Skip to content

Comment on I fear for the unauthenticated webparent

Comments

For targeted scrapes, isn't proof of work trivial to bypass?

1. headless browser 2. get cookie 3. use cookie on subsequent plain requests

It doesn't sound like the scrapers are that smart yet, but when they get there, presumably you'd just lower the cookie lifetime until the requests are down to an acceptable level. It takes a split-second in my browser so it shouldn't interfere much for human visitors.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.