home.social

#botdetection — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #botdetection, aggregated by home.social.

fetched live
  1. Weekend project will be setting up a Fedi instance with Stylo.Bot in front of it.
    I want to start offering 'packs' so a Fedi (Mastodon / pixelfed whatver) pack would be interesting. Allowing federation while blocking all / any other automation by type could be handy!

    #fediverse #botdetection #automation

  2. Weekend project will be setting up a Fedi instance with Stylo.Bot in front of it.
    I want to start offering 'packs' so a Fedi (Mastodon / pixelfed whatver) pack would be interesting. Allowing federation while blocking all / any other automation by type could be handy!

    #fediverse #botdetection #automation

  3. Well Stylo.Bot gets it's 8.7 release tomorrow and with it *the launch of more advanced, paid options*.

    Early days but it gets a full live management and analytics dashboard with Postgres support, multi-node hosting support, domain specific management and reporting and DOZENS more features (I suck at marketing I rock at building stuff so...it has stuff!).

    Competition all starts at £100/mo + usage charges and per seat etc...

    Stylo.Bot is £25 / £50 / month depending if you need the scalability, FREE if you're single site.
    30 Day Free Trials too..

    All self-hosted, ZERO PII is collected, no data leaves your system, adds almost no latency to requests and it runs for EVERY request (sub-millisecond for most requests).

    Website is ZERO cookie for non-signed in users, zero tracking beyond the Stylo.Bot fingerprints (which again are zero PII). I take privacy *seriously*.

    Lets you eliminate. malicious bots attacking your site, control AI bots by slowing them down (or block or ignore etc)...

    Honestly now *for me* the hard bit starts. Not getting too excited when I talk about it!

    FOR SALE TOMORROW - FREE TRIALS TOO!

    Stylo.Bot

    #stylobot #botdetection #self-hosted

  4. Well Stylo.Bot gets it's 8.7 release tomorrow and with it *the launch of more advanced, paid options*.

    Early days but it gets a full live management and analytics dashboard with Postgres support, multi-node hosting support, domain specific management and reporting and DOZENS more features (I suck at marketing I rock at building stuff so...it has stuff!).

    Competition all starts at £100/mo + usage charges and per seat etc...

    Stylo.Bot is £25 / £50 / month depending if you need the scalability, FREE if you're single site.
    30 Day Free Trials too..

    All self-hosted, ZERO PII is collected, no data leaves your system, adds almost no latency to requests and it runs for EVERY request (sub-millisecond for most requests).

    Website is ZERO cookie for non-signed in users, zero tracking beyond the Stylo.Bot fingerprints (which again are zero PII). I take privacy *seriously*.

    Lets you eliminate. malicious bots attacking your site, control AI bots by slowing them down (or block or ignore etc)...

    Honestly now *for me* the hard bit starts. Not getting too excited when I talk about it!

    FOR SALE TOMORROW - FREE TRIALS TOO!

    Stylo.Bot

    #stylobot #botdetection #self-hosted

  5. FYI: Only 5.3% of marketers use IVT tools as 75.6% lose ad budget to bots, Lunio: Just 5.3% of the 131 marketers surveyed run a dedicated IVT platform, and 53.5% know little about them. Half say bidding now optimizes toward bots, not buyers. ppc.land/only-5-3-of-marketers #DigitalMarketing #IVTTools #AdBudget #MarketingTrends #BotDetection

  6. FYI: Only 5.3% of marketers use IVT tools as 75.6% lose ad budget to bots, Lunio: Just 5.3% of the 131 marketers surveyed run a dedicated IVT platform, and 53.5% know little about them. Half say bidding now optimizes toward bots, not buyers. ppc.land/only-5-3-of-marketers #DigitalMarketing #IVTTools #AdBudget #MarketingTrends #BotDetection

  7. Cybersecurity Startup Spur Raises $200M for Bot Detection Technology

    📰 Original title: Bot-detection startup Spur nabs $200M from Insight

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cybersecurity-

    #technology #botdetection #cybersecuritystartup #funding

  8. Cybersecurity Startup Spur Raises $200M for Bot Detection Technology

    📰 Original title: Bot-detection startup Spur nabs $200M from Insight

    🤖 IA: It's clickbait ⚠️
    👥 Users: It's clickbait ⚠️

    View full AI summary en.killbait.com/cybersecurity-

    #technology #botdetection #cybersecuritystartup #funding

  9. Just the slow slog of final tasks to get Stylo.Bot *FOR SALE*...Stylo.Bot 8.5 is out now

    github.com/scottgal/stylobot/r

    Too many changes to mention (github.com/scottgal/stylobot/b)

    This is the Free-Open-Shared-Source release (FOSS) it's the FULL Stylo.Bot detection engine. Based on mostlylucid.botdetection, 40k downloads and has Docker Images (15k downloads) etc...

    Realtime, Adpative, Behavioural Bot Detection which runs on your hardware.

    #stylobot #botdetection

  10. Just the slow slog of final tasks to get Stylo.Bot *FOR SALE*...Stylo.Bot 8.5 is out now

    github.com/scottgal/stylobot/r

    Too many changes to mention (github.com/scottgal/stylobot/b)

    This is the Free-Open-Shared-Source release (FOSS) it's the FULL Stylo.Bot detection engine. Based on mostlylucid.botdetection, 40k downloads and has Docker Images (15k downloads) etc...

    Realtime, Adpative, Behavioural Bot Detection which runs on your hardware.

    #stylobot #botdetection

  11. Cloudflare launched Precursor, replacing many CAPTCHA checks with continuous behavioral analysis of mouse, typing, scrolling, and browser activity. 🖱️
    The system aims to detect advanced bots while raising fresh privacy concerns over persistent session monitoring despite limited data collection. 🔒

    🔗 nerds.xyz/2026/07/cloudflare-p

    #TechNews #Cloudflare #Privacy #CAPTCHA #BotDetection #WebSecurity #OpenSource #Cybersecurity #DigitalRights #Technology #Browser #AI #Internet #Security

  12. Cloudflare launched Precursor, replacing many CAPTCHA checks with continuous behavioral analysis of mouse, typing, scrolling, and browser activity. 🖱️
    The system aims to detect advanced bots while raising fresh privacy concerns over persistent session monitoring despite limited data collection. 🔒

    🔗 nerds.xyz/2026/07/cloudflare-p

    #TechNews #Cloudflare #Privacy #CAPTCHA #BotDetection #WebSecurity #OpenSource #Cybersecurity #DigitalRights #Technology #Browser #AI #Internet #Security

  13. In a groundbreaking achievement, some tech wizardry managed to slip past Cloudflare's bot detection by... *drumroll*... reading error messages and declaring victory! 🏆🤖 Getting a 403 error never felt so good, proving once again that if at first you don't succeed, redefine success. 🙃🎉
    tilion.dev/blog/cloudflare-blo #techwizardry #Cloudflare #successstory #errorhandling #botdetection #innovation #HackerNews #ngated

  14. In a groundbreaking achievement, some tech wizardry managed to slip past Cloudflare's bot detection by... *drumroll*... reading error messages and declaring victory! 🏆🤖 Getting a 403 error never felt so good, proving once again that if at first you don't succeed, redefine success. 🙃🎉
    tilion.dev/blog/cloudflare-blo #techwizardry #Cloudflare #successstory #errorhandling #botdetection #innovation #HackerNews #ngated

  15. Microsoft has built a bouncer for Teams meetings. There is now a literal velvet rope for bots. 'Suspected threats' is an actual lobby category. We are so back to nightclub access control as enterprise IT policy

    #MicrosoftTeams #AIBots #EnterpriseIT #DigitalSovereignty #InfoSec #DataPrivacy #M365 #BotDetection #TechHumour #SovereignAuditor

  16. Continuing on StyloBot this weekend, staging site showed a regression after my new work on Browser Modes so working through that - code llm drifted away from a core pattern in a big refactor...as it always does.

    Core lesson: make your test apps *fail loudly* LLMs are great at papering over spreading, structural cracks in your system.

    Distillation phase; not planned work as it's responding to live detection issues. Where a single homan controlled browser sends different headers, request 'shape' for stuff like data / resources / api calls / content.
    Each of those is a different 'mode' which NORMALLY bot detectors will just toss the strange differences and merge into a single 'identity based' fingerprint.

    *However* in StyloBot it can tell them apart because it doesn't throw away these extra discriminators. The bug appeared like multiple clients requesting from the same IP but different 'deceptive' browsers (as I expected all the headers etc). Same goes for AdBlock on/off...it changes what your browser *looks like* by stripping headers etc...
    So instead I actually detect these 'modes' and use them to add to discriminaton signal; the proportion and timing cadence is SUPER hard to fake for automation; humans run browsers in 'noisy' computational environments, bots tend to be synthetically 'cleaner'.

    Anyway that's my weekend, the code llm decided (as it tends to) to layer another parallel system on top of the existing one and it SUCKS - 2s a response as it does a full *db* match against ALL our 'prototyes' each request.
    It got the idea but forgot the pattern; I use a single consolidated behaviourally shaped LFU 'transparent' - you don't worry about DB just read and wwrite through the cache and it handles updates etc - LAZY CQRS with none of the guarantees for *super* high speed & in memory.
    As usual this is an *odd* archutecture of this sub-feature so the Code LLM (Calude) SMEARS it towards the normative for this.
    I told it new in memory stores are not allowed; as it will ALWAYS add these (IMemoryCache) in ASP.NET apps...try and stop it!
    So it decided this was a direct to DB operation; it followed one constraint then SKIPPED all the others.
    #stylobot #botdetection #botprotection

  17. Continuing on StyloBot this weekend, staging site showed a regression after my new work on Browser Modes so working through that - code llm drifted away from a core pattern in a big refactor...as it always does.

    Core lesson: make your test apps *fail loudly* LLMs are great at papering over spreading, structural cracks in your system.

    Distillation phase; not planned work as it's responding to live detection issues. Where a single homan controlled browser sends different headers, request 'shape' for stuff like data / resources / api calls / content.
    Each of those is a different 'mode' which NORMALLY bot detectors will just toss the strange differences and merge into a single 'identity based' fingerprint.

    *However* in StyloBot it can tell them apart because it doesn't throw away these extra discriminators. The bug appeared like multiple clients requesting from the same IP but different 'deceptive' browsers (as I expected all the headers etc). Same goes for AdBlock on/off...it changes what your browser *looks like* by stripping headers etc...
    So instead I actually detect these 'modes' and use them to add to discriminaton signal; the proportion and timing cadence is SUPER hard to fake for automation; humans run browsers in 'noisy' computational environments, bots tend to be synthetically 'cleaner'.

    Anyway that's my weekend, the code llm decided (as it tends to) to layer another parallel system on top of the existing one and it SUCKS - 2s a response as it does a full *db* match against ALL our 'prototyes' each request.
    It got the idea but forgot the pattern; I use a single consolidated behaviourally shaped LFU 'transparent' - you don't worry about DB just read and wwrite through the cache and it handles updates etc - LAZY CQRS with none of the guarantees for *super* high speed & in memory.
    As usual this is an *odd* archutecture of this sub-feature so the Code LLM (Calude) SMEARS it towards the normative for this.
    I told it new in memory stores are not allowed; as it will ALWAYS add these (IMemoryCache) in ASP.NET apps...try and stop it!
    So it decided this was a direct to DB operation; it followed one constraint then SKIPPED all the others.
    #stylobot #botdetection #botprotection

  18. 👀 What's being cooked at CrowdSec?

    Your WAF already knows *what* requests are doing.

    What if it could also help answer *who* is behind them?

    More soon!

    #CyberSecurity #WAF #BotDetection #ThreatIntelligence

  19. 👀 What's being cooked at CrowdSec?

    Your WAF already knows *what* requests are doing.

    What if it could also help answer *who* is behind them?

    More soon!

    #CyberSecurity #WAF #BotDetection #ThreatIntelligence

  20. StyloBot today; more work on Endpoint UX - for ASP.NET core pack you get the ability to live update endpoint policies. So working out the best UX.
    Almso more on the new 'browser mode' work; need to write a blog post on that SEEMS to be anew technique, using the proportion of browser mode changes combined with markov paths to detect subtle timing errors automation lacks.
    Even stuff like how a users' browser runs on a desktop OS in terms of xhr, resource requests etc is influenced by other applications loaded, gpu presence etc.
    NOT a 'fingerprint' per-se (though it could maliciously be used that way) but a parretn StyloBot can connect to human and bot signatures to find the divergence between the two.
    Useful as it's also per-site and likely load dependent so it's a nicely patternable signature - NOT repeatable so not 'this is definietely Scott on his Chrome Mac', that's *identity* no, behaviour; so it *varies* in a human way.
    And because StyloBot already watches centroid drift generally, browser modes become another way to detect subtle mismatches: not "is this request bad?" but "does this client’s behavioural movement make sense for the browser it claims to be?"

    #stylobot #botdetection #zeropii

  21. StyloBot today; more work on Endpoint UX - for ASP.NET core pack you get the ability to live update endpoint policies. So working out the best UX.
    Almso more on the new 'browser mode' work; need to write a blog post on that SEEMS to be anew technique, using the proportion of browser mode changes combined with markov paths to detect subtle timing errors automation lacks.
    Even stuff like how a users' browser runs on a desktop OS in terms of xhr, resource requests etc is influenced by other applications loaded, gpu presence etc.
    NOT a 'fingerprint' per-se (though it could maliciously be used that way) but a parretn StyloBot can connect to human and bot signatures to find the divergence between the two.
    Useful as it's also per-site and likely load dependent so it's a nicely patternable signature - NOT repeatable so not 'this is definietely Scott on his Chrome Mac', that's *identity* no, behaviour; so it *varies* in a human way.
    And because StyloBot already watches centroid drift generally, browser modes become another way to detect subtle mismatches: not "is this request bad?" but "does this client’s behavioural movement make sense for the browser it claims to be?"

    #stylobot #botdetection #zeropii

  22. University of Missouri: User-friendly bot detection. “Traditional bot detection methods like CAPTCHA are effective, but they come at the cost of user experience. Our team wanted to explore whether machine learning could handle the same job entirely in the background — no interruptions, no puzzles, just seamless verification. Beyond bot detection, we saw potential for this approach to extend […]

    https://rbfirehose.com/2026/05/22/university-of-missouri-user-friendly-bot-detection/
  23. University of Missouri: User-friendly bot detection. “Traditional bot detection methods like CAPTCHA are effective, but they come at the cost of user experience. Our team wanted to explore whether machine learning could handle the same job entirely in the background — no interruptions, no puzzles, just seamless verification. Beyond bot detection, we saw potential for this approach to extend […]

    https://rbfirehose.com/2026/05/22/university-of-missouri-user-friendly-bot-detection/
  24. StyloBot free day as I ran myself ragged trying to get it going in my free time (very little of which I HAD finishing up 2x contracts!).

    Biggest win is dropping the ONNX dependency.

    Earlier versions used ONNX embeddings as a shortcut: turn a client signature into a vector and compare it.

    It worked, but it was never quite the right abstraction. Embeddings are built for language. StyloBot’s inputs are behavioural structures.

    The new version defines that behavioural vector space directly. Requests, sessions, browsers, bots, scrapers, and odd clients are placed into a real StyloBot-native space. The system ships with archetype centroids, then adapts those centroids to the actual traffic it sees.

    So instead of asking a model what a client 'means', StyloBot learns what your traffic looks like.

    StyloBot is REALLY a conceptually unfolded ML model so it sort of trains itself on real traffic around centroids and updates as it goes. It's ODD.

    Now out in Release Candidate github.com/scottgal/stylobot/r

    Plan is still for full release June 1st but the FOSS client MAY reach RTM quality before that (lots of manual testing!)

    #BotDetection #CyberSecurity #DotNet #SQLiteVec #VectorSearch #BehaviouralInference #AIInfrastructure #OpenSource

  25. StyloBot free day as I ran myself ragged trying to get it going in my free time (very little of which I HAD finishing up 2x contracts!).

    Biggest win is dropping the ONNX dependency.

    Earlier versions used ONNX embeddings as a shortcut: turn a client signature into a vector and compare it.

    It worked, but it was never quite the right abstraction. Embeddings are built for language. StyloBot’s inputs are behavioural structures.

    The new version defines that behavioural vector space directly. Requests, sessions, browsers, bots, scrapers, and odd clients are placed into a real StyloBot-native space. The system ships with archetype centroids, then adapts those centroids to the actual traffic it sees.

    So instead of asking a model what a client 'means', StyloBot learns what your traffic looks like.

    StyloBot is REALLY a conceptually unfolded ML model so it sort of trains itself on real traffic around centroids and updates as it goes. It's ODD.

    Now out in Release Candidate github.com/scottgal/stylobot/r

    Plan is still for full release June 1st but the FOSS client MAY reach RTM quality before that (lots of manual testing!)

    #BotDetection #CyberSecurity #DotNet #SQLiteVec #VectorSearch #BehaviouralInference #AIInfrastructure #OpenSource

  26. New article about StyloBot - my FREE realtime adaptive automation blocker and detector.

    mostlylucid.net/blog/stylobot-

    Trying to put together a *human* level descriptor as I prepare to make it my full time gig (amongst other self-released projects).

    #botdetection #fraud #stylobot

  27. New article about StyloBot - my FREE realtime adaptive automation blocker and detector.

    mostlylucid.net/blog/stylobot-

    Trying to put together a *human* level descriptor as I prepare to make it my full time gig (amongst other self-released projects).

    #botdetection #fraud #stylobot

  28. Getting stuck in an infinite “please try again” loop while creating a Microsoft account.
    It surely does a decent job blocking batch registrations too, right?

    #Microsoft #AccountSecurity #SpamPrevention #BotDetection #Tech

  29. AI-Driven Ad Fraud Detection | From Bot Identification to Real-Time Protection

    tuvoc.com/blog/ai-driven-ad-fr

    Learn how AI-powered ad fraud detection identifies bots and suspicious traffic in real time. Discover how it helps prevent fraud and safeguard ad revenue effectively.

    #AdFraud
    #AIinAdvertising
    #FraudDetection
    #AdTech
    #ProgrammaticAdvertising
    #BotDetection
    #AdSecurity
    #MachineLearning
    #DigitalAdvertising

  30. AI-Driven Ad Fraud Detection | From Bot Identification to Real-Time Protection

    tuvoc.com/blog/ai-driven-ad-fr

    Learn how AI-powered ad fraud detection identifies bots and suspicious traffic in real time. Discover how it helps prevent fraud and safeguard ad revenue effectively.

    #AdFraud
    #AIinAdvertising
    #FraudDetection
    #AdTech
    #ProgrammaticAdvertising
    #BotDetection
    #AdSecurity
    #MachineLearning
    #DigitalAdvertising

  31. ICYMI: Reddit bots threaten ad quality - here's how the platform fights back: Reddit removes 100,000 bot accounts daily, threatening its $726M ad platform's authenticity. A new [App] label system aims to restore advertiser trust. ppc.land/reddit-bots-threaten- #Reddit #Advertising #SocialMedia #Marketing #BotDetection

  32. Holiday-season scams now hit businesses as hard as consumers, with bots, spoofed sites, and AI-driven phishing targeting employees across SSO, VPN, and admin portals.

    This checklist highlights practical steps security teams can take now — from enforcing strong MFA to tuning bot-detection rules and running focused awareness pushes before Black Friday and Christmas. Download it here: lmgsecurity.com/resources/holi

    #Cybersecurity #FraudPrevention #MFA #DNSFiltering #BotDetection #SecurityAwareness #BYOD #Phishing

  33. ⚠️ Researchers showed ChatGPT-4o can solve CAPTCHAs if convinced they’re “fake.”

    ✔️ Worked on one-click + text CAPTCHAs
    ✔️ Partial success on image puzzles
    ❓ Raises the question: Is CAPTCHA still a viable human test?
    💬 Should we retire CAPTCHAs — or fight harder to keep them relevant?

    👉 Follow @technadu for cyber + AI security coverage.

    #CAPTCHA #ChatGPT #AIsecurity #Infosec #PromptInjection #DataPrivacy #BotDetection

  34. 😆 Ah, The Register, where cutting-edge #journalism meets the 403 Forbidden error. 🇺🇸💼 Apparently, the US is threatening extra tariffs on countries that dare to regulate their tech overlords, but good luck reading about it while battling bot detection! 📴🔒
    theregister.com/2025/08/26/tru #TheRegister #TechTariffs #BotDetection #403Forbidden #HackerNews #ngated

  35. 😆 Ah, The Register, where cutting-edge #journalism meets the 403 Forbidden error. 🇺🇸💼 Apparently, the US is threatening extra tariffs on countries that dare to regulate their tech overlords, but good luck reading about it while battling bot detection! 📴🔒
    theregister.com/2025/08/26/tru #TheRegister #TechTariffs #BotDetection #403Forbidden #HackerNews #ngated

  36. 🕵️‍♂️🔍 A noble quest to decode the mysteries of a bot detection script, because, you know, #privacy matters, or something. The author's Herculean effort to untangle #JavaScript spaghetti would be impressive if it weren't so pointlessly convoluted. 🧩🤦‍♂️ Just remember, kids: everything's a string until you need it to be an integer!
    nullpt.rs/reversing-botid #botDetection #codingMysteries #programmingHumor #developerLife #HackerNews #ngated

  37. 🕵️‍♂️🔍 A noble quest to decode the mysteries of a bot detection script, because, you know, #privacy matters, or something. The author's Herculean effort to untangle #JavaScript spaghetti would be impressive if it weren't so pointlessly convoluted. 🧩🤦‍♂️ Just remember, kids: everything's a string until you need it to be an integer!
    nullpt.rs/reversing-botid #botDetection #codingMysteries #programmingHumor #developerLife #HackerNews #ngated

  38. Think your parcel is popular? Think again. Discover how we built a smarter algorithm that filters fake traffic and reveals true virtual land popularity in a virtual world. 📊✨ #virtualworlds #metaverse #secondlife #parcelpopularity #botdetection #realtraffic

    jackiewallacesl.substack.com/p

  39. 🤖 So, apparently, we're creating an "invisible" Turing Test now—because regular visibility is just too mainstream 🤦‍♂️. 🤔 Google's reCAPTCHA v3 is basically the Sherlock Holmes of bot detection... except when it's not. But hey, if you want to play detective, check out sections 2 and 3 for some thrilling mouse movement drama! 🎭
    research.roundtable.ai/proof-o #invisibleTuringTest #GoogleReCAPTCHA #botDetection #mouseMovementDrama #techHumor #HackerNews #ngated

  40. 🤖 So, apparently, we're creating an "invisible" Turing Test now—because regular visibility is just too mainstream 🤦‍♂️. 🤔 Google's reCAPTCHA v3 is basically the Sherlock Holmes of bot detection... except when it's not. But hey, if you want to play detective, check out sections 2 and 3 for some thrilling mouse movement drama! 🎭
    research.roundtable.ai/proof-o #invisibleTuringTest #GoogleReCAPTCHA #botDetection #mouseMovementDrama #techHumor #HackerNews #ngated

  41. Today, I visited #Twitter for the first time in a month or two. As per usual, I had a few new followers. I went to look at their likes but couldn't; I only now consciously realize likes were my reliable bot test. A normal person will have like clusters — 3 or more in a row with commonalities: topic, tone, media, same user, language, etc. The bot likes were random and often included garbage posts.

    Is that why they removed likes? Prob not, but...

    #BotDetection

  42. Well, I didn't buy this band shirt because I just liked the logo. 😆

    Go ahead system, test me... Bring it on. 🤘

    #BotDetection #website #eCommerce