I built an AI "web harness" running on a sandboxed Chromium (using a custom side-loaded plugin that talks over websockets to a "driver") to basically do anything a normal user could do in a browser. It totally bypasses any and all bot measures and only gets the ones you yourself would get as well (and passes those successfully, e.g. Cloudflare checkbox or those annoying OCR puzzles).
Not sure if I should release it, but I'm sure more people are catching onto the power of agentic browsing.
I'm becoming more and more convinced that a big source of outrage on the internet is caused by people assuming that all other people are a homogenous blob.
It's not that "we" are going from one thing to another. It's that these are two different people, with different ethical boundaries.
There is no detection method that will prevent AI from accessing systems without also blocking humans. The only thing we can do at this point is throttling.
It's sad, but this train has left the station a quarter of a century ago imo. Many people have since become billionaires scraping the web without anyone agreeing (Google, Yahoo, and now possibly Anthropic and OpenAI).
anyone can spin these kind of side projects and do easy talk, but the moment you actually try to use this on signed-in Linkedin or Amazon its going to fail
the only solution is to drive your regular browser with all your sessions/cookies via an extension
no it doesn't fail. Agents are very good at comparing traffic characteristics from a real browser and a headless/automation browser and getting it to behave in the same manner. It's a cat and mouse game for sites stopping unauthorized access but right now llm agents are ahead.
For testing proxies should be used to avoid IP ban issues but given enough time modern agents can figure out how to bypass most of the modern scraping/automation prevention mechanisms.
I have built and used a lot of different automations and web scraping implementations for my business and it's never got permanently stuck yet, some take a bit longer, some shorter, but all within a reasonable time with little external help they have succeeded in their tasks.
> the only solution is to drive your regular browser with all your sessions/cookies via an extension
This is exactly what I'm doing, but mocking/randomizing all the sessions/cookies/params (like resolution, OS, WebGL , etc.) in a separate Chromium binary. It's popular these days, but imo using your normal browser for agenting stuff is a very bad idea. These models do dumb stuff all the time.
Most residential proxies are already far more blocked and rate limited than any Meta IP. The internet is becoming a very weird place, where individual and "trusted" personal IPs are becoming a kind of commodity. Some sites are already scoring IPs based on usage activity - like a credit score. It's only a matter of time until this data is collated and commoditised. AI analysis is turning this up to 11.
Muse ran into a captcha and asked me if I wanted it to solve it.
So of course I clicked yes and it dutifully convinced the site that it was not a bot.
For 2(3?) decades we've been training the robots to tell traffic lights from fire hydrants. It's finally paying off.
I built an AI "web harness" running on a sandboxed Chromium (using a custom side-loaded plugin that talks over websockets to a "driver") to basically do anything a normal user could do in a browser. It totally bypasses any and all bot measures and only gets the ones you yourself would get as well (and passes those successfully, e.g. Cloudflare checkbox or those annoying OCR puzzles).
Not sure if I should release it, but I'm sure more people are catching onto the power of agentic browsing.
Thanks for letting us know that we need a new layer of detection systems.
Also it’s great(!) to see that we’re going from “but ethics” to “I got mine, who cares”.
Humans are interesting creatures.
I'm becoming more and more convinced that a big source of outrage on the internet is caused by people assuming that all other people are a homogenous blob.
It's not that "we" are going from one thing to another. It's that these are two different people, with different ethical boundaries.
There is no detection method that will prevent AI from accessing systems without also blocking humans. The only thing we can do at this point is throttling.
(using a custom side-loaded plugin that talks over websockets to a "driver")
Is that necessary? You could start Chromium with an open debug port and use Chrome Devtools Protocol to send commands.
Camoufox bypasses most blocks with no problems https://camoufox.com/
the 4get dev did the same thing a little while ago for his metasearch engine: https://git.lolcat.ca/lolcat/4play
FYI Muse smashes through those captchas natively without prompting.
Right, but what happens when everyone uses that at scale? Without agreements and standards it isn't pretty.
It's sad, but this train has left the station a quarter of a century ago imo. Many people have since become billionaires scraping the web without anyone agreeing (Google, Yahoo, and now possibly Anthropic and OpenAI).
anyone can spin these kind of side projects and do easy talk, but the moment you actually try to use this on signed-in Linkedin or Amazon its going to fail
the only solution is to drive your regular browser with all your sessions/cookies via an extension
no it doesn't fail. Agents are very good at comparing traffic characteristics from a real browser and a headless/automation browser and getting it to behave in the same manner. It's a cat and mouse game for sites stopping unauthorized access but right now llm agents are ahead.
For testing proxies should be used to avoid IP ban issues but given enough time modern agents can figure out how to bypass most of the modern scraping/automation prevention mechanisms.
I have built and used a lot of different automations and web scraping implementations for my business and it's never got permanently stuck yet, some take a bit longer, some shorter, but all within a reasonable time with little external help they have succeeded in their tasks.
> the only solution is to drive your regular browser with all your sessions/cookies via an extension
This is exactly what I'm doing, but mocking/randomizing all the sessions/cookies/params (like resolution, OS, WebGL , etc.) in a separate Chromium binary. It's popular these days, but imo using your normal browser for agenting stuff is a very bad idea. These models do dumb stuff all the time.
Interesting, how is the chromium sandboxed? profile dir cli param? or deeper like chromium engine framework embeded in the application?
Just simply a separate Chromium binary (not your usual browser).
By describing it here you've already released it no?
their static ip's were initially good and didn't get flagged, but now most sites are recognizing their ip ranges and blocking.
Muse's utility has significantly dropped with the blockages.
To become truly useful again they will need to use residential proxies, but I can't see them use those due to the risks and reputational damage.
Most residential proxies are already far more blocked and rate limited than any Meta IP. The internet is becoming a very weird place, where individual and "trusted" personal IPs are becoming a kind of commodity. Some sites are already scoring IPs based on usage activity - like a credit score. It's only a matter of time until this data is collated and commoditised. AI analysis is turning this up to 11.
they can just use the user ip. i think grok already does this.