Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

111–120 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#111
post #95

Earlier quoted context omitted.

> the vast majority of which will not be empathically awful Yeah, most of the time it's "just" really, really obnoxious, not to mention coercive in a way that aligns with Google's interests. Thanks, Google. > How, in your opinion, should Google have handled the matter in a way that does not give spammers or other abusive users ways to get around the measure? "Our anti-spam systems believe that you might be a robot. Y…

In my opinion and experience, ReCAPTCHA isn't really, really obnoxious most of the time. I suspect that most of the time it trips up bots who have no emotional experiences whatsoever. Most of my personal encounters with it involve solving no puzzles whatsoever. With that in mind, I expect humans and their completely real reactions might not be the default case. Of course, this is speculative, as I do not have any kin…

> I suspect that most of the time it trips up bots who have no emotional experiences whatsoever.

I'll bite: maybe it's good at identifying obedient drones and letting them through :)

It trips up the normies in my life often enough that I suspect being technically inclined is actually a net advantage because it makes you quick to detect the problem and quick to apply workarounds. Those advantages are significant enough to outweigh even the cost of the semi-regular dance where I try to protect myself and Google jerks my chain.

> Have you considered

The fact that I phrased my proposal as a tradeoff should have strongly hinted that I did, in fact, consider.

> Wouldn't that remove any real gains from being vague with tips & tricks?

One bit of information -- locked vs not -- is hardly the same as disclosing the inner workings, or even the information inputs, of the classifier, and smart botters have access to that bit of information anyway because they've built a gaslight detector by leveraging their legions of diverse bots and endless supply of dirt cheap human labor.

Gaslighting humans is really bad. A minimal courtesy would only cost a sliver of efficacy, and ReCAPTCHA still rejects it. That decision earns it the bad will directed its way.

Re: Moving from reCAPTCHA to hCaptcha

#112

Earlier quoted context omitted.

Perhaps the privacy problem for you is then one of the following: - Ad blocking extension not installed or rules too lax - Script blocking not enabled - no VPN used - stores tracking Cookies If all of those do not apply to you, I would feel discriminated against by Google, even more so, than usual.

To address each of your points: 1. I do have an ad blocker installed, but it's not very aggressive. 2. All scripts are enabled. I already have trouble with some sites due to my fairly lax ad blocker. 3. I do not use a VPN (since it just transfers who is able to see my traffic from one party to another). Additionally, virtually every service provider penalizes VPN IPs to the point where it's probably not worth the has…

I will not arguing against protecting ones website from bots, nor am I saying, that VPN traffic is not spammy in practice. Up until that point I am with you. However, making use of ReCaptcha is certainly not an ethical and therefore not a justifiable way of doing it.

Doing all of the stated things these days has become a minimum for protecting your privacy online. The current situation is a quite bad for privacy conscious people. Even if we only trust first party scripts and do not allow them being loaded from a subdomain, which actually has all the third party scripts again, we still face issues, for example fingerprinting.

I can only laud websites, which can be used completely without third party scripts or perhaps even without scripts at all, making sure it all works with REST, offering alternatives, when scripts are blocked.

It's good to see some "competition" in this area, even, if I do not trust cloudflare either. More competition means less Google monopoly. Hopefully in the long run it will lead to better solutions for casual users.

Re: Moving from reCAPTCHA to hCaptcha

#113
post #95

Earlier quoted context omitted.

In my opinion and experience, ReCAPTCHA isn't really, really obnoxious most of the time. I suspect that most of the time it trips up bots who have no emotional experiences whatsoever. Most of my personal encounters with it involve solving no puzzles whatsoever. With that in mind, I expect humans and their completely real reactions might not be the default case. Of course, this is speculative, as I do not have any kin…

> In my opinion and experience, ReCAPTCHA isn't really, really obnoxious most of the time. The percentage of that time goes up as you move away from Chrome and Google cookies.

I don't think Chrome has ever been my daily driver.

That said, I also expect to be treated with more suspicion when I behave more like a bot. So I'm neither surprised nor bothered when Firefox Private gets me an uptick in ReCAPTCHAs. I understand that this is a highly unusual expectation.

Re: Moving from reCAPTCHA to hCaptcha

#114

Can we get back text based captchas instead of annoying whack-a-mole photo picking?

No. Photos of street things are much easier to pick out than warped or miscolored text.

Especially the amount of warping you apparently need to do to text to make it hard for a neural network these days.

Re: Moving from reCAPTCHA to hCaptcha

#115
post #73

Earlier quoted context omitted.

That, and ReCAPTCHA had hellbans. If you blocked cookies or were otherwise problematic, it would sometimes lock you out of all ReCAPTCHA-gated resources not by giving you a message describing what was happening, why, and how to fix it, but rather by simply pretending that your every attempt to solve the captcha failed. Obviously this is extremely frustrating, by design, but it gets even more so with compounding facto…

Captchas are fundamentally anti-human. I'm not saying there isn't a problem to be solved, I'm saying Captchas are a behavior enforcement mechanism overseen by robots and are anti-human. I write the site owner short note when they go bad explaining why they just lost a customer and go somewhere else. Life is too short to put up with shitty tech.

What, in your opinion, is the pro-human way to address the problem to be solved?

I'm always curious to hear what other approaches might be worth considering. CAPTCHAs tend to tick the boxes of performing well enough for website-controllers and being low-effort for them to deploy.

Re: Moving from reCAPTCHA to hCaptcha

#117
post #5

The enterprise grade hCaptcha[1] is not free either. Does anyone have pricing information? [1]: https://www.hcaptcha.com/#plans

According to the article Cloudfront is paying, but is paying "a fraction of what reCAPTCHA would have [cost]". Recaptcha is $1/1000 challenges, so apparently hcaptcha is some small fraction of that. Cloudfront might get a discount for running some of the infrastructure on their own servers, on the other hand that might also be an integration hassle that actually costs them money.

> Recaptcha is $1/1000 challenges

This seems unwise, because many captcha farms charge less than this. A quick Google search shows one service offering $0.50/1000 challenges. If it's 2x cheaper for an attacker to solve a captcha than it is for a provider to display it, it sounds like the attackers win.

Re: Moving from reCAPTCHA to hCaptcha

#119
post #76

Earlier quoted context omitted.

Google pays Mozilla to be the default search engine in firefox. This is Mozilla's main source of revenue, so I doubt they will sue.

I wonder why they don’t negotiate with Msft to use Bing or even DDG instead. Seems... incredibly odd... to put oneself in a position where a third party is directly antagonizing your users, reducing your user satisfaction and likely dramatically increasing churn, but you can’t do anything about it because that same party is your main source of funding. (Disclaimer, I work at msft. Nowhere near this though).

Yahoo was the default from around 2014-2017 in the United States.

Re: Moving from reCAPTCHA to hCaptcha

#120

Earlier quoted context omitted.

That, and ReCAPTCHA had hellbans. If you blocked cookies or were otherwise problematic, it would sometimes lock you out of all ReCAPTCHA-gated resources not by giving you a message describing what was happening, why, and how to fix it, but rather by simply pretending that your every attempt to solve the captcha failed. Obviously this is extremely frustrating, by design, but it gets even more so with compounding facto…

I don't think I've ever been "hellbanned", but I've certainly spent more than 5 minutes on trying to get a captcha to work. After a while I usually need to ask friends in the US to help me, because it asks me a non-localized question. My favourite question was: Select all fire hydrants. I selected only the classic red one's you see in movies. Fail. I selected the one's that were yellow too. Fail. I sent a picture of…

It is pretty straightforward to train a neural network to solve these -- e.g. fire hydrants, traffic lights, cars.

I would have thought ReCAPTCHA would take into account human factors (e.g. speed of clicking) as higher priority to the accuracy of the selection.

Post reply on HN