Cloudflare Turnstile requiring fingerprintable WebGL

18 points by ignaloidas


Riolku

To be clear, I am not in favour of fingerprinting, just interested in bot blocking tools, since that's part of my current job.

Cloudflare's supposed goal with Turnstile is to create a bot protection widget that doesn't require humans to solve captchas. Presumably fingerprinting allows them to largely allow users across different sites by monitoring behaviour, is that correct?

Is the goal of a widget that doesn't require solving captchas viable without fingerprinting? Is it viable at all? I have heard that bypassing Turnstile is not that hard :tm:. Are all bot blocking widgets necessarily just security through obscurity?