Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

421–430 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#421
post #5

You can view your reCaptcha V3 score here: https://recaptcha-demo.appspot.com/recaptcha-v3-request-scor... I get .7 on my iPhone, I’m guessing that my liberal use of Firefox containers and the cookie auto-delete extension on my desktop will give me a much lower score and cause me to have to jump through extra hoops at websites that implement it, just like the reCaptcha V2 does. Edit: I also got 0.7 on Firefox with st…

So, I still have to whitelist Google in uMatrix and allow cookies for this to work. Even after doing so, I get a 0.1. I reloaded the page to check for variation as some other users mentioned but get the same score each time. I guess Google is saying I shouldn't be allowed to use the internet.

Re: Google’s new reCAPTCHA has a dark side

#422

Earlier quoted context omitted.

Yes. Your point? It’s actually ridiculously easy to be compliant with GDPR. Edit: That is, ridiculously easy for new companies. Incumbents have been hoarding data for too long and it was actually harder for existing companies to become compliant.

If you don’t think that lawyer fees scale linearly with regulation complexity you’re either an early Uber employee or mistaken. When you’ve built a social consumer business in Europe that is profitable after compliance, send me a term sheet.

I enjoyed reading what you said as a different perspective on the backend of ad technology vs privacy up until this comment thread.

I didn't build a profitable social consumer business in Europe after compliance, but I was part of a team that implemented compliance for a long existing company within the US due to them having clients and client's clients in Europe. They're profitable. Do you want my term sheet? Or are you weakly attempting to flex while complaining that people's basic right to privacy is preventing you from earning obscene amounts of money?

Re: Google’s new reCAPTCHA has a dark side

#423
post #299

Earlier quoted context omitted.

> It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). That may be the case for some people, but that is not my complaint, nor that of many folks I know. I simply don't care how FB, Google and other surveillance outfits mak…

They have no right to it, and I have every right to try to limit their visibility. That's entirely fair! But also: You have no right to use my website, and I have every right to limit your access. Recaptcha is simply part of this negotiation.

Is that so? What about the webmaster who simply wants to combat bots using his page, is the extent of data gathering on Google's behalf just part of the deal? What if selling user data is against the webmaster's ethics? "Don't use it I guess" Sure, except that no one in the exchange was told the extent to which this data is used, or what for. Users of Google's Captcha aren't told about this exchange. I disagree entirely that it's a matter of voluntarily opting in and out of Google's domain. Their business model depends on becoming inescapable, and they're not being honest about how their services collect our data.

Re: Google’s new reCAPTCHA has a dark side

#424

Earlier quoted context omitted.

This is a ridiculous argument. Advanced technical competency can not be a prerequisite for maintaining personal privacy.

We’re on a site premised on entrepreneurship, and you’re pointing out what sounds like a big market gap. I angel invest now and then, if you have a plausible way to make two billion people care about something that we agree could be better my email is in my profile. Even from the inside I didn’t see a way, but I’ve been wrong before.

Yes, looks like the industry cannot solve that problem alone, just like the electricity and chemical industries somehow didn't achieve clean air and water out of the goodness of their hearts. Another market gap. Or, wait, a case for government regulation.

Re: Google’s new reCAPTCHA has a dark side

#425

Earlier quoted context omitted.

It is not "wild speculative hyperbole" not to give the benefit of the doubt to companies that have repeatedly demonstrated that they are not entitled to the benefit of the doubt.

GPS tracker installed in people’s skull sounds hyperbolic to me.

[deleted]

Re: Google’s new reCAPTCHA has a dark side

#426
post #328

> According to two security researchers who’ve studied reCaptcha, one of the ways that Google determines whether you’re a malicious user or not is whether you already have a Google cookie installed on your browser. This makes sense to me. The presence of cookies is a strong indicator of normal human browsing, and Google would only be able to see their own cookie.

Except a lot of people don't like Google having persistent cookies that track your web usage. Why should giving up that data be a prerequisite for accessing a website?

Re: Google’s new reCAPTCHA has a dark side

#427

Earlier quoted context omitted.

> sour grapes seriously?

search “HN levels.fyi”

I appreciate your comments in this thread. But could you please stop baiting people on this point? If there's one thing I've learned from running HN it's that the generalizations about the community that people come up with are invariably wrong. They're overgeneralized from a small sample of what the generalizer happened to notice—and since we're far more likely to notice what rubs us the wrong way, the results always have have sharp edges. In other words, people remember most the things they most dislike, then tar the whole with it. To borrow your phrase, the actual TLDR is less interesting.

Re: Google’s new reCAPTCHA has a dark side

#428

Earlier quoted context omitted.

> source: I ran Facebook’s ads backend for years Why would anyone ever trust a goddamn thing you have to say about their data? Unless they pay your salary and are asking you to give your expertise on hoarding and abusing user data, obviously.

Me spilling tea about the business is far more in the spirit of a whistleblower than a shill. I have nothing to gain and everything to lose by shedding light on one of the most powerful entities in existence. But TLDR it’s not as interesting as people like to think.

You can gain internet points on a social website…

Re: Google’s new reCAPTCHA has a dark side

#429
post #375

Earlier quoted context omitted.

Potential other causes - Your ISP is a source of a lot of malicious traffic - You have some browser extension or other adjustments that makes it harder to analyse you as a genuine web browser For example, using a browser automation like Selenium testing triggers "hard" reCAPTCHA. Not sure if this because of some automated API that Selenium exposes, or just because your browser profile looks virgin (no cookies) withou…

I use pretty standard extensions... uBlockO, decentral eyes, smart referrer... I just wish that companies would stop using Google's reCAPTCHA service. Also my IP address rarely changes and I don't think that any malicious traffic is coming from it. And I have Comcast, so I hope that they didn't blacklist all of us... (I did talk bad about Google a few times though, maybe that's it)

Those aren’t extensions that an average user would install.

Re: Google’s new reCAPTCHA has a dark side

#430
post #131

Earlier quoted context omitted.

I think this would fail under any directed attack. It’s too hard to generate a database that’s large enough.

This is the answer. It seems that most website owners are somehow super scared of a targeted attack, since it is indeed trivial to bypass (and they realize that), even if nobody will take the time. I've heard stories from people that own small sites and still have someone targeting the site with custom scripts, but never anyone I know (not even a friend of a friend, only ever random people on the internet). But there…

I've had received attacks from custom scripts to post spam in a blog that nobody read. I changed my custom robots tests a couple of times, and each time it took a few days for the bots to adapt. At the end I removed the comments section, so there was nothing to attack.
Post reply on HN