Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

181–190 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#181

Earlier quoted context omitted.

Yeah, I should break down my methodology for arriving at the "hellban" conclusion. If I get a bunch of failures in a row, I'll first try the refresh button built into the captcha, and then re-solve a number of times. Then I'll try re-loading the page and re-solving, then I'll try in a different browser with cleared state and re-solving, then I'll try a different device and re-solving, and finally I'll try a different…

One thing I've found (after others mentioned it here) is that Google seems to reward impatience when trying to solve captchas. Going faster and making more mistakes and not waiting for loading images seems to help convice the algorithm that you are human. This is rough on anyone who thinks they are being rejected for not being accurate enough. OTOH, it is hard to figure out for sure what makes a difference. I use a p…

I usually intentionally get a few wrong to poison their learning data set. It doesn’t seem to impact the number of things I have to click on to get through.

I’m not sure what they’re measuring, but I doubt it has much to do with image recognition performance.

Re: Moving from reCAPTCHA to hCaptcha

#182
post #135

Earlier quoted context omitted.

I don't blame reCAPTCHA for existing, I blame Cloudfare for using. It made using Tor literally impossible. Hopefully this will be better.

Didn't Privacy Pass help here?

I have no idea what privacy pass is, but if it involves setting browser state across more than one site, then it breaks the tor anonymity model.

Anyway, hopefully hCaptcha works with Tor.

Re: Moving from reCAPTCHA to hCaptcha

#183

Earlier quoted context omitted.

The vast majority of users never see a recaptcha puzzle when you're using v2's invisible recaptcha.

And 0% of users see it if you're using reCaptcha v3.

It never presents challenges to users, but instead just buckets them into bot or not bot?

Re: Moving from reCAPTCHA to hCaptcha

#184

There are plenty of services that will happily accept a screenshot from a developer, send it out to live humans who solve it in real time, and then return the answers to the developer. I'm not going to link to them, but you can find them yourself by googling "buy recaptcha solver". The prices for the top two results are $0.50 and $1.39 per 1000 solves (respectively, $0.0005 and $0.00139 per solve). At that price poin…

Are there chrome extensions that I can use these with? I'd be willing to pay those rates to never have to solve a captcha again. I'm fine leaving the tab open for a few minutes while it's solved even.

Re: Moving from reCAPTCHA to hCaptcha

#185
post #40

Earlier quoted context omitted.

How can someone demonstrate this claim? reCaptcha is wildly sophisticated under the hood[1]. I use it on all three major browsers and find the number of challenges varies from 0 to 4: sometimes it says I'm verified without doing anything, other times I need to go through 4 screens. I would love to see someone put some numbers behind this claim, because I think it is false. [1] https://www.blackhat.com/docs/asia-16/ma…

I've experienced reCaptcha simply looping forever. After solving 5 or so screens, I give up and hope that reloading the page works. If not I usually switch to Chromium, which doesn't even get a single puzzle, just verified. That is my repeatable experience as the end user.

Same here. It seems to randomly freak out and block firefox.

I get why Firefox won’t sue Google. I wish end users would.

Re: Moving from reCAPTCHA to hCaptcha

#186
post #182
post #135

Earlier quoted context omitted.

Didn't Privacy Pass help here?

I have no idea what privacy pass is, but if it involves setting browser state across more than one site, then it breaks the tor anonymity model. Anyway, hopefully hCaptcha works with Tor.

Specifically designed to allow you to authenticate once and then use that as a proof of work across multiple sites, without revealing your identity as being connected across those sites. Here's the math: https://blog.cloudflare.com/privacy-pass-the-math/

Re: Moving from reCAPTCHA to hCaptcha

#187
post #183

Earlier quoted context omitted.

And 0% of users see it if you're using reCaptcha v3.

It never presents challenges to users, but instead just buckets them into bot or not bot?

Almost. It gives a botness score to the server, and it's up to the website to decide what to do with that score. They can pick a threshold to approve, reject, or apply stricter verification to.

Re: Moving from reCAPTCHA to hCaptcha

#188
It's not worth a rich person's time to solve captchas, while it is for a poor person. This has lead to captcha solving services, extensions plugins, etc, all which have high latency delay, not over a fast documented API. It would be 100 times easier if cloudfare/google let's you directly buy credits, at the mid-point price between current bid-ask spread, of say 50 cents per 1000 captchas, which would probably last you a few months to a year.

Re: Moving from reCAPTCHA to hCaptcha

#189
post #181

Earlier quoted context omitted.

One thing I've found (after others mentioned it here) is that Google seems to reward impatience when trying to solve captchas. Going faster and making more mistakes and not waiting for loading images seems to help convice the algorithm that you are human. This is rough on anyone who thinks they are being rejected for not being accurate enough. OTOH, it is hard to figure out for sure what makes a difference. I use a p…

I usually intentionally get a few wrong to poison their learning data set. It doesn’t seem to impact the number of things I have to click on to get through. I’m not sure what they’re measuring, but I doubt it has much to do with image recognition performance.

I just click stuff randomly and then hammer the submit button until the new images load. That seems to work even though I rarely tick the correct squares.

My new strategy is to just file support requests to any company using them, complaining that I did their test correctly but it still rejected me. My idea is quite simply to make reCaptcha unfeasibly expensive to use.

Why does the Deezer app installed on my desktop PC need a daily captcha?

That said, I use it myself on all of my companies' customer support forums to discourage people from sending me those pesky requests. In that sense, it's the new "please hold the line".

In any case, I'm glad that Google's motto is "don't be evil". That reassures me that using reCaptcha is morally acceptable ;)

Re: Moving from reCAPTCHA to hCaptcha

#190
This sticks out to me:

> We also had issues in some regions, such as China, where Google's services are intermittently blocked. China alone accounts for 25 percent of all Internet users. Given that some subset of those could not access Cloudflare's customers if they triggered a CAPTCHA was always concerning to us.

They are explicitly saying that China's blackmailing of Google is working so well it even affects decisions on using Google products outside of China.

I'm not a Google fan and think this move is a great improvement for the web and user privacy, but that this was explicitly motivated by China's blackmailing tactics is terrifying.

And we can from this post even make another case that also doesn't paint a nice picture: Cloudflare does not care enough about 25% of internet users to move away from reCAPTCHA - until it affects their bottom line in a visible and immediate way.

Post reply on HN