Hacker News new | past | comments | ask | show | jobs | submit login

If you can identify bots more accurately, you get less "GPT SEO trash".



There is approximately a 0% chance that people won’t figure out how to make their bots “verified” if this goes through.


That's not how it works, because the GPT SEO trash is being generated by the people on the server.


Well there is that and there are users that post GPT SEO trash to Reddit et al, which is what the attestation API could help with.


the spammers are quite capable of buying several hundred old phones with valid attestation certificates to pump out crap


Which is orders of magnitude more expensive than deploying the bot to a cloud or botnet.

I don't know how much bot spam pays these days. Maybe it's still worth it.


the attestation requirement increases the cost but also increases the value of the spam as the spammers competitors are put out of business


This proposal does not affect bots producing web content, only (potentially) bots browsing web content.


It does affect bots creating social media content.


Not necessarily. Even with WEI, spammers could farm legit tokens and then set up their own api that hands one out to their bot when one is necessary.


My understanding is that you can't reuse tokens, because the system uses challenge response.


But can you get a token and then not send it and save it for later? That's more what I was thinking. Not replay attacks but gathering a bunch of tokens thst are valid but never submitted to the origin, and then provide them via api requests to those that need one to use unauthorized devices with that origin.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: