Earlier quoted context omitted.
Remember that from hCaptcha's point of view, by this point they've probably dealt with hundreds of other people claiming that they are blind when they really aren't, so their bots will work. This isn't a defense, just an explanation... but it is also an explanation of why the entire idea of "we'll not give blind people a way past the CAPTCHA but just give a pass to 'real' blind people so we can pass ADA", which is th…
This is a problem so chronic across so many fields that I wish there was single term to describe it. User POV :"Wow, provider is a really shitty entity and had no respect for my legitimate problem." Provider POV: "We get a huge number of illegitimate claims identical to legitimate ones regularly, the system would collapse if we didn't do heavy triage, the problem is the level of abuse, not a moral bankruptcy on our p…
I was banned from the hCaptcha accessibility account for not being blind (2023)
111–120 of 277 posts
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#112I hope we can end the CAPTCHA experiment soon. It didn't work. Phone verification isn't good either, but for as much as I hate phone verification at least it actually raises the cost of spamming somewhat. CAPTCHA does not. Almost all turnkey CAPTCHA services can be solved for pennies. Solving the problems of SPAM and malicious traffic will be challenging... I am worried it will come down to three possible things: - A…
meh, continuing the pearl clutching and asserting there has to be some general "solution" is itself part of the problem. The sheer majority of captchas I come across are while browsing essentially static content. If simple source IP based rate limiting can't keep the server load at something manageable, then the real problem is with how the site is built. And adding even more bloat to address another managerial bulle…
- I don't believe there is a general solution to this problem, but that won't stop people with lots of money and influence from trying to find a general solution. Especially one that is cheap. I still hope for the least user- and ecosystem-hostile approach among the flawed approaches to win. (I guess of the ones I listed, the one that bothers me the least is having more policing of the service providers.)
- CAPTCHAs from static content are almost assuredly for anti-scraping measures. I think anti-scraping measures are mostly pointless and antithetical to an open web in the first place, but, an effective anti-scraping measure kind of has to work off of reputation, because getting access to a very large number of IP addresses isn't free, but it doesn't cost that much (especially if IPv6 is on the table.) I personally doubt it has much to do with server load in most cases, but maybe I am wrong.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#113Earlier quoted context omitted.
Remember that from hCaptcha's point of view, by this point they've probably dealt with hundreds of other people claiming that they are blind when they really aren't, so their bots will work. This isn't a defense, just an explanation... but it is also an explanation of why the entire idea of "we'll not give blind people a way past the CAPTCHA but just give a pass to 'real' blind people so we can pass ADA", which is th…
This is a problem so chronic across so many fields that I wish there was single term to describe it. User POV :"Wow, provider is a really shitty entity and had no respect for my legitimate problem." Provider POV: "We get a huge number of illegitimate claims identical to legitimate ones regularly, the system would collapse if we didn't do heavy triage, the problem is the level of abuse, not a moral bankruptcy on our p…
That's what happens when trust erodes, and why we can't have nice things.
If anyone should be be more understanding and absorb the costs to appease the other, it's probably the big corp, not the little guy.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#114Earlier quoted context omitted.
I assume you never tried to add a contact form to your website. Explanation: I did, and within a few days bots started sending me spam using that form. I just added a trivial captcha (hardcoded '2+3=' question), but if my scale was bigger that would be untenable. Think also of PM spam, autoregistering accounts to abuse free tiers, etc.
I guess I just wouldn't have an open unauthed form and require a CC to use the free-tier. The contact-me form can just be a mailto: link and let the spammers go through the spam filter like everyone else. There are places where captchas is all you can really do but it's not like common use-cases don't have other options.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#115Earlier quoted context omitted.
I routinely have problems with closeup images. To this day I don't know how much of the object I should be selecting? Also what is a traffic light? Is the pole part of it or not? Motorcycles seem to be hard too. Once it showed me a picture of steps nothing but steps. I think I marked like 15 boxes.
If you think you're failing the captchas because you're doing them wrong, think again. Google captcha intentionally fails you a couple times if they don't have enough tracking info to determine that you're legit. So you solve the captcha correctly but are still lied to that "you've failed to solve the captcha, try again". That and the "fading images slowly to pretend like you have bad internet" thing. Disgusting beha…
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#116I hope we can end the CAPTCHA experiment soon. It didn't work. Phone verification isn't good either, but for as much as I hate phone verification at least it actually raises the cost of spamming somewhat. CAPTCHA does not. Almost all turnkey CAPTCHA services can be solved for pennies. Solving the problems of SPAM and malicious traffic will be challenging... I am worried it will come down to three possible things: - A…
> Anonymity of users: validating someone's real-life identity sufficiently would make it possible to permanently ban malicious individuals and filter out bots with good effectiveness, but it will destroy anonymity online. In my opinion, literally untenable.
I see this point constantly made on the echo chamber that is known as HackerNews. The average normie user does not care about anonymity, nor privacy, on the Internet. They want a smooth, fun experience. The solution is secure boot plus attestation via some browser JavaScript API. If you want even less friction, users are required to register their devices with a gov't agency, then their attestation will carry more value.Really, why don't we see HN crying about the need to show a national ID (and register) when buying a mobile phone? I never once saw anyone complaining about it here. Are there any highly developed nations that allow complete strangers with any nationality to buy and use a mobile phone without showing a national ID? I don't know any, or they will all soon be gone. It only takes a few more terrorist assholes to close that door permanently.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#117I hope we can end the CAPTCHA experiment soon. It didn't work. Phone verification isn't good either, but for as much as I hate phone verification at least it actually raises the cost of spamming somewhat. CAPTCHA does not. Almost all turnkey CAPTCHA services can be solved for pennies. Solving the problems of SPAM and malicious traffic will be challenging... I am worried it will come down to three possible things: - A…
There is another option. CAPTCHA is useful only when it is costly to solve. It is a costly signal that this is a real person, or at least is more than 1/10^9th of a real person (you're not running a fully automated spam system). The postal service also has costs - everybody that wants to move something through the postal service needs to buy a stamp. Transport fees are a 'natural' way to moderate traffic and deter sp…
I'm skeptical though. It puts a literal price on abusing a service, but how do you set that price? Is there a guarantee that there's a value high enough to meaningfully disincentivize SPAM but low enough that users, especially users in areas that may have an economic disadvantage, are able to pay it?
That's on top of the other practical problems, such as actually implementing it. I mean, if someone implements it and tries to solve the usability issues involved I would be open to this future, but as it is now, cryptocurrency has disappointed me. In a world with increasing scrutiny towards credit card processors, I was hoping that the silver lining would be that cryptocurrency could at least help mitigate some of the concerns, but there are just too many hurdles right now. (Some of them may be caused by regulation, but to be fair, I think at this point it's hard to blame governments for trying to regulate cryptocurrency exchanges. I'm not happy about silly KYC policies or anything like that, but I am not surprised at all.)
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#118I hope we can end the CAPTCHA experiment soon. It didn't work. Phone verification isn't good either, but for as much as I hate phone verification at least it actually raises the cost of spamming somewhat. CAPTCHA does not. Almost all turnkey CAPTCHA services can be solved for pennies. Solving the problems of SPAM and malicious traffic will be challenging... I am worried it will come down to three possible things: - A…
> Anonymity of users: validating someone's real-life identity sufficiently would make it possible to permanently ban malicious individuals and filter out bots with good effectiveness, but it will destroy anonymity online. In my opinion, literally untenable. I see this point constantly made on the echo chamber that is known as HackerNews. The average normie user does not care about anonymity, nor privacy, on the Inter…
Canada maybe? [I'm 80% sure that] Public Mobile will sell you a prepaid sim card at the counter. You could pay cash, and set your caller ID to a fake name.
If we're talking about mobility plans, the identity requirement is more about the credit check they might want to do than anything else.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#119I hope we can end the CAPTCHA experiment soon. It didn't work. Phone verification isn't good either, but for as much as I hate phone verification at least it actually raises the cost of spamming somewhat. CAPTCHA does not. Almost all turnkey CAPTCHA services can be solved for pennies. Solving the problems of SPAM and malicious traffic will be challenging... I am worried it will come down to three possible things: - A…
There is another option. CAPTCHA is useful only when it is costly to solve. It is a costly signal that this is a real person, or at least is more than 1/10^9th of a real person (you're not running a fully automated spam system). The postal service also has costs - everybody that wants to move something through the postal service needs to buy a stamp. Transport fees are a 'natural' way to moderate traffic and deter sp…
If you switch to direct payments that are still affordable for routine use by your poorest users, then your rich adversaries can afford to generate orders of magnitude more spam (until we solve unequal wealth distribution globally).
Also, the cost of using a postal service nominally covers its operating costs. The cost of actually transferring a spammy HTTP request over the internet is negligible, but the costs imposed on its receiver are less so (i.e. the cost of responding to it (cpu/ram/disk/bandwidth), second-order costs of lowering the quality of the service for everyone else, etc.).
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#120Earlier quoted context omitted.
This sounds like the same argument that was made for about 10 years (2000 to 2010) that micropayments would save traditional (print) media in a digital world. It didn't work due to market fragmentation and friction to make a payment. And, the reality of your fancy idea is that normie users would turn away if they made a mistake on the CAPTCHA and were suddenly presented with a screen "charging" them one pence.
This isn't about "making a mistake on the captcha", this is about charging them one pence for every attempt and just not having a captcha. It's an entirely different sort of system, and it would require a cordoned off section of the Internet to implement it top-down, but it's technically viable. The defining insight here is how many orders of magnitude difference there is between the "That price is negligible" thresh…
According to a random page on internet [0], companies pay in $2-$6 range per 1000 ad impressions. If one pays $0.01 to bypass captcha and just 10 people see the resulting spam post, that's already $1 per 1000 views - much less than facebook charges. This becomes even more lucrative if the ads are expensive or there will be more than 10 people looking at the ad.
It looks you'll want much higher costs than that, which will make it "too much" for other users.
[0] https://spideraf.com/learning-hub/what-is-the-average-cost-p...