{"id":251956,"date":"2021-05-18T00:07:58","date_gmt":"2021-05-17T21:07:58","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/cloudflares-new-captcha-replacement-needs-more-work-review-geek\/"},"modified":"2021-05-18T00:07:58","modified_gmt":"2021-05-17T21:07:58","slug":"cloudflares-new-captcha-replacement-needs-more-work-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/cloudflares-new-captcha-replacement-needs-more-work-review-geek\/","title":{"rendered":"#Cloudflare\u2019s New CAPTCHA Replacement Needs More Work \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#Cloudflare\u2019s New CAPTCHA Replacement Needs More Work \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-83378 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/d58505c9.png?width=1200\" alt=\"An illustration of a USB Security Key\" width=\"1920\" height=\"1080\" data-crediturl=\"https:\/\/blog.cloudflare.com\/introducing-cryptographic-attestation-of-personhood\/\" data-credittext=\"Cloudflare\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.cloudflare.com\/introducing-cryptographic-attestation-of-personhood\/\">Cloudflare<\/a><\/span><\/figcaption><\/figure>\n<p>Popular CDN and DNS service provider Cloudflare wants to <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.cloudflare.com\/introducing-cryptographic-attestation-of-personhood\/\">put an end to CAPTCHAs<\/a>, claiming that humanity wastes 500 hours staring at the annoying \u201cprove you\u2019re not a robot\u201d tests every day. And while the company\u2019s proposed replacement isn\u2019t exactly perfect, it\u2019s a step in the right direction that could lay the groundwork for future authentication standards.<\/p>\n<p>CAPTCHA is a \u201cCompletely Automated Public Turing test to tell Computers and Humans Apart.\u201d Like a bouncer at a nightclub, CAPTCHA uses simple questions or puzzles to prevents robots from overrunning websites. But CAPTCHA sucks. The tests are slow and confusing, they don\u2019t always work correctly, and they\u2019re not always accessible to those who are visually impaired.<\/p>\n<p>Google is trying its hardest <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.google.com\/recaptcha\/about\/\">to fix CAPTCHA<\/a>, but Cloudflare wants to kill it off and replace it with something called \u201cCryptographic Attestation of Personhood,\u201d which is a fancy way of saying \u201ca piece of hardware that proves you\u2019re a human.\u201d Unsurprisingly, Cloudflare is focusing on USB security keys in its early tests for this authentication method.<\/p>\n<p>If you own a YubiKey, HyperFIDO key, or Thetis FIDO U2F security key, then you can test Cloudflare\u2019s impressive <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cloudflarechallenge.com\/\">new authentication system<\/a> now. Simply connect the USB security key to your computer, give the website permission to see your key, click the key, and then you\u2019re off to the races (well, you\u2019re redirected back to Cloudflare\u2019s blog). Not only is the system fast, but it\u2019s accessible to people who are visually impaired. It also protects user privacy, as the security key that vouches for your humanity isn\u2019t uniquely tied to your name or device.<\/p>\n<p>It wouldn\u2019t take much work for the <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">technology<\/a> to support mobile phones, which can <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/support.google.com\/accounts\/answer\/9289445?co=GENIE.Platform%3DAndroid&amp;hl=en\">stand-in for security keys<\/a> thanks to Google. Cloudflare also proposes a future where manufacturers build \u201cCryptographic Attestation of Personhood\u201d hardware directly into devices. These chips could verify that your computer is real and unique using a special code associated with the manufacturer.<\/p>\n<p>But are these authentication methods effective? What\u2019s stopping a robot from using (or spoofing) a USB security key, or any other \u201cattestation\u201d tools? As Webatuthn Works CEO Ackermann Yuriy <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/herrjemand.medium.com\/why-cloudflares-captcha-replacement-with-fido2-webauthn-is-a-really-bad-idea-d5487f6c7566\">points out<\/a>, FIDO keys are not only easy to spoof, but they also work incredibly fast and are relatively anonymous, so a bot farm hook up to a handful of keys could easily overrun a website protected with Cloudflare\u2019s system.<\/p>\n<p>People are already plotting elaborate schemes to break past Cloudflare\u2019s proposed CAPTCHA replacement, an indicator that \u201cCryptographic Attestation of Personhood\u201d isn\u2019t the future, at least not in its current sate. But the authentication method is incredibly convenient, fairly private, and fairly easy to implement. In short, the floodgates are open, it\u2019s time for CAPTCHA to die, and Cloudflare is taking the first step in the right direction.<\/p>\n<p><small>Source: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.cloudflare.com\/introducing-cryptographic-attestation-of-personhood\/\">Cloudflare<\/a> via <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.theverge.com\/2021\/5\/16\/22436395\/cloudflare-end-captcha-madness-security-key-cryptographic-attestation-of-personhood\">The Verge<\/a><\/small>\n<\/div>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/83366\/cloudflares-new-captcha-replacement-needs-more-work\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Cloudflare\u2019s New CAPTCHA Replacement Needs More Work \u2013 Review Geek&#8221; Cloudflare Popular CDN and DNS service provider Cloudflare wants to put an end to CAPTCHAs, claiming that humanity wastes 500 hours staring at the annoying \u201cprove you\u2019re not a robot\u201d tests every day. And while the company\u2019s proposed replacement isn\u2019t exactly perfect, it\u2019s a step&#8230;<\/p>\n","protected":false},"author":1,"featured_media":251957,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/05\/d58505c9.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-251956","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/251956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=251956"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/251956\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/251957"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=251956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=251956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=251956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}