14 ms·
Moving from reCAPTCHA to hCaptcha
- cm2187 6y ago> But, sometimes, when we're not 100% sure if something is malicious or good we issue it a “challenge”. I think they meant “bot or human”, not “malicious or good”. Bot != malicious. And these challenges will do no good to non malicious bots.
- deleted 6y ago[deleted]
- lucideer 6y agoI think you're confusing intent with implementation. You're right that the implementation excludes non-malicious bots and fails to solve for malicious humans, but that just makes it an imperfect implementation of the intent: which is to differentiate malicious & good.
- blakesterz 6y ago> "Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA. That is entirely within their right. Cloudflare, given our volume, no doubt imposed significant costs on the reCAPTCHA service, even for Google." Even in the article they say... "Google provided reCAPTCHA for free in exchange for data from the service being used to train its visual identification systems." ... I thought this was one of those win/win things... Google gets something, websites get something... what's changed? Is Google not getting much out of reCAPTCHA now?
- Hello71 6y agomy bet is that the bean counters have caught up with this product, and it'll be run into the ground with excessive pricing, because Google products have to make millions or otherwise they'll be killed. most notably, Reader.
- IAmEveryone 6y agoThese complaints about Google "moving too fast" used to really confuse me. I couldn't really spot a meaningful difference in mean survival b/w Google products, start-ups similar to individual Google products, and other businesses' behaviour. But I've now attained zen-like clarity on the issue: the complaints are coming only, and always were coming mostly, from people whose idea of appropriate change over time is to still complain about Google Reader almost a decade after it happened.
- Hello71 6y agothis is being intentionally obtuse. Hire shutting down got 200 points 7 months ago: https://news.ycombinator.com/item?id=20815293 https://news.ycombinator.com/item?id=20815293, also see: Hangouts, Google+, Nest, Code Search, Site Search..... it's not about "moving fast" at all. it's about google killing anything that doesn't make millions as opposed to just thousands (enough for basic maintenance). I never said anything about timeframe.
- raxxorrax 6y agoI think using captchas for image recognition was one of the most ingenious strategies of the modern web. Don't think Google is making the correct move here. Overall I would like to see these checks removed and Cloudflare is using them quite excessively.
- oefrha 6y agoSeeing that reCAPTCHA v3 doesn't use endless streams of images any more, I would guess that Google no longer benefits much from having users tag storefronts, traffic lights, buses or fire hydrants. Maybe their image recognition algorithm is past that stage.
- robin_reala 6y agoIt does as a fallback. But you’re missing the main point of v3, which is that it shifts the legal onus of blocking from Google to the integrating site. No longer can Google be sued for accessibility violations, if it’s the site that’s stopping the user from entering purely on a suggestion from Google.
- dathinab 6y agoJust because you do some technically workarounds doesn't mean you get a legal free pass. I don't think this aspect did matter much because it was always the sites decision to use reCAPTCHA and that didn't change. I also don't think Google gets much profit out of the image tagging part anymore, they already have a huge database of tagged images.
- bscphil 6y ago> Seeing that reCAPTCHA v3 doesn't use endless streams of images any more On the other hand, I've been effectively banned from several sites because I don't accept third-party requests to Google from non-Google sites as a result of this change.
- crazygringo 6y agoPure speculation, but at some point your dataset is large enough. The original reCAPTCHA corrected errors in scanned books published decades/centuries ago. At some point, they're all fixed. Similarly, more recent images have all been of traffic images. And they probably have way more than enough now -- at least of the type that can be done by reCAPTCHA. So unless Google comes up with a new mass-categorization problem easy enough for literally everyone to do and simple and small enough to fit in a reCAPTCHA... then they charge.
- peeters 6y agoIn the article they also say: > Again, this is entirely rational for Google. If the value of the image classification training did not exceed those costs, it makes perfect sense for Google to ask for payment for the service they provide. This might be exacerbated in the case of Cloudfare. Imagine a system where 99% of the visitors being challenged are human. The data gathered from such visitors is quiet, quality data. That fits the usecase of validating an anonymous poster on some random blog. Now consider the Cloudflare usecase. Visitors will only be challenged when Cloudflare already expects you're a bot. Most of the challenges are served to bots. The data is much lower quality, but their cost per challenge has remained the same. It could just be that as this type of usecase became dominant, the balance of value tipped.
- gurrone 6y agoI guess this is very true. Our quite elaborate Cloudflare Firewall setup combining bot management scores with GeoIP and network information to decide on the action has solve rates below 0.5% on most rules. The only case where we see up to 3% solved is on rules targeting networks which contain mostly free (as in beer) VPN providers (the new pest of the internet). Those networks sent a lot of malicious and automated traffic with the mixed in 3% of real users. To put this into numbers of the past 24h: ~ 76 Million requests served ~ 1 Million of those were captchas ~ 0.5 Million were outright blocked Captchas solved: 1233
- dx034 6y agoIt's probably a question of size. Same as with Google Analytics. Google can afford to offer it free of charge for smaller websites but charges for larger ones. Cloudflare was probably one of the heaviest users with a very high percentage of bots (as they're good in pre-filtering).
- thewebcount 6y ago> Google provided reCAPTCHA for free in exchange for data from the service being used to train its visual identification systems. Has this been true lately? Every time I see it, it gives me the same images from a set of 3. 90% of the time it's classifying street lights, and it's the same street lights every time. About 7% of the time, it's pictures with cars in them, and again, it's the same pictures most times (but in a different order, I think). The remaining times it's fire hydrants or store fronts, often in a language I can't read, so I don't know if it's a store or not. (And again - mostly the same images each time.)
- kennydude 6y agohCAPTCHA looks interesting, although it seems they use Blockchain for no real reason compared to just storing the payments as rows (i.e what they gain from being chained on top of another)
- colejohnson66 6y agoThe point of a blockchain is that to edit an earlier record, you would need to edit every record that comes after (due to storing a hash of the previous block in the current block). However, it doesn’t make sense when one entity controls the entire system because if a hacker (or even an insider) can change one record, they could change all of them. Hence why a good blockchain would be distributed. Then, if one node edits the history, the other nodes will see the anomaly and ignore that node. This is also why Git’s history is easy to edit when it’s only on your machine. But once you push to GitHub and others clone your repo, it becomes a lot harder to edit history. Yes, Git isn’t a blockchain, but it does use the idea of hashing the previous “block” (commit) and storing it in the current “block.”
- kennydude 6y agoYup, that's my thing is that they control the entire thing. Although it could be like joke where "AI" ends up being just a bunch of "if statements".
- speedgoose 6y agoYes if do not you want to distribute your data with random people over the internet, you need a Merkle tree. Not a stupid blockchain with all the downsides a blockchain have.
- deleted 6y ago[deleted]
- wongarsu 6y agoIf you strip out the proof-of-work algorithm you're basically left with a chain of Merkle trees, and the payloads hashed by the Merkle trees. Calling it a blockchain is just a way to make it sound more familiar to potential investors.
- devy 6y agoThe enterprise grade hCaptcha[1] is not free either. Does anyone have pricing information? [1]: https://www.hcaptcha.com/#plans https://www.hcaptcha.com/#plans
- StavrosK 6y agoIt says it's free for non-enterprises .
- yjftsjthsd-h 6y agoOkay, but Cloudflare is very much an enterprise, and lots of people here are working in such places, so it's a decent point.
- StavrosK 6y agoThe parent edited their comment, it didn't say "enterprise" when I commented.
- Macha 6y agoIt sounds like Cloudflare is paying at least partially in free/discounted Cloudflare services.
- wongarsu 6y agoAccording to the article Cloudfront is paying, but is paying "a fraction of what reCAPTCHA would have [cost]". Recaptcha is $1/1000 challenges, so apparently hcaptcha is some small fraction of that. Cloudfront might get a discount for running some of the infrastructure on their own servers, on the other hand that might also be an integration hassle that actually costs them money.
- meowface 6y ago> Recaptcha is $1/1000 challenges This seems unwise, because many captcha farms charge less than this. A quick Google search shows one service offering $0.50/1000 challenges. If it's 2x cheaper for an attacker to solve a captcha than it is for a provider to display it, it sounds like the attackers win.
- datafix 6y agoHey, I interviewed with them a year ago. Their captchas are actually harder than reCaptcha's.
- jasonhansel 6y agoHas anyone else seen reCAPTCHA getting way more difficult of late? It often takes me a full minute to find all of the tiny traffic lights hidden away in a set of low-quality images.
- ship_it 6y agoJust use Buster[1] [1] https://chrome.google.com/webstore/detail/buster-captcha-solver-for/mpbjkejclgfgadiemmefgebjfooflfhl?hl=en https://chrome.google.com/webstore/detail/buster-captcha-sol...
- drusepth 6y agoWorth noting that it's possible to get a hellban if you get too many wrong guesses using extensions like Buster.
- jsjddbbwj 6y agoWhat I don't like is that Buster doesn't work with hcaptcha... But I don't live in a shitty country so very very rarely do I get captchas from Cloudflare.
- deleted 6y ago[deleted]
- elric 6y agoIt's a start. reCAPTCHA is a notorious pain in the arse for anyone whose browser isn't Chrome and for anyone who doesn't keep cookies. I'm not sure if hCaptcha will be better, but it's hard to imagine it being any worse.
- tgv 6y agoBy now, I almost immediately close a page with a reCAPTCHA, because the stream of buses, traffic lights, and cycles never seems to end when you're using Firefox. And then it says "too many requests from this computer" and refuses to continue.
- tcd 6y agoI'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again". The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form again", and reloads the entire page. That's the cost of privacy; broken pages and refused access because Google says "NO!". And businesses are okay with Google denying them money. I wonder if they did a cost/ben analysis if they find it worthwhile. Thanks to Google, I've actually saved quite a bit of money, they lost out hundreds recently when their automated systems decided to refuse my transaction. Their loss and my gain.
- fludlight 6y agoGoogle pays Mozilla to be the default search engine in firefox. This is Mozilla's main source of revenue, so I doubt they will sue.
- jakear 6y agoI wonder why they don’t negotiate with Msft to use Bing or even DDG instead. Seems... incredibly odd... to put oneself in a position where a third party is directly antagonizing your users, reducing your user satisfaction and likely dramatically increasing churn, but you can’t do anything about it because that same party is your main source of funding. (Disclaimer, I work at msft. Nowhere near this though).
- deleted 6y ago[deleted]
- zachware 6y agoOne of the more insidious elements of ReCAPTCHA is its propensity to challenge users who have robust cookie blocking in place. So as we encourage people to be more privacy-aware, the web gets harder and harder to use. We've seen ReCAPTCHA pop all over ecommerce, all over benign websites with little to no need to challenge use almost completely because of the increase in privacy-aware users. ReCAPTCHA essentially flies in the face of the recent blocking features rolling into Safari and Firefox and more privacy-aware users...growing by the day. In many ways it's a genius structure from Google. 1. Convince people to use your privacy challenge. 2. Serve it when you don't see Google tracking cookies. 3. Offer a way around that with the least privacy-aware browser available (Chrome use is growing steadily month over month. So good on Cloudflare.
- noad 6y agoYou're forgetting the main benefit for google, which is getting humans to train all their vision models for free. At one point they were just forcing X% of clicks to fill out a captcha regardless of origin or identity just to get more data. I for one am getting quite tired of trillion dollar corporations getting things for free out of me. Hard pass.
- 0xff00ffee 6y agoDid you even RTFA and look at hCAPTCHA? hCAPTCHA couldn't be more grossly focused on neural-net training. Hell, one challenge asks you to draw a bounding box and another is a classification tagging.
- Nicksil 6y agoThere was no argument being made for HCAPTCHA in the post to which you replied. So, yeah, everything you mentioned is indeed gross, including Google's behavior.
- 0xff00ffee 6y agoThe parent post was edited.
- worble 6y agoA little off-topic, but the article mentions they support Privacy Pass. I remember seeing the announcement a little ways back when they first released it but just kind of forgot about it. Is anyone using the browser extensions? Has it reduced the amount of captchas you end up seeing, or made your browsing experience better in any way?
- chrismorgan 6y agoA few days ago I encountered this when Cloudflare decided my IP address (which is behind an ISP-level NAT) was suspicious all of a sudden (which it hadn’t been doing, a pleasant change from when I was at this location three years ago when half the internet sprouted Cloudflare CAPTCHAs at me). It was awful to solve, worse than the substantial majority of reCAPTCHA checks I’ve encountered. Certainly nothing like the illustrations in the article.
- hbvvvvgff 6y agoI tried a hcaptcha and it was way harder to solve than the usual recaptcha. However, It was significantly easier than the recaptchas you get when using tor.
- IAmEveryone 6y agoI had the same experience. But this may just be an artefact of humanity now having been trained exceptionally well to identify traffic lights and busses, but being relative novices at identifying elephants. And now I'm wondering if this may not be a spectacularly useful tool to raise standards of education world-wide. Imagine, say, the French government buying them and asking every person on the internet twice a day to match some vocabulary to images: Identify "le baguette"! Lingua Franca, le sequel. Or a maps puzzle: "Please identify Equatorial Guinea, Papua New Guinea, and Guinea-Bissau".
- tcd 6y agoIt's funny that we need to ensure humans are the ones performing certain actions like making a purchase or accessing a service, but we let machines make decisions over very important matters in our lives (credit/financial decisions). It's intriguing they said Google will charge for reCaptcha, any information on that? I can't imagine all the small business owners will have to start paying, but perhaps if they did they'd just remove it altogether (a net win!).
- deleted 6y ago[deleted]
- noncoml 6y agoIMHO CPATCHA is a lazy way to protect your service as you shift the burden to your users. Maybe if you are big and essential for some users, you can afford that. But if not, be aware that users will turn their back on you if you add obstacles between them and your service. Edit: meant to say “be aware that some users will turn their back to you”
- onion2k 6y agoBut if not be aware that users will turn their back on you if you add obstacles between them and your service. You have to balance that against how many users you'd lose if the site was down/vandalized/compromised by an attacker if the captcha protection wasn't there to keep it out. It's often worthwhile moving the captcha away from the initial login or signup form and only putting it on the second or third attempt to login, or on features that put significant load on the server.
- hombre_fatal 6y ago> It's often worthwhile moving the captcha away from the initial login or signup form and only putting it on the second or third attempt to login Though if your service is a lucrative target for {uname,pass} combolist spam, you'll see that each attempt comes from its own IP address and only makes that one request. It's pretty sobering.
- gurrone 6y agoYes it's trade off as usual. The main benefit I see is on networks where you've a mix of good and bad traffic and you would still like to offer the service to the few good users. I see this a lot on networks hosting a lot of free VPN providers. The other option we choose before was outright blocking. That is even more harmful for the few good users.
- eythian 6y agoI run a small forum, and it was getting flooded with fake and spam accounts, the moderators were struggling to keep up and the users were finding it annoying. So I put a captcha on the registration page. The problem went to zero, new users still showed up, and more people were happier than before.
- aeonflux 6y agoThis is what I recently got on CF's HCAPTCHA (look closely): https://imgur.com/a/QZNHmUC https://imgur.com/a/QZNHmUC
- alberth 6y agoI see 2 clear images of dogs. 2 possible dog images. And zebras humping. Nice.
- _nickwhite 6y agoFrom the article: "We evaluated a number of CAPTCHA vendors as well as building a system ourselves." and "We worked with hCAPTCHA in two ways. First, we are in the process of leveraging our Workers platform to bear much of the technical load of the CAPTCHAs and, in doing so, reduce their costs. And, second, we proposed that rather than them paying us we pay them. This ensured they had the resources to scale their service to meet our needs. While that has imposed some additional costs, those costs were a fraction of what reCAPTCHA would have. And, in exchange, we have a much more flexible CAPTCHA platform and a much more responsive team." So Cloudflare are basically cloud hosting hCAPTCHA's services. I wonder why Cloudflare didn't just buy them, as it seems like it would be a win-win with getting an excellent CAPTCHA service, and not have to build it themselves?
- beojan 6y agoI suspect that might happen eventually.
- dathinab 6y agoAt the end they mention that there long term goal is to eliminate captchas fully if possible.
- IAmEveryone 6y agoCF likes the CAPTCHA part of CAPTCHAS, but any vendor is probably far more invested in the "generating ML training data" scheme. CF probably has zero interest in that part of the product: It doesn't fit with their existing products nor customers, and it's just too small relative to their other business to devote much attention to it. At the same time, the business opportunity is probably too large for hCAPTCHA's founders to just forget about it, or for CF to compensate them on the hot-new-technology assumption when they're only looking for peace-of-mind-utility tech.
- Legogris 6y agoApart from the surveillance aspect, one thing that bothered the hell out of me with Cloudflare using ReCAPTCHA was that it yielded a much larger part of the web than necessary effectively blocked in China, since the CAPTCHAs would get triggered, and not load, from Chinese IPs. I had a customer where we had to migrate away from Cloudflare for this reason - this was about 5 years ago and the issue has been there to this day. Glad to hear they've finally done something about it. Even if it took Google starting to charge money for ReCAPCHA to trigger it.
- yjftsjthsd-h 6y agoWell. That's probably fantastic news; using ReCAPTCHA (and thereby making users subject to Google's tender mercies) was honestly my main reason to dislike cloudflare from a user's perspective. ReCAPTCHA is utterly foul; it follows you everywhere it can, exists to undermine privacy, punishes non-Chrome users, and throws you in an infinite loop when it decides that you're not a human.
- curiousgal 6y agoI don't blame reCAPTCHA for existing, I blame Cloudfare for using. It made using Tor literally impossible. Hopefully this will be better.
- lol768 6y agoDidn't Privacy Pass help here?
- hedora 6y agoI have no idea what privacy pass is, but if it involves setting browser state across more than one site, then it breaks the tor anonymity model. Anyway, hopefully hCaptcha works with Tor.
- eastdakota 6y agoSpecifically designed to allow you to authenticate once and then use that as a proof of work across multiple sites, without revealing your identity as being connected across those sites. Here's the math: https://blog.cloudflare.com/privacy-pass-the-math/ https://blog.cloudflare.com/privacy-pass-the-math/
- IanCal 6y agoI'm not so hot on this stuff so this might be answered or clear on the site and I didn't get it - can the other sites tell who authenticated you? Can the authenticator add metadata? I'm wondering about other use cases, using it to prove you've paid for something, or donated perhaps. Or passed a daily quiz/challenge. I feel like there's some fun ways of using this.
- outloudvi 6y ago1. I think challenges from hCAPTCHA is harder than reCAPTCHA. It's far and even further from human-friendly compared to reCAPTCHA. 2. hCAPTCHA seems to be using the similar revenue model as early stage reCAPTCHA and it even pay its users. I doubt that its model is sustainable. 3. A huge company like Google may not be able to handle user data well, so a small company will be able to?
- jccalhoun 6y agoI've ran into hCaptcha a couple times recently and found it vague and I had to try to guess what they meant. Both times it asked me to identify the truck. Well, what do you mean by "truck?" are you counting a semi as a truck? I ended up having to do it twice because I don't consider a semi a "truck" but they did.
- Keverw 6y agoInteresting, I know some people consider a Truck a semi but your pick up truck isn't really a truck according to others. So confusing with all the different definitions.
- garaetjjte 6y agoCan we get back text based captchas instead of annoying whack-a-mole photo picking?
- theandrewbailey 6y agoNo. Photos of street things are much easier to pick out than warped or miscolored text.
- hombre_fatal 6y agoEspecially the amount of warping you apparently need to do to text to make it hard for a neural network these days.
- cinbun8 6y ago> Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA So it came down to cost. > Over the years, the privacy and blocking concerns were enough to cause us to think about switching from reCAPTCHA. But, like most technology companies, it was difficult to prioritize removing something that was largely working instead of brand new features and functionality for our customers. I like that they're upfront about this. In most companies / teams of this size, these issues are always swept under the carpet until something ugly forces you to clean up at a later point in time. It's just unavoidable.
- alexnewman 6y agoHey everyone. HCaptcha founder here. We are so happy to be on hackernews. I'm curious if anyone is having any problems? We are trying hard to respond carefully to customer requests but as you can guess we are very busy. Also we are hiring :)
- deleted 6y ago[deleted]
- ronyfadel 6y agoHey Alex, one suggestion, the HCaptcha challenge box is way to tall, sitting at 725px, it's larger than the chrome viewport on a 13" MBP, so I have to keep on scrolling up and down to solve the captcha.
- alexnewman 6y agoYou would not believe how much we think about these things. We appreciate the feedback and will continue to tune for every puzzle. Thank you so much for the feedback.
- splintercell 6y agocan you get 4chan to start using hcaptcha, I can't tell you how much I hate Google recaptcha. not to mention the brainiacs at 4 Chan have figured out how to solve Google's recaptcha easily.
- rstupek 6y agoDid anyone notice that hcaptcha runs on top of etherium?
- shp0ngle 6y ago> Earlier this year, Google informed us that they were going to begin charging for reCAPTCHA. Wait. Is this news? I don’t see other article about this. What is the pricing?
- kevindong 6y agoThere are plenty of services that will happily accept a screenshot from a developer, send it out to live humans who solve it in real time, and then return the answers to the developer. I'm not going to link to them, but you can find them yourself by googling "buy recaptcha solver". The prices for the top two results are $0.50 and $1.39 per 1000 solves (respectively, $0.0005 and $0.00139 per solve). At that price point, it's feasible for the truly determined to just use those solvers to bypass ReCAPTCHA (or similar services).
- alexnewman 6y agoHCaptcha's enterprise solution is designed to detect this threat and other's.
- xur17 6y agoAre there chrome extensions that I can use these with? I'd be willing to pay those rates to never have to solve a captcha again. I'm fine leaving the tab open for a few minutes while it's solved even.
- spsrich2 6y agoI hate Hcaptcha. It keeps presenting the same challenge over and over again. Everytime I need to access a site it protects it wastes so much time.
- TechBro8615 6y agoThis is fantastic news for privacy on the web. Thank you Cloudflare! I’ve been seeing hcaptcha in more and more places recently. It’s a bit rough around the edges still, but it works well and feels far less hostile than recaptcha.
- maallooc 6y agoI hope this captcha is tor friendly.
- aaron695 6y agoSo no one can turn free human labour into enough money to pay hosting fees? And given spammers a lot of the time are messing with Google, it's also in Google's interest to do this for free! What are they thinking? Is this one department make $100 internally while killing $1000 in another internal department?
- blackdogie 6y agoOne look at what cookie domain (google.com) recaptcha runs on will give you a hint to its usefulness.
- KCUOJJQJ 6y agoI just tried it on a website that uses Cloudflare and that always asks me to solve a captcha. (I guess this website does this if the user has a foreign IP address.) In the past I managed to get the non-script Recaptcha. But I don't see a non-script Hcaptcha. I'm a little afraid of possible browser fingerprinting scripts. If there was an unwaivable, enforced right to privacy I wouldn't be afraid. Also, I don't want to solve any script captchas anymore because of a traumatic experience with script Recaptcha. I had a portable Chromium with login cookies for a few websites. I didn't use that Chromium for other websites than these few. Suddenly, one service almost always demanded a new login after just 1 day. On each login I had to solve a script Recaptcha. I didn't find a way to get non-script Recaptcha. According to the service evil spambots had attacked it. Once, Recaptcha let me solve captchas for minutes, just to eventually tell me I was a bot. I had an IP of a large internet provider. I deleted cookies, got a VPN IP, tried it again, worked on the captchas in the exact same way as before and managed to log in to my account. A website operator wrote in a forum thread that Recaptcha was the only solution to the bot problem. One user suggested "email login as an optional alternative". This was not implemented, because apparently Recaptcha was really specifically the only solution. I then switched to another service, which cost me a few hours of work. This traumatic experience has made me completely unwilling to solve any script captcha.
- foob4r 6y agoHow good or bad is the new system on tor? ReCAPTCHA straight up was a 0/10 over tor for me.
- paulie_a 6y agoThe funny thing is that Google doesn't even use recaptcha and instead use some awkward hard to read piece of shit. After 4-5 guesses, and they are guesses you might proceed.
- synsynack 6y agoIt's not worth a rich person's time to solve captchas, while it is for a poor person. This has lead to captcha solving services, extensions plugins, etc, all which have high latency delay, not over a fast documented API. It would be 100 times easier if cloudfare/google let's you directly buy credits, at the mid-point price between current bid-ask spread, of say 50 cents per 1000 captchas, which would probably last you a few months to a year.
- notechback 6y agoThis sticks out to me: > We also had issues in some regions, such as China, where Google's services are intermittently blocked. China alone accounts for 25 percent of all Internet users. Given that some subset of those could not access Cloudflare's customers if they triggered a CAPTCHA was always concerning to us. They are explicitly saying that China's blackmailing of Google is working so well it even affects decisions on using Google products outside of China. I'm not a Google fan and think this move is a great improvement for the web and user privacy, but that this was explicitly motivated by China's blackmailing tactics is terrifying. And we can from this post even make another case that also doesn't paint a nice picture: Cloudflare does not care enough about 25% of internet users to move away from reCAPTCHA - until it affects their bottom line in a visible and immediate way.
- realtalk_sp 6y agoAre people here not aware of reCAPTCHA v3? It doesn't involve user interaction. I just integrated it into a site. Works well.