Live data from Hacker News

Moving from reCAPTCHA to hCaptcha

blog.cloudflare.com

71–80 of 200 posts

Re: Moving from reCAPTCHA to hCaptcha

#72
post #8

> "Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA. That is entirely within their right. Cloudflare, given our volume, no doubt imposed significant costs on the reCAPTCHA service, even for Google." Even in the article they say... "Google provided reCAPTCHA for free in exchange for data from the service being used to train its visual identification systems." ... I thought thi…

my bet is that the bean counters have caught up with this product, and it'll be run into the ground with excessive pricing, because Google products have to make millions or otherwise they'll be killed. most notably, Reader.

These complaints about Google "moving too fast" used to really confuse me. I couldn't really spot a meaningful difference in mean survival b/w Google products, start-ups similar to individual Google products, and other businesses' behaviour.

But I've now attained zen-like clarity on the issue: the complaints are coming only, and always were coming mostly, from people whose idea of appropriate change over time is to still complain about Google Reader almost a decade after it happened.

Re: Moving from reCAPTCHA to hCaptcha

#73

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

That, and ReCAPTCHA had hellbans. If you blocked cookies or were otherwise problematic, it would sometimes lock you out of all ReCAPTCHA-gated resources not by giving you a message describing what was happening, why, and how to fix it, but rather by simply pretending that your every attempt to solve the captcha failed. Obviously this is extremely frustrating, by design, but it gets even more so with compounding facto…

Captchas are fundamentally anti-human. I'm not saying there isn't a problem to be solved, I'm saying Captchas are a behavior enforcement mechanism overseen by robots and are anti-human.

I write the site owner short note when they go bad explaining why they just lost a customer and go somewhere else. Life is too short to put up with shitty tech.

Re: Moving from reCAPTCHA to hCaptcha

#74
post #60

Earlier quoted context omitted.

I've lost track of how many times I've had to read house numbers from Google Street View...

I haven't gotten one of those in years. These days it's just picking out buses, cars, traffic signals, and sometimes motorcycles. Maybe once in a while it'll ask for storefronts.

Most of mine lately have been traffic features also. This is a little tricky in some cases, e.g. with crossings, as it sometimes gives me things that I don't think are crossings but it insists I select, perhaps they are in the US, or the perspective is weird, or someone else has told it that a series of white squares is a crossing and it requires me to agree.

Re: Moving from reCAPTCHA to hCaptcha

#75

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

That, and ReCAPTCHA had hellbans. If you blocked cookies or were otherwise problematic, it would sometimes lock you out of all ReCAPTCHA-gated resources not by giving you a message describing what was happening, why, and how to fix it, but rather by simply pretending that your every attempt to solve the captcha failed. Obviously this is extremely frustrating, by design, but it gets even more so with compounding facto…

I don't think I've ever been "hellbanned", but I've certainly spent more than 5 minutes on trying to get a captcha to work.

After a while I usually need to ask friends in the US to help me, because it asks me a non-localized question.

My favourite question was: Select all fire hydrants.

I selected only the classic red one's you see in movies. Fail.

I selected the one's that were yellow too. Fail.

I sent a picture of the grid to a friend. He spotted that some of the pipes on a wall were fire hydrants, which I didn't know. Pass.

In my country we don't have hydrants. We have holes in the ground that are covered by a lid. After removing it you can attach the water hose there.

Re: Moving from reCAPTCHA to hCaptcha

#76
post #30

Earlier quoted context omitted.

I'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again". The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form…

Google pays Mozilla to be the default search engine in firefox. This is Mozilla's main source of revenue, so I doubt they will sue.

I wonder why they don’t negotiate with Msft to use Bing or even DDG instead. Seems... incredibly odd... to put oneself in a position where a third party is directly antagonizing your users, reducing your user satisfaction and likely dramatically increasing churn, but you can’t do anything about it because that same party is your main source of funding.

(Disclaimer, I work at msft. Nowhere near this though).

Re: Moving from reCAPTCHA to hCaptcha

#77

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

That, and ReCAPTCHA had hellbans. If you blocked cookies or were otherwise problematic, it would sometimes lock you out of all ReCAPTCHA-gated resources not by giving you a message describing what was happening, why, and how to fix it, but rather by simply pretending that your every attempt to solve the captcha failed. Obviously this is extremely frustrating, by design, but it gets even more so with compounding facto…

How, in your opinion, should Google have handled the matter in a way that does not give spammers or other abusive users ways to get around the measure? Bear in mind that any such approach has to be scalable to many zeros daily, the vast majority of which will not be empathically awful cases like your brother's very real pain and distress - most will be genuinely abusive behavior.

I want to be clear that I am not attempting to minimize your brother's pain or emotional suffering. I'm hoping that there might be an approach that's kinder and more compassionate to him while still accomplishing the same goals.

Re: Moving from reCAPTCHA to hCaptcha

#78
post #30
post #20

Earlier quoted context omitted.

By now, I almost immediately close a page with a reCAPTCHA, because the stream of buses, traffic lights, and cycles never seems to end when you're using Firefox. And then it says "too many requests from this computer" and refuses to continue.

I'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again". The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form…

> And businesses are okay with Google denying them money

Make sure they know. I write to sites and tell them they just lost a customer because Google doesn't give a shit. I've gotten replies from smaller outfits that had no idea what was going on.

Re: Moving from reCAPTCHA to hCaptcha

#79
post #30
post #20

Earlier quoted context omitted.

By now, I almost immediately close a page with a reCAPTCHA, because the stream of buses, traffic lights, and cycles never seems to end when you're using Firefox. And then it says "too many requests from this computer" and refuses to continue.

I'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again". The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form…

I think their cost analysis would mark you as a bot that got stumped by the captcha and thus a bet benefits. (Sales to bots are worse than not selling, else they wouldn’t implement this at all)

Re: Moving from reCAPTCHA to hCaptcha

#80

One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flie…

> One of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place.

It is understandable and I expect HCAPTCHA to do the same thing. The goal of a CAPTCHA is to identify you as a human. I don't know how ReCAPTCHA works, but I expect it to be like spam filters: they have a sample of bots, a sample of humans and assign weights to every aspect, in the end, the algorithm spits out a probability of you being human, and it will challenge you until it reaches a set value.

The thing is: if you hide everything for privacy reasons, you are making yourself indistinguishable from anything else using HTTP, including bots. That's the point, but it also means the only way to prove you are human is through a challenge.

Think of it like a private club. If you a regular and the bouncer is likely to recognize you and let you in without asking anything. But if you don't want to show your face, you will need to show your membership card every single time. That's the price of anonymity.

Post reply on HN