8 ms·
CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
- ghuroo1 2y agoThat made us spend 819 million hours clicking on traffic lights to generate nearly $1 trillion for Google.
- voisin 2y agoAt an approx 750,000 hours in a human lifespan, they wasted 1100 human lives in totality. Unbelievable.
- thechao 2y agoThere's a dystopian short story in your comment about AI that can't self-bootstrap without ground-truth from humans, so they keep us around just to mark images, music, etc. Lives wasted annotating things. I like to think they'd drag us from solar system to solar system for this purpose.
- extraduder_ire 2y agoDoes solving captchas generate $1000/hour? I assume you're conflating amounts here, or messed up an order of magnitude somewhere.
- rozab 2y agoThat's just the headline of the article. The researchers put the vast majority of this value to tracking cookies, and this revenue happens whether or not a manual challenge is completed.
- scubadude 2y agoThat's just the direct value, how about the whole dimension of training the AI models
- nonrandomstring 2y agoYou can get people to do almost anything if you lie to them that it's for "security".
- catlikesshrimp 2y agoExcept captcha is not supposed to be security for the user, but security for the website. But in the end it is not (effective) security for a website, is an antifeature for users and is profit for google.
- jisnsm 2y agoAs a website developer and host, I can assure you recaptcha works very well to stop spam and automated login requests. It is not perfect, but no system is.
- internetter 2y agoyeah, a sufficiently motivated attacker can deploy some countermeasures to bypass it, but only really worth it for targeted attacks. Anyone who has a form on the internet knows that without any sort of captcha, you get lots of stupid bots just typing in jumbo. Likely you could tone back the captchas and still get a similar result in stopping the dumb bots[0] [0] on my contact page my email is protected via a custom cypher. if the bots execute javascript and wait 0.5s they can read it, but most don't. It’s the dumbest PoW imaginable, but it works
- nonrandomstring 2y ago> It’s the dumbest PoW imaginable, but it works Nice one! I guess you mainly need to get above a certain novelty threshold, because all ML is based on what has already been seen/learned rather than actually outsmarting the defence.
- radlad 2y ago> Anyone who has a form on the internet knows that without any sort of captcha, you get lots of stupid bots just typing in jumbo. I recall a form of "CAPTCHA" that involved a text input which was hidden via CSS, but which bots would fill in anyway. Any text in the input caused the entire form to be rejected. I wonder if that style still works today.
- pupppet 2y agoWhat's the alternative?
- atoav 2y agoBuilding your own captcha or running one that doesn't sell your users data to the highest bidder? What a time where people on a site called "Hacker News" ask such a question..
- phoronixrly 2y agoAnd if you ever get so big that people start writing bespoke software to break your CAPTCHA, then investing some more engineering effort into it will quite likely not be a problem. Of course reCAPTCHA is also still vulnerable to the use of a mechanical turk so even giving away your users' data won't save you.
- ThatPlayer 2y agoI've come across a CAPTCHA on a website I was scraping that was absolutely terrible. It was 10 multiple image choice answer, with a question to click the image that had "X". Their implementation didn't even have a nonce, so I would just attempt every single answer and get past it.
- nonchalantsui 2y agoSince this was focused on v2 and other interactive captcha, the alternative is to upgrade to new versions that don’t do so. Still some downsides (and the study does address very briefly the use of AI to trick v3), but at the very least it does address some of the concerns. Important to note though that as AI gets more accessible then the downsides of v3 start to weigh more.
- e2le 2y agoThere are two alternatives I'm aware of, one is Attestation of Personhood[1] proposed by Cloudflare, the other is a proof-of-work[2] which the Tor project have themselves introduced[3]. [1]: https://blog.cloudflare.com/introducing-cryptographic-attestation-of-personhood/ https://blog.cloudflare.com/introducing-cryptographic-attest... [2]: https://github.com/mCaptcha/mCaptcha https://github.com/mCaptcha/mCaptcha [3]: https://blog.torproject.org/introducing-proof-of-work-defense-for-onion-services/ https://blog.torproject.org/introducing-proof-of-work-defens...
- jdietrich 2y ago-
- loloquwowndueo 2y agoIt’s not three years, it’s thirteen. > A lifetime value of $888 billion for all of reCAPTCHAv2's tracking cookies produced between 2010 and 2023.
- phoronixrly 2y agojdietrich, I feel your pain, I am also completely convinced that 2010 was 3 years ago :(
- jp191919 2y agoI'm at the point now that if I get a CAPTCHA, I'm just going to leave the site. I'll spend my money elsewhere or find an alternative
- a2128 2y agoMy government's websites require solving a reCAPTCHA for basic services, which is horrifying. They also use Cloudflare which blocks me sometimes. This is in the EU
- phoronixrly 2y agoConfirming this. I am also completely certain that gratuitous CAPTCHA use is banned for government systems by my country's set of laws governing their implementation. The judicial system and the community have not matured enough to consider this a breach of law worthy of fighting against...
- openplatypus 2y agoName and shame, please!! ReCAPTCHA due lack of opt out is effectively illegal in the EU.
- phoronixrly 2y agoreCAPTCHA (and others based outside of EU) is illegal on privacy ground (in any site, not just owned by EU entities). Homebrew CAPTCHAs are illegal due to their general lack of accessibility (in any site owned by an EU entity), and in Bulgaria their gratuitous use is banned in government sites on account of them being poor UX (not enforced unless caught during the acceptance phase of a project). An example of an inaccessible homebrew CAPTCHA that causes very poor UX can be found on the portal that provides access to the legal acts of the Bulgarian judicial system: https://legalacts.justice.bg/ https://legalacts.justice.bg/ . Try taking the legal system to court. I tried for this one, you can see for yourself how it went.
- veeti 2y agoIf it's "effectively" illegal can you name a single court decision saying so?
- unethical_ban 2y agoWhat proof of humanity is sufficient? Today it is a phone call, or a verification sent to a real address (limit one registration per household), or a video call. How will we verify humanity in 20 years when audio and video emulation is foolproof? We'll have to have in-person attestation or make all services paid, perhaps.
- thatguy0900 2y agoRealistically it will be a government or private service that everyone will have to have to verify that it is a real person. Or at least tied to a real person so that banning will be more sticky.
- apitman 2y agoLike Google
- phoronixrly 2y agoI would wager all services will be linked to a verified credit or debit (non-temporary) card. Most of them are now... How are you going to connect the physical person with an identity with in-person attestation? Many (several of which major English-speaking) countries don't have mandatory government IDs... A commenter below suggests that government eIDs could be used. I bet this will be harder to implement and will have much worse conversion rates than (the already terrible) mandatory credit/debit cards... Not to mention the hell that we as non-US citizens will have to endure if anyone tries to impose any form of mandatory ID there... One can only take so much complaining about government overreach about something that is basic necessity here in the EU...
- nervysnail 2y agoNothing less than drinking a "verification can", as presciently propounded by a 4chan user a decade ago.
- eykanal 2y agoThe problem with this paper is that, while technically true, there are many website owners who have found that CAPTCHAs have effectively reduced the spam on their site to zero. The fact that a CAPTCHA _can_ be bypassed doesn't mean that it _will_, and most spam bots are not using cutting-edge tech because that's expensive. To say "it's worthless from a security perspective" is a pretty harsh and largely inaccurate representation. It's been tremendously useful to those who have used it. If it wasn't valuable, it wouldn't be so widely used. Definitely agree with the whole "tons of free $$$ for Google", but that's kind of their business model, so yeah, Google is being Google. In other breaking news, water is still wet.
- chrbr 2y agoYeah, we've used CAPTCHAs to great effect as gracefully-degraded service protection for unauthenticated form submissions. When we detect that a particular form is being spammed, we automatically flip on a feature flag for it to require CAPTCHAs to submit, and the flood immediately stops. Definitely saves our databases from being pummeled, and I haven't seen a scenario since we implemented it a few years ago where the CAPTCHA didn't help immediately. Reminds me of the advice around the deadbolt on your house - it won't stop a determined attacker, but it will deter less-determined ones.
- Scaevolus 2y agoFar too many people talk about security as if it's a simple binary and not about effort levels and dissuading attackers.
- rachofsunshine 2y agoPeople really struggle with things that have measurable, probabilistic effects. You see it with healthcare ("Steve smoked his whole life and never got cancer, so cigarettes aren't bad for you!"), environmental effects ("Alice was poor and she didn't rob anyone, so poverty is no excuse!"), hiring ("Charlie is a great employee and he had no experience, so you should never look at backgrounds!"), etc. It should be a general standard of proof for any sort of sociological claim that you look at rates, not just examples, but it usually isn't.
- ChrisArchitect 2y ago[dupe] Earlier: https://news.ycombinator.com/item?id=42997755 https://news.ycombinator.com/item?id=42997755 https://news.ycombinator.com/item?id=42970780 https://news.ycombinator.com/item?id=42970780
- darkwater 2y agoNaive question: how can clicking on the motorbike or traffic light image help to train an ML algorithm if they already know what image has a motorbike in it, or otherwise the captcha would not make sense. Maybe they put 3 image which are already with a score of >0.90 and one which is just 0.40?
- woleium 2y agothey ask you to solve two. one they know, the other they don’t
- DougN7 2y agoI’m not sure. If I don’t click on one that is a bus it won’t let me forward. It’s not like I click an “Ok, I’m done” button. I guess we could all delay clicking and maybe it would give up and assume the unknown bus wasn’t really a bus after all?
- deleted 2y ago[deleted]
- mbb70 2y agoYes, known images are used for validation, unknown images are used for training.
- deleted 2y ago[deleted]
- michaelt 2y agoHypothetically speaking, if they've got a 97% good ML model, they could implement a captcha where if you disagree with their model you have to do a second image, and a third image and so on. Then they could show each image to several different humans, and only if a bunch of people disagree with the model do they take a closer look. Frankly a lot of the images I get are... kinda easy? This isn't the classic book-reading recaptcha where you could see why the text had confused the OCR.
- 2y ago
- breppp 2y agoI get that people are here to hate on Google, but I am just here to say that reCAPTCHA albeit acquired, is an absolutely brilliant idea. The kind that solves two (three? if you count tracking) problems so elegantly
- phoronixrly 2y agoAbsolutely agreed on the 'very elegant solution for global-scale tracking' part!
- therein 2y agoMulti-purpose trojan horse. Not only will it look beautiful in your city but you can use it as scaffolding to repair tall buildings or children in your community could use it as a play gym.
- extraduder_ire 2y agoThe people who created the initial version that got bought went on to create duolingo, with a similar goal of getting people to produce translations of text.
- deleted 2y ago[deleted]
- Dotnaught 2y agoGoogle addressed the claims in this paper last year, and one of the authors challenged the company's responses. See: https://www.theregister.com/2024/07/24/googles_recaptchav2_labor/ https://www.theregister.com/2024/07/24/googles_recaptchav2_l...
- kevin_thibedeau 2y agoAs of two weeks ago my locked down Firefox profile gets hit with captchas on every visit to Google search. DDG has also gone to shit with captchas and stupid low cache lifetime because I use their non-javascript site. I'm giving Bing a test run before making the leap to Kagi.
- EVa5I7bHFq9mnYK 2y agoTry also Startpage, it doesn't give me any captchas even though I am a career criminal: guilty of adblocking under Firefox influence, while commiting a VPN. They also have a nice Anonymous view.
- vitehozonage 2y agoYou might want to try Mullvad Leta, it's what i use for this issue. I would try Kagi if it could be used privately but i suppose it still requires an account and has no way to pay privately
- yegg 2y agoWe (at DuckDuckGo) shouldn’t have a lot of captchas and when we do (intended to keep away non-human traffic) they are completely anonymous, self-hosted, and not related to any AI or other machine learning. As such, I’d love to figure out why you are getting ensnared in them when you aren’t supposed to. If you want to reach out via email (see my profile) I will look into it.
- deleted 2y ago[deleted]
- btown 2y agoThe "cookie farm for profit" point is worth elaborating on. From the original paper https://arxiv.org/pdf/2311.10911 https://arxiv.org/pdf/2311.10911 : > More concretely, the current average value life-time of a cookie is €2.52 or $2.7 [58]. Given that there have been at least 329 billion reCAPTCHAv2 sessions, which created tracking cookies, that would put the estimated value of those cookies at $888 billion dollars. The cited paper is https://www.sciencedirect.com/science/article/pii/S0167811623000708 https://www.sciencedirect.com/science/article/pii/S016781162... - but it doesn't deal with CAPTCHAs, just with the general economics of third-party cookies. In practice, many of these cookies will have already been placed by other Google services on the site in question, with how ubiquitous Google's ad and analytics products are. And it's unclear whether Google uses the _GRECAPTCHA cookies for purposes other than the CAPTCHA itself (in the places where this isn't regulated). But reCAPTCHA does gives Google an ability to have scripts running that fundamentally can't be ad-blocked without breaking site functionality, and it's an effective foot in the door if Google ever wanted to use it more broadly. It's absolutely something to be aware of.
- bigbuppo 2y ago819 million hours of unpaid labor. And just think, a large chunk of that was performed by children. CAPTCHAs are slave labor in small doses. It's also a way of avoiding paying taxes on that labor. But hey, what's a few billion dollars in unpaid taxes and unpaid wages and child labor violations between friends?
- aaron695 2y ago[dead]
- deleted 2y ago[deleted]
- jvdvegt 2y agoTo prevent the cookie wall with no 'reject all': https://archive.is/oHc1e https://archive.is/oHc1e
- kykeonaut 2y agoWouldn't some sort of proof of work be a good solution to the captcha problem? Specially since all of the sudden, a bot service running hundreds of thousands of requests will suddenly and inadvertedly have to compute cryptographic hashes at the cost of the user running the bots?
- theamk 2y agono, because a lot of bot service run on botnets, made out of hacked regular residential computers, routers and so on. They will feel a bit more sluggish, but it won't cost the botnet authors that much more. On the other side, an amount of work reasonable for modern desktop will absolutely overwhelm an older cell phone.