I don't get why, when and how Google uses reCAPTCHA within their own tools. E.g. within the Webmaster Tools, I can submit up to 500 URLs for manual fetch/render and subsequent index submission. So the rate limit is already there and reasonable. However, after 4 submitted URLs, I get a reCAPTCHA. From then on for every URL, I have to complete it with additionaly visual quizzes.
> I don't get why, when and how Google uses reCAPTCHA within their own tools. This may or may not help with your quest. Google triggers recaptcha when i use their search using one of my digitalocean servers as vpn and incognito mode, thus my IP address belongs to a datacentre, there isn't a cookie header and the user-agent is linux.
I’m not a human: Breaking the Google reCAPTCHA [pdf]
11–20 of 70 posts
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#12I don't get why, when and how Google uses reCAPTCHA within their own tools. E.g. within the Webmaster Tools, I can submit up to 500 URLs for manual fetch/render and subsequent index submission. So the rate limit is already there and reasonable. However, after 4 submitted URLs, I get a reCAPTCHA. From then on for every URL, I have to complete it with additionaly visual quizzes.
Another way they get triggered is when people use browser/desktop based rank checkers. There are also plugins some SEOs use to pull lots of requests. These tools are quite old now and not very useful, but people still use them.
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#13You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#14I don't get why, when and how Google uses reCAPTCHA within their own tools. E.g. within the Webmaster Tools, I can submit up to 500 URLs for manual fetch/render and subsequent index submission. So the rate limit is already there and reasonable. However, after 4 submitted URLs, I get a reCAPTCHA. From then on for every URL, I have to complete it with additionaly visual quizzes.
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#15Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#16I have a bad feeling CloudFlare is going to break the internet for Tor users with impossible-to-solve CAPTCHAs again after this...
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#17You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#18You could also just pay a service that uses human workers in third world counties. It's a little over a tenth of a cent per captcha.
From the paper: "We compare our performance to that of Decaptcher, the (self-reported) oldest captcha-solving service. We selected Decaptcher for two reasons. First, it supports the image reCaptcha, charging $2 per 1000 solved captchas. [...] Interestingly, some of our summitted challenges rejected due to the service being overloaded, and had to be resubmitted at a later time, and received a time-out error as the solvers did not provide an answer in the time window allocated by the service. 258 challenges (36.85%) were an exact match. When taking into account the flexibility, 321 (44.3%) of the captchas were solved. The average solving time for the challenges that received a solution was 22.5 seconds. While the accuracy may increase over time as the human solvers become more accustomed to the image reCaptcha, it is evident that our system is a cost-effective alternative. Nonetheless, our completely offline captcha-breaking system is comparable to a professional solving service in both accuracy and attack duration, with the added benefit of not incurring any cost on the attacker."
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#19fucking fuckers.
Re: I’m not a human: Breaking the Google reCAPTCHA [pdf]
#20From the paper: 'Assuming a selling price of $2 per 1,000 solved captchas, our token harvesting attack could accrue $104 - $110 daily, per host (i.e., IP address). By leveraging proxy services and running multiple attacks in parallel, this amount could be significantly higher for a single machine.'