5 ms·
I don't think I've ever been "hellbanned", but I've certainly spent more than 5 minutes on trying to get a captcha to work. After a while I usually need to ask
by RadiantUnicorn 6y ago
I don't think I've ever been "hellbanned", but I've certainly spent more than 5 minutes on trying to get a captcha to work.
After a while I usually need to ask friends in the US to help me, because it asks me a non-localized question.
My favourite question was: Select all fire hydrants.
I selected only the classic red one's you see in movies. Fail.
I selected the one's that were yellow too. Fail.
I sent a picture of the grid to a friend. He spotted that some of the pipes on a wall were fire hydrants, which I didn't know. Pass.
In my country we don't have hydrants. We have holes in the ground that are covered by a lid. After removing it you can attach the water hose there.
- 101404 6y agoI see a million dollar lawsuit for discrimination >:-}
- dheera 6y agoIt is pretty straightforward to train a neural network to solve these -- e.g. fire hydrants, traffic lights, cars. I would have thought ReCAPTCHA would take into account human factors (e.g. speed of clicking) as higher priority to the accuracy of the selection.
- wyre 6y agoAFAIK it takes into account mouse movement and the speed of clicks.
- therein 6y agoIn my experience, relatively easily defeated by `await Promise.delay(randomDelay())`
- dheera 6y agoSounds like a cat and mouse game. Mouse: They could then try to analyze human delay randomness -- it's probably not uniform. Cat: And then someone will come up with a replacement to randomDelay that mimics the above pattern. Mouse: And then they will look for changes in the distribution itself from person to person etc.
- MertsA 6y agoI know back in the day for RuneScape bots using SCAR there were macros to move the mouse from one position to another on the screen with randomized acceleration, randomized curvature, overshoot, clicking in some bounding box, etc. all using a normal distribution in an effort to thwart detection. Imagine being the poor developer tasked with trying to recover some signal out of that.
- drusepth 6y agoJust alt-tabbed in from writing runescape bots to HN and wanted to say that's still the case (for the client I use). The code is pretty complicated now but still functions much like you say. Mouse position is tracked, then any input which repositions the mouse accelerates at a "reasonable rate" and with a randomized curvature to get "close enough" before it self-corrects and gets a pixel-perfect click. A few years ago the client stopped sending mouse data back to Jagex altogether. Luckily, I don't think there's many poor developers tasked with trying to recover any signal out of that anymore. :)
- floatingatoll 6y agoRegularity of clicking is considered a sign of robot behavior, which is especially frustrating if you learned to perform repetitive image identification mouse tasks in a computer with rhythmic regularity (think Turk, for example).
- jjoonathan 6y agoYeah, I should break down my methodology for arriving at the "hellban" conclusion. If I get a bunch of failures in a row, I'll first try the refresh button built into the captcha, and then re-solve a number of times. Then I'll try re-loading the page and re-solving, then I'll try in a different browser with cleared state and re-solving, then I'll try a different device and re-solving, and finally I'll try a different connection, device, and cleared browser state and re-solving. I'll consider something a hellban if I get persistent failures across several different challenge types but switching to a clean connection+device+state results in immediate success with the captcha. Look, I get it, they can't be too explicit with the errors or they tip their hand to the botters and effectively give them a "to-do" list. Still, the gaslighting is persistent enough that there's just no way it's marginally beneficial all the way through. At some point, everyone figures it out: bots, techies, and normies. My guess is that they figure it out in this order, from quickest to slowest: smart bots, techies, normies, dumb bots. I'm not calling normies dumb here, they just don't have much background knowledge about the inner workings of captchas, so it takes longer. By that point, they're so far past the typical number of captcha attempts that only the very dumbest of bots, those without heuristics to detect this sort of thing, are going to be fooled along with them. Surely having the captcha tip its hand at this point -- which only gives an advantage to the dumbest of bots, because the smart bots figured it out long ago -- is the right thing to do. Re:CAPTCHA has no mercy on the normies, and I really think they could do a lot better.
- joveian 6y agoOne thing I've found (after others mentioned it here) is that Google seems to reward impatience when trying to solve captchas. Going faster and making more mistakes and not waiting for loading images seems to help convice the algorithm that you are human. This is rough on anyone who thinks they are being rejected for not being accurate enough. OTOH, it is hard to figure out for sure what makes a difference. I use a proxy/VPN with a fixed IP address that only I use and Google eventually seems to have figured it out; I used to get the hard or impossible ones on Google Scholar at times but now never do. So possibly in my case they decided to stop giving them to me around when I changed strategies, but I suggest giving it a try at least.