Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

21–30 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#21
One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use.

We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users.

ReCAPTCHA essentially flies in the face of the recent blocking features rolling into Safari and Firefox and more privacy-aware users...growing by the day.

In many ways it's a genius structure from Google. 1. Convince people to use your privacy challenge. 2. Serve it when you don't see Google tracking cookies. 3. Offer a way around that with the least privacy-aware browser available (Chrome use is growing steadily month over month.

So good on Cloudflare.

Re: Moving from reCAPTCHA to hCaptcha

#22

> "Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA. That is entirely within their right. Cloudflare, given our volume, no doubt imposed significant costs on the reCAPTCHA service, even for Google." Even in the article they say... "Google provided reCAPTCHA for free in exchange for data from the service being used to train its visual identification systems." ... I thought thi…

In the article they also say:

> Again, this is entirely rational for Google. If the value of the image classification training did not exceed those costs, it makes perfect sense for Google to ask for payment for the service they provide.

This might be exacerbated in the case of Cloudfare. Imagine a system where 99% of the visitors being challenged are human. The data gathered from such visitors is quiet, quality data. That fits the usecase of validating an anonymous poster on some random blog. Now consider the Cloudflare usecase. Visitors will only be challenged when Cloudflare already expects you're a bot. Most of the challenges are served to bots. The data is much lower quality, but their cost per challenge has remained the same.

It could just be that as this type of usecase became dominant, the balance of value tipped.

Re: Moving from reCAPTCHA to hCaptcha

#23
A little off-topic, but the article mentions they support Privacy Pass. I remember seeing the announcement a little ways back when they first released it but just kind of forgot about it. Is anyone using the browser extensions? Has it reduced the amount of captchas you end up seeing, or made your browsing experience better in any way?

Re: Moving from reCAPTCHA to hCaptcha

#24

Has anyone else seen reCAPTCHA getting way more difficult of late? It often takes me a full minute to find all of the tiny traffic lights hidden away in a set of low-quality images.

Just use Buster[1]

[1] https://chrome.google.com/webstore/detail/buster-captcha-sol...

Re: Moving from reCAPTCHA to hCaptcha

#25
A few days ago I encountered this when Cloudflare decided my IP address (which is behind an ISP-level NAT) was suspicious all of a sudden (which it hadn’t been doing, a pleasant change from when I was at this location three years ago when half the internet sprouted Cloudflare CAPTCHAs at me). It was awful to solve, worse than the substantial majority of reCAPTCHA checks I’ve encountered. Certainly nothing like the illustrations in the article.

Re: Moving from reCAPTCHA to hCaptcha

#26

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

You're forgetting the main benefit for google, which is getting humans to train all their vision models for free. At one point they were just forcing X% of clicks to fill out a captcha regardless of origin or identity just to get more data.

I for one am getting quite tired of trillion dollar corporations getting things for free out of me. Hard pass.

Re: Moving from reCAPTCHA to hCaptcha

#28
It's funny that we need to ensure humans are the ones performing certain actions like making a purchase or accessing a service, but we let machines make decisions over very important matters in our lives (credit/financial decisions).

It's intriguing they said Google will charge for reCaptcha, any information on that? I can't imagine all the small business owners will have to start paying, but perhaps if they did they'd just remove it altogether (a net win!).

Re: Moving from reCAPTCHA to hCaptcha

#29

A few days ago I encountered this when Cloudflare decided my IP address (which is behind an ISP-level NAT) was suspicious all of a sudden (which it hadn’t been doing, a pleasant change from when I was at this location three years ago when half the internet sprouted Cloudflare CAPTCHAs at me). It was awful to solve, worse than the substantial majority of reCAPTCHA checks I’ve encountered. Certainly nothing like the il…

I tried a hcaptcha and it was way harder to solve than the usual recaptcha. However, It was significantly easier than the recaptchas you get when using tor.

Re: Moving from reCAPTCHA to hCaptcha

#30
post #20
post #14

It's a start. reCAPTCHA is a notorious pain in the arse for anyone whose browser isn't Chrome and for anyone who doesn't keep cookies. I'm not sure if hCaptcha will be better, but it's hard to imagine it being any worse.

By now, I almost immediately close a page with a reCAPTCHA, because the stream of buses, traffic lights, and cycles never seems to end when you're using Firefox. And then it says "too many requests from this computer" and refuses to continue.

I'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again".

The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form again", and reloads the entire page.

That's the cost of privacy; broken pages and refused access because Google says "NO!".

And businesses are okay with Google denying them money. I wonder if they did a cost/ben analysis if they find it worthwhile.

Thanks to Google, I've actually saved quite a bit of money, they lost out hundreds recently when their automated systems decided to refuse my transaction. Their loss and my gain.

Post reply on HN