Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

281–290 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#281
post #211

Earlier quoted context omitted.

I was amused that Elizabeth Warren's campaign site wouldn't display the content for me unless I permitted scripts from google.com (w/ umatrix) since she is promoting breaking up google.

Although you can be pro break-up-Google while using one, or even many, of their services. So I don't really see the amusement.

Reminds me of Matt Bors' Mister Gotcha: https://thenib.com/mister-gotcha

Re: Google’s new reCAPTCHA has a dark side

#282

Earlier quoted context omitted.

Install the PrivacyPass Firefox or Chrome extension. It was developed by Cloudflare, Firefox, and Tor in partnership. It has you answer a ReCAPTCHA and using some crypto magic, generate a bunch of CAPTCHA bypass tokens that can't be traced to your specific computer. https://support.cloudflare.com/hc/en-us/articles/11500199265... https://blog.cloudflare.com/cloudflare-supports-privacy-pass... https://blog.cloudflare.c…

Does not work with Tor. The plugin requires "privacy passes". Those passes can be obtained by solving captchas, but when trying to do so, one is greeted with this message about being blocked: https://i.imgur.com/qXJfl6J.png

Try rebuilding your Tor circuit when this happens.

https://tb-manual.torproject.org/managing-identities/

Re: Google’s new reCAPTCHA has a dark side

#283
post #163

Earlier quoted context omitted.

You are required to use reCAPTCHA on the California DMV website when making appointments and other functions. https://www.dmv.ca.gov It will also log you in to google on the first page. Additionally, the stations at the DMV all have tablets on stands, showing Google logins for some operations.

When did this start? I used the DMV page without a google account in February with no issues, and the local DMV has no tablets as of May.

It's been quite a while. At some point in the last year maybe with google blocked, it became impossible to register for a DMV appointment. Filling in the forms and pressing submit ended up with an unhelpful "Server Unavailable" and "Call xxx-xxx-xxxx during business hours"

Re: Google’s new reCAPTCHA has a dark side

#284

Earlier quoted context omitted.

I admit that I inferred the proposed intent for grabbing maximum personal data, but if you’re interested in anecdotes from the trenches: no one below senior director level gets a couple million in stock for any other reason than they pushed CTR by a few basis points. What I was trying to say is that seen through the lens of mechanism design no one is incentivized to query the like button table because there’s no upsi…

I'm not sure I understand correctly. Are you saying that all the personal user data is in reality not as valuable as everyone says it is? That is, all those megacorps are collecting terabytes of mostly useless data? Then why is this data collected and archived in the first place?

I was never involved in those decisions but I suspect that when you’ve got a multi-dollar CPM and your biggest pain in the ass is pouring concrete and running power fast enough that a few PB of spinning disks are cheap enough that you hang onto it in case you ever find a way to make it useful.

Re: Google’s new reCAPTCHA has a dark side

#285
post #209

I'm torn on this. reCAPTCHA v2 (mostly useless[0]) and v3 function largely on browser fingerprinting plus a few other heuristics (e.g., whether or not you have a Google cookie). Any meaningful privacy measures to resist fingerprinting end up with a low reCAPTCHA score. I personally run into a wall on most sites using it. That said, it's one of the most effective means of combatting automated spam and credential stuff…

It is used irresponsibly. A responsible spam protection system should allow every spam (and consequentially responsible user) from an ISP. If a ISP shows sign of abuse, then show Captcha or other system that will block some spam while also blocking some valid users . This is a evil-for-the-greater-good solution. Do not fool yourself into thinking this is a solution (i.e. without caveats) Impacted users can complain t…

lots of salty people in denial about being part of the problem ;)

Re: Google’s new reCAPTCHA has a dark side

#286
post #209

I'm torn on this. reCAPTCHA v2 (mostly useless[0]) and v3 function largely on browser fingerprinting plus a few other heuristics (e.g., whether or not you have a Google cookie). Any meaningful privacy measures to resist fingerprinting end up with a low reCAPTCHA score. I personally run into a wall on most sites using it. That said, it's one of the most effective means of combatting automated spam and credential stuff…

It is used irresponsibly. A responsible spam protection system should allow every spam (and consequentially responsible user) from an ISP. If a ISP shows sign of abuse, then show Captcha or other system that will block some spam while also blocking some valid users . This is a evil-for-the-greater-good solution. Do not fool yourself into thinking this is a solution (i.e. without caveats) Impacted users can complain t…

It seems that your suggestion is that ISP is a good signal for detecting spam, but it's not obvious to me that this is true. For example a site targeted by a botnet could be hit with traffic from a wide range of otherwise legitimate looking ISPs, in which case you're going to be getting a lot of spam on your website.

Re: Google’s new reCAPTCHA has a dark side

#287
post #129
post #85

Earlier quoted context omitted.

This looks like a RNG: I got 0.7, 0.9, and 0.1 successively. It can't make up its mind whether I'm almost certainly not a bot (0.9) or almost certainly a bot (0.1)?

Perhaps the rapid, repeated identical requests outweighed the initial factors which gave you a positive response

Might very well be. I also get errors on hacker news about "can't process requests that fast". When asking about it (initially because I thought votes didn't work randomly), the limit is a few requests per second. Turns out I click faster than that, either by reading a whole comment thread and making up my mind whose comments were most helpful (to upvote all at once) or by navigating too fast.

Re: Google’s new reCAPTCHA has a dark side

#288
post #85

Earlier quoted context omitted.

This looks like a RNG: I got 0.7, 0.9, and 0.1 successively. It can't make up its mind whether I'm almost certainly not a bot (0.9) or almost certainly a bot (0.1)?

from the link >the score returned here is not a reflection on your Google account or type of traffic I got random scores as well. It looks like this is just a sample of the data structure that the service returns, not the actual score.

That would be a useless site, but that's not how I read it. I understand it as "this is not that Google thinks your account is a bot, it's that this request might be made by a bot. And since you didn't use this site as a normal website, it also doesn't score your type of traffic, just this one request". You might be right, but it really does seem to be doing a request to their API.

Re: Google’s new reCAPTCHA has a dark side

#289
post #259

Stupid question: why do companies care so much about bots to the point of degrading the customer experience significantly? I can understand for things like public forums. But like why would an ecommerce website ever put a captcha between you and your order (or a news website)?

For example: - bots sign up with email addresses that are owned by other people that don't appreciate your welcome/activation/etc. mails. - all that automatically generated data can start to hurt performance. Especially on a smaller site, having millions of useless users in your database can slow things down significantly.

That's one thing, but like why would the FT put a captcha on the login page. I am not signing up. I just want to access a website I already paid for. This is just terrible UX.

Re: Google’s new reCAPTCHA has a dark side

#290
post #102

Earlier quoted context omitted.

Indeed, if they need to pay, there is no need for a CAPTCHA. As for responding to discussions, sure, you'd ban any human that posts spam the same as any bot. However, bots can spam your site faster than your human moderators can keep up with, so by using a CAPTCHA, only humans can post (ideally, of course), and thus moderators can keep up. As a security consultant, it is not uncommon to recommend a CAPTCHA for things…

> if they need to pay, there is no need for a CAPTCHA > As a security consultant Hm? How does a security consultant not know that credit card numbers can be stolen and used by bots?

Sure, I know credit cards exist and that the numbers are stolen because they're so trivially easy to abuse, but payment systems are not very related to my work. I very rarely come across a product where I have to test payment features, and when I do, it's out of scope. Either the payment is handled by some third party (the usual case), or it has already been tested years ago and they're now asking to test some new feature (all other cases).

More typical projects are testing traffic filtering solutions (firewall-like), blockchain startups (those are the worst), back-end (no payment) or b2b (contract-based payment, not online) applications... Even in the months that I was consulting at a bank, I never touched any sort of money system, there were a thousand other applications, services, websites, infrastructure things, and mobile apps to test. To give you a random example, they wanted to give people advice when buying a house through an app (where the final screen goes "and that's where $bank comes in: we can finance all this!"), so they had some external company prototype an app that was riddled with bugs in the login system. Or some internal service that POSTs data from one system into another. Or some API endpoint used for statistics. Etc.

So the cases that I see are as a consumer, where I pay either by bank transfer (logging into my own bank's website), via iDeal (which also redirects you to your own bank's website to complete the transaction, but that one is instant instead of having to wait a working day), or sometimes via PayPal if that is the only option (I guess paypal do their own bot detection? No idea). So from my perspective, when I paid for something, the money is in the hands of the merchant and only customer support or a lawsuit would get it back.

Post reply on HN