Earlier quoted context omitted.
I had to add a captcha to a registration page a couple years ago. Bots were signing up for thousands of fake accounts with other people’s email addresses. The email confirmation we sent would then get reported as spam since the recipient didn’t sign up for our service. Our email provider suspended our account for high spam reports.
What's is the play by the spammers here? Is it a direct attack on your website, perhaps because they were competitors? Or are they hoping that 1% of spammed email addresses will accidentally verify their email?
I was banned from the hCaptcha accessibility account for not being blind (2023)
171–180 of 277 posts
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#172Earlier quoted context omitted.
Cryptocurrency micropayments have been proposed and even attempted as a solution to various problems. Hell, there's also Hashcash, an early proposed anti-SPAM measure for e-mail using just proof-of-work. (Since this is just burning CPU though, it probably isn't effective in the modern world of most people using low-power mobile computers and many SPAMers having access to cheap very high power computers. Might serve a…
> It puts a literal price on abusing a service, but how do you set that price? Start with a nominal one and increase it until the spam problem goes away. Create escape hatches for people who can't afford it, e.g. you can either pay/mine a couple dollars worth of cryptocurrency, or you can have someone who paid vouch for you (but then if either of you spam you both get banned), or you can do some rigorous identity ver…
On the UX side, I think a huge problem is making it possible for users to participate using a non-custodial wallet with as little risk of data loss or compromised credentials as possible. So it needs to be hardened against ignorance, stupidity, house fires, malware, and social engineering. That is hard. Irreversible transactions greatly up the stakes while increasing the incentive to attack. Do you ever feel a bit nervous about the send address being wrong when you use cryptocurrency?
A thing I didn't mention but is equally important to solve is developer experience. I wish there was a turnkey SDK that took care of most of the technical stuff and just let you use cryptocurrency like it's PayPal. If we had on-chain subscriptions (I think Ethereum can do this?) it could be even more powerful. The technologies offer a ton of possibilities but taking advantage of it correctly and securely feels like a tall order. Dealing with cryptocurrencies feels more serious than dealing with traditional payment processors: you can't undo when you fuck up.
Some of this can be resolved. On the user side, users can keep less value stored in wallets long term... Though this is more cumbersome and less usable. On the developer side, developers can make nodes that can verify transactions but not spend currency... But this can be challenging (I think it's weird to do with Monero for example?) and it closes off some use cases ("escrow" style transactions; Skeb-style commissions would be a good use case.)
If it gets solved I will celebrate as it seems like it would have a lot of positive upsides, but I think you might need to pardon my skepticism: it's been a lot of years and it hasn't gotten that much better. (Granted, it's still pretty new, but the momentum is slower than I would have hoped.)
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#173Earlier quoted context omitted.
This is how use of language concealed aphantasia for so long. When you use a word in a context similar to how another used it in that context there seems to be a presumption that the subjective experience is the same in that context. Given how we learn languages and words based upon encountering them in contexts, it makes sense that terms that we use in outwardly similar contexts reflect the subjective experience tha…
Here's the thing. We're talking about people who are the accessibility team for hCaptcha. They should at least have a figleaf of an understanding of life for blind people. The other problem we have is that online companies tend to be accountable to no one. Short of law suits, my friend who got banned from hCaptcha for "not being blind" has no recourse, because nobody is accountable.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#174Earlier quoted context omitted.
I distinctly remember a captcha which asked me to identify fire hydrants. Some of the pictures were hydrants, while others were standpipes. These are different things, and I answered accordingly. The service refused to acknowledge my humanity until I relented that a standpipe was a hydrant. If at some future date any of us burn to death due to an automated fire truck that misbehaved due to this, we’ll know why.
Yup - I recognize this problem. I am a motorcyclist and I frequently have to grit my teeth and misidentify scooters as motorcycles if I want to get past captcha. For non-bikers, a scooter has an automated gearbox and small wheels etc. Think vespa. In the UK at least they are generally a different category of license, although that's because of the size of a standard scooter engine.
Scooters are cycles that have motors, and are thus motorcycles in the most-inclusive definition of such.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#175Some captchas are getting pretty discriminatory, not everyone lives in the West and can identify the objects they are asking you to. Another recent one sticks out where they asked me to pick a shape as the same number of conoids on screen. If you ask people on a street what a conoids I bet a significant amount will give you blank looks Also at least now I know some people call those markings crosswalks
But on the internet the answer to „what is a conoid“ is just a web search away. The bigger problem is when other options of a captcha fit in another cultural context. Taxi colors are an example for that.
Not when it's your search engine that's asking you to identify conoids.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#176Earlier quoted context omitted.
Although solving a captcha can be translated into a monetary cost (often the cost of labour for a human in a clickfarm to solve it for you), the nice thing is that it's still "free" to solve normally. If you switch to direct payments that are still affordable for routine use by your poorest users, then your rich adversaries can afford to generate orders of magnitude more spam (until we solve unequal wealth distributi…
> until we solve unequal wealth distribution globally Is this a joke?
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#177Some captchas are getting pretty discriminatory, not everyone lives in the West and can identify the objects they are asking you to. Another recent one sticks out where they asked me to pick a shape as the same number of conoids on screen. If you ask people on a street what a conoids I bet a significant amount will give you blank looks Also at least now I know some people call those markings crosswalks
The Google dictionary says it's a zoological term "approximately conical in shape".
The Wikipedia panel says "In geometry a conoid is a ruled surface, whose rulings fulfill the additional conditions: All rulings are parallel to a plane, the directrix plane. All rulings intersect a fixed line, the axis." The graphics are... nothing intuitive.
The M-W link in the search results says "a cone-shaped structure; especially : a hollow organelle shaped like a truncated cone that occurs at the anterior end of the organism".
None of this seeming relevant, I clicked on the Image tab and it's all these complicated Mathematica-style graphs of things that are very much not cones.
I see other people in the HN comments similarly have no idea.
Can you please explain what you saw on screen? What did the captcha think was a conoid...? Like, traffic cones or something?
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#178I am also blind. hCaptcha is the worst. Their stupid cookie expires so I have to go through their getting an email to set the cookie almost every time I encounter one. It's a horrendous UX, especially when using different devices and browsers. I imagine others just give up instead of dealing with the crap. They shouldn't use the word accessibility when their whole service is the exact opposite. The bots can probably…
Believe me, hCaptcha isn't much better even if you're not blind! They show me minuscule images which are barely distinguishable from each other. It manages to be much worse than reCaptcha, which is some achievement.
It sucks more when you work in the space and take a lot of care to usability. It's not that hard most of the time.
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#179I hope we can end the CAPTCHA experiment soon. It didn't work. Phone verification isn't good either, but for as much as I hate phone verification at least it actually raises the cost of spamming somewhat. CAPTCHA does not. Almost all turnkey CAPTCHA services can be solved for pennies. Solving the problems of SPAM and malicious traffic will be challenging... I am worried it will come down to three possible things: - A…
Re: I was banned from the hCaptcha accessibility account for not being blind (2023)
#180Audio captchas don't work for people with hearing issues and/or who don't speak your n supported languages, where n is usually Even for people for whom they do work, it's worth keeping in mind that bots can solve them by now, and so users whose activity looks too fraudulent, who are still given access to the visual captchas, have to be blocked from using the audio ones. I have also seen this happen.
Text captchas are a non-option by now, they're very easy to solve with LLMs, and the way they have to be phrased makes it impossible to align LLMs not to solve them, like you can do with the visual ones.
Google's ReCaptcha can get away with having no actual challenge for most users, blind or otherwise, but that's because they're Google, they do enough user tracking that they don't actually need a captcha. Google is the only company that can get away with this, and even for them, it doesn't work in all situations, even when the user fully trusts Google and has not adjusted any privacy preferences.
Sure, you could stop using captchas entirely, if you're fine with receiving dozens of viagra ads on every single platform each day, abolishing all "contact us" and comment forms on the internet, having a significantly higher credit card fraud rate (which translates directly to higher prices and a much worse experience for consumers), and getting all your semi-public records and social media activity immediately scraped by shady companies and sold to anybody who expresses any interest. Unsurprisingly, most users are, in fact, not fine with this.