Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

331–340 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#331

Earlier quoted context omitted.

You could either stop using these services or (as I suspect) you find them too valuable to dismiss entirely quarantine them to a VPN/incognito interaction in less time than it took to type that comment. I don’t want to single you out personally but there’s a broad trend on HN of bitter-sounding commentary on the surveillance powers of these companies by people who can easily defeat any tracking that it’s economical f…

How about our friends and family? Should we configure a VPN for them too? Btw the argument you just made applies to any form of surveillance or censorship. Just because your can still find functional VPN services for China, is China's great firewall OK? And what happens when web services start blocking VPNs? Netflix does it quite successfully. And I'm sure Cloudflare could provide such a service for free.

I’m not making a moral argument for the surveillance state, I wear Curve25519 on one arm and the word “citizenfour” on the other.

I agree that there is a vast and almost impossible to regulate overreach by these companies. Your argument is extremely compelling.

But when HN users complain about being spied on I smell a FAANG rejection letter.

Re: Google’s new reCAPTCHA has a dark side

#332

Earlier quoted context omitted.

Human moderation and ad-hoc heuristics seems to make the difference at Reddit too, rather than the CAPTCHA at registration.

I get a recaptcha when trying to sign up for a new account: https://i.judge.sh/Flutter/45DyMRuL.png maybe this is related to some other heuristic they're using for determining whether or not to show recaptcha (although this is in a no-extension Chrome on a residential IP address).

Right, they have that at registration but it's either superfluous or it only catches the really easy stuff because they rely on an army of human moderators who spend all day cleaning up after bad actors able to click buses.

Re: Google’s new reCAPTCHA has a dark side

#333

Earlier quoted context omitted.

You could either stop using these services or (as I suspect) you find them too valuable to dismiss entirely quarantine them to a VPN/incognito interaction in less time than it took to type that comment. I don’t want to single you out personally but there’s a broad trend on HN of bitter-sounding commentary on the surveillance powers of these companies by people who can easily defeat any tracking that it’s economical f…

> Again, you’re not likely part of that group, but seriously who hangs out on HN and can’t configure a VPN? Recaptcha tracks users / devices, not IPs. A VPN won't help, it'll only lower your score. At that point: not allowing them to track you just means you can't use large parts of the web. "You don't want that GPS tracker installed into your skull? Well, we won't force you, of course, but public transportation, gov…

Wild speculative hyperbole hurts the case of people like you and I who care about doing something positive on the ground today.

Re: Google’s new reCAPTCHA has a dark side

#334

Google has been doing the same with reCAPTCHA v2 [1]. They are aware of the legal risk of outright blocking users from accessing services, so reCAPTCHA v3 contains no user facing UI, Google merely makes a suggestion in the form of a user score, so the responsibility to delay or block access and the legal liability that comes with it falls on websites. reCAPTCHA v2 is superseded by v3 because it presents a broader opp…

If the v3 script is supposed to be installed on all pages of the website, in order to track the user's actions, I don't understand how that can be done without explicit user consent under GDPR.

Re: Google’s new reCAPTCHA has a dark side

#335
post #78

Earlier quoted context omitted.

Most sites use reCAPTCHA to protect against bot registrations, sometimes targeted to their specific registration system. Any simple solution would defeat the purpose of a CAPTCHA.

Would it though? If each system was unique and rotated through different types of challenges, the bot would have to be custom tailored to handle every challenge type. i.e. free form questions, count the gray dots (vision impaired friendly), math questions, play tic-tac-toe and get a stalemate, ascii hang-man ... I could think of hundreds of different challenges. The bot would have to constantly adapt and the bot deve…

The spammers can also use cheap overseas labor to update the bots.

Re: Google’s new reCAPTCHA has a dark side

#336
post #327

Earlier quoted context omitted.

You could either stop using these services or (as I suspect) you find them too valuable to dismiss entirely quarantine them to a VPN/incognito interaction in less time than it took to type that comment. I don’t want to single you out personally but there’s a broad trend on HN of bitter-sounding commentary on the surveillance powers of these companies by people who can easily defeat any tracking that it’s economical f…

> You could either stop using these services or ... Are you serious? Have you tried not using their services? Try blocking Google Analytics, Tag Manager, ReCaptcha, fonts, gstatic,... What you will see is that you can no longer access much of the Internet. Want to participate in StackOverflow? Good luck if you block Google. My beef is not with them trying to find my data when I'm on their site(s). They are however ev…

Unfortunately politically acceptable regulation only deters new ventures because it makes the costs of compliance too high.

The right vehicle for this is antitrust, but if you think you can sell that in this climate then I’ve got a great deal for you on the London Bridge.

Re: Google’s new reCAPTCHA has a dark side

#337
post #299

Earlier quoted context omitted.

> It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). That may be the case for some people, but that is not my complaint, nor that of many folks I know. I simply don't care how FB, Google and other surveillance outfits mak…

You could either stop using these services or (as I suspect) you find them too valuable to dismiss entirely quarantine them to a VPN/incognito interaction in less time than it took to type that comment. I don’t want to single you out personally but there’s a broad trend on HN of bitter-sounding commentary on the surveillance powers of these companies by people who can easily defeat any tracking that it’s economical f…

This is a ridiculous argument. Advanced technical competency can not be a prerequisite for maintaining personal privacy.

Re: Google’s new reCAPTCHA has a dark side

#338
post #5

You can view your reCaptcha V3 score here: https://recaptcha-demo.appspot.com/recaptcha-v3-request-scor... I get .7 on my iPhone, I’m guessing that my liberal use of Firefox containers and the cookie auto-delete extension on my desktop will give me a much lower score and cause me to have to jump through extra hoops at websites that implement it, just like the reCaptcha V2 does. Edit: I also got 0.7 on Firefox with st…

[deleted]

Re: Google’s new reCAPTCHA has a dark side

#339

So this is probably a bit off topic, but why don't more site owners just create their own unique anti-spam system? In my opinion, if they were simpler, yet all unique, there would be less bots that could mass spam and privacy would be improved. Even something as simple as a question: "How many legs does a spider have?" ____ And then cycle through different types of free form questions of things that most people shoul…

Forum software like vBulletin and Invision often has this feature built in, and I've used it on a forum I help run. Unfortunately, after writing four or five custom questions, I soon found server logs showing spam bots blowing through the questions in seconds -- I suspect that since this is a common enough strategy, it's worth their time to pay someone $0.10 to pick the correct answer, then save the question and answ…

I don't remember what forum software it was, but they'd render a number or word using all periods (kind of like ASCII art) and ask you to enter it in a text field. I wonder how well that worked.

Re: Google’s new reCAPTCHA has a dark side

#340
post #299

Earlier quoted context omitted.

> It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). That may be the case for some people, but that is not my complaint, nor that of many folks I know. I simply don't care how FB, Google and other surveillance outfits mak…

You could either stop using these services or (as I suspect) you find them too valuable to dismiss entirely quarantine them to a VPN/incognito interaction in less time than it took to type that comment. I don’t want to single you out personally but there’s a broad trend on HN of bitter-sounding commentary on the surveillance powers of these companies by people who can easily defeat any tracking that it’s economical f…

> You could either stop using these services or

How do you stop using a service when you have little or no indication that it does something like this before hand, and afterwards the privacy is already gone?

If I use a site and view my profile page and the url contains aa account id or username and some google or facebook analytics is loaded, or a like button is sitting somewhere, how am I to know that before the page is loaded? What if I'm visiting the site for the first time after it's been added?

It doesn't even matter if I have an account on Google or Facebook, they'll create profiles for me aggregating my data anyway.

> quarantine them to a VPN/incognito interaction

Which does very little. I spent a few hours this morning trying to get a system non-unique on panopticlick, but the canvas and WebGL hashing is enough to dwarf all the other metrics. There are extensions to help with that, but for the purpose I was attempting, were sub-optimal (and the one that seemed to do time-based salting of the hashes wasn't working right).

So, I don't have any confidence that a VPN and incognito really does much at all.

Post reply on HN