Live data from Hacker News

hCaptcha now runs on fifteen percent of the internet

hcaptcha.com

371–380 of 380 posts

Re: hCaptcha now runs on fifteen percent of the internet

#371
post #311

Earlier quoted context omitted.

Similar deal where I am at present in India: the small ISP uses carrier-grade NAT, so there’s malware and related activity occurring every day from at least one of the who-knows-how-many people behind this one IP address. Last time I was here in 2016 it was actually a lot worse than it is now (then, any Cloudflare site would trigger it, so I’d be hitting dozens of challenges per day), but I still get the occasional h…

Try using privacy pass. It's designed for use cases like yours.

That still requires you to fill out a CAPTCHA at least once, and also requires that you install a browser extension, which I baulk at doing, especially when it needs the “do anything on any website” permission.

Re: hCaptcha now runs on fifteen percent of the internet

#372

Earlier quoted context omitted.

>Not once did it tell me that I'm a robot Right, unfortunately you've completely misunderstood the point of Friendly Captcha, a question which is answered right there on its main page. >>How does FriendlyCaptcha tell apart bots from humans? >>It doesn't, FriendlyCaptcha adds a small cost and complexity for spammers that becomes large at scale.

Right, I guess it's time for you to upgrade the UI of your tool then, as when it's inactive it says "Anti-Robot Verification" and once the challenge is done it says "I'm not a robot", while in reality, none of those things are true, as you said yourself. You might also want to rebrand to use a different word than "Captcha" as you're not actually telling robots and humans apart, you're simply adding PoW to an action,…

Actually the user you're replying to is not the author of the service, from what I can tell.

Re: hCaptcha now runs on fifteen percent of the internet

#373

Earlier quoted context omitted.

Right, I guess it's time for you to upgrade the UI of your tool then, as when it's inactive it says "Anti-Robot Verification" and once the challenge is done it says "I'm not a robot", while in reality, none of those things are true, as you said yourself. You might also want to rebrand to use a different word than "Captcha" as you're not actually telling robots and humans apart, you're simply adding PoW to an action,…

Actually the user you're replying to is not the author of the service, from what I can tell.

Oh dear, it seems so. Thanks for letting me know, I guess I just assumed it would be the creator of the service who would defend it, not someone else, but seems you're right.

Re: hCaptcha now runs on fifteen percent of the internet

#375
post #126

Earlier quoted context omitted.

> it seems to me there's usually a way to handle that without invading the user's privacy or wasting their time As much as I agree with your dislike of captchas, I don't think this is true at scale (unless universal online identities existed, which could and should include anonymous identifiers by design). When you need to accept information from anonymous users (comments, votes, forms, registrations), there's no way…

CAPTCHA does not scale. CAPTCHA spams real people with requests and wastes my VALUABLE time, and still labels disabled people as subhuman. It's offensive. It's ineffective. It's outdated. It's reaching a point where encapsulating a VPN with anti-captcha is something I'd pay for.

[deleted]

Re: hCaptcha now runs on fifteen percent of the internet

#376

Earlier quoted context omitted.

I largely agree. Cloudflare requires hcaptcha if you mistype your password a single time when accessing their dashboard. The UX of hcaptcha is not good, especially in a flow where I'm already fixed on goal (doing something in my dashboard). If I need to stop thinking about dns settings or caching to pick out photos with bicycles, that's a really expensive context switch for my brain. And in my experience, you need to…

You're probably leaking lots of data to Google. Browse the Web with strong privacy protection (temporary container addon in firefox, ublock, privacy badger, decentralize...) and you'll see that recaptcha UX is just worse (slowly loading new pieces to identify after you solve them, one after the other). I can't count the number of stairs, hills, fire hydrants, cars, trucks, bicycles, traffic lights, pedestrian crossin…

I've completed both of them, and I am firmly of the opinion that hcaptcha is harder to complete than recaptcha. That is when I'm being prompted to complete it.

I'm comfortable with the amount of data I'm exposing online. And where I'm at, hcaptcha is not better. And even if recaptcha prompted at the same rate, I'd still prefer recaptcha over hcaptcha.

Re: hCaptcha now runs on fifteen percent of the internet

#377
post #306

Earlier quoted context omitted.

Just turn on "Resist Fingerprinting" in Firefox and you'll find ReCAPTCHA _really_ annoying! I have to solve 3-5 "panes" of a ReCAPTCHA on _every_ page... It's very annoying that preserving privacy comes with this cost. I almost want to just add a "DeathByCaptcha" extension to handle these for me and pay a few cents for every page I visit, lol

> It's very annoying that preserving privacy comes with this cost. It doesn't necessarily have to if Google supported privacy pass like hcaptcha does. The problem is that they don't.

Why would they? Supporting privacy-preserving options is not within their business interests.

Re: hCaptcha now runs on fifteen percent of the internet

#378
post #42

Earlier quoted context omitted.

> Google's reCaptcha code seemed to be very keen on knowing my 'cadence' or the way I used my mouse and how quickly (or how slow) I completed the captcha. It also looked at things like timezone, screen resolution, battery charge level etc So they could determine if it was 'you' who was using the captcha, soon after, in a separate session (even on a different device!) I'd bet a good amount that they store that along w…

Just turn on "Resist Fingerprinting" in Firefox and you'll find ReCAPTCHA _really_ annoying! I have to solve 3-5 "panes" of a ReCAPTCHA on _every_ page... It's very annoying that preserving privacy comes with this cost. I almost want to just add a "DeathByCaptcha" extension to handle these for me and pay a few cents for every page I visit, lol

It's not a cost. Google doesn't want you to protect your privacy from them. It's a punishment.

Re: hCaptcha now runs on fifteen percent of the internet

#379
post #192

Earlier quoted context omitted.

It doesn't work for me, comes back with the error: Verification failed: Background worker error undefined I'm using latest Firefox on GNU/Linux. Admittedly I've got a lot stuff blocking all sorts of things, and I'm not really sure what's kicking to block background workers, but I'm glad it's blocked. Anyway, after disabled literally all blocking tools that I have, it still refuses to load.

That's not good, could you maybe provide more details in the Github repo [0]? The widget is open source, hopefully we can figure out what is blocking it here. We test the captcha in browsers up to 8 years old and on many devices, do you perhaps have background workers disabled entirely? Here is a link to the widget on its own [1], does that have the same behavior? How about a minimal worker example [2]? [0]: https://…

Didn't try the other links but the jsfiddle link just says Preparing worker in Firefox here and neither button ever does anything.

Re: hCaptcha now runs on fifteen percent of the internet

#380
post #102

Earlier quoted context omitted.

Maybe would be kind of fun if we, the users, could form a coalition to deliberately mislabel photos on captures on a mass scale. It just seems there lacks a way to make it happen beyond the hacker community.

4chan users already used to do this for the old text based ReCaptcha. The idea was everyone put in a particular racial slur (they're not very imaginative) for the second word. I doubt it had any impact.

If I remember correctly, it did have some impact.

I believe at one point you could use that racial slur in place of the second word in the captcha and it would accept it.

Post reply on HN