Live data from Hacker News

Why Captchas have gotten so difficult

theverge.com

61–70 of 218 posts

Re: Why Captchas have gotten so difficult

#61

What many commentors here don't realise is that Google also uses reCaptcha to make you do free work for them.

I think people realize that, but is it much worse than proof of work that is helpful to nobody? It's easy to take a position against Google and Recaptcha. It's easy to take a position against something that inconveniences you.

What people actually don't seem to realize ITT is that abuse is becoming so easy and such a problem that we are becoming increasingly reliant on centralized services like Cloudflare and Google.

You used to be able to just generate your own captcha on the server with simple libraries, but Xrumer (mass website-spamming software) could crack those 10 years ago.

I'd like to see more comments addressing the ever-lowering barrier of online spam/abuse instead of opting for the low hanging fruit of condemning people for trying to save their websites/platforms from it.

Re: Why Captchas have gotten so difficult

#62
post #38

Earlier quoted context omitted.

Unfortunately Buster no longer works. Google detects it now and makes you start over.

Buster works if you set it to another STT service than the Google API Demo. They seem to have caught onto that one.

Yes, and it is also working with google cloud speech using your own key.

Re: Why Captchas have gotten so difficult

#64
post #24

Google reCAPTCHA is the absolute worst. It makes me solve several puzzles very often, usually when I use a mobile network and I’m not logged in with any Google account. It’s so frustrating that most of the times I find a reCAPTCHA I give up before trying and just go elsewhere e.g. when a site uses reCAPTCHA for sign up or after the first failed login, I’ll most likely skip if I don’t absolutely need to access such we…

The worst part is that quite a huge percentage of the Internet relies on it! Soon we won't be able to use any sites whatsoever because of it. I don't like where this is going. :/

Indeed, I definitely am not happy with how much control Google has over the Internet in general. Everything from how they present and rank search results, Google Analytics scripts everywhere, the sometimes vaguely-political messages on their homepage, the ostensibly-anti-bot checks including CAPTCHAs and just plain banning you if you want to do more "advanced" searches (like the ones Fravia would've taught...), etc.

Re: Why Captchas have gotten so difficult

#65
post #28

These really make my blood boil. I continually trip whatever it is that makes Google think I'm a bot (probably a VPN + ublock). Sometimes it takes upwards of 5 tries (each with 3 or 4 tests) to pass. After the first failure the audio one stops working, and sometimes that's unintelligible. I honestly wonder how anyone who's even slightly visually impaired is supposed to pass them. I wouldn't be surprised if in the not…

A few years back Google changed recaptcha to use a bunch of extra information to make a decision as to whether someone was a real person. This resulted in sometimes there not being any images, once you click to start the CAPTCHAS, it just shows a checkmark and let's you through. What also seems to have happened then is that they use additional I formation to make the process much harder sometimes. Ublock never seems…

> What also seems to have happened then is that they use additional I formation to make the process much harder sometimes.

Correct. Your reCAPTCHAv3 (which is the new completely challenge-less version that doesn't even make you click a checkbox) score is a good indication of how much reCAPTCHAv2 (the clickbox version) will fuck around with you.

In case anybody is wondering, v1 was the two-word OCR version and got shut down last year.

Re: Why Captchas have gotten so difficult

#66

What many commentors here don't realise is that Google also uses reCaptcha to make you do free work for them.

My first reaction to your comment was that I would be pretty shocked if anyone here didn’t realize that, and wouldn’t you know I have now read more of the comments and here I am shocked. The idea that this problem results from heightened security measures is wrong, but it’s not laughable; it’s just sad.

Whenever I browse with the TOR browser, it's been 100% impossible for me to verify myself as a human even if all my answers are correct. I think they need to fix this bug, or at least give a message that the CAPTCHA won't be solved so we no longer waste our time.

Their No CAPTCHA's are very rare for me when I'm browsing logged in to my personal google account under the same session, on a normal browser.

They can be confident I'm not some kind of a bot, yet they still require me to solve on average two different tests to train their "AI".

Re: Why Captchas have gotten so difficult

#67
post #16

For Google ReCaptcha, simply install the Buster addon, it solves the captcha for you via speech-to-text. For captcha's in general, I think we should stop pretending that we can prevent bot traffic from a dedicated attacker without annoying the users. A simple captcha from the 2000's (the ones with lines over a word or number of letters and numbers), should be good enough to hold off basic script kiddies. Same for a b…

Google won't even serve the audio captcha in the first place to many users who use firefox, adblockers, etc.

Re: Why Captchas have gotten so difficult

#68

And I SUCK at these to the point where I think I’m not getting the rules of the game. For example, for the one with traffic lights: Am I supposed to just mark the light bulbs or also the poles and beams?

You're doing it right. Google is gaslighting you; lying and telling you you've failed challenges when you actually solved them correctly. They do this to punish users who opt out of the google 'ecosystem' by not having a google account, not using chrome, using adblockers, etc. The proof of this assertion comes when you manage to enable the noscript version of reCAPTCHA (which is only available on sites that have opte…

I've seen those ones too, and was planning on writing a filter that replaces the "normal" ones with the noscript one, on the assumption that it was just someone not copying in a "..." fragment, but since you mention "is only available on sites that have opted to use the lowest security setting", I suspect that won't work.

Accessibility guidelines used to mandate that content was accessible without JS, which may be the reason why the noscript version exists, but it seems the latest revision has unfortunately removed that requirement. No, I will not run arbitrary code on my computer just to access your site...

Re: Why Captchas have gotten so difficult

#69

And I SUCK at these to the point where I think I’m not getting the rules of the game. For example, for the one with traffic lights: Am I supposed to just mark the light bulbs or also the poles and beams?

This has tripped me up as well. I’m somewhat sure now that only the bulbs matter. I have also had higher success rates when not marking tiles that contain only a very small part of what they are asking for. They are sort of teaching me to better approximate more careless people.

Re: Why Captchas have gotten so difficult

#70
Is it not monopolistic behavior that Google favors their own customers in their captchas?

I hope the EU fines Google for leveraging their security library prevalence to coerce people to use Chrome and/or open Google accounts.

I also wonder if that’s GDPR compliant: unless you accept Google’s data collection terms on GMail and/or Chrome products, they will use their position as security authority to degrade your browsing experience on third party sites.

Post reply on HN