Live data from Hacker News

Google's Captcha in Firefox vs. in Chrome

grumpy.website

241–250 of 503 posts

Re: Google's Captcha in Firefox vs. in Chrome

#241

Earlier quoted context omitted.

To be fair, lots of things on the internet don’t work in the most populous country in the world.

> the most populous country in the world The United Nations estimates the current population of China around 50,000 more than the population of India. Given the uncertainty of these numbers, I can't exclude that India already has the most numerous population.

Could be, I don't know. 50,000 is a village in these contexts! I'd really like to explore India, it is, also, vast.

Re: Google's Captcha in Firefox vs. in Chrome

#242

I thought this was just me and their stupid caption being impossible for even humans to solve; turns out I was just being gaslighted this entire time and they're just discriminating against Firefox users? How does the EU or someone not shut down this sort of anti-competative monopolostic nosense? I didn't think I could get more furious about having to struggle with these captions all day, but somehow I am. Please eve…

EU may end up dealing with it, they need complaints first. You’d be amazed how few people fill out complaints with the government. I just filed a complaint about this with the US department of justice antitrust division, feel free to do so as well so they realize how abusive this is!

Re: Google's Captcha in Firefox vs. in Chrome

#243

Earlier quoted context omitted.

Sending my data to Google as a condition of using someone else’s site also isn’t secure. Training Google AI also isn’t something I signed up for.

Not saying I like the precedent of Google being inescapable, you're not "signing up" for anything. A web server is 100% in its rights to refuse to send you a page, on their terms.

Unless you dont want to access to whatever is behind a sites captcha, you are signing up to solving their ai cv problems.

Re: Google's Captcha in Firefox vs. in Chrome

#244

I've never understood what happened to reCAPTCHA, it was originally so great and is now just so, so toxic. Originally it was an awesome solution based on OCR'ing books that usually worked quickly on the first try, and almost never took more than two. Then it turned into a single checkbox (analyzing mouse movement) so it was even faster... and I remember some simple image-based like "select the images of cats" that we…

They also changed it so that if you've seemed human in the past, they're able to determine if you're probabilistically a human now.

This data is a few years old but I imagine it's the same based on my experience.

They're using your cookie + IP + your account data to determine if you're probably a human.

A LOT of reCAPTCHA sites never prompt you. You only know if it's there because you're on Tor or something.

Re: Google's Captcha in Firefox vs. in Chrome

#246

Google Captcha is a complete mess at this point and I often leave websites that use it if it's not essential to what I am doing

Even more annoying are those sites that insist on using it, even though they know I'm human -- for reasons like I've paid them some money or jumped through their KYC hoops. At that point it's just being rude and exploitive, and, personally, I've reached the point where I'll simply take my business elsewhere if a site chooses to treat me with so little basic respect.

There's a case for preventing bot action even if the bot is willing to pay. Though putting a captcha right after a payment step is borderline fraud.

What's KYC?

Re: Google's Captcha in Firefox vs. in Chrome

#247

Earlier quoted context omitted.

The problem with recaptcha alternatives is that they either are insecure or require time and money to continue to be ahead of bots. All of the "interactive stand-alone approaches" from that page can be beaten with run-of-the-mill OCR (other than perhaps the 3d challenge) and with almost any mobile phone speech recognition engine (and, if the attacker has the money, can send it off to Google's cloud speech-to-text). A…

I implemented simple question / answer antibot filters on registration forms for a few sites. Nobosy ever made the effort to customize their bot to answer to those very few questions. I guess it doesn't make sense economically. However if a big site would go that way, it would be filled with bots in a day.

This is probably good enough for 90% of websites that accept user content. Then in the small chance it isn't because of growth or some random spammer decided to spend some time on your site, then you can switch to something like recaptcha.

Re: Google's Captcha in Firefox vs. in Chrome

#248

I consider putting the following on my cv: 2016-2019: working for google - analyzing street footage for implementing AI for self driving cars. Maybe I should also invoice google for the effort.

Would a class action lawsuit for unpaid wages be plausible?

Re: Google's Captcha in Firefox vs. in Chrome

#250
post #39

I was going through the same ordeal as a Firefox user, so I've made Buster to solve challenges and reclaim some of that lost time: https://github.com/dessant/buster If you're a developer, please consider replacing reCAPTCHA on your site with an alternative. reCAPTCHA discriminates against people with disabilities and those who seek privacy, and it gaslights you into thinking you did not solve the challenge correctly,…

The problem with recaptcha alternatives is that they either are insecure or require time and money to continue to be ahead of bots. All of the "interactive stand-alone approaches" from that page can be beaten with run-of-the-mill OCR (other than perhaps the 3d challenge) and with almost any mobile phone speech recognition engine (and, if the attacker has the money, can send it off to Google's cloud speech-to-text). A…

The problem with CAPTCHA and the like are they seek to stop programmatic-browsing of websites, that both Firefox and Chrome support out of the box. If companies are concerned about non-human access they should make an official API instead of their website being a de-facto unofficial API. If they are concerned about fraud they will be woefully defended by CAPTCHA, it makes no judgement on the validity of transactions at all and doesn't prevent frauds signing in manually.

Ironically, Google has committed at least $75 million and likely hundreds more of fraud, via stolen refunds and stolen banned-account balances!

https://www.businessinsider.com/google-emails-adtrader-lawsu...

https://www.searchenginejournal.com/adsense-lawsuit/248135/

Post reply on HN