Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

151–160 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#151
post #88

Earlier quoted context omitted.

Did you even RTFA and look at hCAPTCHA? hCAPTCHA couldn't be more grossly focused on neural-net training. Hell, one challenge asks you to draw a bounding box and another is a classification tagging.

There was no argument being made for HCAPTCHA in the post to which you replied. So, yeah, everything you mentioned is indeed gross, including Google's behavior.

The parent post was edited.

Re: Moving from reCAPTCHA to hCaptcha

#152
post #76

Earlier quoted context omitted.

Google pays Mozilla to be the default search engine in firefox. This is Mozilla's main source of revenue, so I doubt they will sue.

I wonder why they don’t negotiate with Msft to use Bing or even DDG instead. Seems... incredibly odd... to put oneself in a position where a third party is directly antagonizing your users, reducing your user satisfaction and likely dramatically increasing churn, but you can’t do anything about it because that same party is your main source of funding. (Disclaimer, I work at msft. Nowhere near this though).

I'm not sure why you think they don't negotiate with other search providers.

Re: Moving from reCAPTCHA to hCaptcha

#153

Earlier quoted context omitted.

> Recaptcha is $1/1000 challenges This seems unwise, because many captcha farms charge less than this. A quick Google search shows one service offering $0.50/1000 challenges. If it's 2x cheaper for an attacker to solve a captcha than it is for a provider to display it, it sounds like the attackers win.

This only works if you are Soviet Russia vs the USA and your plan is to ruin the other by draining their money and you have equal pools of cash. Spammers don't want to hurt the company they attack if they can help it, they need them! I don't understand why ReCAPTCHA cost so much though. A human solving them is cheaper than a computer/human hybrid creating them?

True, the attacker is much less likely to have anywhere near the funds of the target, and they don't want to hurt them.

Regardless of the actual price multiple, it costing anywhere near the price to serve as the price to solve just seems to defeat the point. Really, it costing any money per captcha served just punishes sites that happen to face a higher volume of bots, even if they're a small site. It's just going to push the company to switch to a different captcha service, which may be even cheaper for attackers to solve.

Re: Moving from reCAPTCHA to hCaptcha

#154
post #152
post #76

Earlier quoted context omitted.

I wonder why they don’t negotiate with Msft to use Bing or even DDG instead. Seems... incredibly odd... to put oneself in a position where a third party is directly antagonizing your users, reducing your user satisfaction and likely dramatically increasing churn, but you can’t do anything about it because that same party is your main source of funding. (Disclaimer, I work at msft. Nowhere near this though).

I'm not sure why you think they don't negotiate with other search providers.

The fact that they’re still on google even though google is screwing over their userbase? I don’t use Firefox because of how difficult it makes captcha. There are others like me.

If they are negotiating with other providers, they certainly aren’t doing a very good job of it.

Re: Moving from reCAPTCHA to hCaptcha

#155
post #38

IMHO CPATCHA is a lazy way to protect your service as you shift the burden to your users. Maybe if you are big and essential for some users, you can afford that. But if not, be aware that users will turn their back on you if you add obstacles between them and your service. Edit: meant to say “be aware that some users will turn their back to you”

> IMHO CPATCHA is a lazy way to protect your service as you shift the burden to your users. What is the non-lazy solution to having a basic website contact form that _doesn't_ receive hundreds of spam submission per day?

Filter the submitted content, not the sender. What Akismet does seems to work really well and not push back on the users too much.

Re: Moving from reCAPTCHA to hCaptcha

#156
post #137

Earlier quoted context omitted.

In my experience, relatively easily defeated by `await Promise.delay(randomDelay())`

Sounds like a cat and mouse game. Mouse: They could then try to analyze human delay randomness -- it's probably not uniform. Cat: And then someone will come up with a replacement to randomDelay that mimics the above pattern. Mouse: And then they will look for changes in the distribution itself from person to person etc.

I know back in the day for RuneScape bots using SCAR there were macros to move the mouse from one position to another on the screen with randomized acceleration, randomized curvature, overshoot, clicking in some bounding box, etc. all using a normal distribution in an effort to thwart detection. Imagine being the poor developer tasked with trying to recover some signal out of that.

Re: Moving from reCAPTCHA to hCaptcha

#157

Earlier quoted context omitted.

I don't think I've ever been "hellbanned", but I've certainly spent more than 5 minutes on trying to get a captcha to work. After a while I usually need to ask friends in the US to help me, because it asks me a non-localized question. My favourite question was: Select all fire hydrants. I selected only the classic red one's you see in movies. Fail. I selected the one's that were yellow too. Fail. I sent a picture of…

Yeah, I should break down my methodology for arriving at the "hellban" conclusion. If I get a bunch of failures in a row, I'll first try the refresh button built into the captcha, and then re-solve a number of times. Then I'll try re-loading the page and re-solving, then I'll try in a different browser with cleared state and re-solving, then I'll try a different device and re-solving, and finally I'll try a different…

One thing I've found (after others mentioned it here) is that Google seems to reward impatience when trying to solve captchas. Going faster and making more mistakes and not waiting for loading images seems to help convice the algorithm that you are human. This is rough on anyone who thinks they are being rejected for not being accurate enough.

OTOH, it is hard to figure out for sure what makes a difference. I use a proxy/VPN with a fixed IP address that only I use and Google eventually seems to have figured it out; I used to get the hard or impossible ones on Google Scholar at times but now never do. So possibly in my case they decided to stop giving them to me around when I changed strategies, but I suggest giving it a try at least.

Re: Moving from reCAPTCHA to hCaptcha

#158

Earlier quoted context omitted.

I know this is a common complaint, but I personally have no issues on both macOS and iOS Safari.

Perhaps the privacy problem for you is then one of the following: - Ad blocking extension not installed or rules too lax - Script blocking not enabled - no VPN used - stores tracking Cookies If all of those do not apply to you, I would feel discriminated against by Google, even more so, than usual.

[deleted]

Re: Moving from reCAPTCHA to hCaptcha

#159
I just tried it on a website that uses Cloudflare and that always asks me to solve a captcha. (I guess this website does this if the user has a foreign IP address.) In the past I managed to get the non-script Recaptcha. But I don't see a non-script Hcaptcha. I'm a little afraid of possible browser fingerprinting scripts. If there was an unwaivable, enforced right to privacy I wouldn't be afraid.

Also, I don't want to solve any script captchas anymore because of a traumatic experience with script Recaptcha. I had a portable Chromium with login cookies for a few websites. I didn't use that Chromium for other websites than these few. Suddenly, one service almost always demanded a new login after just 1 day. On each login I had to solve a script Recaptcha. I didn't find a way to get non-script Recaptcha. According to the service evil spambots had attacked it. Once, Recaptcha let me solve captchas for minutes, just to eventually tell me I was a bot. I had an IP of a large internet provider. I deleted cookies, got a VPN IP, tried it again, worked on the captchas in the exact same way as before and managed to log in to my account. A website operator wrote in a forum thread that Recaptcha was the only solution to the bot problem. One user suggested "email login as an optional alternative". This was not implemented, because apparently Recaptcha was really specifically the only solution. I then switched to another service, which cost me a few hours of work. This traumatic experience has made me completely unwilling to solve any script captcha.

Re: Moving from reCAPTCHA to hCaptcha

#160
post #17

> "Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA. That is entirely within their right. Cloudflare, given our volume, no doubt imposed significant costs on the reCAPTCHA service, even for Google." Even in the article they say... "Google provided reCAPTCHA for free in exchange for data from the service being used to train its visual identification systems." ... I thought thi…

Seeing that reCAPTCHA v3 doesn't use endless streams of images any more, I would guess that Google no longer benefits much from having users tag storefronts, traffic lights, buses or fire hydrants. Maybe their image recognition algorithm is past that stage.

> Seeing that reCAPTCHA v3 doesn't use endless streams of images any more

On the other hand, I've been effectively banned from several sites because I don't accept third-party requests to Google from non-Google sites as a result of this change.

Post reply on HN