Live data from Hacker News

Introducing the Invisible reCAPTCHA

google.com

51–60 of 245 posts

Re: Introducing the Invisible reCAPTCHA

#51

Earlier quoted context omitted.

Wasn't recaptcha originally associated with Project Gutenberg's digitization efforts?

I guess not. https://en.wikipedia.org/wiki/ReCAPTCHA#Origin

It says there that it was.

Seems like a bait-and-switch. Do free labor for a good cause (PD books), turns out you're just growing Goolge's library which can be taken down at a whim.

Re: Introducing the Invisible reCAPTCHA

#52
post #8

This is so confusing. It doesn't explain how it works nor a demo page nor the reason behind why it went invisible.

It doesn't seem to be fundamentally different than reCAPTCHA. They will probably replace the click-this-checkbox box with a set of elements already on the hosted page. Only indexing a page's HTML isn't good enough -- it's better to also know how people interact with the HTML. Unfortunately, as soon as they click a link on Google, Google is no longer invited to the party, and is blind to how the user interacts with the page.

The next best thing a search company can do is have every website willingly track their users' mouse and key movements, and then willingly send all of that data to the company's inbox. In return, Google provides them with a binary classifier trained on all of the user click-stream/click-move data which determines whether or not the user is a bot!

It's an OK deal for the website owner; it's a great deal for Google. Not to mention, the user is now sending anonymous data to Google, at the expense of the website's Privacy Policy.

Google gets website owners to willingly install live-cameras on every corner of their website, and then willingly send over all of the footage, in exchange for "protection" from bots. Cough The Government gets citizens to willingly fill out lengthy tax forms, and then willingly send over a bunch of money, in exchange for "protection" from criminals. Cough

Re: Introducing the Invisible reCAPTCHA

#53
post #45
post #35

Earlier quoted context omitted.

I see lot's of those on Tor browser. There's nothing about entering street numbers, just identifying images that include street numbers. But perhaps that's also valuable. And what about the other major types, such as rivers, mountains, store fronts and street signs?

It depends on whether you're presented with the v1/noscript version or the v2 captcha. Desktop users may prefer the noscript version since it's faster to fill out with a keyboard if you're already typing into a form anyway instead of having to switch to the mouse.

Both v1 and v2 have noscript versions. Here is what the v2 noscript version looks like:

https://vc.gg/B9zmj4hi https://vc.gg/CTskizZe

Re: Introducing the Invisible reCAPTCHA

#55
post #30

What I want to know is what happens if you get 'trapped' in this invisible ReCAPTCHA? The most frequent encounters with CAPTCHA's I see are rejected API requests over VPN.

I also expect I will start getting silent registration failures with this. I'm using uMatrix to block most third-party scripts, and it's usually quite clear when I have to allow extra things with traditional captchas.

Then again, it's allow-more-and-retry on many pages already so nothing new in that regard.

Re: Introducing the Invisible reCAPTCHA

#56
post #42

I always wondered how blind people entered captchas. Does this finally make captchas accessible?

There is usually an audio version available, presumably screen readers are pre-configured to present the audio option on popular captchas by default.

I'm curious now, will have to give it a whirl when I get into the office :D

Suspect Google will rely on their vast knowledge of people's browsing habits based off IP/account/ad-tracking/browser-fingerprinting to skip the user input aspects. Although that said, a screen reader won't have the standard physical interaction clues client-side that a user is a real person, mouse tracking for ex. is probably a moot point. Not really sure how Google will handle those, or if blind users will get a degraded always-on captcha experience.

Either that or a headless screen reader becomes the scraping/botting tool of choice.

Re: Introducing the Invisible reCAPTCHA

#57

Earlier quoted context omitted.

Because you feel that data mining everything you do and serving you creepy-level ads isn't enough?

What's wrong with showing me relevant ads?

The problem is the method of building the "profile" that determines what's "relevant" for you.

Re: Introducing the Invisible reCAPTCHA

#58
post #5

While I like the idea of not having to deal with these annoying ReCAPTCHA prompts, something somehow feels "intrusive ?". I mean does this mean google is going to keep track of what I would be doing when I visit a site? Say for instance I am signing up for a website, does the password I enter get sent to google servers to be analyzed now?

>I mean does this mean google is going to keep track of what I would be doing when I visit a site? Oh buddy, I have bad news for you... https://support.google.com/dfp_premium/answer/1716364?hl=en https://www.google.com/analytics/#?modal_active=none https://www.doubleclickbygoogle.com/solutions/measurement/

Wow, I never heard of Pixel Tracking. That sounds super evil. Are there browser plugins to fight back on this one?

Re: Introducing the Invisible reCAPTCHA

#59

Earlier quoted context omitted.

What is "the jitter test"?

I would guess testing that the mouse pointer moves semi-randomly over the button, in a fashion typical of the way humans browse a web page

What about the Tab and Enter users?
Post reply on HN