Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

241–250 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#241
> Because reCaptcha v3 is likely to be on every page of a website, if you’re signed into your Google account there’s a chance Google is getting data about every single webpage you go to that is embedded with reCaptcha v3—and there many be no visual indication on the site that it’s happening, beyond a small reCaptcha logo hidden in the corner.

There’s a potentially bigger risk being overlooked. Google can execute first-party script. This means they get every user’s session credentials and can freely impersonate that user. So can all the other trackers in use.

I don’t understand how anyone thinks this is remotely okay.

Re: Google’s new reCAPTCHA has a dark side

#242

Google has been doing the same with reCAPTCHA v2 [1]. They are aware of the legal risk of outright blocking users from accessing services, so reCAPTCHA v3 contains no user facing UI, Google merely makes a suggestion in the form of a user score, so the responsibility to delay or block access and the legal liability that comes with it falls on websites. reCAPTCHA v2 is superseded by v3 because it presents a broader opp…

Your comment adds a lot to the conversation, so I don’t want to be more contrary than necessary. It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). Much like the highest information-gain feature for the future price of a…

Can you provide any evidence that personal data doesn't improve CTR prediction for companies like Google/Facebook?

You state yourself that Google/Facebook publicly claim to advertisers that personal data improves CTR prediction. So I have a hard time believing that personal data isn't useful.

Re: Google’s new reCAPTCHA has a dark side

#243

Earlier quoted context omitted.

Ublock Origin + NoScript on FF 60.7.2esr and got 0.9 as well. [edit] tried in a private window and got the same score.

Does it change if you set privacy.resistFingerprinting=true in about:config?

FF private window + UBlock + Resist Fingerprinting = 0.1 for me

In my main FF window with UBlock + Resist Fingerprinting, logged into a ton of Google accounts, I also got 0.1

Going to guess that without fingerprinting data they are probably going to give you a 0.1.

Re: Google’s new reCAPTCHA has a dark side

#244
post #5

You can view your reCaptcha V3 score here: https://recaptcha-demo.appspot.com/recaptcha-v3-request-scor... I get .7 on my iPhone, I’m guessing that my liberal use of Firefox containers and the cookie auto-delete extension on my desktop will give me a much lower score and cause me to have to jump through extra hoops at websites that implement it, just like the reCaptcha V2 does. Edit: I also got 0.7 on Firefox with st…

With Firefox fingerprint resisting turned on and with Ublock Origin/UMatrix, I get a score of 0.1. And I'm not even on a VPN; I'm sure on my home network I'd have an even lower score. To me, it feels like Google's entire strategy behind reCaptcha is to make it harder to protect your privacy. We've basically given up on the idea that there are tasks only humans can do, and to me V3 feels like Google openly saying, "Yo…

Your privacy isn't nearly as important as you think, and as long as you continue to overvalue it, you'll continue to be unwilling to trade it for convenience.

That's on you, not Google.

Re: Google’s new reCAPTCHA has a dark side

#246

Earlier quoted context omitted.

> That means Google services are entirely off-limits over Tor If only it was Google services alone. CloudFlare loves serving up a ReCAPTCHA for Tor users before they can even passively read site contents. That hugely expands the damage done.

Install the PrivacyPass Firefox or Chrome extension. It was developed by Cloudflare, Firefox, and Tor in partnership. It has you answer a ReCAPTCHA and using some crypto magic, generate a bunch of CAPTCHA bypass tokens that can't be traced to your specific computer. https://support.cloudflare.com/hc/en-us/articles/11500199265... https://blog.cloudflare.com/cloudflare-supports-privacy-pass... https://blog.cloudflare.c…

Does not work with Tor.

The plugin requires "privacy passes". Those passes can be obtained by solving captchas, but when trying to do so, one is greeted with this message about being blocked: https://i.imgur.com/qXJfl6J.png

Re: Google’s new reCAPTCHA has a dark side

#247

Earlier quoted context omitted.

Your comment adds a lot to the conversation, so I don’t want to be more contrary than necessary. It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). Much like the highest information-gain feature for the future price of a…

Anectotally, I keep no browser history and do not feel my experience with captchas is different than a user who does.

I would contend that the reason for that is that none of the engineers involved get paid more if that experience is different.

Re: Google’s new reCAPTCHA has a dark side

#248

Earlier quoted context omitted.

Your comment adds a lot to the conversation, so I don’t want to be more contrary than necessary. It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). Much like the highest information-gain feature for the future price of a…

Can you provide any evidence that personal data doesn't improve CTR prediction for companies like Google/Facebook? You state yourself that Google/Facebook publicly claim to advertisers that personal data improves CTR prediction. So I have a hard time believing that personal data isn't useful.

I’m already on a shaky limb being so candid about how the business actually works. If you want the opinion (albeit a little dated but still relevant) of someone who doesn’t give a fuck about who the truth pisses off I recommend a book called “Chaos Monkeys” written by a former YC (exited) founder.

Re: Google’s new reCAPTCHA has a dark side

#249
post #81

Earlier quoted context omitted.

reCAPTCHA on VPN is difficult, but on the Tor network, they are downright impossible. I've never been able to get past it, even after a few dozen painful attempts. That means Google services are entirely off-limits over Tor, even Search, which is a disgrace.

You can hardly blame anyone for blocking Tor traffic. You might not be using it for abuse but a large volume of abuse originates from it.

>You can hardly blame anyone for blocking Tor traffic.

Yes I can and do. It's bad enough that some websites won't let you do certain things over Tor, but preventing access to the website entirely is unacceptable. I made this account and comment entirely over Tor.

I don't see how it's okay to block Tor. That generic claim is made, but how are your spam measures doing if you couldn't handle Tor spam?

>You might not be using it for abuse but a large volume of abuse originates from it.

There is infinitely more ''abuse'' coming from Google, and yet it seems most every page I visit contains Google malware.

On principle, I hold the idea that Tor should be a first-class citizen and not disadvantaged in any way. Notice that Google's ''HTTP/3'' is over UDP, which Tor doesn't work with; I don't find that a coincidence.

Re: Google’s new reCAPTCHA has a dark side

#250

Earlier quoted context omitted.

idk, recaptcha solvers are about $3/1000 or something. That sounds like a very low hurdle to mess with most websites if that's their line of defense.

We still lock our car doors even though you can jimmy them open in a few seconds.

Yeah, but you won't build a business on that, you'll add GPS trackers, make renters show you their drivers licenses etc. A captcha isn't "wrong" in general in my mind, it's just not something you add and you're all done, and it shouldn't be your first line of defense. It can be part of a multi-pronged anti-abuse strategy, but it's a very tricky part: it doesn't offer a lot of protection but creates a lot of friction for actual, legit users. Running a DNA test on somebody can be a good way to verify their identity. But asking for their ID card and looking at the picture is a lot quicker, cheaper and less intrusive.

I don't see captchas a lot, because I'm not frequenting sites that use them. A friend of mine apparently does, so often that he pays for a captcha solver while he's sitting in front of his computer. He just can't be bothered to play Google's mind games, so he'd rather pay a few cents a day to not deal with it.

We've come to the point where humans are paying for services that were created for bots so they can bypass technological hurdles that were meant to tell humans from bots.

Post reply on HN