Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

31–40 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#32
post #30
post #20

Earlier quoted context omitted.

By now, I almost immediately close a page with a reCAPTCHA, because the stream of buses, traffic lights, and cycles never seems to end when you're using Firefox. And then it says "too many requests from this computer" and refuses to continue.

I'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again". The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form…

Google pays Mozilla to be the default search engine in firefox. This is Mozilla's main source of revenue, so I doubt they will sue.

Re: Moving from reCAPTCHA to hCaptcha

#33
post #14

It's a start. reCAPTCHA is a notorious pain in the arse for anyone whose browser isn't Chrome and for anyone who doesn't keep cookies. I'm not sure if hCaptcha will be better, but it's hard to imagine it being any worse.

I know this is a common complaint, but I personally have no issues on both macOS and iOS Safari.

Re: Moving from reCAPTCHA to hCaptcha

#34
post #26

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

You're forgetting the main benefit for google, which is getting humans to train all their vision models for free. At one point they were just forcing X% of clicks to fill out a captcha regardless of origin or identity just to get more data. I for one am getting quite tired of trillion dollar corporations getting things for free out of me. Hard pass.

Did you even RTFA and look at hCAPTCHA? hCAPTCHA couldn't be more grossly focused on neural-net training. Hell, one challenge asks you to draw a bounding box and another is a classification tagging.

Re: Moving from reCAPTCHA to hCaptcha

#35

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

I would love to see the raw data on how many transactions have been abandoned because of ReCaptcha; if I had to solve a test to purchase my shopping, I'd go elsewhere (and there are places that are not as hostile out there).

I cannot understand the stupidity of putting your entire business in the hands of an advertisement company who gives no shits about you as a business or a person, apart from your data.

I can say for certain ReCaptcha has made me reconsider a purchase and is a major factor in my purchasing decision. If I can't use all my privacy tools (including noscript, and I only whitelist a few times to get the right scripts), then I don't care about what you're selling.

Hopefully in the near future ReCaptcha breaks altogether due to enhanced privacy protection.

Re: Moving from reCAPTCHA to hCaptcha

#37
post #14

It's a start. reCAPTCHA is a notorious pain in the arse for anyone whose browser isn't Chrome and for anyone who doesn't keep cookies. I'm not sure if hCaptcha will be better, but it's hard to imagine it being any worse.

How can someone demonstrate this claim?

reCaptcha is wildly sophisticated under the hood[1]. I use it on all three major browsers and find the number of challenges varies from 0 to 4: sometimes it says I'm verified without doing anything, other times I need to go through 4 screens.

I would love to see someone put some numbers behind this claim, because I think it is false.

[1] https://www.blackhat.com/docs/asia-16/materials/asia-16-Siva...

EDIT: Are you downvoting because you don't like reCaptcha, or because you can't (or won't) set up an experiment to demonstrate this claim and prefer to just jump on the bandwagon?

Re: Moving from reCAPTCHA to hCaptcha

#38
IMHO CPATCHA is a lazy way to protect your service as you shift the burden to your users.

Maybe if you are big and essential for some users, you can afford that. But if not, be aware that users will turn their back on you if you add obstacles between them and your service.

Edit: meant to say “be aware that some users will turn their back to you”

Re: Moving from reCAPTCHA to hCaptcha

#39
post #38

IMHO CPATCHA is a lazy way to protect your service as you shift the burden to your users. Maybe if you are big and essential for some users, you can afford that. But if not, be aware that users will turn their back on you if you add obstacles between them and your service. Edit: meant to say “be aware that some users will turn their back to you”

But if not be aware that users will turn their back on you if you add obstacles between them and your service.

You have to balance that against how many users you'd lose if the site was down/vandalized/compromised by an attacker if the captcha protection wasn't there to keep it out.

It's often worthwhile moving the captcha away from the initial login or signup form and only putting it on the second or third attempt to login, or on features that put significant load on the server.

Re: Moving from reCAPTCHA to hCaptcha

#40
post #14

It's a start. reCAPTCHA is a notorious pain in the arse for anyone whose browser isn't Chrome and for anyone who doesn't keep cookies. I'm not sure if hCaptcha will be better, but it's hard to imagine it being any worse.

How can someone demonstrate this claim? reCaptcha is wildly sophisticated under the hood[1]. I use it on all three major browsers and find the number of challenges varies from 0 to 4: sometimes it says I'm verified without doing anything, other times I need to go through 4 screens. I would love to see someone put some numbers behind this claim, because I think it is false. [1] https://www.blackhat.com/docs/asia-16/ma…

I've experienced reCaptcha simply looping forever. After solving 5 or so screens, I give up and hope that reloading the page works. If not I usually switch to Chromium, which doesn't even get a single puzzle, just verified.

That is my repeatable experience as the end user.

Post reply on HN