Live data from Hacker News

Ask HN: When did HN start using recaptcha?

news.ycombinator.com

11–18 of 18 posts

Re: Ask HN: When did HN start using recaptcha?

#11

I was also made to log in via a recaptcha today. The recaptcha widget appears just below the HN login form so pretty sure this is added by HN, not Cloudflare. If people are complaining about it on this thread, I would also like to register my complaint with it. I think Recaptcha has two major problems: - It's Google. I would want it to be technically impossible for someone in Google to link my HN profile with my Goog…

- Privacy and security enhancing techniques make the captcha harder or impossible. For example, the tracking protection built into firefox blocks the recaptcha.js (in a certain view even rightfully so, because google will use that for tracking)

- Apps do not work anymore. This cannot be solved. For recaptcha, one needs a working browser steered by humans. Apps necessarily act like robots.

This comes in line with increased usage of "2"-factor authentication. For example, amazon now requires a browser cookie to login. If you don't have such a cookie, you need to enter a code received via e-mail or SMS. If you delete your cookies (maybe automatically), you This comes under the pretense of security but really is used to fight user privacy.

One general point: Businesses uses machines to provide services. Why shouldn't we as consumers be allowed to rely on machines to consume said services? 15 years ago there was this "semantic web" fad with "intelligent agents". This mess is a huge step backwards.

The root-cause of this is two-fold: - advertising-based business model. If every "bot" needed to pay for the service as well as any other user, revenue will not be hurt by "bots". - other misuse - "Dumb users" as more computer-illiterate people are using these services, it gets easy for businesses to dismiss user choice.

If this should not end in a dystopian nightmare, we will need: - Privacy-preserving login protocols that are stronger than user/password - Privacy-preserving and low-friction micropayment (e.g. Taler) - Some privacy-preserving way to fight misuse. I have no idea here. Maybe some crypto-social-network with zero-knowledge-foo?

Re: Ask HN: When did HN start using recaptcha?

#12

I was also made to log in via a recaptcha today. The recaptcha widget appears just below the HN login form so pretty sure this is added by HN, not Cloudflare. If people are complaining about it on this thread, I would also like to register my complaint with it. I think Recaptcha has two major problems: - It's Google. I would want it to be technically impossible for someone in Google to link my HN profile with my Goog…

Same happens on Safari, I feel I have to do the recaptcha a lot more frequently on Safari than on Chrome. I cannot find any serious study to back this though ...

Re: Ask HN: When did HN start using recaptcha?

#13
post #6
post #2

Might be cloudflare. They use Recaptcha.

No. It's a 2nd screen to complete login. It also breaks mobile clients such as materialistic and is plain evil anyway

I was wondering why I couldn't upvote anything through the app and then also wondering why the app kept thinking I wasn't signed in. This is poor indeed. I like using Materialistic. I guess I just won't vote, submit or comment until this madness is over.

Re: Ask HN: When did HN start using recaptcha?

#15
I didn't see this question until earlier. That's why the site guidelines ask you to email hn@ycombinator.com if you want to ask us something: https://news.ycombinator.com/newsguidelines.html

We turned it on temporarily because HN was under attack by an account-stealing botnet. Obviously we don't leave it on any longer than we have to. We also are happy to put anyone's username on a whitelist, as the people who emailed us found out.

Re: Ask HN: When did HN start using recaptcha?

#17
post #15

I didn't see this question until earlier. That's why the site guidelines ask you to email hn@ycombinator.com if you want to ask us something: https://news.ycombinator.com/newsguidelines.html We turned it on temporarily because HN was under attack by an account-stealing botnet. Obviously we don't leave it on any longer than we have to. We also are happy to put anyone's username on a whitelist, as the people who emaile…

Thank you for clarifying. I wasn't aware you run a whitelist, this sounds like a good approach.
Post reply on HN