Live data from Hacker News

hCaptcha now runs on fifteen percent of the internet

hcaptcha.com

311–320 of 380 posts

Re: hCaptcha now runs on fifteen percent of the internet

#311

I'm really starting to hate all the captchas with a burning passion. Partly because the corporation I work for seems to have gotten our NAT addresses onto a blacklist so I get captcha'd constantly , and partly because my close up vision is getting noticeably weaker (pushing 50, that's why) and without hunting down my reading glasses it can be difficult to make out the smaller details necessary to solve the puzzle. Es…

Similar deal where I am at present in India: the small ISP uses carrier-grade NAT, so there’s malware and related activity occurring every day from at least one of the who-knows-how-many people behind this one IP address. Last time I was here in 2016 it was actually a lot worse than it is now (then, any Cloudflare site would trigger it, so I’d be hitting dozens of challenges per day), but I still get the occasional h…

Try using privacy pass. It's designed for use cases like yours.

Re: hCaptcha now runs on fifteen percent of the internet

#312

My mom and dad's shared IP (somewhere in Europe) repeatedly gets on CloudFlare's IP ban list meaning my mom keeps having to solve these hCaptcha's. hCaptcha's is a lot more difficult to complete than Google's reCaptcha and she has a lot of trouble with it. Why they get on these IP lists is I think because it's a general consumer ISP and probably a lot of people get bot nets on there.

Install privacy pass on their computers. It won't eliminate the captchas completely but will decrease the number of times they'll see them. I believe cloudflair gives you 30 passes for each captcha solved.

Re: hCaptcha now runs on fifteen percent of the internet

#313
post #311

Earlier quoted context omitted.

Similar deal where I am at present in India: the small ISP uses carrier-grade NAT, so there’s malware and related activity occurring every day from at least one of the who-knows-how-many people behind this one IP address. Last time I was here in 2016 it was actually a lot worse than it is now (then, any Cloudflare site would trigger it, so I’d be hitting dozens of challenges per day), but I still get the occasional h…

Try using privacy pass. It's designed for use cases like yours.

Not available for Safari though. Or any mobile browser?

Re: hCaptcha now runs on fifteen percent of the internet

#314
post #48

I dislike the widespread use of captcha regardless of provider. I realize anything connected to the internet will be subject to automated abuse, and it's impossible to run some types of services without taking some steps to defend against it, but it seems to me there's usually a way to handle that without invading the user's privacy or wasting their time. The exact details will vary based on the type of service, of c…

It's easier for me to switch from google to ddg. Then to actually complete a captcha. I don't understand why businesses don't understand this.

Re: hCaptcha now runs on fifteen percent of the internet

#315

Earlier quoted context omitted.

It's not perfect, and you are right about the downsides. These resources that spammers have can be applied as easily to re/hcaptcha (either through ML or clickfarms). No CAPTCHA will actually lock out targeted attacks. The difficulty increase per IP can be seen as a form of soft rate limiting, it's shared between all websites (which is where it's different from ordinary rate limiting). In the future we may use IP rep…

I get re-captcha'ed all the time from the same IP. And if I don't use Chrome, the captcha count is like 4x-5x higher just for using Firefox.

That's why I have even stopped using google services. If I literally have to get another browser to use your snowflake site, then why would I use your service anyway?

Re: hCaptcha now runs on fifteen percent of the internet

#316
post #90
post #82

Earlier quoted context omitted.

Google uses reCAPTCHA labels exclusively for themselves, and is extracting hundreds of free person years of labor from internet users every single day via this. hCaptcha lets anyone access this type of service, provided they follow certain ethical AI guidelines

How long has the content of the recaptcha puzzles been entirely unchanged, despite being shown to billions of users? Like five years? It should be painfully obvious that there is no actual labeling going on at this point, they have all the training data they'll ever need for traffic lights... And by a corollary, since they haven't started labeling different kind of data, it's clear that either they no longer need any…

Anecdotally I don’t think I’ve ever seen the same image twice on recaptcha.

Re: hCaptcha now runs on fifteen percent of the internet

#317
I personally found hCaptcha harder to pass than reCaptcha, to the point where I will leave a site that demands one if that's a realistic option (e.g. not really an option if it's my bank, totally an option if it's one of many stores selling an item).

It's possible that I just got unlucky (one of my recent experiences was a site that didn't let me in even after solving it, which really soured me), but I feel like the main reason it's hated less is because people haven't seen it as much yet.

Edit: TIL how offputting a single bad experience can be. From going through my HN history, I found out that this terrible experience was 6 months ago.

Re: hCaptcha now runs on fifteen percent of the internet

#319

My mom and dad's shared IP (somewhere in Europe) repeatedly gets on CloudFlare's IP ban list meaning my mom keeps having to solve these hCaptcha's. hCaptcha's is a lot more difficult to complete than Google's reCaptcha and she has a lot of trouble with it. Why they get on these IP lists is I think because it's a general consumer ISP and probably a lot of people get bot nets on there.

What service they use have a big implication of if they get captcha'd. Try switchingservices

Re: hCaptcha now runs on fifteen percent of the internet

#320

I personally found hCaptcha harder to pass than reCaptcha, to the point where I will leave a site that demands one if that's a realistic option (e.g. not really an option if it's my bank, totally an option if it's one of many stores selling an item). It's possible that I just got unlucky (one of my recent experiences was a site that didn't let me in even after solving it, which really soured me), but I feel like the…

I largely agree. Cloudflare requires hcaptcha if you mistype your password a single time when accessing their dashboard. The UX of hcaptcha is not good, especially in a flow where I'm already fixed on goal (doing something in my dashboard). If I need to stop thinking about dns settings or caching to pick out photos with bicycles, that's a really expensive context switch for my brain. And in my experience, you need to do two "pages" to complete the captcha.

By comparison, I've been asked to complete recaptcha exactly zero times day to day (perhaps I'm lucky?). The last time must have been many months ago.

It's hard to speak to the specific UX qualities of the captcha itself, but I find recaptcha generally less difficult. But a captcha that I don't need to complete always wins out over one that I do.

Post reply on HN