16 ms·
Why Captchas have gotten so difficult
- diafygi 8y ago> Malenfant says that five to ten years from now, CAPTCHA challenges likely won’t be viable at all. Instead, much of the web will have a constant, secret Turing test running in the background. I wonder how tracking-based captchas can be compatible with privacy regulations like the GDPR. Do you have to positively opt-in to a website seeing whether or not you're a robot? We're basically moving towards a world where the venn diagram for the web and privacy no longer intersect.
- withdrawn 8y agoI’ve already mostly stopped using the internet. I’m down to about four sites now, and even those are beginning to look like they’re in doubt. If I chart the trajectory of TV, and consider that much of what I do on the internet fills the void that TV once held, then I might completely drop the web from my list of time killing behaviors. Not impossible, since it’s pretty much a less convenient version of sitting on the couch, listlessly surfing hundreds of low quality cable channels with the remote control. And of course, even TV is reaching an invasive climax too, these days. DVR set top boxes are worse than nielsen devices. So, my spare time is mine to use as I wish, and we’ll see what I do with it...
- CM30 8y agoThe issue isn't just that humans struggle with them or that bots are getting better or what not, it's because there's no way to make a captcha that works across multiple websites like a standard 'library' and expect it to remain uncracked. Anything that becomes common will be attacked and defeated, because there becomes a financial incentive for spammers and no gooders to do so. The solution is to make captchas that are bespoke to each site, since it means the same bot or script can't be used on every one and spammers have to go out of their way to crack each one. You can already see this right now; sites with their own systems generally get no spam at all. But given that most people aren't programmers, well it means they're stuck with mainstream captcha systems which present a giant target to the internet's never do wells. Niche sites can avoid the issue with topic specific questions though.
- Invictus0 8y agoThis doesn't really hold water. 1. It's not feasible for various website to implement their own custom CAPTCHA formats. Building custom CAPTCHAs is a lot of work. 2. The custom CAPTCHA tasks wouldn't be that different from each other. As the article discusses, image/text/audio recognition are some of the only universal tasks that can work for CAPTCHA. 3. Nothing is stopping a malicious actor from implementing a "check which type of captcha" function and then selecting one of several CAPTCHA cracking functions. Fragmentation of CAPTCHA format just delays the cat and mouse game. 4. Some custom captchas, like the chess captcha, are actually not even that difficult for computers to solve. https://nakedsecurity.sophos.com/2013/03/12/chess-captcha/ https://nakedsecurity.sophos.com/2013/03/12/chess-captcha/
- CM30 8y ago1. As I said, this is a huge reason stuff like Recaptcha exists, and why custom ones can't work here, even if they're probably better if done correctly. 2. You can also use stuff like timing how long it takes someone to fill in the field, hiding form fields with CSS or JavaScript, randomising field input names, checking the referrer, etc. All these come up in tutorials about captchas. 3. You could ask them niche specific questions instead of requiring them to do general tasks. This is what I do with all topical internet forums and sites; have a wide array of custom written questions on the topic in place of stuff a bot can easily figure out. For instance, all questions on Wario Forums are about Wario Land and WarioWare games, not things meant to be 'culturally neutral'.
- hombre_fatal 8y ago#3 (a rotation of specific questions) is definitely a measure some sites could use, but as you point out, it's incredibly niche -- I've only even seen it on forums. For example, what questions could Reddit ask you? Wario Forums is pretty much the ideal on the niche spectrum, so it's not a very useful baseline for comparison. I rotated questions on the /register page for a large forum I run, but as my forum became more popular and more of a spam magnet, my attackers simply built a lookup table of my questions->answers. I regressed back to Recaptcha. Another problem is that I was surprised how many legit users would be pruned out by a simple question like the equivalent of "what color is Wario's hat?" for, say, a forum that covers games in general. I did basic stat tracking on the pass-rate per question to know which were bad ones, and it seemed pretty random which ones users had trouble with. Or they'd accidentally be riddles like (made-up example) "How many triangles in a triforce?" 3? 4? 5? And people would finally register and complain on the forum that a seemingly trivial question was too hard. Or they didn't know what "the website footer" was. At a point, especially if you're not so extreme on the niche/theme spectrum, Recaptcha was the better trade-off. I've said this in another comment, but I'd love to see an HN submission where we discuss anti-spam/anti-abuse strategies instead of just doing the easy thing of bashing Recaptcha.
- hedora 8y ago> Google wouldn’t say what factors go into that score, other than that Google observes what a bunch of “good traffic” on a site looks like A few days ago, I signed up for some service on a new-ish laptop, and it made me pass the storefront captcha three separate times. This is yet another example of the social credit score being implemented in the US; in this case punishing users for opting out of continuous tracking (which will in turn be used for price discrimination or worse). The good news is that this is almost certainly going to lead to a massive backlash as it becomes more common.
- Cacti 8y agoWhile I see your point, social credit is not tracking, it is tracking with legal, economic, and political consequences. Given that the consequences to you of opting out of this tracking are little more than a minor inconvenience of your time, comparing it to the nightmare that is the social credit system is laughable. And, I would add, you're in part trivializing the horrendous impact of the social credit system by making this comparison, because it gives others the impression that this is merely a difference of degree, rather than of substance. It allows people to make arguments like "Oh, the US credit score is just like China's social credit score, so the social credit system can't be that bad." Yeah, NO. You don't get denied freedom of movement between cities or states because you owe a few dollars, you don't have your passport revoked because you don't use Google cookies, you're not forced to sit in the back of the bus because of something vaguely political you posted on twitter, you don't get denied the ability to send your kids to certain schools because you rolled a stop sign. The social credit system is not a _tracking system_, it is a _legal system_ (made possible by surveilance), and while the US may one day be there, to suggest they are anywhere even on the same planet yet is laughable. Your average person in the US still, even after decades of abuse, has innumerably more rights than your average Chinese citizen.
- bennofs 8y ago> ... little more than a minor inconvenience of your time This is not entirely correct. I have seen recaptchas that simply deny access without giving any option to solve them when browsing with Tor. The message says something like: automated systems detected unusual activity, try again later
- rahuldottech 8y agotbh I'm sick of just how often I have to solve those click-on-image captchas. It's a pain.
- dplgk 8y agoYou don't need to prepend your statement with tbh unless we are to presume things you say without that prefix are dishonest.
- josephorjoe 8y agoI avoid them as much as possible -- if someone wants me to train their machine learning algorithm, they can pay me. newegg lost some of my business recently after thinking it was a good idea to make me fill in a captcha before taking my money.
- mschuster91 8y ago> newegg lost some of my business recently after thinking it was a good idea to make me fill in a captcha before taking my money. Probably they are combatting fraud, especially the variant "check if the credit card is still valid". There's not much defense against a botnet operator trying out a 100k dataset of stolen CC numbers other than captchas :( For the interested, this kind of fraud simply orders cheap (on the order of 1-2$) stuff online to check if the card/cvv is valid. Doesn't draw much attention unless one of the victims has transaction notification active or diligently checks their CC bill.
- zaarn 8y agoJust install the buster addon; it solves the captcha automatically via speech-to-text recognition.
- OnlyRepliesToBS 8y ago'we want more free labor'
- sys_64738 8y agoI find if I use VPN then google will display one on search. In particular, when I try using Opera VPN then I always get one. I decline to do them so search via bing instead. Forcing users to prove their not bots is totally the wrong approach. They should be forcing bots to prove they're human so that real humans don't see this nonsense. Easier said than done, but that's not my problem.
- zaarn 8y ago>Forcing users to prove their not bots is totally the wrong approach. They should be forcing bots to prove they're human so that real humans don't see this nonsense. How do you tell who's the user? A bot can look like a user and a user can look like a bot.
- Cacti 8y agoI agree with you, but, to be clear, the issue isn't VPNs, it's that the VPNs you are using are also used by spammers/bots/etc. or a large amount of other people. If you set up your own VPN somewhere that is just used by you and your family (for example), you will never run into this issue. As a case in point, the same issue crops up with lots of users going through the same corporate proxy. And it's the same reason that you can run Netflix (for example) through a personal VPN with no issue but will run into problems if you use a popular, retail VPN service.
- nprateem 8y agoWhat's the point of a VPN if you're easily identifiable? Surely you want to blend into a crowd?
- Cacti 8y agoI mean, unless you're going through additional effort, you're still identifiable through a VPN. Any web tracking, whether through cookies or through fingerprinting, still works just fine. At best you're merely making it more difficult. Also, there is also no reason, though it would be a PITA, that you can't add your own measures to a private VPN, whether that's rotating IPs or some other measure. Is it going to keep your illegal activities truly anonymous? No, but neither is a retail VPN. It is a matter of degree and what tradeoffs you're willing to make. As far as uses for a private VPN, the most obvious is to ensure intermediate parties, particularly on the same subnets, can't snoop on your actual traffic _content_. This isn't going to keep you anonymous from the NSA, but it sure will help against corporations (ISPs and their numerous corporate parents/cousins/siblings). Another benefit is that by protecting against packet level inspection, you are protecting yourself from many current forms of traffic shaping and bandwidth metering/throttling, as well as from limits on services you are running or the content of files you are downloading, as well as from intermediaries (e.g. ISPs) from inserting ads or additional tracking or whatever else into your (mainly web) traffic. This also comes into play not just with your normal ISP but any you are using while traveling (coffee shops, airports, hotels, and other untrusted networks).
- nprateem 8y agoThese really make my blood boil. I continually trip whatever it is that makes Google think I'm a bot (probably a VPN + ublock). Sometimes it takes upwards of 5 tries (each with 3 or 4 tests) to pass. After the first failure the audio one stops working, and sometimes that's unintelligible. I honestly wonder how anyone who's even slightly visually impaired is supposed to pass them. I wouldn't be surprised if in the not too distant future they were hauled up before the courts on discrimination grounds, and not before time. There's something very wrong when a human consistently fails CAPTCHAs. For one thing I've tried selecting all boxes containing parts of a traffic light/fire hydrant, and only the ones that mostly contain parts of the object and have failed both times.
- jesseb 8y agoI run Linux, use my own VPN, and use Firefox with uMatrix. CAPTCHAs are one of the most user-hostile things I experience on the web. I've had to give up on registering for sites, or signing into sites I'm already registered with, because after literally minutes I still hadn't gotten through. I actively try to avoid sites that use CAPTCHA but unfortunately it's not always possible.
- tootahe45 8y agoHad the same setup &, i found that on brave i can do them in 20 secs compared to 3 minutes. Not saying I support them messing with FF but at the end of the day, I need to get things done.
- nyolfen 8y agoi have what sounds like the same setup as you but i don’t think i’ve ever done more than 3 captchas sequentially, and almost always 1 or 2. /shrug
- jrootabega 8y agoIf you're using an adblocker, you probably also don't have any positively identifying google cookies, which has become more and more synonymous with "bot" to them. They could defend it from the opposite direction: when you're logged in to google they trust they know you, so when you're not, there's a lack of trust. Not suspicion, no, but a factual lack of trust. There's plausible deniability if anyone ever claimed it's suspicion, and that they do it to punish people who want to remain independent and anonymous. But if that's the effect and they don't do anything to prevent it... To me it feels similar to the duality of gas station "cash discounts," which have also been perceived as "credit card penalties." Or mobile providers' "free data for the music streaming service of our choice."
- zaarn 8y agoFor Google ReCaptcha, simply install the Buster addon, it solves the captcha for you via speech-to-text. For captcha's in general, I think we should stop pretending that we can prevent bot traffic from a dedicated attacker without annoying the users. A simple captcha from the 2000's (the ones with lines over a word or number of letters and numbers), should be good enough to hold off basic script kiddies. Same for a basic TTS audio clip.
- slezyr 8y agoOld captchas allowed you to see the content without need to pass it. I'm too tired to see cloudfront pages with recaptcha.
- driverdan 8y agoUnfortunately Buster no longer works. Google detects it now and makes you start over.
- zaarn 8y agoBuster works if you set it to another STT service than the Google API Demo. They seem to have caught onto that one.
- tobias2014 8y agoYes, and it is also working with google cloud speech using your own key.
- n_ary 8y agoThis. Google just disables captcha immediately. Also I tried clicking the audio manually, it immediately disables with a notice that “we are getting .... please try again later”.
- zaarn 8y agoUse on of the other STT apis than the Google Speech demo.
- outime 8y agoGoogle reCAPTCHA is the absolute worst. It makes me solve several puzzles very often, usually when I use a mobile network and I’m not logged in with any Google account. It’s so frustrating that most of the times I find a reCAPTCHA I give up before trying and just go elsewhere e.g. when a site uses reCAPTCHA for sign up or after the first failed login, I’ll most likely skip if I don’t absolutely need to access such website. Glad to see I’m not the only one who’s getting tired!
- johnisgood 8y agoThe worst part is that quite a huge percentage of the Internet relies on it! Soon we won't be able to use any sites whatsoever because of it. I don't like where this is going. :/
- userbinator 8y agoIndeed, I definitely am not happy with how much control Google has over the Internet in general. Everything from how they present and rank search results, Google Analytics scripts everywhere, the sometimes vaguely-political messages on their homepage, the ostensibly-anti-bot checks including CAPTCHAs and just plain banning you if you want to do more "advanced" searches (like the ones Fravia would've taught...), etc.
- pmoriarty 8y agoThere's other (mysterious to me) stuff that sites call to Google for, apart from captchas and analytics. As a uMatrix (and former NoScript) user, I've long noticed that many sites make calls to ajax.googleapis.com for I have no idea what. Quite often the site will refuse to work without that. To be fair, a lot of sites make use of javascript from a lot of other sites as well: cloudfront and amazon are common.
- johnisgood 8y agoYeah, or Akamai.
- leni536 8y agoGoogle: Hey, you don't have any Google login/session cookies? Not even one from a previous login (yeah, you can't fully log out)? That's wrong! Here, click on the traffic lights for 5 minutes! Or have one of those super slow fade-in fade-out captchas!
- tootahe45 8y agoBeen testing captchas inadvertently quite a bit in fresh installs across multiple VMs, from what I can tell it has nothing to do with whether you have cookies or privacy configurations, it comes down to whether you use Chromium or use a shared IP. If you use Firefox even without privacy configs, expect to spend 3x the time as Chrome, that's not even including the fact that those fading images load 5x slower on Firefox. If you use a shared IP (in my case a $6/mo vpn) + Firefox, it's not even worth trying imo as it can take 3+ mins to complete captchas on most sites and it's much quicker to just open Brave to complete it in 10 seconds, the amount of tries you have to do also has nothing to do with getting all the pictures correct.
- deleted 8y ago[deleted]
- darkpuma 8y agoI've found it easier to get past their captchas with chrome from a shared IP than from firefox on any normal residential IP.
- c0nducktr 8y agoThe fade-in fade-out captchas are especially infuriating. Captchas are already bad for UX but those which purposely slow down how fast you can solve them are on a whole different level.
- lowkeyokay 8y agoWell google’s traffic CAPTCHA’s main purpose is to label a huge data set for Waze. At least it must be a huge beneficial (to google) side effect. Am I wrong?
- konschubert 8y agoWaze or Waymo?
- hyperman1 8y agoSo if it asks to click on traffic lights, and a large enough group of people click on, say, red cars, can we make their their self-driving cars stop if they see red cars on the road? Come on HN, lets all do this for a few days, you know we can do it ;-)
- webmobdev 8y agoWhat many commentors here don't realise is that Google also uses reCaptcha to make you do free work for them.
- yyyymmddhhmmss 8y agoMy first reaction to your comment was that I would be pretty shocked if anyone here didn’t realize that, and wouldn’t you know I have now read more of the comments and here I am shocked. The idea that this problem results from heightened security measures is wrong, but it’s not laughable; it’s just sad.
- ypolito 8y agoWhenever I browse with the TOR browser, it's been 100% impossible for me to verify myself as a human even if all my answers are correct. I think they need to fix this bug, or at least give a message that the CAPTCHA won't be solved so we no longer waste our time. Their No CAPTCHA's are very rare for me when I'm browsing logged in to my personal google account under the same session, on a normal browser. They can be confident I'm not some kind of a bot, yet they still require me to solve on average two different tests to train their "AI".
- yyyymmddhhmmss 8y agoOh wow, yeah I use FF with uBlock Origin and they are not short by any means. An aside from the corporate dystopia at hand: I do not know as much as I wish about how this works, but am intrigued at how the objects so often bleed into other “boxes” at just the right amount to demand multitudes more cognitive energy to negotiate with myself over what side of this false binary to place my bets on. Back to corporate dystopia, my awareness of the procedure and intent is so blackboxed that I feel like a mule. Since I started approaching them with sloppy selection and minimal to no discern, I’m doubtful that the length of the challenge has any correlation with a measurement of suspicion at all. Rather, those liable to be this considerate will similarly recognize identify the wrath the cookie monster.
- oil25 8y ago
- vpmpaul 8y agoI've actually started trying to see how wrong the newer Capchas from will let me be on purpose. Either by not selecting all of them or picking wrong ones. They let you through a lot of the time.
- danShumway 8y agoMe too! My working theory was that companies like Google were using the capchas mostly to generate AI data, so only a few of the images on any given test were actually already labeled. Any of the other images (particularly the really grainy ones) would accept any answer because they were genuine classification questions. Reading this article, I wonder if it's not even that -- that companies like Google are assuming, "you're not going to get everything right, so we'll give you some leeway."
- vharuck 8y agoI remember when a forum I browsed introduced the text captcha. Users intentionally typed in the same incorrect expletive for the word not known to captcha. It was easy to tell by the font. The goal was skew the algorithm.
- onetimemanytime 8y agoJust use Chrome, and be logged in as a Google user. What a coincidence that this serves Google's interests...
- konschubert 8y agoAnd I SUCK at these to the point where I think I’m not getting the rules of the game. For example, for the one with traffic lights: Am I supposed to just mark the light bulbs or also the poles and beams?
- darkpuma 8y agoYou're doing it right. Google is gaslighting you; lying and telling you you've failed challenges when you actually solved them correctly. They do this to punish users who opt out of the google 'ecosystem' by not having a google account, not using chrome, using adblockers, etc. The proof of this assertion comes when you manage to enable the noscript version of reCAPTCHA (which is only available on sites that have opted to use the lowest security setting). Once you start using noscript reCAPTCHA, you discover that your correct answers are accepted the first time every time. The challenges have the same format; click the cars, click the traffic lights, etc. There are two differences: the tiles don't fade in slowly, and the correct answers are always accepted. Presumably when google implemented their dark patterns in reCAPTCHA, they couldn't be bothered to implement them when javascript wasn't available. I hesitate to draw attention to this since Google might correct their error, but I'd like for people to become more aware of their anti-social business practices. (By the way, the noscript version will accept either sort of answer. Only the bulbs, or the entire enclosure. Both answers are accepted.)
- userbinator 8y agoI've seen those ones too, and was planning on writing a filter that replaces the "normal" ones with the noscript one, on the assumption that it was just someone not copying in a "<noscript>...</noscript>" fragment, but since you mention "is only available on sites that have opted to use the lowest security setting", I suspect that won't work. Accessibility guidelines used to mandate that content was accessible without JS, which may be the reason why the noscript version exists, but it seems the latest revision has unfortunately removed that requirement. No, I will not run arbitrary code on my computer just to access your site...
- RobertRoberts 8y ago
- erokar 8y agoI've concluded I am not human.
- FakeComments 8y agoIs it not monopolistic behavior that Google favors their own customers in their captchas? I hope the EU fines Google for leveraging their security library prevalence to coerce people to use Chrome and/or open Google accounts. I also wonder if that’s GDPR compliant: unless you accept Google’s data collection terms on GMail and/or Chrome products, they will use their position as security authority to degrade your browsing experience on third party sites.
- TorKlingberg 8y agoI find it strange how all the comments here are blaming Google. Isn't it obvious that CAPTCHAs have gotten difficult because AI got better at solving them? Soon bots will be better than humans at solving CAPTCHAs, and the system will fail completely. I predict that then Google and Facebook will completely block new user signup from Tor, VPNs or browsers without cookines. Everyone else will require an existing Google, Facebook or similar account to create an account.
- csydas 8y agoI think the main thrust is that the tool is not fit for purpose, but Google benefits from it anyways. They get the AI training data, but the website owners still get hammered by bots, and privacy conscious users and users who have the audacity to be from a country flagged by RECAPTCHA get to struggle. Living in Russia at the moment, I almost prefer the sites that just outright block me to the stupid RECAPTCHA that cycles me through 3-4 iterations of images only to ask me to try again. RECAPTCHA is no longer doing what it promised, and that's the general thrust of the article; the bots are just getting too good for it.
- CM30 8y agoIt's not even bots that are breaking them much of the time. The spammers just get people in third world countries/using mechanical turk type services to break them. Captchas like this cannot stop a human determined to break the rules.
- hombre_fatal 8y agoRight, but eliminating all attackers except the ones who are willing to spend money on human labor is an incredibly strong filter.
- Pharmakon 8y agoWe hate them for the same reason we hate airport security theater; they do not work and have a high burden on the people being subjected to them. Plus, as it’s Google doing it, you can hardly escape the goddamned things. So yeah, we blame Google for using us as data classifiers and adding hoops and hurdles to the open net, while accomplishing precisely dick. I for one hope that AI gets to the point that it can effortlessly beat them, so we can stop dealing with them.
- pmoriarty 8y agoI've long suspected that Google quickly realizes when the user is human, but then serves up some more images for them to "solve" to get some extra training data for its pattern recognition AIs.
- deleted 8y ago[deleted]
- sizzzzlerz 8y agoThis is so eye-opening. I've been frustrated with these things for a while and I always figured it was me. When asked to click on the traffic signs, I'm never sure whether to click on just panes that have a part of a sign or include cells that show the posts it is attached to. I finally got so discouraged, I tried the audio clues and have found that to be easier. I've found that, after listening closely, I only need to identify a single word and that is usually relatiely easy. All in all, however, I really do hate these things.
- deleted 8y ago[deleted]
- hippich 8y agoThat's why I created hashcash.io in 2014 =) Some ridiculus examples - https://twitter.com/hashcashio https://twitter.com/hashcashio =)
- dessant 8y agoI've made a browser extension that solves CAPTCHAs using the audio challenge. Native user input simulation will come with the next release. https://github.com/dessant/buster https://github.com/dessant/buster On my part it is a direct reaction to developers and their employers cutting corners and adding these challenges to login forms and anything else you can imagine. It's entirely reasonable to show a challenge after a couple of failed login attempts, but they should never be part of the default login flow. These decisions hurt users. If you work on a product that shows a CAPTCHA while logging in, please discuss this issue with your team and consider not challenging your users during their first login attempt.
- tyingq 8y agoI do use a CAPTCHA, but not on a login form. It's solely for a "contact us" form. We do try to encourage just regular email with a mailto: href, but unfortunately, customers expect a form. And, if I don't use the captcha, we get flooded with spam. We are using Google's "nocaptcha", which is usually unintrusive, but is a pain for anyone not logged into some Google property.
- alexdumitru 8y agoI manage to get rid of line 99.99% of spam with a hidden checkbox. Bots tend to check them, so I just ignore it if it's checked.
- Izkata 8y agoI remember reading about a blog that used this method something like 10 years ago, and wondered why I don't hear about it more often. Glad to know it still works just as well as back then.
- ficklepickle 8y agoI made a contact form that sends the data URL encoded if JS is disabled, or JSON if JS is enabled. If the back end gets url-encoded data, it's spam. I also use the hidden field trick, but I label it phone number and fill it with zeros. Then I hide it with an external stylesheet. I don't actually want a phone field, its a decoy. If it is changed from zeros, it is spam. Most spam bots don't seem to parse external stylesheets. I've had zero contact form spam with this method. Mind you it is a very low volume site. I was just having fun with it, making a php-style contact form backend but using node.js. I read lots of those old blog posts you mention.
- robin_reala 8y agoEvery time a CAPTCHA thread comes up I have to point this out. By using one you’re externalising your business costs onto your users. You can make that choice, but if you do you’re far more likely to negatively impact the section of society that already has problems online: those who need to use assistive technologies.
- seandougall 8y agoI came here because that last point is getting lost in the discussion. > While a bot will interact with a page without moving a mouse, or by moving a mouse very precisely, human actions have “entropy” that is hard to spoof, Ghosemajumder says. It's bad enough that systems working from this (highly dubious, IMO) premise will force us all to use the mouse even if we're used to the tab and arrow keys; much worse is that there's no workaround for people who _can't_ use the mouse and rely on switch control. It sounds like an accessibility nightmare.
- jplayer01 8y agoSo, I use Vimium to interact with my browser with solely my keyboard 90% of the time. I wonder how much this in any way correlates with the absolutely infuriating amount of captcha challenges I get one after the other.
- fxfan 8y agonot to mention that somewhere in the back of your head there is a calculation going as a user that this is an expensive website to you, in terms of effort.
- zzo38computer 8y agoIf you need CAPTCHA I may suggest plain text CAPTCHA (preferably ASCII only) with entirely server side computation, meaning anyone can read it and has maximum compatibility. If necessary, make your own rather than using an existing package, since that makes it less likely that automated spam will get through if you use a different one for each thing. However, you should never need CAPTCHA to login (except possibly anonymously; Fossil requires a CAPTCHA to login anonymously), or to do stuff while logged in. You should not require CAPTCHA to read public information either, or to download (since you may wish to use external download management; for example, I prefer to use curl to download files rather than using the web browser, and it seems that I may not be the only one). Of course manually entered spam will still get through even if you do use CAPTCHA.
- EvanAnderson 8y agoEach time I'm faced with a Google reCAPTCHA I think about how how I, and so many people like me, are unwittingly helping to train our eventual robot overlords.
- salgernon 8y agoI'd welcome a CashCaptcha that charged me $.05usd to click past a reCaptcha. They happen enough to be annoying, but not often enough to present a financial burden - but if I were a spammer trying to abuse automated access, the actual cost might finally outweigh the return.
- jsmith99 8y agoI use Firefox android with Ublock origin and am logged into Google (boo). I used to use a plugin to change my user agent to Chrome when on Google sites. This was necessary as you get the old style search results page if you use Firefox, but if you pretend to be Chrome you get the current page style which works perfectly. With that plugin enabled I always had to solve multiple recaptchas and my recaptcha v3 score was 0.1. Disabled it jumps to 0.9 and v2 gives me no puzzles. Guess I will have to live without shiny Google search results then.
- Macha 8y agoHonestly, I'm finding Google's captchas quite difficult of late because its Americanised. It asks me to identify crosswalks (oh.. pedestrian crossings, I thought you meant the pavement), find traffic lights (I don't traditionally expect them to be above the road or on motorways), or identify storefronts which are not always clear, maybe because I lack the cultural context. And I'm from a major Western European city, which is about the closest I can get to American culture without being not, I wonder if they present the same captchas if they think you're from rural China or Uganda.
- mmagin 8y agoWhat's actually wrong with reCAPTCHA is that google has convinced so many sites all over the web to require it to use them, and all that free labor is going to just improve Google's machine learning programs.
- umvi 8y agoI'm not convinced OCR is as good as humans. I recent did a project making an unauthorized copy of a rare ($2000) book from a university library. I scanned in every page, but tesseract OCR really struggled with pages that started off straight but curved off. I tried lots of preprocessing techniques with limited success. My options were to type it in by hand or rescan that page so the lines were straight.
- computerex 8y agoWhat a weird way to compare OCR to humans. If a human can't see the writing because the page surface is curving away, they'd adjust the page surface. Likewise, getting decent scans is the most cost and effort effective way of getting good performance in OCR. I personally found tesseract to be incredibly good, and have even used it in non-traditional OCR applications for doing things like reading signs.
- umvi 8y agoI'm saying that I can read skewed/bending pages easily, but I'm having a super hard time getting tesseract to play nice with such images. I almost always need to rescan. Tesseract is incredibly good... as long as your lines of words are straight.
- peteretep 8y ago> The latest version, reCaptcha v3, announced late last year, uses “adaptive risk analysis” to score traffic according to how suspicious it seems; website owners can then choose to present sketchy users with a challenge, like a password request or two-factor authentication eg: if you're not browsing the web signed into a Google account and allowing all their tracking. Fuck that.
- oil25 8y agoIt seems they are difficult because they're intentionally designed to de-anonymize users coming in over VPN/Tor, using the small variation in click timing. If you see one of these and want to stay anonymous, close the tab and walk away.
- MASM32_COM 8y agoThis [captcha] thing is exactly how you make people stay away in droves. If people are too inconveinienced by an extra click or two, or by password and login, why would any one stick around for waves of recaptcha? my response to captcha is very simple. "ill find the info later, likely on a competitors site"
- niqmk 8y agoI removed it, I'd lost almost 70% registered account because 3 loops of Google Recaptcha
- mcv 8y agoI fear any test where a machine has to decide whether you're human enough, is always going to be easy to game for a machine. You can't replace humans with machines and then not expect machines to replace humans. When you look at it that way, the whole captcha approach, no matter how clever, seems doomed to fail. Why not simply allow bots? If it is because bots exhibit behaviour you don't want (like spamming), why not filter them based on the behaviour you don't want? Learn to recognise spam rather than fabricating some test. And when bots are truly indistinguishable from people, is it really a problem that they're not real people?
- deleted 8y ago[deleted]
- kenzieL 8y agoRecently I have felt like half the time I'm browsing I am filling in god-awful captchas, multiple times. They're so infuriating.
- hanging 8y agoRelated article from 2012, 230+ comments: https://news.ycombinator.com/item?id=4307136 https://news.ycombinator.com/item?id=4307136 Reposted in 2014, 190+ comments: https://news.ycombinator.com/item?id=7945283 https://news.ycombinator.com/item?id=7945283