CF
ClearFeed
Trust Analysis
72Trust
Likely Accurate
πŸ” Web Verified
Christine Lemmer-WebberonMastodon15h ago
ChatGPT Won't Let You Type Until Cloudflare Reads Your React State. I Decrypted the Program That Does It https://www.buchodi.com/chatgpt-wont-let-you-type-until-cloudflare-reads-your-react-state-i-decrypted-the-program-that-does-it/ There's a comment by one of OpenAI's employees over on Hacker News https://news.ycombinator.com/item?id=47567575 Of course, the irony of "this is being done to be able to keep our endpoints from being abused" isn't being lost over there either https://news.ycombinator.com/item?id=47568172 I continue to say: I am not against AI, but I *am* against the AI industry (and deeply critical of the effectiveness of current tech and its risks vs how it is sold), and a large portion of it is the intentional power grab dynamics and hypocrisy. Hard to think of a better example of hypocrisy that apparently one of the mitigations is that they require clients to execute proof of work! Anubis, anyone?
Trust Metrics
78
Accuracy
82
Sources
65
Framing
55
Context
Claim Accuracy78%
Source Quality82%
Framing & Tone65%
Context55%
Analysis Summary
A security researcher decrypted Cloudflare Turnstile's bot-detection program used by ChatGPT and found it collects 55 browser, network, and React properties to verify you're running the actual applicationβ€”not just a headless bot. The technical analysis is detailed and appears rigorous (50/50 successful decryptions claimed), but the specifics can't be independently verified without live access. The post frames this as a 'power grab' and hypocrisy by OpenAI, which is commentary on OpenAI's public stance versus actual practicesβ€”a fair rhetorical point but separate from the technical findings.
Claims Analysis (5)
β€œChatGPT triggers a Cloudflare Turnstile program that runs silently in your browser”
Technical analysis with detailed decryption of 377 samples. Cloudflare Turnstile is publicly documented; article provides specific technical evidence of its deployment in ChatGPT.
βœ“ Verified
β€œThe Turnstile program checks 55 properties spanning browser, network, and React application layers”
Article lists specific properties and their categories. Claims are technically detailed and internally consistent. Cloudflare's actual implementation details cannot be independently verified outside the decryption analysis provided.
◐ Mostly True
β€œThe program verifies that you're running a real browser that has fully booted a specific React application”
Article demonstrates React internals checking (__reactRouterContext, loaderData). The inference about 'full boot' requirement is reasonable but derived from bytecode analysis, not Cloudflare/OpenAI's stated design.
◐ Mostly True
β€œThe Turnstile bytecode arrives encrypted and can be decrypted using the XOR key embedded in the payload”
Technical walkthrough appears rigorous with 50/50 verification claimed. The decryption chain is detailed. However, we cannot independently replicate the decryption without access to live ChatGPT traffic.
◐ Mostly True
β€œOne mitigation involves requiring clients to execute proof of work”
Post mentions 'proof of work' requirement but the article excerpt doesn't detail this as a separate mechanismβ€”it describes Turnstile fingerprinting. Post may be referring to undescribed challenge layers but specificity is unclear.
? Unverifiable
Was this analysis helpful?
Try ClearFeed free β†’
clearfeed.app β€” Trust scores for your social feed