Earlier quoted context omitted.
Except captcha is not supposed to be security for the user, but security for the website. But in the end it is not (effective) security for a website, is an antifeature for users and is profit for google.
As a website developer and host, I can assure you recaptcha works very well to stop spam and automated login requests. It is not perfect, but no system is.
CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
11–20 of 143 posts
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#12Earlier quoted context omitted.
As a website developer and host, I can assure you recaptcha works very well to stop spam and automated login requests. It is not perfect, but no system is.
yeah, a sufficiently motivated attacker can deploy some countermeasures to bypass it, but only really worth it for targeted attacks. Anyone who has a form on the internet knows that without any sort of captcha, you get lots of stupid bots just typing in jumbo. Likely you could tone back the captchas and still get a similar result in stopping the dumb bots[0] [0] on my contact page my email is protected via a custom c…
Nice one! I guess you mainly need to get above a certain novelty threshold, because all ML is based on what has already been seen/learned rather than actually outsmarting the defence.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#13Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#14What's the alternative?
Building your own captcha or running one that doesn't sell your users data to the highest bidder? What a time where people on a site called "Hacker News" ask such a question..
Of course reCAPTCHA is also still vulnerable to the use of a mechanical turk so even giving away your users' data won't save you.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#15What's the alternative?
Important to note though that as AI gets more accessible then the downsides of v3 start to weigh more.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#16Earlier quoted context omitted.
Except captcha is not supposed to be security for the user, but security for the website. But in the end it is not (effective) security for a website, is an antifeature for users and is profit for google.
As a website developer and host, I can assure you recaptcha works very well to stop spam and automated login requests. It is not perfect, but no system is.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#17That made us spend 819 million hours clicking on traffic lights to generate nearly $1 trillion for Google.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#18You can get people to do almost anything if you lie to them that it's for "security".
Except captcha is not supposed to be security for the user, but security for the website. But in the end it is not (effective) security for a website, is an antifeature for users and is profit for google.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#19We'll have to have in-person attestation or make all services paid, perhaps.
Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
#20What's the alternative?
[1]: https://blog.cloudflare.com/introducing-cryptographic-attest...
[2]: https://github.com/mCaptcha/mCaptcha
[3]: https://blog.torproject.org/introducing-proof-of-work-defens...