this post was submitted on 23 Jun 2026
75 points (97.5% liked)

Technology

85670 readers
3575 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

Cloudflare is working with the makers of Chrome, Edge, and Firefox on a new way for websites to tell whether incoming traffic is legitimate โ€“ without resorting to the usual mix of CAPTCHAs, logins, and extra tracking.

The system is called Private Access Control Tokens, or PACT, and it arrives at a time when bots have surpassed human traffic online.

top 8 comments
sorted by: hot top controversial new old
[โ€“] Zwuzelmaus@feddit.org 0 points 3 hours ago

"DO WE LOOK LIKE BOTS?"

No, but you look like bicycles ๐Ÿ˜

[โ€“] treadful@lemmy.zip 54 points 12 hours ago (1 children)

The basic idea is that sites with strong knowledge of "personhood" can issue anonymous tokens. A user's browser can then present those tokens elsewhere as proof that a human is involved, or that an automated agent is acting on behalf of one, without revealing the person's identity or browsing history.

These issuers will 100% sell these identifiers to be matched up with other databases.

There's what companies admit to publicly, and then there's what they're working on behind closed doors.

Most EULA have vague lines like "We will use your data to improve our services" which translates to something like: Your data is used in the services we sell.

Perhaps there would be a legal argument against shit like this, but how do you prove it in court? Even if you get discovery the odds of them offering up database tables they've hidden away that key up users to the data is never gonna happen. You'd have to report it as an insider.

Maybe we should be offering up $10m+ whistleblower bounties for stuff like this, because short of giving someone a golden parachute they're sure as shit not going to lose their careers over it.

[โ€“] pHr34kY@lemmy.world 6 points 9 hours ago* (last edited 9 hours ago)

This sounds a bit like a passport-stamping scheme. But the passport doesn't have your name and photo on it. Hopefully it only stores verifiable stamps, but not who stamped it.

I hope they use this to tackle age verification. I'd like to just have a token to prove my age without handing over an actual ID to questionable companies.

[โ€“] Feyd@programming.dev 13 points 13 hours ago

I don't see any details here that make me understand how sites couldn't just save the PACT and collude to build profiles.

[โ€“] shortwavesurfer@lemmy.zip 19 points 14 hours ago* (last edited 14 hours ago)

Clearly, they haven't heard of proof of work.

Ask tor, it helps tremendously.

Hidden services went from being absolutely horribly unreliable to being very reliable.

[โ€“] gapa@feddit.nu 16 points 14 hours ago (1 children)

I had to solve two captchas last time I tried ordering groceries online.

[โ€“] Zarobi@aussie.zone 0 points 7 hours ago

I keep getting fraud alerts and having to sooth my bank account into permitting my groceries. You'd think after the 20th time on the same day with the same price they'd stop flagging my groceries.