8 ms·
> Google's reCaptcha code seemed to be very keen on knowing my 'cadence' or the way I used my mouse and how quickly (or how slow) I completed the captcha. It al
by gaieges 6y ago
> Google's reCaptcha code seemed to be very keen on knowing my 'cadence' or the way I used my mouse and how quickly (or how slow) I completed the captcha. It also looked at things like timezone, screen resolution, battery charge level etc So they could determine if it was 'you' who was using the captcha, soon after, in a separate session (even on a different device!)
I'd bet a good amount that they store that along with all the other personally identifying info they have on you (and google of course has a massive amount of that); which is basically why after a single reCAPTCHA solve, you wont see them prompt you again for ages - they know who you are.
- lumberjack 6y agoThat's no secret, ... that's exactly how it is supposed to work.
- topynate 6y agoJust looked on Takeout and there don't seem to be any reCAPTCHA data there. I wonder what a GDPR request would produce.
- edoceo 6y agoThat is an investigative blog post I would like to read too.
- pests 6y agoSomeone on here has tried to get all their data from both Facebook and Google. I wish I could find the blog post. The tech companies are claiming their Takeout/equivalent is sufficient under the GDRP and anything extra we ask for is not being provided due to it being "non user understandable" or in a "machine format". IIRC.
- xncl 6y agoThat's still their data though, no?
- dodobirdlord 6y agoreCAPTCHA only needs to make a determination that the user is some human, not that they are any particular human. And reCAPTCHA is usable without being logged into Google’s identity system. The profiles it builds are clearly not associated with Google’s primary identity database, and its trivial if you don’t need to preserve identity to one-way hash every piece of data that GDPR considers user-identifying at the entry point to the system and store only the hash. The EU isn’t shy about handing out billion-dollar fines to Google, so while Google can match a user to a stored profile there’s no reason to suspect that Google has a way to reverse that mapping.
- hedora 6y agoReCaptcha seems to use your logged-in status (and, I’d guess, account reputation), along with an ip reputation score when deciding whether to serve a captcha or not. A GPDR request naming an IP address should allow them to provide those scores. If not, it’s easily demonstrable that they are storing and using information that they’re not including in a GPDR response, and they deserve their multi-billion dollar fine. Also, ReCaptcha’s behavior is obviously anticompetitive, and also using Google’s dominant positions in some markets to establish dominance in unrelated markets. This is anti-trust lawyer candy.
- dodobirdlord 6y agoLogged in status and account reputation are obviously useful input, but reCAPTCHA objectively works without requiring login. IP reputation also obviously makes sense to take into account, but the fact that Google collects all of this fingerprinting information demonstrates that’s again only a part of what factors in. The same profile can show up from behind a different IP. Not sure what you’re getting at about GDPR and IP reputation. GDPR says that an IP address is PII if it can be associated with an individual, but that doesn’t mean an IP address is a “subject” for the purpose of filing an Article 15 Data Subject Access Request. And it doesn’t mean that stored information that is keyed by an IP address is personal data, even if the IP address can be associated back to a particular individual. I also find it strange that you’re talking about reCAPTCHA being “anti-trust candy” in the comments of an announcement about how a different captcha service now handles 15% of the entire internet.
- shakna 6y ago> which is basically why after a single reCAPTCHA solve, you wont see them prompt you again for ages - they know who you are. If only. If the same site has reCaptcha across more than one page, within mere minutes of having to slog through multiple screens of one, I can guarantee I'll be doing it again. And I'm never sure if Google has served me either a very long sequence of reCaptchas, or whether they've decided I'm not a person and are serving me an infinite reCaptcha.
- mindslight 6y agoI'm guessing that the comment you're responding to uses Chrome/ium, and that you don't.
- skellera 6y agoBeing on a VPN, have blockers on, or not logged into google are a few things that will increase the captchas you’ll see.
- shakna 6y agoAlso using a screen-reader and using anything other than Chrome.
- marcosdumay 6y agoAdd "running Firefox" to that list.
- deleted 6y ago[deleted]
- quantumofalpha 6y agoAnd that's how you know that your VPN and adblockers work :)
- freeqaz 6y agoJust turn on "Resist Fingerprinting" in Firefox and you'll find ReCAPTCHA _really_ annoying! I have to solve 3-5 "panes" of a ReCAPTCHA on _every_ page... It's very annoying that preserving privacy comes with this cost. I almost want to just add a "DeathByCaptcha" extension to handle these for me and pay a few cents for every page I visit, lol
- hda2 6y ago> It's very annoying that preserving privacy comes with this cost. It doesn't necessarily have to if Google supported privacy pass like hcaptcha does. The problem is that they don't.
- foxrob92 6y agoWhy would they? Supporting privacy-preserving options is not within their business interests.
- ttsda 6y agoIt's way cheaper than that, you'll pay significantly less than a cent for each captcha.
- anoncake 6y agoIt's not a cost. Google doesn't want you to protect your privacy from them. It's a punishment.