Menu

Post image 1
Post image 2
1 / 2
0

Cloudflare Turnstile's WebGL Fingerprint Push Exposes Tensions in Bot Defense and Privacy

Reading 0:00
15s threshold

Cloudflare’s Turnstile widget promises a frictionless alternative to traditional CAPTCHAs. No puzzles. No traffic lights. Just a quick check that you are human. Yet a technical analysis published Friday reveals the system now demands something more specific from many browsers: consistent, fingerprintable data from WebGL calls. The finding comes from security researcher lanodan in a post on hacktivis.me . Users of WebKitGTK-based browsers such as Badwolf began seeing indefinite loops on sites protected by Turnstile. The error message points to spoofed graphics information. “WebGL renderer info is spoofed.” Turnstile refuses to proceed. Cloudflare’s own diagnostic page at browser-compat.turnstile.workers.dev confirms the behavior. When the renderer string or other WebGL details appear altered or blocked, the check fails. The company explains the mechanism plainly. “Turnstile uses browser fingerprinting to verify you’re human,” it states.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More