Live data from Hacker News

Why can’t a bot tick the 'I'm not a robot' box?

quora.com

291–300 of 647 posts

Re: Why can’t a bot tick the 'I'm not a robot' box?

#291
post #80

I feel a sense of dread whenever I see this box. Is it going to let me through, or am I going to spend the next few minutes futilely clicking signs and lights, only to give up and leave the site?

> only to give up and leave the site?

Personally, I've reached the point where this is the first thing that I do. If a site is presenting a CAPTCHA (especially one run by Google) to me, then 90% of the time, that's a site I'm better off avoiding anyway.

That last 10% can be infuriating, though, and I certainly won't feel positively about it.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#292

Earlier quoted context omitted.

I'm getting closer to doing that. Lately, I check the box, and if I'm presented with images, I leave. I have also trained myself to wait a few seconds before clicking the box, which seems to help assert my humanity.

Wait til it's standing between you and your bank account.

It can't block the doorway into the bank branch.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#293
post #262

Earlier quoted context omitted.

That's what ReCaptcha always was... it was originally a known and another unsure text blurb from scanned books/text documents. Now it's street signs etc.

Isn't there a good OSS alternative for ReCaptcha?

The Turing test. Have one of your ops chat with them to see if they’re a bot.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#294
post #282
post #247

Earlier quoted context omitted.

Were you using an unusual user agent or a VPN or something?

I got banned from Twitter within 5 Minutes of trying to figure out the user interface, and my best guess as to why it happened is that their anomaly detection is overfit to their existing users. So when a new user starts exploring randomly instead of directly going to look at ads, they're behaving much more like a scraper than what the system has learned to recognize as a normal user.

I think that's very unlikely. There are over 100,000 new accounts created on Twitter every day so we would expect a large and frequent amount of bans if what you are saying were true. Furthermore most Twitter visitors don't have accounts so it would be pretty foolish to base their anomaly detection on a metric that most of their visitors fail.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#295

Why wouldn't a bot just use a proper browser (not headless), detect the "not a robot" box at the pixel level, and click on it using browser automation or some mouse movement script? At today's level of bot sophistication this seems almost trivial. Sure it might cost more in resources, but I doubt it's economically prohibitive when you're making at least a cent per fraudulent ad click?

I believe the Quora answer is putting a little too much faith in Google using "fair" factors when determining if a client is a robot.

I'm sure it plays a part in determining "hijacked extension" activity vs human activity, but it's likely that the majority of the decision is how much recent activity your signed-in Google account has, whether or not you're signed in on Chrome (Firefox has a lot more stories of recaptcha challenges), and maybe even if you have Google WiFi or Google Home linked to your account. I wouldn't be surprised if they purely whitelist accounts that subscribe to Google Fiber or Fi.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#296
post #9

The box has made browsing using TOR insufferable! It fusses and makes me click storefronts and traffic lights until I run out of patience and close out of whatever webpage I was trying to visit. I assume it has to do with a lack of Google cookies on the browser, essentially punishing me for trying to protect my privacy.

The worst thing is that Cloudfare is using ReCaptcha, and it's everywhere. The internet is broken at this point.

CloudFlare at least is using a thing where you only have to solve a ReCaptcha once, and then you can cryptographically prove you did, without compromising anonymity.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#297

Earlier quoted context omitted.

I've been thinking about this a lot lately. Where is our compensation? It's our time and brain power training Google's AI that will one day be sold back to us. I'm really not into this.

You might be interested what https://hcaptcha.com is doing.

I don't really understand the case where you'd use this.

First, it seems tacky scrounging for peanuts from the users' captcha work. Or it's like a product/services website showing Adsense ads. It's a cheapening message to send.

Second, since you make more money from more captcha volume, you're incentivized to maximize your use of captcha which is at odds with every complaint in this comments section about captcha. Most sites only use captcha to gate low-volume actions like register/login (e.g. HN).

They created their own Ethereum token too which always puts a bad taste in my mouth these days.

Finally, it doesn't address the upstream complaint that someone else is profiting off the user's "work" rather than the user. Though I don't find that complaint very reasonable. And a tiny fraction of a cent sounds about right. The truth is that users benefit from anti-abuse systems. The number of bots that HN's recaptcha on register/login has stopped is worth that tiny fraction of a cent to most users.

Re: Why can’t a bot tick the 'I'm not a robot' box?

#298
post #175

Earlier quoted context omitted.

Are you kidding? Your compensation is all the free apps you get (Gmail, Maps, etc.) You’ll rarely see a Captcha for a paid product once they have your cc info.

I get most of my captchas while attempting to access products I've paid for already (very few at purchase time).

Yeah, that is what annoys me. “Thanks for paying us to use our product. Now do free work for us for the privilege of using the product you already paid for!”

Re: Why can’t a bot tick the 'I'm not a robot' box?

#300
post #274
post #26

Earlier quoted context omitted.

Turn off javascript, mostly. To hide your ip you need to use a VPN.

Turn off JavaScript... And almost any site you visit will be broken.

I use NoScript, and only allow very specific scripts to run. There are sites that won't work without allowing a metric ton of sketchy scripts to run, but those are both a minority and tend to be sites run by major companies -- so I can ignore them without loss.
Post reply on HN