logoalt Hacker News

Dylan16807yesterday at 7:02 PM1 replyview on HN

I thought that cloudflare system worked on any hardware and the tokens are anonymous. Did that change at some point? If it didn't change, then yeah it should get a very different reaction!

(Edit: it looks like the new system is still private and still interlinked with the old system that lets you use any hardware? I think?)

Also I don't know how you could have missed the widespread criticism of apple and especially cloudflare on this site.


Replies

doctorpanglossyesterday at 9:02 PM

apple has blessed cloudflare WAF with backend access to the apple ID service tokens that they manage for things like iMessage authenticity

I think it has also blessed Amazon's WAF

Cloudflare has a turnstile product that i'm sure uses this apple IDS token

Mobile Safari generally is not shown Cloudflare captchas or similar because of Apple-Cloudflare cooperation. it's not complicated.

Apple calls it a "Personal Access Token" but that makes it sound more like a DRM scheme - which it sort of is, it is managing your right to a free-as-in-beer access scheme - than a broad web integrity environment solution