Most mass scrapers, on the other hand, simply grab the raw HTML underneath. ShieldFont exploits this difference through an automated process called OpenType glyph substitution.
That said, because the whole defense rests on scrapers reading code rather than screens, taking a screenshot of a shielded page and running OCR on the image can still recover the real words.
Screen readers used by blind readers also work from the code, so they read the decoys aloud. ShieldFont ships with a beta feature that provides those readers with the real text instead.
51 Comments
sun_is_ra@sh.itjust.works · 119 pts · 22d
does this also block blind people who depend on an e-reader?
FTonsilStones@lemmy.ca · 77 pts · 22d
Per the article, yes:
But:
ViatorOmnium@piefed.social · 81 pts · 22d
AI scrappers will just pretend to be screen readers then.
And if the approach becomes popular they will just OCR the text instead.
Zarobi@aussie.zone · 24 pts · 22d
Per the GitHub:
In summary, they have two ways to get around this.
RobotToaster@mander.xyz · 22 pts · 22d
Sounds like an overly convoluted way to do exactly what Anubis does...
Zarobi@aussie.zone · 3 pts · 22d
Yeah, if you care about screen reader users, functionally it's just "Anubis but worse". Unfortunately, most people don't care, so for them and all visual users, it has the benefit of no additional "load time" computational check — the page appears instantly without the Anubis step. Though I'm not sure how long it takes the page to do the de-scrambling.
The primary purpose of this project is to mutilate your HTML so bots can't scrape it, rather than preventing bot traffic in the first place. The screen reader stuff is a bolt-on.
cley_faye@lemmy.world · 9 pts · 22d
There are laws about accessibility, at least for public websites, and probably for larger websites as they have such a large audience that disability can't be ignored (as much).
Zarobi@aussie.zone · 5 pts · 22d
In my experience, those laws aren't followed much in reality. The biggest sites, sure, but most smaller sites are a mess under the hood. As long as something is "technically usable", even if very awkward and annoying, it's often hard to sue or anything like that. Maybe it's different in other countries though, I live in Australia.
Next time you use a website, try only using your keyboard to navigate it and accomplish your task, and you'll see what I mean. It's a rough test of how much they value accessibility. For example, many websites disable the border around what you're highlighting, so you have no idea what the tab button is about to click. Or popup windows don't actually change your tab selection, so you have to tab through literally the entire page in the background to get to the popup window. Stuff like that; technically usable but annoying as hell.
cley_faye@lemmy.world · 10 pts · 22d
There's a fair chance they're already doing that. It provides better insight on the content, less formatting to handle, and even visual stuff gets text alternatives.
Sims@lemmy.ml · 5 pts · 22d
It is also very easy to detect surprising text by looking at the perplexity levels by feeding it to a very small model. If there's a problem, OCR/'screen read' it instead..
cley_faye@lemmy.world · 18 pts · 22d
screen reader, SEO, indexation, in page search, etc.
Basically, it breaks everything except people… unless they block/substitute fonts for accessibility reasons, in which case fuck people too.
This is a terrible idea, and it won't even achieve it's original "purpose" as it is trivially detectable. Only negatives in this.
eager_eagle@lemmy.world · 15 pts · 22d
it does, unless the reader has an OCR mode of sorts
T156@lemmy.world · 9 pts · 22d
Presumably the AI scraper would also have OCR, and would sidestep things like this?
sudo@programming.dev · 12 pts · 22d
A scraper has many more ways around something like sheildfont than just OCR. The question will be if it was actually programmed to check for such measures.
gex@lemmy.world · 11 pts · 22d
Yes, the decoy text is marked aria-hidden, so it won't be read out loud. The real text is sent to the browser encrypted, and the decryption process takes ~20 seconds, roughly the same as running ocr.
FaceDeer@fedia.io · 78 pts · 22d
DRM is suddenly popular and people think it will work this time.
ren@reddthat.com · -38 pts · 22d
I bet you could even get some foaming-at-the-mouth anti-AI activists to endorse Israel's right to resist if Israel decides to ban all AI. Worth a thought, Bibi.
Rothe@piefed.social · 27 pts · 22d
What a laughable strawman from a coglover. On the contrary LLM lovers will happily give money to techbro oligarchs who directly supports Trump and Israel. They will also eagerly burn down the planet just for the sake of some sloppy code.
Anarki_@lemmy.blahaj.zone · 15 pts · 22d
Clanker wankers will invent just about anything to convince others they are correct. Just like their sloppy overlords.
merdaverse@lemmy.zip · 65 pts · 22d
If this gets any adoption, it will work for about a week, after which scrapers will just detect the font, and do a reverse lookup of its mapping table.
Ironic that the repo of the font is also AI slop. If the author had asked any competent person how viable the solution is, instead of a sycophantic AI, they would have just gotten a laugh instead.
merdaverse@lemmy.zip · 11 pts · 22d
Thinking more about it, even if the mapping would be generated dynamically (let's say you could generate them secretly on your server), the scraper could just parse the font file and reverse lookup the words.
boonhet@sopuli.xyz · 7 pts · 22d
And if you ask an AI to be critical, it'll also tell you why this is useless lol.
vext01@feddit.uk · 1 pts · 22d
My thoughts exactly. And so the arms race continues.
ki4jgt@feddit.org · 1 pts · 22d
Nah. Gregg Shorthand Anniversary Edition is practically indecipherable to AI.
It uses human intuition heavily.
cley_faye@lemmy.world · 64 pts · 22d
A terrible idea that will hinder everyone and not serve it's original purpose in a flash.
It's basically a kid playing with "encrypshun" client-side, giving both the cipher and the key to the client and hoping it'll work. Or, as other put it, DRM that don't work for any of its original purpose, but create an additional layer of complexity and missing features, a common trend in modern projects.
isVeryLoud@lemmy.ca · 5 pts · 21d
Speaking of flash, serving your content in Flash keeps scrapers at bay
/hj don't do that, it does work though!
Pika@sh.itjust.works · 28 pts · 22d
I want to follow that project. The only thing that I don't like is how heavily reliant the person who runs the github is on AI-gen
Normally, I don't really care about it because I know that it's something that is just a part of the industry now, but they're using it even on their responses to people on the issue requests, and it's to the point where it's hurting my head trying to read it due to how drawn out and detailed it ends up being.
It's really hard to follow along a project where something as simple as someone opening an issue about how it doesn't work with screen readers turns into a multi paragraph essay about the project and possibilities on how it works.
khanh@lemmy.zip · 25 pts · 22d
JUST USE ANUBIS
isVeryLoud@lemmy.ca · 1 pts · 21d
lol anus bi
(love Anubis, have it fronting my client's websites)
eyesaremosaics@lemmy.zip · 1 pts · 19d
When is Anubis useful (eg vs CloudFlare)? The GitHub page doesn't say much-
shirasho@feddit.online · 23 pts · 22d
Protection through obfuscation is not real protection. This has been an ongoing thing in the security world and is especially relevant for software. All obfuscation does is protect you from script kiddies (which AI isnt) and make the actual process slower for legitimate users. Like all DRM it only really hurts the people legitimately using your software.
jsnfwlr@lemmy.ml · 1 pts · 20d
This isn't about securing sites or content. It is just for poisoning the data AI scrapers steal by obfuscating the readily accessible information.
If you read the article or the ShieldFont website, it works pretty well when you use their React widget, even from an accessibility stand point.
eager_eagle@lemmy.world · 1 pts · 22d
they really cooked with that video, got me more excited than with most trailers
DanceMomsSavedMe@lemmy.zip · 1 pts · 22d
Someone needs to tell Sxan about this
Sxan@piefed.zip · 0 pts · 22d
White knights already complain about screen readers being too stupid to interpret Thorns, while simultaneously claiming Thorns don't fool AI because it's trivial for software to replace it. ¯\(ツ)/¯
I can't imagine þe sort of hate I'd get from using homography.
ayyy@sh.itjust.works · 2 pts · 22d
Both things are true. I don’t understand why you think thats a gotcha of some kind.
AbouBenAdhem@lemmy.world · 1 pts · 22d
If the underlying text says one thing but the font makes it appear to say something else, which version does the author own the copyright to?
Catoblepas@lemmy.blahaj.zone · 6 pts · 22d
Who cares if gibberish text is copyrighted? Putting your work in a funky text doesn’t make what you wrote no longer copyrighted.
AbouBenAdhem@lemmy.world · 0 pts · 22d
Say someone else takes the visual result of the font’s output and re-posts it as plain text.
If anyone searches for that text, their version will come up as the first (and only) published version. Anyone who tries to reference it will cite their version instead of yours. You’d have to convince the court that a clearly different text you published earlier is really the same thing, as long as you view it with a special font that magically transforms it into the text you’re trying to claim—the judge would just as likely think you’re a copyright troll.
Catoblepas@lemmy.blahaj.zone · 3 pts · 22d
I’m not sure who told you posting things online is how you prove copyright, but it’s not.
Aqivex@fedinsfw.app · 1 pts · 22d
You entirely sidestepped the scenario and issue. In the example given, the copyrighted work is being produced directly onto a medium that obfuscates its provenance, literally. Yet, gives an opening for another to publish it in such a way, that they could claim it's their copyrighted work. They would be lying, and they would be wrong, but then you would have to prove to a body composed of ancient mummies who uphold an ancient code, why one of the few ways they thought they understood technology and codified into their verification process, isn't actually showing them the truth this time. Do you know how to defend a copyright claim?
ViatorOmnium@piefed.social · 5 pts · 22d
The human readable text. Copyright applies to the actual content not to how it's stored or encoded.
Zier@fedia.io · 0 pts · 22d
Download from where?
REDACTED@infosec.pub · 3 pts · 22d
Probably starts with https://
CubitOom@infosec.pub · 0 pts · 22d
ki4jgt@feddit.org · -4 pts · 22d
Learn shorthand. AI can't read it. Gregg Shorthand Anniversary Edition is practically indecipherable to AI. And it allows you to write at up to 300 wpm.
nyan@lemmy.cafe · 5 pts · 22d
If it were to become popular enough, AI would learn.
ki4jgt@feddit.org · 2 pts · 22d
The problem with that is that shorthand relies a lot on abbreviations: B = Be or By. But, at the end of a word, it can be ble, like tab. J can be J, or -age. A uses a single dot. So does -ing.
Because of that, I'm curious whether it would catch on or not.