Live data from Hacker News

hCaptcha now runs on fifteen percent of the internet

hcaptcha.com

41–50 of 380 posts

Re: hCaptcha now runs on fifteen percent of the internet

#41

I really hate all these captcha codes Why can’t they do something like a reverse SSL where we have to authenticate ourselves as humans? For example if I have an Apple account on my Apple devices, why can’t they figure out a way to authenticate me as a human from that information? This doesn’t work for all scenarios (eg throwaway accounts), but it could work for the majority?

Well, the point is to avoid automated abuse. Your Apple account on your Apple device doesn't stop you from unwittingly being part of a botnet, for example.

Why wouldn’t it? Unless they hack my account

Genuine question - I don’t know much about this field

Re: hCaptcha now runs on fifteen percent of the internet

#42
post #11

I think it's great. So many sites sit behind Cloudflare now and Cloudflare now uses hCaptcha, which is a big win. And the hCaptchas themselves are easy to complete. No more wondering if you actually clicked on 'all' the traffic lights anymore, yay! I inspected the source code of Google's reCaptcha offering and was disgusted at how many bits of information they were collecting. They also seem to be fingerprinting user…

> Google's reCaptcha code seemed to be very keen on knowing my 'cadence' or the way I used my mouse and how quickly (or how slow) I completed the captcha. It also looked at things like timezone, screen resolution, battery charge level etc So they could determine if it was 'you' who was using the captcha, soon after, in a separate session (even on a different device!)

I'd bet a good amount that they store that along with all the other personally identifying info they have on you (and google of course has a massive amount of that); which is basically why after a single reCAPTCHA solve, you wont see them prompt you again for ages - they know who you are.

Re: hCaptcha now runs on fifteen percent of the internet

#43
post #29
post #11

I think it's great. So many sites sit behind Cloudflare now and Cloudflare now uses hCaptcha, which is a big win. And the hCaptchas themselves are easy to complete. No more wondering if you actually clicked on 'all' the traffic lights anymore, yay! I inspected the source code of Google's reCaptcha offering and was disgusted at how many bits of information they were collecting. They also seem to be fingerprinting user…

reCaptcha has also gotten increasingly annoying lately. I forgot my password to one site and tried about 2 or 3 different passwords and in-between each it asked me to do about 7 or 8 of those labelling exercises. I finally just gave up and left the site. Not only that, but the labelling exercises weren't clear. It wanted me to label a "公交車" which means more like a public city bus and there were also school buses whic…

Recently Google's captcha asked me to mark all the traffic meters on the photos, and amongst the choices was a photo of a mailbox. It didn't let me through until I marked it as a meter as well.

Good luck to whatever self driving car they are training using this data.

Re: hCaptcha now runs on fifteen percent of the internet

#44

I really hate all these captcha codes Why can’t they do something like a reverse SSL where we have to authenticate ourselves as humans? For example if I have an Apple account on my Apple devices, why can’t they figure out a way to authenticate me as a human from that information? This doesn’t work for all scenarios (eg throwaway accounts), but it could work for the majority?

Webauthn may make it easy because it supports platform authenticators like Touch ID / Face ID. Two good demos are at http://webauthn.me/ and https://webauthn.io/ It's now supported in all major browsers but platform authenticators are likely not supported on all OS yet.

This makes a lot of sense - exactly what I was thinking

Re: hCaptcha now runs on fifteen percent of the internet

#45
How do we know your product preserves privacy when it's close sourced? Also, users should not be manipulated and used for training your machine learning models when they are trying to sign in on a website. I simply don't used it if the website is trying to give me this kind of nonsense.

Re: hCaptcha now runs on fifteen percent of the internet

#46
post #11

I think it's great. So many sites sit behind Cloudflare now and Cloudflare now uses hCaptcha, which is a big win. And the hCaptchas themselves are easy to complete. No more wondering if you actually clicked on 'all' the traffic lights anymore, yay! I inspected the source code of Google's reCaptcha offering and was disgusted at how many bits of information they were collecting. They also seem to be fingerprinting user…

NOPE

Its a fucking cancer. CANCER.

Its a gatekeeper...

It is a litmus of those that do not want tracking.

FUCK THIS TECH.

Period.

Its a proxy of bots/terrorists... and if you cant see that, then, fuck you.

We do not need this tech.

We need anti-bot tech, for sure, but this is the lamest way to accomplish such.

FUCK this tech

Re: hCaptcha now runs on fifteen percent of the internet

#47

I really hate all these captcha codes Why can’t they do something like a reverse SSL where we have to authenticate ourselves as humans? For example if I have an Apple account on my Apple devices, why can’t they figure out a way to authenticate me as a human from that information? This doesn’t work for all scenarios (eg throwaway accounts), but it could work for the majority?

Forget adding more draconian identity requirements. 95% of CAPTCHA use is simply unnecessary and could be straightforwardly removed or replaced with rate limiting login attempts per IP. Never mind sites that use it to prevent scraping. If serving static pages is that much of a burden that you want to discourage automated means of retrieving information that you're trying to publish, then work on your website performa…

That’s exactly what I’m thinking too! Lot of it is to prevent scraping and a lot of it is unnecessary

Re: hCaptcha now runs on fifteen percent of the internet

#48
I dislike the widespread use of captcha regardless of provider.

I realize anything connected to the internet will be subject to automated abuse, and it's impossible to run some types of services without taking some steps to defend against it, but it seems to me there's usually a way to handle that without invading the user's privacy or wasting their time. The exact details will vary based on the type of service, of course.

One particularly egregious misuse of captcha in a service I use presents one after I enter a correct username and password. An incorrect login says so without presenting a captcha. The potential reward for an attacker who successfully gains access to an account is high, so it seems almost certain anyone running a targeted attack would defeat this by handing it off to a human upon detecting that they had a good account.

Re: hCaptcha now runs on fifteen percent of the internet

#49
post #33

Curious what people think about hCaptcha?

Dislike it, to say the least. Since it doesn't seems to remember that I'm a human (reCpatcha did), now I have to constantly solve captchas on CF sites.

With hCaptcha (enterprise ver) this is entirely under the control of the customer.

We're not "remembering" in the same way, but have good enough instantaneous scoring to correctly guess whether or not a challenge is required most of the time.

Some customers may disable that option to meet their requirements. Not much we can do about that :)

Re: hCaptcha now runs on fifteen percent of the internet

#50
post #6

Curious what people think about hCaptcha?

Far, far superior to reCaptcha from a user's perspective using Tor. I can solve a few puzzles with hCaptcha and I know I'll get through and see the content. With reCaptcha I might solve 3 puzzles and then get denied anyway, or I might solve 10 puzzles with no end in sight and give up.

But also far superior to reCaptcha from a bot's perspective using Tor. Don't get me wrong: I also hate solving a gazillion captchas only because I'm using a VPN or get outright denied because my IP address happens to be a Tor exit node. At the same time you have to acknoledge that captchas don't stop bots, only slow them down or increase their operating costs. People in third world countries happily solve one image recognition challenge by Google or hCaptcha for far less than a penny. If Google's goal is to drive the costs up for malicious bot operators, then they're definitely doing the right thing. In the end, it won't stop them either since buying a couple thousand infected computers is probably not that expensive, but it is yet another stepping stone for anyone trying to bypass their captcha.
Post reply on HN