‹ BackHN Continuity

Thread

Meta's Muse is fantastic for web scraping

60 points · 74 comments · STRiDEX

  1. dvt · · focus · HN ↗
    I built an AI "web harness" running on a sandboxed Chromium (using a custom side-loaded plugin that talks over websockets to a "driver") to basically do anything a normal user could do in a browser. It totally bypasses any and all bot measures and only gets the ones you yourself would get as well (and passes those successfully, e.g. Cloudflare checkbox or those annoying OCR puzzles).

    Not sure if I should release it, but I'm sure more people are catching onto the power of agentic browsing.

    1. ares623 · · focus · HN ↗
      By describing it here you've already released it no?
    2. d0vs · · focus · HN ↗
      FYI Muse smashes through those captchas natively without prompting.
    3. frabcus · · focus · HN ↗
      Right, but what happens when everyone uses that at scale? Without agreements and standards it isn't pretty.
      1. dvt · · focus · HN ↗
        It's sad, but this train has left the station a quarter of a century ago imo. Many people have since become billionaires scraping the web without anyone agreeing (Google, Yahoo, and now possibly Anthropic and OpenAI).
        1. csnover · · focus · HN ↗
          There is a huge difference between a clearly identifiable, robots.txt-respecting, largely symbiotic search engine spider versus this new AI-driven casual sociopathy of firing shotguns of deliberately masked bots at sites in ways which benefit no one except for, maybe, the bot-owner.

          I agree with you, though, that the future has almost certainly already been decided, and see the eventual outcome of all this selfishness to be mandatory device attestation to access most services on the internet—which will of course never be allowed on any open platform. AI engineers who believed in freedom to compute (or just individual freedom more generally) have committed perhaps the greatest self-own in the history of our species to date.

    4. bayindirh · · focus · HN ↗
      Thanks for letting us know that we need a new layer of detection systems.

      Also it’s great(!) to see that we’re going from “but ethics” to “I got mine, who cares”.

      Humans are interesting creatures.

      Edit: Please before assuming that I'm assuming things, this is an observation I'm making over time. It's possible that I'm in a bubble, but it's not a sample size of 1 (i.e. The comment I replied only).

      1. pcthrowaway · · focus · HN ↗
        There is no detection method that will prevent AI from accessing systems without also blocking humans. The only thing we can do at this point is throttling.
        1. kees99 · · focus · HN ↗
          Agreed on inevitable collateral blockage of real people using real "headed" browser. I'm getting a ton of that already, personally.

          Throttling is poor help though. Mass scrapers are using "residential proxy" loophole + rotating UA and other attributes. You can't throttle somebody without identifying them. Unless you're talking about a global rate-limit.

          1. pcthrowaway · · focus · HN ↗
            throttling based on sessions kind of works; we're headed in the direction that sites like Reddit will probably prevent logged-out users from viewing threads (as they already do with mobile devices)

            Once the LLMs create sockpuppets to get around that, the web services will need to resort to profiling users more aggressively so that they know which actual human an account corresponds to.

            If someone has a malicious browser extension that uses their session to scrape Reddit then, they're probably going to see significant usage obstacles.

            We are headed to a very user-hostile place.

            1. mvt67 · · focus · HN ↗
              Only if your life revolves around reddit.
          2. rennf93 · · focus · HN ↗

            [dead]

        2. cyanydeez · · focus · HN ↗
          I assume most people have see the photos of various "far east" people sitting at a bench with an array of 100 phones.

          This predates AI as a _capitalism_ problem.

      2. afro88 · · focus · HN ↗
        I'm becoming more and more convinced that a big source of outrage on the internet is caused by people assuming that all other people are a homogenous blob.

        It's not that "we" are going from one thing to another. It's that these are two different people, with different ethical boundaries.

      3. Cakez0r · · focus · HN ↗
        You're framing this as if people are deliberately making decisions that they believe are unethical. The reality is that people have different ethical frameworks. For example, I believe that there is no ethical distinction between whether a web request originates from a browser or from an LLM on my behalf.
        1. dd8601fn · · focus · HN ↗
          It’s a big question mark in the conversation.

          Is defeating captchas unethical? I don’t think so. Not on its own.

          Is scraping unethical? I don’t think so. Not on its own.

          Are there tons of uses for both of those that are sketchy or outright wrong? Yeah, absolutely.

        2. Kepten-Hook · · focus · HN ↗
          Another person replied already and I agree with them, but also I think you need to see this from the perspective of the people operating the service you are accessing.

          As an example, imagine a really small community maintaining a small site/wiki/cms/forum that has the ultimate goal of promoting human relationships around a common interest (let's say retro computing as an example, but it could be anything). There are many many many such communities on the internet.

          It's very improbable you will specifically instruct your LLM to access their site, it's way more probable it will happen without you even knowing, as a result of you doing some /deep-research or something. And not only that, but your LLM will probably spawn a ton of agents to gather as much information as possible in as little time as possible. A torrent of requests will go at this community's site, effectively killing it. They are a small community, they use their spare time and money to maintain something to serve them, they don't have the resources to serve your LLM and until you showed up they probably never even had to think about Cloudflare. They are certainly not against you getting the content, but they don't want you causing them issues either and you just did.

          End result? Your LLM (effectively you) DoSed a small community's site. You caused harm. Could you have caused similar harm if you were doing it on your own? Sure. But you would have done it on purpose, not accidentally while instructing your LLM to do something else.

          This isn't a made up story, it has happened already more than 1 times.

          So the question is, now that you know your LLM can cause harm without you even knowing it, how does this change your stance?

          1. mvt67 · · focus · HN ↗
            Already have whatsapp and signal for this. Hardly need a website for these thing anymore.
            1. bayindirh · · focus · HN ↗
              So shall we build more walls around our content and make it anti-FAIR?

              We can stop putting information in the open in any form, as well.

              FAIR: Findable, Accessible, Interoperable, Reusable.

              1. mvt67 · · focus · HN ↗
                Why do you build a wall around your house genius?
                1. bayindirh · · focus · HN ↗
                  A public website is not a house, it's something between a big board in the city square or a community center where people can meet an interact.

                  Considering that, shall we paint the boards black or lock the doors to community spaces?

                  Also, while I assume this is not your first account here, these are worthy of reminding:

                  > Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.

                  > Throwaway accounts are ok for sensitive information, but please don't create accounts routinely. HN is a community—users should have an identity that others can relate to.

                  For more, please refer to <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html

          2. murderfs · · focus · HN ↗
            The answer is that no one gives a shit: just look at people&#x27;s views on adblock.
        3. watwut · · focus · HN ↗
          &gt; The reality is that people have different ethical frameworks.

          Sure, Nazi, Hitler or Stalin all considered themselves to be the good guys. Kushner, Trump, etc are also acting within their ethical system (if I am getting money or power or fame it is ok to do it). Just about the only exception is Thiel who openly frames himself as evil, but is proud of it.

          That does not mean we cant criticize their crappy actions or &quot;ethical frameworks&quot;.

          And yes, all the above are making deliberate decisions to be unethical assholes.

        4. cyanydeez · · focus · HN ↗
          There&#x27;s two types of cares:

          1. People like other people.

          2. Businesses need to sell product

          The internet mixes those people, and an Agent basically pushes the signal to noise ratio that businesses have relied on the intenet to basically zero.

          If the internet just allowed indescriminate traffic, neither #1 nor #2 survives, and while it&#x27;s interesting to think the value is, it certainly isn&#x27;t anything we understand.

          Maybe you think the value will still exist, but some how agents will replace all value with equivelents. That&#x27;s an argument, but I don&#x27;t think it will.

      4. jareklupinski · · focus · HN ↗
        humans also change over time

        in batman, bruce wayne shuts does the massive surveillance network, seeing it was problematic (2008)

        in spiderman, peter parker just shrugs off being able to know where anything is happening anytime (2026)

        1. bayindirh · · focus · HN ↗
          &gt; humans also change over time

          Yes, that&#x27;s what I&#x27;m referring to. Citing myself:

          &gt; Also it’s great(!) to see that we’re going from “but ethics” to “I got mine, who cares”.

          This is exactly how I observe a shift in general.

          1. jareklupinski · · focus · HN ↗
            maybe it&#x27;ll go backwards? or the direction is chaotic &#x2F; tick-tock
            1. bayindirh · · focus · HN ↗
              I believe that the movement is sinusoidal,since every trend feeds its counterbalance.

              OTOH, stabilizing at &quot;0&quot; or any point is impossible since the system is 2nd order and the response of the system is also an input to itself.

              1. jareklupinski · · focus · HN ↗
                &gt; sinusoidal

                &gt; OTOH, stabilizing

                any function is stable; im just dissppointed if its predictable &#x2F; manipulable &#x2F; only has 2d

    5. bel8 · · focus · HN ↗
      Interesting, how is the chromium sandboxed? profile dir cli param? or deeper like chromium engine framework embeded in the application?
      1. dvt · · focus · HN ↗
        Just simply a separate Chromium binary (not your usual browser).
    6. rjtc · · focus · HN ↗
      anyone can spin these kind of side projects and do easy talk, but the moment you actually try to use this on signed-in Linkedin or Amazon its going to fail

      the only solution is to drive your regular browser with all your sessions&#x2F;cookies via an extension

      1. dvt · · focus · HN ↗
        &gt; the only solution is to drive your regular browser with all your sessions&#x2F;cookies via an extension

        This is exactly what I&#x27;m doing, but mocking&#x2F;randomizing all the sessions&#x2F;cookies&#x2F;params (like resolution, OS, WebGL , etc.) in a separate Chromium binary. It&#x27;s popular these days, but imo using your normal browser for agentic stuff is a very bad idea. These models do dumb stuff all the time.

      2. carsoon · · focus · HN ↗
        no it doesn&#x27;t fail. Agents are very good at comparing traffic characteristics from a real browser and a headless&#x2F;automation browser and getting it to behave in the same manner. It&#x27;s a cat and mouse game for sites stopping unauthorized access but right now llm agents are ahead.

        For testing proxies should be used to avoid IP ban issues but given enough time modern agents can figure out how to bypass most of the modern scraping&#x2F;automation prevention mechanisms.

        I have built and used a lot of different automations and web scraping implementations for my business and it&#x27;s never got permanently stuck yet, some take a bit longer, some shorter, but all within a reasonable time with little external help they have succeeded in their tasks.

    7. kurisufag · · focus · HN ↗
      the 4get dev did the same thing a little while ago for his metasearch engine: <a href="https:&#x2F;&#x2F;git.lolcat.ca&#x2F;lolcat&#x2F;4play" rel="nofollow">https:&#x2F;&#x2F;git.lolcat.ca&#x2F;lolcat&#x2F;4play
      1. dvt · · focus · HN ↗
        Yep, it&#x27;s super similar to this! I think his is a bit overengineered, but tbh I haven&#x27;t built Firefox plugins in forever so that might be the way you have to do stuff on FF. All you need is the websocket plugin to have &quot;full access&quot; to all visited webpages, and then your driver just hooks into the DOM like normal (with the extra ws layer—and even the websocket layer can be simplified away I think).
    8. pprotas · · focus · HN ↗
      Camoufox bypasses most blocks with no problems <a href="https:&#x2F;&#x2F;camoufox.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;camoufox.com&#x2F;
    9. onion2k · · focus · HN ↗
      (using a custom side-loaded plugin that talks over websockets to a &quot;driver&quot;)

      Is that necessary? You could start Chromium with an open debug port and use Chrome Devtools Protocol to send commands.

      1. dvt · · focus · HN ↗
        It is, because `--remote-debugging-port` is detected via the root DOM object (and that can&#x27;t be changed unless you want to recompile Chromium), so for example, if you try doing a Google search with debugging enabled, you&#x27;ll get blocked (usually just by being served a blank page).
        1. LunaSea · · focus · HN ↗
          Interesting, do you know what exactly changes on said root DOM node in case the remote debugging feature is enabled?
          1. dvt · · focus · HN ↗
            `navigator.webdriver` afaik, but I think there&#x27;s a couple more, I did some research on it a few months ago. If using Playwright&#x2F;Puppeteer, they also have a few special things injected that you have to strip.
            1. Cakez0r · · focus · HN ↗
              What model did you use to build this? I recently looked in to building something similar and got refusals.
              1. dvt · · focus · HN ↗
                I built the POC by hand (just had like 3 things it could do: scroll, click, type), and then Codex used my established patterns to make it slightly more general and cleaned it up.
            2. LunaSea · · focus · HN ↗
              Ah right, there are stealth plugins to remediate these types of hints I believe.
        2. raffraffraff · · focus · HN ↗
          Does remote debugging port itself get detected, or does the presence of a webdriver connection to the port get detected? I believe it&#x27;s the latter.

          I&#x27;ve had success launching the browser and using dumb dumb methods to get around the captcha before attaching playwright.

          Dumb dumb methods = wmctrl, xdotool, bash (work fine for Cloudflare&#x27;s &quot;are you human&quot; check)

          1. dvt · · focus · HN ↗
            I think it&#x27;s the latter, and that&#x27;s why I think using a &quot;normal&quot; non-debug browser is the best idea because it&#x27;s essentially undetectable. And for the record, you can technically control Chromium using IPC if you feel like adding that feature &amp; fully rebuilding it from scratch.
    10. kees99 · · focus · HN ↗
      Some webshops (e.g. Aliexpress) already soft-block Chromium (at least Chromium-on-Linux). I.e. such users see larger-than-usual share of captchas.

      Assuming &quot;more people catching onto&quot; this, expect Cloudflare and most everyone else to follow the suite.

      1. dvt · · focus · HN ↗
        Are you saying they&#x27;re blocking the `User-Agent`? Because that&#x27;s trivial to bypass. I&#x27;m not exactly sure what you mean by &quot;Chromium&quot; because that&#x27;s a whole class of browsers (Edge, Brave, Chrome, etc. are all forked &quot;Chromium&quot; browsers).
        1. kees99 · · focus · HN ↗
          Aliexpress specifically uses a javascript blob to do detection, and quite a sophisticated one. There was a recent story about that blob messing with bluetooth headphones.

          &gt; not sure what you mean by &quot;Chromium&quot;

          I meant that literally. This thing: <a href="https:&#x2F;&#x2F;www.chromium.org&#x2F;getting-involved&#x2F;download-chromium&#x2F;#chromium" rel="nofollow">https:&#x2F;&#x2F;www.chromium.org&#x2F;getting-involved&#x2F;download-chromium&#x2F;...

          1. dvt · · focus · HN ↗
            Here&#x27;s my agentic Chromium browser browsing Aliexpress[1]. Usually I&#x27;d run it in headless mode, but wanted to test and make sure I&#x27;m getting the website proper.

            It searched for &quot;Aliexpress&quot; on Google and clicked the link, hence the Google UTM params.

            [1] <a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;eNulg11" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;eNulg11

      2. kotaKat · · focus · HN ↗
        And the worst part is humans just getting more cognitively demanding captchas.

        Some days I&#x27;m literally fatigued enough I can&#x27;t clear the overly complex hCaptchas these days I keep getting forced upon me and bots sail right through this crap.

    11. Cakez0r · · focus · HN ↗
      I think it&#x27;s inevitable that eventually one of the big AI companies makes something like this. It&#x27;s such an obvious consumer win. &quot;I am not a bot&quot; checkboxes are a string and peg tethering the elephant.
    12. busssard · · focus · HN ↗
      please release it and call it SilverSurfer
    13. cyanydeez · · focus · HN ↗
      I&#x27;ve got a plugin in development that&#x27;ll do the same: via an extension, connect to a standard coding bot, so it can drive.

      It can be used for testing software and using it as a human support.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.