As much as I _despise_ modern ReCAPTCHA, I have always been able to pass the challenge eventually; it has never flatly rejected me with no recourse. If I made a mistake or was insufficiently human for it, I got a new challenge and tried again. There are apocryphal stories of Google tar-pitting users with it, but I have never seen it in action.<p>If this judges the browser more than the user, what do I do when the browser fails? Do I refresh the page hoping for a different batch of invisible challenges? Do I submit a ticket to CF customer support... despite not being a customer?
This is yet another example of Cloudflare centralizing the web. I’m tired of this. Sure the only previously viable solution was ReCAPTCHA from Google. But it’s Google. I depend on them for search. And, sure, their business model depends on them being able to track me online. But I know them. And it’s hard for me to live without them. So I’m ok with depending on them, but I worry about further centralization of the Internet if there’s an alternative. At the end of the day, I like the Internet how it is and how I’ve gotten used to it. Facebook is clearly evil, but I still check them from time to time to keep up with my friends, but a lot less than I used to. I, of course, need to use Google so even though their business is inherently about tracking me, what’s the alternative. But Cloudflare, they’re new. They disrupt what I’m used to. They add another player to the mix. So how dare they centralize the Internet?? This is total BS. I’ll stick with ReCAPTCHA.
Cloudflare: "Cloudflare has a long track record of investing in user privacy, which we will continue with Turnstile."<p>Also Cloudflare: Tracks and fingerprints everyone, and blocks anyone who hardens their browser ("First we run a series of small non-interactive JavaScript challenges gathering more signals about the visitor/browser environment. Those challenges include proof-of-work, proof-of-space, probing for web APIs, and various other challenges for detecting browser-quirks and human behavior. As a result, we can fine-tune the difficulty of the challenge to the specific request.").
What is the failure case for the Cloudflare captcha? In case browser fingerprinting fails to identify me as a human, do they fallback to a challenge that humans can solve, such as audio or image challenges?<p>Say what you will about Recaptcha, but they do have a way to eventually pass through the challenge.
For Cloudflare employees going through this thread, the linked "Turnstile Developer Documentation" link [1] in the Turnstile dashboard is returning a 404.<p>[1]: <a href="https://developers.cloudflare.com/turnstile/" rel="nofollow">https://developers.cloudflare.com/turnstile/</a>
FYI: The docs link in the Dashboard [1] points to a 404.<p>[1]: <a href="https://developers.cloudflare.com/turnstile/get-started/client-side-validation/" rel="nofollow">https://developers.cloudflare.com/turnstile/get-started/clie...</a>
This looks great, Cloudflare will always be Better Privacy wise than Google.<p>> without having to be a Cloudflare customer or sending traffic through the Cloudflare global network<p>And you don't even need to use CF as a proxy.
Just a heads up for CF folks: Once you create a Turnstile, the link below the generated secret ("Server side integration code") leads to 404.
My problem with this is I want to use the CAPTCHA to deter <i>humans</i> from continuing. Letting them thru automatically allows spammers/attackers to just continue on, but many will actually skip pages/sites where they have to do the CAPTCHA etc.<p>This helps the bot problem, but doesn't solve the SPAM problem.