Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not only did iOS implement this, but everyone either sleep-walked on it, or worse, praised it, because Apple sold it as a CAPTCHA bypass instead of a DRM scheme: https://mastodon.delroth.net/@delroth/110775677023220850


How is PrivacyPass related to iOS?


PrivacyPass is an extension that lets you pre-solve CloudFlare CAPTCHAs if you're on a VPN. However, that was too frustrating, so CloudFlare partnered with Apple to integrate PrivacyPass into Safari.

How did they do this? Simple: iOS provides cryptographic attestation that your browser isn't a bot and isn't hacked, and CloudFlare takes that as your CAPTCHA solution. This works exactly the same way that Google proposes Web Environment Integrity work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: