46 comments

[ 1.7 ms ] story [ 58.2 ms ] thread
[flagged]
Cool product launch, though it feels a little weird to me that Cloudflare sells agentic products alongside this new service that seems designed to block agentic usage of the web?

I expect there's much more going on than just mouse path detection but I can imagine that this is already tricky for touchscreens and for people using non-traditional mouse inputs (the thinkpad nub comes to mind - but it would also be bad optics to accidentally block people using accessibility mouse tools as bot users, though then this becomes a loophole for agentic browsing!)

In general though I think this is almost definitely a good thing to reduce agentic bot abuse & spam.

please drink verification can to continue
What prevents bots/agents from just adding "jitter" to their movements that mimics how humans move their cursor?

I know there are other signals being used but this one in particular seems like it wouldn't be hard to beat with a small amount of sophistication from the bot.

how does this interact with keyboard navigation & accessibility tools?
It’s a bit alarming how cloudflare is establishing itself as arbiter of all things bots…both on blocking and allowing.

Doesn’t seem healthy for the internet as a whole

Gosh, this is all pretty nauseating.
I can’t wait for cloudflare to sell data on how well my wrist is working to my insurance company. What a wonderful hell we’ve created for ourselves.
As a real user who uses an Ultimate Hacking Keyboard with the mouse layer, this frustrates me immensely. Yes I'm a corner case, but this is likely to make certain website not work for me because my lines are perfectly straight and my arcs zig-zag much like a bot might.

Considering the keyboard/mouse layer feels like an advancement to me, this feels like tech that will lock in the "old" way of doing things.

I really detest how adversarial the web is getting. I'm not a cloudflare hater but please, please consider people like me when rolling out stuff that affects millions or maybe even hundreds of millions or billions of people.

control+F accessibility no results

Yeah so this mouse movement astrology is going to completely lock non-sighted/keyboard only users out of large swaths of the Internet isn't it.

I have been noticing a lot of Cloudflare false positives where it keeps spinning on my sessions never actually redirecting me to the underlying page. If they keep just vibe coding and releasing a new solution every day, I am afraid it will be reflected in their services quality.
(comment deleted)
Cloudflare has a lot of enterprise customers. Selling bot check to companies wanting to protect their content & also taking a cut out of payments for access by bots could be a good earner for them.
So now instead of having the slow-axx Cloudflare turnstile slowing down your requests, you get surprised with a "You are a BOT!!!" while you are conducting your business on a website.

I already quickly close any website that I do not need for business purposes when it shows me the Cloudflare spinner. Now I might have to start considering competitors who do not implement this shit.

even before the llm era sites would flag me as a bot for opening 15 links to read later. its fucking infuriating now
One interesting aspect is of course that the movement from the same user can be different depending on what type of mouse they use. I use a mouse at work on my PC, touchpad on my private laptop, and thinkpad nipple on work laptop. Three different profiles for one user.

Obviously different movements from a AI, but if we come to the day where mouse movement fingerprinting becomes another gatekeeper, there could be some interesting outliers.

I wonder how it'll handle those of us who try and use the mouse as infrequently as possible. I imagine the cognitive delay part would be largely telling. But it'll be interesting to see if I start getting blocked because I use vimium.
There is nothing stopping a bot from moving their cursor like a human. This is basically just putting up a door with zero walls and telling people to stay out of your house.

All of these things are completely abusable/bypass-able and just annoying for actual humans who trigger flags.

It's a bleak world in terms of bots flooding the web, but out of all possible solutions, this seems to be preferable over invasive and identifying fingerprinting that everyone wants to roll out. Here's hoping that mouse movements aren't sufficiently unique as to be fingerprintable too.
as a heavy user of computer use, i hope enterprises realize that people like me will switch to competitors that support native computer use & APIs
I implemented all of this in hCaptcha 6 years ago, not just to distinguish bot from human but also to recognize the keyboard/mouse behavior of the same person signing up for many accounts or testing multiple credit cards. This kind of abuse detection was a part of Cloudflare when they switched to hCaptcha in 2020 and I had thought they already implemented all this themselves four years ago when they transitioned away from hCaptcha in 2022.
I dislike bots as much as anyone else... when weird inquiries come through my company's lead form, it costs some time and attention to sort them.

But what makes Cloudflare so confident that automation always equates to "fraud and abuse?" If I send my agent to go retrieve some information, do they consider that fraud?

If I block various ad trackers does that trigger their "bot detection" incorrectly? Do I have any recourse? Or is Cloudflare appointing themselves judge, jury and executioner?

And let's not forget this little chestnut: > 4. Privacy by design. Precursor was designed to collect signals that help to distinguish human patterns from automated and abusive patterns.

Ahh, so to "protect" against bots they're standing up a whole new regime of user surveillance and session-level monitoring. And they definitely won't be selling that, they promise. Got it.

This crap should be illegal. In the real world, I can authorize others to act on my behalf. The same should be true with software agents.

Yawn. Train a domain-specific model on human inputs and then run inference against that. At integration, you change what, one line of code with another? You at best raise the expense to bot, but in today's world, this isn't much compute expense. You can do it on 10-year-old Xenon processors, the same ones used by companies promoted on LowEndBox.

Skids already fall into the trap of using open source automation like playwright-extra-stealth.

Your keyboard and mouse rhythm and timings are probably so unique that they can be considered PII. Wonder how that works out legally.