really good at network bot detection. Rate-limiting is super helpful here, for example during DDoS attacks.

Our customers are a little different. They sometimes struggle with high-volume bot attacks (e.g. SMS toll fraud in ticketing marketplaces), but we specifically focus on online platforms that want to verify a human is on the other side of the screen. For example, survey pollsters and labor marketplaces want to stop a slow agent that can complete traditional CAPTCHA even if it's solving it a human speed

reliefcrew · 11 hours ago
I see. I'll have to read the marketing more closely next time, lol. The cynic in me only notices the detection rate comparisons, which I'm sure the marketing folks don't mind much ;-)
reliefcrew commented on AI search engine – How to prevent bots?    · Posted by u/chaztaubelman
timshell · 12 hours ago
Check out a demo of a similar tool we created (https://model-guessr.com/) that was bot-gated by Roundtable Proof of Human.

Happy to talk more details about PoH (disclaimer: I'm a cofounder and this is my YC S23 company)

reliefcrew · 12 hours ago
Can you comment on the notion that Turnstile's primary goal isn't to keep bots out 100% but instead to slow them down to "human" speeds.

Asking because as a dev I hate when sites don't allow bots... however can appreciate that automation should be rate-limited. IOW, isn't preventing bot access actually an anti-pattern since rate-limiting is sufficient?

I see a lot of marketing which bashes Turnstile [detection] rates and tries to leverage this misunderstood nuance. And, it seems to be a dishonest point of contention but am willing to hear opposing arguments.

Thanks.

reliefcrew commented on AI search engine – How to prevent bots?    · Posted by u/chaztaubelman
reliefcrew · 12 hours ago
reliefcrew commented on Ask HN: Share a random link from your bookmarks    · Posted by u/TechSquidTV
reliefcrew · a day ago
https://unbound.docs.nlnetlabs.nl/en/latest/use-cases/home-r...

(EDIT: pretty random; chosen via: `grep -Po "http[^ ]+" index.htm | shuf -n1`)

reliefcrew commented on Ask HN: What email providers don't recycle email addresses?    · Posted by u/supermatt
supermatt · 2 days ago
Don't worry about it - clearly I am not explaining it well enough for you to understand. It is a well documented security concern, so feel free to do your own research on why as we are just going in circles here.
reliefcrew · a day ago
> It is a well documented security concern

A reference would be appreciated.

reliefcrew commented on Ask HN: What email providers don't recycle email addresses?    · Posted by u/supermatt
reliefcrew · 2 days ago
> do a `dig soa hey.com` and you'll see they're registered w/ cloudflare

Sorry, this should be a whois search to see their registrar, the dig will show you who provides their DNS. In hey.coms case both are the same.... cloudflare.

My point remains the same though. The worry of losing your address should remain largely the same because email depends on dns.

reliefcrew · 2 days ago
> The worry of losing your address should remain largely the same

You should actually worry more about losing your address because now there are two people who can screw you... the ESP (email service provider) _and_ their registrar.

If you hire the ESP to host email on your own domain though (or self host), then you can screw yourself (this is always a possibility) or the registrar can screw you... but you can always just switch ESPs if they're criminals or incompetent. This is what I was referring to when I said this:

> just shuffling things around (probably in the wrong direction).

... in the first reply. Phew... what a long strange trip! I hope the picture is clearer now.

Now I have to leave you to your own devices, sorry.

reliefcrew commented on Ask HN: What email providers don't recycle email addresses?    · Posted by u/supermatt
reliefcrew · 2 days ago
> I am referring to an email provider that uses its own domain

Well, where do you think they get their domain from? The same place you do, a registrar. You're just adding a layer.

For example, you mention hey.com.... do a `dig soa hey.com` and you'll see they're registered w/ cloudflare. If you register with cloudflare too, you will have the same chance of having your domain ripped away from you as hey.com does.

The email service provider isn't particularly special in that sense. That said, it is true that there's a lot about infrastructure people can use help with.

So, if you're not familiar w/ technicalities such as these I wouldn't blame you for outsourcing. It's a big world and we can't do it all ourselves. Good luck!

reliefcrew · 2 days ago
> do a `dig soa hey.com` and you'll see they're registered w/ cloudflare

Sorry, this should be a whois search to see their registrar, the dig will show you who provides their DNS. In hey.coms case both are the same.... cloudflare.

My point remains the same though. The worry of losing your address should remain largely the same because email depends on dns.

reliefcrew commented on Ask HN: What email providers don't recycle email addresses?    · Posted by u/supermatt
supermatt · 2 days ago
A registrar isn't going to keep your domain active if you don't renew.

Maybe you are confused about what I mean by email service provider.

I am referring to an email provider that uses its own domain, and provides you with an email account - like gmail, live, hey (the examples I have given). I thought I made that clear when I said: "It would be nice to have a memorable user-part, so nothing oversubscribed would be ideal."

reliefcrew · 2 days ago
> I am referring to an email provider that uses its own domain

Well, where do you think they get their domain from? The same place you do, a registrar. You're just adding a layer.

For example, you mention hey.com.... do a `dig soa hey.com` and you'll see they're registered w/ cloudflare. If you register with cloudflare too, you will have the same chance of having your domain ripped away from you as hey.com does.

The email service provider isn't particularly special in that sense. That said, it is true that there's a lot about infrastructure people can use help with.

So, if you're not familiar w/ technicalities such as these I wouldn't blame you for outsourcing. It's a big world and we can't do it all ourselves. Good luck!

reliefcrew commented on Ask HN: Can someone explain why Meta makes such bad design decisions?    · Posted by u/Desafinado
Desafinado · 3 days ago
I don't see how, in the scenario I mentioned, that just allowing a user to click away from a modal is a problem, though. Are they not losing value from alienating users who they do stuff like this to? Are they really gaining any value by forcing them to follow accounts they don't want to follow?

It just sounds like they have no better ideas to me. Why not just make the feature human and build a little bit of customer loyalty? That's kind of my point. After a while people get so tired of this crap this might be why these users provide Meta no value.

And I guess, if they're already making ridiculous profits, why not just accept that some of your users are low value monetarily but do provide value by being on the network at all.

reliefcrew · 2 days ago
> some of your users are low value monetarily but do provide value by being on the network

That's not how advertising works. If you're not looking at the advertising, you don't provide any value, nothing. In that case you're now a losing proposition and they don't want those users because they're lowering margins and ROE. It's about good decisions that make money... goodwill only goes so far on the balance sheet.

Now, you got my full explanation. If you still don't understand why it's not as bad a design as you first thought... we'll just have to disagree ;-)

u/reliefcrew

KarmaCake day122March 11, 2022
About
in base64…

cmVsaWVmY3Jldy5uZXQK

View Original