Live data from Hacker News

Google’s new reCAPTCHA has a dark side

fastcompany.com

531–540 of 566 posts

Re: Google’s new reCAPTCHA has a dark side

#531
post #299

Earlier quoted context omitted.

> It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). That may be the case for some people, but that is not my complaint, nor that of many folks I know. I simply don't care how FB, Google and other surveillance outfits mak…

They have no right to it, and I have every right to try to limit their visibility. That's entirely fair! But also: You have no right to use my website, and I have every right to limit your access. Recaptcha is simply part of this negotiation.

Recaptcha v3 is an invasion of privacy and a blatant violation of the GDPR.

It's as much of a negotiation as offering someone to pay through perpetually indentured servitude is: it's illegal and immoral.

Re: Google’s new reCAPTCHA has a dark side

#532

I'm... actually struggling to see what this dark side is. The data is collected under a non-reuse agreement. It's specifically there to make a good captcha. There are other captcha vendors, and they don't make that promise (and I can think of at least one who admits they collect and resell data via captcha). So the downside here is that no one has a credible way to compete with Google? Maybe because their Google cook…

It's a land grab of the general web and browser market, not of the captcha market. They're using the captcha to disincentivize users from using browsers other than Chrome or from not having a Google account. And now with v3, it's supposed to happen on every page of the web? It shouldn't be too hard to see it's a disaster.

> They're using the captcha to disincentivize users from using browsers other than Chrome or from not having a Google account.

It has absolutely nothing to do with Chrome. And anyone who is sane has switched to Firefox and is now patiently enduring how lousy it is by comparison because ad blockers are sacrosanct.

> And now with v3, it's supposed to happen on every page of the web? It shouldn't be too hard to see it's a disaster.

Yes, site owners gotta opt in to captchas. Most sites already have enough connections to Google on every page they could already do most of this work. But that's unethical.

Ultimately, a increasingly sophisticated statistical analysis of users is the only reliable way to get robots out of spaces meant for humans. Our social media is crippled by robots masquerading as humans for the profits of various agencies who's names you aren't even privileged to know, but you're concerned about opt-in countermeasures because... Why again? That in a dark future every mom and pop web shop is gonna have sophisticated log analytics at their disposal, either because free software finally gets off its ass or because state capitalism does what it does and awards all the business to 1-2 competitors?

To me, you're arguing about the color of the insulin bottle rather than pointing out how absurd the system that can cheerfully jack it's price 10x is.

Re: Google’s new reCAPTCHA has a dark side

#533
post #494

Earlier quoted context omitted.

Crummy solution, but get the FF user agent switcher in TBB. And then set it to Windows/Chrome. And all those Scroogle-captchas are easy-peasy.

can you expound on this? not sure I grok

     1. Download Tor Browser Bundle
     2. Connect to the Tor network
     3. Download a user-agent switcher in the plugin store in TBB
     4. Change user-agent to "windows, chrome"

Re: Google’s new reCAPTCHA has a dark side

#534

Earlier quoted context omitted.

If you don’t think that lawyer fees scale linearly with regulation complexity you’re either an early Uber employee or mistaken. When you’ve built a social consumer business in Europe that is profitable after compliance, send me a term sheet.

Why would you need lawyer fees? How is GDPR complex? It literally is: - you only store data you require to run your business - you delete data if customer requested deletion - you give the customer their data if they ask for it If your profitable business is built upon selling customer data wholesale to third parties, then good riddance.

Google and Facebook et al stores and processes PII on non-customers, without informed consent given from users.

It's still early days. We'll see what will happen when the DPA's and the courts have fielded a few high profile cases.

Re: Google’s new reCAPTCHA has a dark side

#535

Google has been doing the same with reCAPTCHA v2 [1]. They are aware of the legal risk of outright blocking users from accessing services, so reCAPTCHA v3 contains no user facing UI, Google merely makes a suggestion in the form of a user score, so the responsibility to delay or block access and the legal liability that comes with it falls on websites. reCAPTCHA v2 is superseded by v3 because it presents a broader opp…

Your comment adds a lot to the conversation, so I don’t want to be more contrary than necessary. It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). Much like the highest information-gain feature for the future price of a…

Part of the point of objecting to big data surveillance is that we ultimately don't know how it's being used, despite what companies claim about its use.

Can I believe you? ...even if you're telling the truth, big corps can hide their most malicious practices from most of their own employees.

To me, it doesn't matter how e.g. Facebook actually uses my data today, because even if they're telling the truth they could change their policies tomorrow, or get hacked, or some third party (incl. the gov't) could get hacked, etc. It's better as a user to try and prevent such data from ever existing in the first place.

Re: Google’s new reCAPTCHA has a dark side

#536
post #534

Earlier quoted context omitted.

Why would you need lawyer fees? How is GDPR complex? It literally is: - you only store data you require to run your business - you delete data if customer requested deletion - you give the customer their data if they ask for it If your profitable business is built upon selling customer data wholesale to third parties, then good riddance.

Google and Facebook et al stores and processes PII on non-customers, without informed consent given from users. It's still early days. We'll see what will happen when the DPA's and the courts have fielded a few high profile cases.

This! I hope it costs them dearly. I have never (willingly) given them consent to have my data, yet I know they have loads of it, just because other people I know are careless with data about me.

Re: Google’s new reCAPTCHA has a dark side

#537
post #299

Earlier quoted context omitted.

Your comment adds a lot to the conversation, so I don’t want to be more contrary than necessary. It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). Much like the highest information-gain feature for the future price of a…

> It’s nonetheless a shame that it’s so universally misunderstood how ad-supported megacorps make their money that even highly sophisticated users of the web still talk about the value of personal data (source: I ran Facebook’s ads backend for years). That may be the case for some people, but that is not my complaint, nor that of many folks I know. I simply don't care how FB, Google and other surveillance outfits mak…

And you never know what those corporations could do with the data politically. Recently there has been a lot of talk about how these types of companies seem to favor certain politics. Who's to say that they won't use this data in the future for influence?

Re: Google’s new reCAPTCHA has a dark side

#538

Earlier quoted context omitted.

> You could either stop using these services or How do you stop using a service when you have little or no indication that it does something like this before hand, and afterwards the privacy is already gone? If I use a site and view my profile page and the url contains aa account id or username and some google or facebook analytics is loaded, or a like button is sitting somewhere, how am I to know that before the pag…

> How do you stop using a service when you have little or no indication that it does something like this before hand, and afterwards the privacy is already gone? It is small comfort for the average user, but the way you do it is use noscript. It makes the web awful , sure, but it won't happen to you. > It doesn't even matter if I have an account on Google or Facebook, they'll create profiles for me aggregating my dat…

> I sort of wonder what you envision this actually meaning.

I mean it to respond to the common response people sometimes give in conversations like these, which is "that's why I don't use Facebook" or "that's why I stopped using Google services". For this conversation, whether you use Facebook or not is irrelevant, they still gather your information, and in the same way myriad other advertisers (or however they bill themselves) do through online tracking. Google and Facebook are large, and have a portion that's easily visible, but they are not the whole problem by a long shot.

> If when a user tries to log in I check the referrer to see if it contains a proper URL, have I violated your privacy?

No. Noting which door a customer came into your store seems fine to me. That by default customers come in wearing the logo of the last store they visited is weird, but entirely something they can control. Having people shadowing all your customers while in the store looking and listening for tidbits they can report back on to get more info about those people is pretty creepy. As you suggest, the way to get around most of that is to dress blandly and say nothing.

Here's the thing, we're a market economy. There's a transaction going on, where we're trading away something (our information and privacy) to a company for some product, or possibly the right to view a product we might consider buying. How many people are actually aware of this transaction? If they aren't aware of the transaction, there's a name for that when it's a regular good, and it's theft (or fraud). The difference here is that most of our government systems don't apply any rights of ownership to this information, so our regular rules don't apply. I admit, they may not make sense to apply entirely, but at the same time, it's obvious that something is lost in the transaction, whether the person losing it realizes it at the time, or views it as important enough to make a big deal about when they notice.

Re: Google’s new reCAPTCHA has a dark side

#539

I'm... actually struggling to see what this dark side is. The data is collected under a non-reuse agreement. It's specifically there to make a good captcha. There are other captcha vendors, and they don't make that promise (and I can think of at least one who admits they collect and resell data via captcha). So the downside here is that no one has a credible way to compete with Google? Maybe because their Google cook…

> The data is collected under a non-reuse agreement Oh you sweet summer child. Would you by any chance be interested in buying a bridge? Despite that, even assuming if it's true and we'll have a lovely accurate AI captcha system. The big down-side is that captcha is breaking programmable web. I maintain a lot of small software crawlers from simple notification applets to bigger analytic crawlers and the web in the pa…

> Despite that, even assuming if it's true and we'll have a lovely accurate AI captcha system. The big down-side is that captcha is breaking programmable web.

I actually find this argument to be a bit compelling, if I'm being selfishly honest. It's super annoying that crawlers are so awkward to write these days, and I miss the days when they worked better.

> but services like cloudflare, distils, captcha break them and while there's always solutions to these systems they are very hard to distribute to users (you can't really pack in pupeteer, selenium or some other webengine automation stack with your app).

I don't disagree, but I also think we may be asking to keep model T's or gasoline driven 1-person bikes around. These technologies made more sense once, but make much less sense now.

> Public data should be public.

Sure, but what you don't get to mandate is how their public. If someone wants to make public information available in a specific way and you don't like that way, the burden is on you to republish it. Outside of a very narrow accessibility scope, I'm neither legally nor morally obligated to cater to your specific needs. And indeed, as a service or data provider I have my own problems.

It's by no means an imaginary threat CAPTCHAs are solving. This is not a classical phantom security issue that statism uses to justify authoritarianism. It's equivalent to locking my doors when I leave a shop or making sure that my wares are properly labeled and not spoiled.

> These sort of idiotic measures are not compatible with web protocol.

The web protocol as you envision it hasn't been compatible with reality for a long time now. Hell, your crawlers are themselves a violation of the spirit of the original web. You are part of the very problem you're railing against!

> The web only know one thing - 1 IP address == 1 person and it should be encouraged not dismissed.

I suspect this statement is why you got downvoted, for what it's worth.

Re: Google’s new reCAPTCHA has a dark side

#540

Earlier quoted context omitted.

It doesn't block it because it's generally not active on all pages of a site. The description of v3 sounds more like Google Analytics and will probably be treated similarly.

I find a v3 block to be unlikely for the same reason v2 isn't in easylist - too much friction for the list users. Websites will likely break completely when performing actions if they don't receive any sort of verify token from the browser. It would probably be best to have a list for recaptcha v3 as a built-in optional filter so that users know they've enabled it and know why websites might be breaking.

On the other hand, the lists haven't removed ad / tracker blocking for sites that block ad block users. I still see "disable adblock to view this site" occasionally. I think leaving rules in place that result in blocked access to sites, but letting through Google tracking scripts on every page because it results in the same would be a huge misjudgment on the part of the list maintainers.
Post reply on HN