Live data from Hacker News

CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

pcgamer.com

111–120 of 143 posts

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#111
post #106

Earlier quoted context omitted.

If you are a EU government wanting a no-captcha experience on your website you could solve it thusly: * Don't have captcha. * Make it illegal for bots to access. * Block foreign ips. * Make it illegal to provide a proxy for foreign bots.

Yeah, that's great until you're a european citizen who needs to access a government service while travelling in the US, or living in French Guyana, or any amount of exceptions to your clever idea.

If you travel to places unwilling to enforce basic rules of civility you should be willing to suffer additional consequences, rather than having the entirety of Europe continue to suffer because we are unwilling to do the right thing, which is to put an end to the far west of the internet.

Countries unwilling to sign regulations that would have them lock up scammers/DDoS botters and other toxic e-criminal, or unwilling to enforce their own laws when they exist, should not be allowed to continue to pollute the internet at large. Block them until they learn their lesson.

In the west, you can and will lose your access to the internet even if you are not doing this sort of shit on purpose but have an infected computer. See for example : https://it.slashdot.org/story/05/04/13/0320249/major-aussie-...

We enforce the rules on our own citizens, why are we tolerating this level of criminal traffic from China, India, and, the worst of them all, Russia, the country through which we are very much fighting a proxy war right now in funding Ukraine?

We can send missiles to kill russians but we can't cut them from the internet at large ? Really?

Internet access is not a human right. Just like driving on the roads is not a human right and terrible drivers get their license revoked.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#112

Google addressed the claims in this paper last year, and one of the authors challenged the company's responses. See: https://www.theregister.com/2024/07/24/googles_recaptchav2_l...

As of two weeks ago my locked down Firefox profile gets hit with captchas on every visit to Google search. DDG has also gone to shit with captchas and stupid low cache lifetime because I use their non-javascript site. I'm giving Bing a test run before making the leap to Kagi.

We (at DuckDuckGo) shouldn’t have a lot of captchas and when we do (intended to keep away non-human traffic) they are completely anonymous, self-hosted, and not related to any AI or other machine learning. As such, I’d love to figure out why you are getting ensnared in them when you aren’t supposed to. If you want to reach out via email (see my profile) I will look into it.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#113
post #107

Earlier quoted context omitted.

Name and shame, please!! ReCAPTCHA due lack of opt out is effectively illegal in the EU.

If it's "effectively" illegal can you name a single court decision saying so?

In my country: MED-2020-015 (against the ministry of health), SAN-2023-023. Maybe more.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#114
post #37

I'm at the point now that if I get a CAPTCHA, I'm just going to leave the site. I'll spend my money elsewhere or find an alternative

My government's websites require solving a reCAPTCHA for basic services, which is horrifying. They also use Cloudflare which blocks me sometimes. This is in the EU

Where in the EU? Maybe you can file a GDPR complaint

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#115
post #112

Earlier quoted context omitted.

As of two weeks ago my locked down Firefox profile gets hit with captchas on every visit to Google search. DDG has also gone to shit with captchas and stupid low cache lifetime because I use their non-javascript site. I'm giving Bing a test run before making the leap to Kagi.

We (at DuckDuckGo) shouldn’t have a lot of captchas and when we do (intended to keep away non-human traffic) they are completely anonymous, self-hosted, and not related to any AI or other machine learning. As such, I’d love to figure out why you are getting ensnared in them when you aren’t supposed to. If you want to reach out via email (see my profile) I will look into it.

[deleted]

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#116
post #20

Earlier quoted context omitted.

There are two alternatives I'm aware of, one is Attestation of Personhood[1] proposed by Cloudflare, the other is a proof-of-work[2] which the Tor project have themselves introduced[3]. [1]: https://blog.cloudflare.com/introducing-cryptographic-attest... [2]: https://github.com/mCaptcha/mCaptcha [3]: https://blog.torproject.org/introducing-proof-of-work-defens...

While I get the draw, I never understood how PoW is ever supposed to work practically. PoW tasks are meant to work on a wide range of mobile phones, desktops, single-board computers, etc... you have vastly different compute budgets in every environment. For a PoW task that is usable on a five year old mobile phone, an adversary with a consumer RTX 50 series card (or potentially even an ASIC) can easily perform it man…

Perhaps you think all PoW algorithms are still crackable by ASICs? A few years ago that was the case, but some years ago Monero developers made a breakthrough with RandomX. Now it is no longer true that a GPU or ASIC can outperform a typical consumer device to the extent that you seem to imagine. The Tor project uses a similar algorithm, i think with the same developer contributing to it as RandomX. It is nothing like bitcoin's SHA256 PoW - with that, the performance of an ASIC does indeed mean a consumer PC becomes completely useless at the algorithm

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#117
post #6

What's the alternative?

I've been using Truesign [0] for several months and been impressed with the results, it detects bots, VPNs, disposable emails and suspicious traffic patterns all in one. I use it to protect my payment form but it seems it can also protect APIs.

Still in beta though.

[0] https://truesign.ai

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#118
Wouldn't some sort of proof of work be a good solution to the captcha problem?

Specially since all of the sudden, a bot service running hundreds of thousands of requests will suddenly and inadvertedly have to compute cryptographic hashes at the cost of the user running the bots?

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#119
post #106

Earlier quoted context omitted.

If you are a EU government wanting a no-captcha experience on your website you could solve it thusly: * Don't have captcha. * Make it illegal for bots to access. * Block foreign ips. * Make it illegal to provide a proxy for foreign bots.

Yeah, that's great until you're a european citizen who needs to access a government service while travelling in the US, or living in French Guyana, or any amount of exceptions to your clever idea.

I guess you could offer travelers a captcha. Also note that the fourth point didn't prohibit proxies in all cases, just proxying for bad things.

Re: CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'

#120

Earlier quoted context omitted.

Logon forms are another whole issue. "Lock out the account" is just a DoS vector. People are quick to talk about systems that can defeat a captcha but if the brute force goes from 50 passwords/sec to one password/10 sec it's mission accomplished.

Can't you just put a 5 second "loading bar" delay instead of a captcha then i wonder?

Not easily: if it's enforced client side it may as well not exist, if it's enforced server side you just let anyone lock anyone else out of their account by running a constant brute force attack against their account (a DoS vuln). It also does nothing for attackers who try a giant list of accounts but only one or two passwords for each.

I worked on Google's system for solving this. It's a pretty sophisticated analysis that decides whether to demand CAPTCHAs or not based on a lot of factors. The CAPTCHA was needed (at that time) because it's the only way to slow down the attacker without bothering the real user, who won't be shown one.

Post reply on HN