Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

61–70 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#61
1. I think challenges from hCAPTCHA is harder than reCAPTCHA. It's far and even further from human-friendly compared to reCAPTCHA.

2. hCAPTCHA seems to be using the similar revenue model as early stage reCAPTCHA and it even pay its users. I doubt that its model is sustainable.

3. A huge company like Google may not be able to handle user data well, so a small company will be able to?

Re: Moving from reCAPTCHA to hCaptcha

#62
I've ran into hCaptcha a couple times recently and found it vague and I had to try to guess what they meant. Both times it asked me to identify the truck. Well, what do you mean by "truck?" are you counting a semi as a truck? I ended up having to do it twice because I don't consider a semi a "truck" but they did.

Re: Moving from reCAPTCHA to hCaptcha

#63
post #5

The enterprise grade hCaptcha[1] is not free either. Does anyone have pricing information? [1]: https://www.hcaptcha.com/#plans

It says it's free for non-enterprises .

Okay, but Cloudflare is very much an enterprise, and lots of people here are working in such places, so it's a decent point.

Re: Moving from reCAPTCHA to hCaptcha

#64
post #26

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

You're forgetting the main benefit for google, which is getting humans to train all their vision models for free. At one point they were just forcing X% of clicks to fill out a captcha regardless of origin or identity just to get more data. I for one am getting quite tired of trillion dollar corporations getting things for free out of me. Hard pass.

If that was still the main benefit for them, they wouldn’t be planning to start charging for it, because that would—and, as this article shows, has—cut off much of that data flow, as reCAPTCHA clients abandon the service for another one that isn’t charging them.

Re: Moving from reCAPTCHA to hCaptcha

#65
post #14

It's a start. reCAPTCHA is a notorious pain in the arse for anyone whose browser isn't Chrome and for anyone who doesn't keep cookies. I'm not sure if hCaptcha will be better, but it's hard to imagine it being any worse.

On the other hand, their new HCAPTCHA is a notorious PITA for anyone, including those whose browser is Chrome and keep cookies.

Browsing an "I'm under attack"-mode website behind Cloudflare has been super annoying for me since last week. To the point that I usually close the page when I see a HCAPTCHA. Their visual challenge is harder to navigate than reCAPTCHA, and because this is their business model I suspect they have incentive to make it easier.

Re: Moving from reCAPTCHA to hCaptcha

#67

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

That, and ReCAPTCHA had hellbans.

If you blocked cookies or were otherwise problematic, it would sometimes lock you out of all ReCAPTCHA-gated resources not by giving you a message describing what was happening, why, and how to fix it, but rather by simply pretending that your every attempt to solve the captcha failed. Obviously this is extremely frustrating, by design, but it gets even more so with compounding factors like "the library is closed at this hour, so I can't get a fresh connection."

The worst I've seen has been when it happens to people who aren't well equipped to guess what's happening. When my friend's younger brother got hellbanned from his PlayStation account, he spent 30 minutes trying to identify traffic lights (or whatever) and then retreated crying to his room, because he wasn't able to deduce that Google was gaslighting him. He trusted Google. They had him convinced that he was such a failure he couldn't even identify traffic lights correctly, and he was -- quite reasonably -- inconsolable for a while.

Thanks a lot, Google.

Re: Moving from reCAPTCHA to hCaptcha

#68

Earlier quoted context omitted.

It says it's free for non-enterprises .

Okay, but Cloudflare is very much an enterprise, and lots of people here are working in such places, so it's a decent point.

The parent edited their comment, it didn't say "enterprise" when I commented.

Re: Moving from reCAPTCHA to hCaptcha

#69
> Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA

So it came down to cost.

> Over the years, the privacy and blocking concerns were enough to cause us to think about switching from reCAPTCHA. But, like most technology companies, it was difficult to prioritize removing something that was largely working instead of brand new features and functionality for our customers.

I like that they're upfront about this. In most companies / teams of this size, these issues are always swept under the carpet until something ugly forces you to clean up at a later point in time. It's just unavoidable.

Re: Moving from reCAPTCHA to hCaptcha

#70

Earlier quoted context omitted.

The point of a blockchain is that to edit an earlier record, you would need to edit every record that comes after (due to storing a hash of the previous block in the current block). However, it doesn’t make sense when one entity controls the entire system because if a hacker (or even an insider) can change one record, they could change all of them. Hence why a good blockchain would be distributed . Then, if one node…

Yes if do not you want to distribute your data with random people over the internet, you need a Merkle tree. Not a stupid blockchain with all the downsides a blockchain have.

[deleted]
Post reply on HN