Not only was this made with an LLM, it breaks so many other things but If you use this font to protect your text from AI, it also blocks *me, a human* because I use a screen reader.
-
@WeirdWriter@caneandable.social I first saw this here and it looks neat but if its at the cost of accessbility its a major issue.
It says screenreader accessibility is a beta feature that is being worked on so hopefully that all works out soon. Would be neat to have some accessible way to mess with the AI scrapers but not humans. Not sure how well this works or if its really being used yet though.
That does really suck though...@ChaosKitsune It doesn’t even prevent scraping because the LLM would need to still scrape it in order to know that it is gibberish so ultimately I do find it very pointless and there are other solutions that do a better job at preventing LLMs from visiting your website anyhow. I, on the other hand, think you should go the opposite way like Starbreaker.org does and allow everything, no restrictions whatsoever
-
@WeirdWriter For someone this obsessed with text you'd think their actual writing would be better.
@prism Hah! You can say that again!
-
@WeirdWriter LLMs will just find a workaround anyway. They can use tesseract.
@Elizafox Bingo, and I have since learned that this was even created via LLM anyhow, so it’s the tech industry capitalizing on the hatred and it’s absolutely ridiculous. I can’t remember if it was you that shared the link or not, but someone shared a link where the tech industry is also now selling its own solution to the LLM problem they created in the first place
-
@2something @WeirdWriter I have JS turned off, so the demo on the main page was hellish.
My friend needs a custom font to help with his dyslexia. This too, fucks him over.
Another friend who checks things with a machine translator when she's uncertain, is also screwed.This declares them both inhuman. I'm fine, I'm therian, but I sure as fuck try not to be ableist, and I'm sick and fucking tired of 'humanity' being pulled away from any path not 'standard'.
@warden @2something This is ultimately why I’m honestly getting very tired of these preventative solutions that really don’t prevent any scraping or anything else of the sort. I get it, LLMs suck, but every single preventative solution except for one that I’ve seen earlier today breaks more things than it prevents AI scraping.
-
@WeirdWriter I love the idea, but it's not worth making the internet less accessible.
@alice Yup. I honestly wish everybody would just quit trying because everything anybody does that tries to prevent LLMs has made everything bloated, a far worse user experience, and will prevent LLMs from scraping will inevitably fuck up those that don’t use JavaScript, or maybe have a custom font, or anything else and besides, every single one of these preventative measures can be circumvented
-
@ChaosKitsune It doesn’t even prevent scraping because the LLM would need to still scrape it in order to know that it is gibberish so ultimately I do find it very pointless and there are other solutions that do a better job at preventing LLMs from visiting your website anyhow. I, on the other hand, think you should go the opposite way like Starbreaker.org does and allow everything, no restrictions whatsoever
@WeirdWriter@caneandable.social Yeah honestly that is fair
LLMs are a major blemish on society but I dont think this can solve it well.
Also after seeing its contributions from AI my faith and giving them the benefit of the doubt it done. -
@smolbrain The timer isn’t a solution because not every screen reader user can navigate with the ease and the speed that timer requires, but it also breaks reader mode on browsers and it breaks copying paste, and it also breaks user defaults also from what others have told me because they use magnification and otherwise on their browsers and this apparently breaks all of that
@WeirdWriter hmm interesting. Good to know. Hopefully they keep working on it and make a more accessible solution.
-
@WeirdWriter CAPTCHAs for adding comments actually work: they reduced the fake comments on my site from 100 a day to 1 per week.
But they also prevented two in three humans from commenting.
That’s why my personal website has no comments at all anymore and my roleplaying one puts every comment in moderation.
1 out of 20 comments is genuine. Without CAPTCHAs it would be 1 out of several thousands. I couldn’t moderate that.
But I see no value of CAPTCHA’s for reading.
@2something@ArneBab @2something Ah yeah good point! I went the route of scrambling my email address for machines, but it works perfectly as a Mailto link. I also pre-populated the subject line and you would not believe how many automated email things don’t remove that pre-populated text, so it makes filtering incoming emails that much easier. Https://sightlessscribbles.com/contact/
-
@WeirdWriter it plain doesn't work with uBO lmao
@hyphen This made me laugh!
-
@alice Yup. I honestly wish everybody would just quit trying because everything anybody does that tries to prevent LLMs has made everything bloated, a far worse user experience, and will prevent LLMs from scraping will inevitably fuck up those that don’t use JavaScript, or maybe have a custom font, or anything else and besides, every single one of these preventative measures can be circumvented
There's a tiiiiny little problem with "quit trying": I can't afford to. Without defenses up, a €46/month VPS (4 CPUs, 8GiB RAM) died under the crawler assault in about 2 minutes.
It's not that what I was serving was inefficient... it never got to serving! It died while trying to keep up with TLS handshakes at over 10 thousand requests / second. Yes, that was sustained over multiple days. I temporarily scaled up to 16 cores, and that still died.
For comparison, I currently pay €8/month for my VPS. There is no proof of work, no JavaScript required, no silly fonts. I've been using the same measures for about a year now, the bots have not adapted (and if they do, I have a dozen other tricks up my sleeve, none of which affects the legit visitor any more than the current measures do).
I can afford €8/month. I cannot afford €45+. They can very easily DDoS me if I let my guards down, yet, I can't scale up infinitely.
So defense it is. There are reasonable defenses that work.
-
@byteback @WeirdWriter
Screen readers (the text to speech kind) don't care about fonts. They read the raw text.This font tries to stop scrapers by turning the raw text into garbage, then using a font to make it look right. So anything that doesn't care about fonts (screen readers) see the garbage.
-
@unkx @WeirdWriter
I was told it would be ableist of me to deny the benefits of AI, SMH
Roflcry@RnDanger @unkx @WeirdWriter
I'd forgotten about that line of argument -
There's a tiiiiny little problem with "quit trying": I can't afford to. Without defenses up, a €46/month VPS (4 CPUs, 8GiB RAM) died under the crawler assault in about 2 minutes.
It's not that what I was serving was inefficient... it never got to serving! It died while trying to keep up with TLS handshakes at over 10 thousand requests / second. Yes, that was sustained over multiple days. I temporarily scaled up to 16 cores, and that still died.
For comparison, I currently pay €8/month for my VPS. There is no proof of work, no JavaScript required, no silly fonts. I've been using the same measures for about a year now, the bots have not adapted (and if they do, I have a dozen other tricks up my sleeve, none of which affects the legit visitor any more than the current measures do).
I can afford €8/month. I cannot afford €45+. They can very easily DDoS me if I let my guards down, yet, I can't scale up infinitely.
So defense it is. There are reasonable defenses that work.
@algernon @alice Yeah you have a point. I hate this timeline so much! What about https://rollenspiel.social/@ArneBab/117032564006229790
-
Not only was this made with an LLM, it breaks so many other things but If you use this font to protect your text from AI, it also blocks *me, a human* because I use a screen reader. I did try the demo. If you want me to remove your RSS feed, this is the best font to prevent blind people from reading your blog/words. That timer is an inaccessible solution. https://shieldfont.org/#hero #AI #LLM #Accessibility #A11y
@WeirdWriter
But the page says:Screen readers get the real words.
ShieldFont hides scrambled passages from accessibility tools by default with aria-hidden="true".
The real words ship sealed in the same page, and the reader’s own browser uncovers them by solving a compute-heavy puzzle — a few seconds of their CPU, and a cost a bulk scraper would rather not pay. It needs JavaScript, the reader waits while everyone else does not, and a shielded block still
-
@WeirdWriter
But the page says:Screen readers get the real words.
ShieldFont hides scrambled passages from accessibility tools by default with aria-hidden="true".
The real words ship sealed in the same page, and the reader’s own browser uncovers them by solving a compute-heavy puzzle — a few seconds of their CPU, and a cost a bulk scraper would rather not pay. It needs JavaScript, the reader waits while everyone else does not, and a shielded block still
fails WCAG 2.2 SC 1.3.1. This makes a shielded page humane. It does not make it compliant, and we will not say otherwise.
@WeirdWriter -
@ArneBab @jpaskaruk @WeirdWriter If the decoy text amounts to an unvarying word substitution cipher, any AI model seeing enough cases of it should be able to trivially solve it.
If for any reason that fails, AI owners who also own captcha farms will be able to have humans working for pennies display the text on a splitscreen, one with JS enabled and one not so as to show both texts at once. They can then list what decoy words go with what real ones and feed that back to the AI.
@ArneBab @jpaskaruk @WeirdWriter In general fixed substitution ciphers are extremely weak. If this was applied to a single word as a captcha, I doubt it could resist being solved by a cheap, bottom of the barrel Android phone CPU.
-
@alice Yup. I honestly wish everybody would just quit trying because everything anybody does that tries to prevent LLMs has made everything bloated, a far worse user experience, and will prevent LLMs from scraping will inevitably fuck up those that don’t use JavaScript, or maybe have a custom font, or anything else and besides, every single one of these preventative measures can be circumvented
@WeirdWriter @alice I think things like this are probably a "just stop trying", but, things like trying to stop scrapers is, at this point, mandatory for a lot of smaller sites/hosts, just... due to bandwidth limits and cost, I think.
The best solution would be to prevent it through social or legal changes - as in, not a technical solution to the problem at all. There is some political pressure in that direction, but, a lot of money pushing back, so, hard to tell where that lands currently. -
@WeirdWriter it plain doesn't work with uBO lmao
@WeirdWriter@caneandable.social @hyphen@duwa.ng
this concert is already copped
couldn't have said it better myself -
Not only was this made with an LLM, it breaks so many other things but If you use this font to protect your text from AI, it also blocks *me, a human* because I use a screen reader. I did try the demo. If you want me to remove your RSS feed, this is the best font to prevent blind people from reading your blog/words. That timer is an inaccessible solution. https://shieldfont.org/#hero #AI #LLM #Accessibility #A11y
@WeirdWriter@caneandable.social Even as a sighted person, I couldn't read that page without JavaScript so... cool /s.
-
@algernon @alice Yeah you have a point. I hate this timeline so much! What about https://rollenspiel.social/@ArneBab/117032564006229790
@WeirdWriter My website couldn't be simpler (it's all static, neatly fits into memory). Server dies before it even has a chance to serve it - during TLS handshake. Can't make that much more efficient.
Granted, I host a... few handful of sites on that €8 VPS. But the content isn't the problem, the crazy request rate is, and that is outside of my control.
(Hence part of my defense is firewalling crawlers off. Can't TLS handshake if packets are dropped! Problem solved.)