1. The anti-bot bots that must stop you from proceeding, because they aren't entirely sure you aren't a bot
and 2. The bots that can get past them, which we all must eventually deploy, if we want a chance to visit a web pageCloudflare is a blight on the internet, but HN loves it.
The question is, what is the alternative to cloudflare? We've tried (to various degrees) user id, micropayments, device attestation... I'm not hopeful we can actually solve this. Maybe if there was a neutral, "NGO-like" cloudflare of some sort?
How about an internet where we don't need CloudFlare?
One without zillions of AI crawlers and script kiddies with Terabit DDoS capability… (the latter being the harder problem)
But
The llm thing started to change me in a sense that I no longer really feel obligated to use everybody else's solutions. It may be harder and harder to get onto the 'old web', but my new small project put a website from cellphone and is available for as long as I need it to be available.
The short answer to what we can do is 'adjust accordingly'.
There is popular sentiment on HN that CF is making internet worse by being a core infrastructure element most websites use.
I know I know, it's original purpose was to be a weapon. [2] It has certainly devolved into a weapon to divide the people.
We can make our own internet though - with blackhack and jookers.
E.g. If the internet is super-fast and has the capability to deliver video ads, it will be used for that. If everyone just had a connection with the speed of a 56K modem, that video-based ad model wouldn't work.
If we really want the internet to be a certain way, we have to change the underlying technology used, not the ideology behind it. Because if an technology has a capability, it will be used to do whatever is most successful in the capitalistic system, not what's best for 'end users'.
Regulation sometimes be effective, but...the model of regulation in a world of freely-evolving technology is a broken system most of the time.
Is the end user viewed as an ISPs client? a consumer of tech companies?
The idealistic language is fine but isnt based on any scientific approach to society. Its neutral at best.
The internet is for end users, but how if its not "by end users"?
If most protocols and standard implementations depend on adoption by ISPs and tech companies what does it mean to be "for the end user"?
Is prison architecture "for the prisoners"?
So how do we solve the "by end users" dilemma?
Unless you own your hardware, you aren't the end user. When your phone, tv, camera, or even laptop on a non-free OS is on your network, you can get some semblance of control by controlling what network services it uses.
Things like DoH are part of the removal of my control as a home user and give it to Sony, or Apple, or TPLink
The most obvious thing is it becomes harder to block adverts.
Throw in internet-centralisation through HN darlings like cloudflare and you're screwed. You have no idea what anything is talking to, as it's the same destination IPs, so the choice is either block it completely, or allow it with no control.
In countries where the internet is subject to censorship, as well as in regions with underdeveloped infrastructure, DNS queries are highly likely to be deliberately tampered with, poisoned, or hijacked. DoH is a very practical way to mitigate this problem, and I do not believe that the ability to block advertisements is more important than that.
Moreover, advanced users can still run their own DNS services for ad blocking, and, at least for the foreseeable future, DoH will not prevent them from continuing to use traditional DNS. You cannot criticize an important improvement in security merely because it makes ad blocking less convenient. Other people may face threat models that are a hundred times more serious than yours.
I think in this context it'd be any netizen who does not hold a significant amount of power to influence other [unrelated to them] netizens?
DoH works against that
That idea being that AI is less important than humans.