Earlier quoted context omitted.
I've seen multiple comments suggesting HN uses ReCAPTCHA, but I have never encountered it myself, and I even have Javascript disabled and login through 'anonymous' IPs such as tor, so I'm unsure what these users could be doing that is 'worse' to trigger ReCAPTCHAs. If most users don't even know that ReCAPTCHA is used, that's a good sign that it is being used as little as possible, though.
Same here. I only log in through Tor and I'd never have imagined HN uses ReCAPTCHA if it wasn't for people suggesting that.
You probably don’t need ReCAPTCHA
131–140 of 246 posts
Re: You probably don’t need ReCAPTCHA
#132Earlier quoted context omitted.
So you force your users to consent to sharing all of their data with Google? That’ll teach ‘em.
"all their data" is a bit much, isn't it? ReCAPTCHA gives Google exactly one datum, namely the user's visit to the one page it is on. And I would even hazard a guess that the TOS specify that Google will not retain/link that information, considering that's how Analytics is run.
Re: You probably don’t need ReCAPTCHA
#133Earlier quoted context omitted.
So you force your users to consent to sharing all of their data with Google? That’ll teach ‘em.
"all their data" is a bit much, isn't it? ReCAPTCHA gives Google exactly one datum, namely the user's visit to the one page it is on. And I would even hazard a guess that the TOS specify that Google will not retain/link that information, considering that's how Analytics is run.
Re: You probably don’t need ReCAPTCHA
#134In my experience, the biggest issue I run into is targeted botnet brute force attacks. In cases like these, someone loads up a huge botnet, a downloaded list of hacked usernames and passwords, and tries every single combination hoping to find a reused username/password combination. In these cases, it is almost always extremely targeted. Log correlation has helped quite a bit, but it is still very painful since they a…
Re: You probably don’t need ReCAPTCHA
#135Earlier quoted context omitted.
As the commenter said, they rotate IPs. It is not that easy. I've also been on the other side of a sophisticated attack like this. The really savvy adversaries do the following, at least: 1. Rotate through several thousand to several hundred thousand noncontiguous, geographically distributed, residential IP addresses, 2. Associate each IP address with a single user agent and suite of cookies, 3. Associate each IP add…
Sounds like big operations like that should have been putting people into jail
Re: You probably don’t need ReCAPTCHA
#136Re: You probably don’t need ReCAPTCHA
#137Earlier quoted context omitted.
So you force your users to consent to sharing all of their data with Google? That’ll teach ‘em.
What's an alternative that works at scale, though? It's easy to say "this is bad for these reasons, don't use it" while ignoring that there's not really better options once you get targeted.
You can use common knowledge or simple ambiguity of language. You can use simple math arithmetic, written in properly obfuscated html. and randomly generated on each page load. You can use custom question about the content of the article (helps with informed answers).
On a small blog of mine just one question with one answer on the contact form prevented all spam for over 5 years already although it would be trivial to exploit in a targeted attack.
Targeted attacks are rare unless your captcha protects a juicy target that is worth a targeted attack at some point.
Re: You probably don’t need ReCAPTCHA
#138Re: You probably don’t need ReCAPTCHA
#139“It’s worth noting how much easier it is to successfully solve ReCAPTCHAs when the user is logged into their Google account”. Well to me it makes absolute sense as Google knows that the logged in user is a human. This article is just following the current trend all Google is bad.
Re: You probably don’t need ReCAPTCHA
#140Literally none of those alternative methods listed worked on my moderate traffic wiki. Recaptcha (and before it went away, identify the dogs or cats from Microsoft) is literally the only solution that stopped us from getting spammed. I wonder how much experience the author of this article really has in this domain. Recaptcha has saved the internet as far as I'm concerned.
[1] https://esolangs.org/wiki/Special:CreateAccount "Which number does this Befunge code output: [...]"