AI 产品解读Privacy Pass anonymous token client that obtains unlinkable cryptographic tokens from attesters to present to websites supporting the PrivateToken protocol
Enables users to prove they are human to Cloudflare-protected websites without compromising privacy—avoids repeated CAPTCHAs and prevents tracking across sites through anonymous, unlinkable tokens
1. User visits a website that supports Privacy Pass and sends a PrivateToken WWW-Authenticate challenge header. 2. The extension detects the challenge and opens a new tab to the Cloudflare Turnstile attester. 3. User solves the attestation challenge (proves they are human). 4. The extension receives an anonymous cryptographic token from the attester. 5. The token is automatically included in subsequent requests to the website, proving the user is human without linking to their identity.
Intercepts WWW-Authenticate PrivateToken challenges from supported websitesOpens attester challenge tab (Cloudflare Turnstile) to obtain cryptographic tokensAutomatically redeems anonymous tokens to bypass bot-detection without revealing identityConfigurable attester URLs and development/demo/production modes via options page
- 目标用户
- Privacy-conscious web users / Users frequently visiting Cloudflare-protected websites / Users who want to avoid repeated CAPTCHA challenges while preserving anonymity
- Extension source is bundled/minified (background.js is 238KB single file), making deep logic analysis harder but key patterns are clear
- Cannot fully verify if destination Cloudflare attester service requires login since it's external—however the extension itself does not
付费分析未识别到付费功能
No payment, subscription, premium, upgrade, billing, or price references found in the source code. Grep for 'premium', 'payment', 'subscription', 'upgrade', 'billing', 'price' all returned 0 matches in background.js. The 'pro' keyword hits from the static scan are all false positives: Object.prototype methods (lines 2-21), Object.getOwnPropertyNames (line 19), and SERVICE_WORKER_MODE.PRODUCTION (line 633). The extension is fully functional without any gated features or payment flows.
- 置信度
- 95
- 支付平台
- --
- 来源
- AI / 高
- 需要登录
- 否
- 登录理由
- The extension implements the Privacy Pass anonymous authorization protocol. No user account, login UI, or credential entry exists anywhere in the codebase. Grep for 'login' and 'account' in background.js returned 0 matches. The 'auth' keyword hits are all cryptographic authentication (AES-CCM tags, WWW-Authenticate header parsing at lines 6340-6396), not user account authentication. The 'token' hits refer to anonymous Privacy Pass cryptographic tokens, not login/session tokens. The options page (options/index.html) only contains attester URL configuration and service worker mode selection—no login fields.
It's horrible and never ever ever works, crashes every single time and is totally useless.
Greyed out, does not work.
Не работает
Doesn't work.
Va bastante bien bloqueando los captcha, pero a veces da error y no funciona o dice que una extensión ha bloqueado la página. Totalmente recomendable si los captchas entran en bucle infinito (como es mi caso)
一星都多,没有什么作用
não funcionou no site da egyptair.com
I'm not 100% sure about how exactly this is supposed to work. Note that I'm a fan of everything Cloudflare, and that's why I still have this extension turned on. However, I have increasingly been suspected of "not being human" — possibly because I'm using the Brave browser? It's Chromium underneath, obviously (or the extension wouldn't work!), but perhaps Brave blocks some additional things, managing to confuse Cloudflare. The point of "saving" a token so that you just need to get validated as being human once (or once per day...) makes a lot of sense, but it's not obvious how it works *now*. In the past, it *did* work in 100% of the cases, as others have reported. Currently... it's most a question of luck, I guess. Note that it's not easy to understand _what_ triggers the actual requirement for "human validation"; I have it appearing on my own websites, installed on my very own servers, which are also behind Cloudflare, but I would *assume* that, by now, Cloudflare would have "learned" that I'm supposed to be a legitimate user of my own websites — or so I would think. Granted, nothing can be worse than using Tor to browse the regular Web — you get validated twice, first (usually) by Cloudflare, and then by Google, which is _much_ worse and takes a lot of time, clicking on all those pictures until Google's happy... it's an annoyance in exchange for being able to browse the Web without being tracked.
Advertised as an extension to fix issues with Cloudflare verification, while it just makes the verification problems worse. Not recommended.
没有用