Viewing profile — eatbots
eatbots
HN member- Joined
- Wed, Nov 25, 2020, 7:37 PM UTC
- HN karma
- 241
- Public activity
- 36 items
- HN profile
- View on Hacker News ↗
About eatbots
No profile information was provided.
Recent public activity
- story
- story
-
comment
Comment #41819655
Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company. I doubt we were the first. That…
-
comment
Comment #38676755
If you report the website/sitekey to hCaptcha support it'll get banned pretty quickly.
-
comment
Comment #36230911
hCaptcha tested popular detectors on confirmed LLM and human output. No public AI text detector scored better than random chance.
- story
- story
-
comment
Comment #34315129
hCaptcha has completely passive score-only modes. When to challenge and how hard is up to the site.
-
comment
Comment #34313939
This is entirely configurable by the site owner. hCaptcha has entirely passive score-based detection, 99.9% passive mode, and more aggressive options as needed. (disclosure: work t…
-
comment
Comment #32557134
No: enterprise customers like that pay hCaptcha. https://www.hcaptcha.com/enterprise
-
comment
Comment #32437517
This is not what empirical measurements show. It is referring to a minimum internal benchmark, rather than what actually happens. (source: work there) If you're getting shadow bann…
-
comment
Comment #31688453
Like any attestation scheme, it doesn't prove anything about the humanity of the button-presser, only that software, hardware, or flesh triggered an action in iOS. hCaptcha's annou…
- story
-
comment
Comment #30878332
Reducing challenges to real people is everyone's goal, including the goal of everyone working on modern CAPTCHA / bot mitigation platforms.. And no one will ever succeed at bringin…
-
comment
Comment #30766434
Vast majority of traffic from Tor IPs is abuse, which makes it challenging to deliver a good experience for the handful of normal users mixed in there. You might be interested in o…
-
comment
Comment #30353704
hCaptcha really doesn't care who you are, and has no incentive to do so. Pretty different economic model than an ad seller like Google. People who build their own generally end up …
-
comment
Comment #30353593
hCaptcha is in fact tested this way, and has pretty consistent accuracy across hundreds of countries: https://www.hcaptcha.com/post/do-captchas-really-discriminat... (disclosure: w…
-
comment
Comment #30164111
Actually, no. hCaptcha has always been very privacy-focused, so in this case there are technical safeguards available: enterprise customers can pre-blind all data on their end, mea…
- story
-
comment
Comment #27327718
As a fan of ProtonMail, will just add a few points: Every popular online service today is being continuously attacked. Bad actors get a lot of economic value from credential stuffi…
-
comment
Comment #27327126
This is not actually true: every relevant aspect is different from a privacy perspective, both technical and legal. Looking only at the technical differences, hCaptcha lets enterpr…
-
comment
Comment #27158379
Yep. https://www.hcaptcha.com/why-captchas-will-be-with-us-always (disclosure: work there)
-
comment
Comment #26649958
This is under the control of the site with hCaptcha, so you'll tend to see more variety in difficulty levels depending on their settings. There will always be some individual varia…
-
comment
Comment #26615933
Our system is indeed designed not to leak detections in real-time. By contrast, with reCAPTCHA you can simply sign up and get a bot score, which makes it trivial to break. This lim…
-
comment
Comment #26170114
This was an implementation issue that bit them briefly at launch, and is now resolved. hCaptcha is quite a big supporter of privacy, and has been coordinating closely with ECI. (so…