Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

361–370 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#361

Earlier quoted context omitted.

> Again, you’re not likely part of that group, but seriously who hangs out on HN and can’t configure a VPN? Recaptcha tracks users / devices, not IPs. A VPN won't help, it'll only lower your score. At that point: not allowing them to track you just means you can't use large parts of the web. "You don't want that GPS tracker installed into your skull? Well, we won't force you, of course, but public transportation, gov…

Wild speculative hyperbole hurts the case of people like you and I who care about doing something positive on the ground today.

It is not "wild speculative hyperbole" not to give the benefit of the doubt to companies that have repeatedly demonstrated that they are not entitled to the benefit of the doubt.

Re: Google’s new reCAPTCHA has a dark side

#362
post #335

Earlier quoted context omitted.

The spammers can also use cheap overseas labor to update the bots.

I would be honored to help them feed their families. It would be a fun game of cat and mouse. Based on discussions here, it sounds like people have already automated Google captcha. I will go ahead and work on a few of my own and see what happens. Maybe we can turn this into a public competition.

Looks like you have a great business plan at hand. Beat Google with a potentially superior product and help employ some people in developing countries!

Re: Google’s new reCAPTCHA has a dark side

#363

Earlier quoted context omitted.

I’m not making a moral argument for the surveillance state, I wear Curve25519 on one arm and the word “citizenfour” on the other. I agree that there is a vast and almost impossible to regulate overreach by these companies. Your argument is extremely compelling. But when HN users complain about being spied on I smell a FAANG rejection letter.

People care about others, not just themselves.

Unless the topic is affordable housing, that is.

Re: Google’s new reCAPTCHA has a dark side

#364

Google has been doing the same with reCAPTCHA v2 [1]. They are aware of the legal risk of outright blocking users from accessing services, so reCAPTCHA v3 contains no user facing UI, Google merely makes a suggestion in the form of a user score, so the responsibility to delay or block access and the legal liability that comes with it falls on websites. reCAPTCHA v2 is superseded by v3 because it presents a broader opp…

Your comment adds a lot to the conversation, so I don’t want to be more contrary than necessary. It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). Much like the highest information-gain feature for the future price of a…

I am falling behind replying to all the comments that this has generated.

For the record I am inked all over with anti-equation group stuff: I agree that these companies are too big and powerful (and I would know).

I just don’t see a solution with the present judiciary. If anyone has a bright idea my email is in my profile.

I will thank you all in advance for not shooting the messenger.

Re: Google’s new reCAPTCHA has a dark side

#365

Earlier quoted context omitted.

> You could either stop using these services or How do you stop using a service when you have little or no indication that it does something like this before hand, and afterwards the privacy is already gone? If I use a site and view my profile page and the url contains aa account id or username and some google or facebook analytics is loaded, or a like button is sitting somewhere, how am I to know that before the pag…

I assure you that a clean browser and IP will break any surveillance that I know about.

No, a clean browser and IP with the combination of what fonts I have installed, how my video card renders a canvas and WebGL instance (which may be affected not just by the video card you have, but the driver version used with it), my screen size, and a few other system level items that come through may or may or may not be enough to uniquely identify you. Along with linking to a prior profile if you screw up one time (or load a URL that has identifying information they can use), and you're busted.

So, sure, a clean browser and IP and never logging into a site you're previously visiting might be enough, but who does that, and doesn't that halfway defeat the purpose?

Re: Google’s new reCAPTCHA has a dark side

#366

Earlier quoted context omitted.

You can hardly blame anyone for blocking Tor traffic. You might not be using it for abuse but a large volume of abuse originates from it.

>You can hardly blame anyone for blocking Tor traffic. Yes I can and do. It's bad enough that some websites won't let you do certain things over Tor, but preventing access to the website entirely is unacceptable. I made this account and comment entirely over Tor. I don't see how it's okay to block Tor. That generic claim is made, but how are your spam measures doing if you couldn't handle Tor spam? >You might not be…

https://blog.cloudflare.com/the-trouble-with-tor/

> like all IP addresses that connect to our network, we check the requests that they make and assign a threat score to the IP. Unfortunately, since such a high percentage of requests that are coming from the Tor network are malicious, the IPs of the Tor exit nodes often have a very high threat score.

Re: Google’s new reCAPTCHA has a dark side

#368
post #356

Earlier quoted context omitted.

From the service provider and devops perspective I find reCAPTCHA beautiful. It brings down malicious form fill, form spam, user creation and password brute forcing rates. Also as a VPN user, I found out that migrating to more expensive, higher grade VPN, solved a lot of my problems. In the end it is not privacy, not your VPN that matters from the service provider point of view. It matters that your IP address is spe…

I don't even use a VPN and have lots of issues solving google's captcha...

Potential other causes

- Your ISP is a source of a lot of malicious traffic

- You have some browser extension or other adjustments that makes it harder to analyse you as a genuine web browser

For example, using a browser automation like Selenium testing triggers "hard" reCAPTCHA. Not sure if this because of some automated API that Selenium exposes, or just because your browser profile looks virgin (no cookies) without any prior reCAPTCHA solves.

Re: Google’s new reCAPTCHA has a dark side

#369
post #211

Earlier quoted context omitted.

I was amused that Elizabeth Warren's campaign site wouldn't display the content for me unless I permitted scripts from google.com (w/ umatrix) since she is promoting breaking up google.

Although you can be pro break-up-Google while using one, or even many, of their services. So I don't really see the amusement.

It seems foolish to me to target Google while simultaneously sending a constant feed of data about people visiting your campaign site.

In this case the only "service" it appeared to be using was hosting for jquery...

Re: Google’s new reCAPTCHA has a dark side

#370

The other tradeoff is you're giving Google an extraordinary amount of power to decide who is allowed and not allowed on your website with no transparency on how this decision was made. Not sure what company is willing to blindly trust Google with that power.

Bank of America is...
Post reply on HN