

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Is the video on shieldfont.org AI-generated? It sounds like that voice again.by frollogaston
- > I don't have anything against these specific examples [...]. This post is meant to critique the idea itself. I'm not trying to put-down anyone here!
This is self-contradictory. Either you want to critique something or you do not. Make up your mind.
- So a rounding error of nerds, who themselves are a rounding error, will invest a lot of effort and trouble to use tech that makes their and their user's lives harder, and probably won't even work, to hide text that LLM big tech couldn't care less about anyway.
Cool.
by simonh - Anti-AI fonts seems like scrambled porn on cable back in the 1980s.by hk1337
- I can tell right away that is stupid because one of the things I've used AI for was for deciphering someone's illegible handwriting, which it did amazingly. Once it figures out for you what is written, you can't unsee it, so you know it has to be right.
Illegible fonts will only create accessibility problems for humans, even ones with normal vision, high literacy and no cognitive defects (dyslexia), while AI will blow right through the text.
If this is done in electronic documents, where the AI won't even see the glyps becaue it's reading the underlying character codes, it's even stupider.
I can't believe anyone would even try this (and then believe it is working without putting their hypotheses to the test).
by kazinator - There could be benefits unlocked in legal documents by retaining a machine-readable version and distributing the obfuscated version with a legend at the top. We proposed one that said:
"This document contains mitigations against review by automated systems. Recipients should ensure that they have read the contents on screen or in print. Recipients with bona fide vision impairments may be entitled to unmitigated documents upon request."
In testing, obfuscating small portions of text slipped under the radar of most (then-)frontier LLMs.
We used a font that was rendered on the fly and reported faulty or fake Unicode mappings: https://tritium.legal/blog/noroboto but others have proposed and done the same with ligatures.
by piker - You will surely not have a good time enforcing the terms of a legal document that explicitly spells out that it is intentionally obfuscated from the party it intends to bind.by aleksejs
- It is not sufficient to work against current AI. It needs to also work against AI that has been trained by a competent team aware of your mitigation. Or worse, a competent developer with no particular AI skills.
Otherwise, you are relying on obscurity, and will lose as soon as you become interesting enough to matter.
You will also break non-AI machine processing use cases. That isn't just accessibility, it is things like search.
by gizmo686 - There was a story once about a boy with a wheelchair who needed a ramp to get into school, and the school made him use the loading dock ramp used for garbage and other things at the back. The school argued that it was an appropriate accommodation.
Accessibility is not accessible if you need to go through extra steps to get it.
Cerebrally, this as a solution makes sense. But if you know anyone with a vision or other impairment, gating it behind a request is not only cruel but gets within dangerous striking distance of an ADA lawsuit, for general applications.
Maybe in the legal field or specific niche cases it's possible. But this would represent a major step backwards in the work we've done lowering barriers for a population whose only difficulty in accessing common resources is because they were born, or got sick, differently than anyone else.
by tbalsam - I think this is an example of just catering to the gullible solely because the market exists without pondering anything about the individuals in the market
like the "pink tax", which isn't a tax at all but just a premium on consumer gullibility as the consumer can purchase other products that do the same thing simply marketed in a different way
playing into anti AI sentiment in a useless way fits the criteria
by yieldcrv - > Like it or not, all publicly available information will inevitably become accessible to anyone and anything that has permission to access it. This is the baseline scenario people need to plan around.
The entire point of the situation is that permission is not involved. They just do it. Meanwhile, if I do it to them, I am fined/sent to prison/executed. Until such a time that this baseline scenario of inequality is somehow remedied, there will be a motivation to stop them.
by logseman - Are these even meant to be used though? It seems more like performance art.by condour75
- Agreed. There was a thing a few years ago for dazzle-painting your face to avoid face recognition. This just makes you stand out.by Animats
- "Go ahead, obfuscate your contribution to the repository of all human knowledge, see if that impedes our imminent invasion! Moooahahahar!!!" - Kang and Kodos
- "caveman speak" skill, need I say more?
People aren't particularly bright. That's why the scientific method was developed to counteract our built-in tendency for... Unorthodox approaches
by ffsm8 - With this kinda of stuff it's hard to tell whether the person is doing it unironically, or knows it's "performative art". A while ago there was a trend of using a tool which imperceptibly perturbs an image in a way that supposedly breaks AI training on it. Of course, artists ate it up, despite the skepticism from AI researchers. Same with people setting up their sites to be "AI scraper traps", generating gibberish content. Probably also trivial to filter out, but people do it.by gruez
- The irony of championing accessibility using low-contrast simulated VGA text...by blehn
- When I first was reading this I thought that the author was deliberately using a shitty font to make the point that obfuscated fonts are hard to read.
- Agree. My vision is not even that bad and yet I literally had to squint and hold my phone very close to be able to read this page.by flexagoon
- Also the notion that the sides of the pages flash as you scroll due to simulating that old Macintosh monochrome monitor dithering effect. My eyes.
- Where do you see the low contrast?by Narishma
- Thanks for introducing me to shieldfont.org! It's the first of these I've seen that feels designed to be more than a visual experiment, reading through their landing page is interesting. In particular, their section on accessibility seems to contradict this post's opening premise:
> Screen readers get the real words. A screen reader reading down the page is never handed scrambled text, and our NVDA test asserts exactly that. Screen review and touch exploration are untested. ShieldFont hides shielded passages from accessibility tools by default with aria-hidden="true", because a decoy read aloud is fluent, grammatical, wrong English, and that is worse than silence.
> The real words remain sealed in the same page, and a visible notice above the block carries the control that uncovers them. It is on by default and reachable by mouse, keyboard and screen reader alike. Pressing it sets the reader’s browser to solving a compute-heavy puzzle: JavaScript and a few seconds of processing, more than most mass scrapers are willing to spend. That puts the words within reach of a screen reader, a translator and copy/paste.
I'd love to hear your thoughts on that. Also just aside, love this TUI-esque blog design and color palette (maybe a bearblog theme? still worth an upvote)
by evnp - > I'd love to hear your thoughts on that.
“Claude: make the scraper mimic a screen reader.”
And just like that, in 10 seconds, their site feeds my “screen reader” the real words.
by SideQuark - A bit ironic that this is written in idiomatic Claudese.by svara
- It's funny, I was just thinking that the one thing I hate most about the terminal is that its monospaced fonts and overly-long lines are a nightmare for reading. So the fact that somebody designed a blog reading experience to mimic this is just… ugh for me.
But you seem to appreciate it, and I'm sure others do too. Different strokes for different folks.
by csallen - I had no idea this was even posted on HN until a short while ago, lol
Regarding shieldfont, if a screen reader can get the real words, then AI scrapers will eventually be able to get them one way or the other... I stand by my points in the post. I guess I'd say if someone uses a lesser-known obfuscation technique that remains uncracked or unnoticed by the bots, then more power to them. But if and when everyone else catches on, it will become useless.
I am very proud of the theme, which originally started out as a bearblog theme but I think by now it's all been replaced with my own CSS. The light color theme consists of the Windows web colors, while the dark theme is modified from the CGA 16-color palette.
I appreciate the feedback from people in this thread. I realize the irony of the blog not necessarily conforming to the ideal of an accessible format, but it's all in plain text and shouldn't be too much trouble for any reader-mode or accessibility tool to parse... I was aware the dark theme needed some more contrast. I just tightened it up a bit by darkening the gray palette value.
by ayaros - When you look at their live demo (https://shieldfont.org/demo/), it says: If you use a screen reader, custom font, or translator, please uncover the text before reading.
They also actively block copying the text, telling you to "uncover" the text first. The uncover operation is VERY expensive.
Anyone using assistive technologies or trying to copy "protected" text is SOL.
Search engines will index the decoy. You'll get no traffic. Their solution is basically putting yourself in a black hole.
by kstenerud - > The public posts and discussions being had about this subject are already informing AI companies on how to train their multimodal models to get around these obfuscations, most of which have already been broken. I'd argue every new font and tech demo is effectively a benchmark, daring AI firms come up with solutions to sidestep them. And they will be sidestepped, one way or another. If a human can see the information, that means there is a way the information can be parsed. "Ghost" fonts will become just another scraping obstacle with its own set of contingencies.
1. I don't like the sense of futility and powerlessness this advocates for.
2. I'm not sure it is so futile. I agree this stuff isn't encryption, which means it'll always be possible to circumvent the obfuscation, but it could raise the cost. Hopefully that can be done to the point where it's just not worth the bother.
That could happen if:
1. There are so many schemes out there the catalog of circumventions gets unwieldy.
2. Doubly so if the schemes allow generation of new obfuscated fonts per site or per page.
3. Then you're forcing the scrapers to pay a greater tax to get your text: spin up a Chrome instance to OCR a screenshot, or spend some a buck or two or LLM credits to reverse engineer the page in order to scrape it.
by palmotea - > I agree this stuff isn't encryption, which means it'll always be possible to circumvent the obfuscation, but it could raise the cost. Hopefully that can be done to the point where it's just not worth the bother.
Did it work for non-cryptographic DRM? (Broadcast flag, Macrovision, deliberately miswritten floppy sectors, port dongles, physical manual challenge-response...)
- I also don't like the fatalistic mindset, but I feel like we're better off trying to retaliate against the makers and operators of the bots, rather than getting into a technological arms race against the bots themselves. That is, the fight is one of policy, law, and morality, not of technology.by BrenBarn