3 ms·
An interesting thing is that for Arkose to be effective against bad actors, they can't just make CAPTCHAs that are hard for bots. They also have to be not-easy
by mbcros 3y ago
An interesting thing is that for Arkose to be effective against bad actors, they can't just make CAPTCHAs that are hard for bots. They also have to be not-easy or at least expensive for a subset of humans who aren't legitimate users, namely 'CAPTCHA Farms' like https://anti-captcha.com/ https://anti-captcha.com/.
Most CAPTCHAs, including ones made by Arkose, have site keys that are unique to that CAPTCHA and public/visible in the browser -- so companies like Anti Captcha can then automate sending challenging CAPTCHAs directly to a human solver in a 'CAPTCHA farm' who can solve it (in a different browser) and have the CAPTCHA return that it was successfully passed, usually all within ~a minute.
So to get around this and -- as Arkose's site says -- make fraud expensive for hackers, Arkose Labs has to make their CAPTCHAs hard/slow to solve. If they do that, then it becomes expensive for bad actors to rely on labor to solve them (anti-captcha.com cites 58 seconds/$3 per CAPTCHA).
As long as the site key is publicly exposed, this basically isn't going to change; you either need to also couple it with other anti-fraud tactics like device fingerprinting, or use a CAPTCHA that doesn't expose the site key at all.
Disclaimer - I work for a company (Stytch) that has a competing CAPTCHA product.