8 ms·
Ask HN: Is it time for HN to implement a form of captcha?
First off, this thread is NOT a petition to rally against the moderation team. Considering the deluge of trash they deal with every day, I think they are doing a valiant job and are to be commended. Consider it merely a place to discuss, which is what HN does best.
That said, it's becoming more and more obvious every day that there is a tremendous amount of attempts by bots, and specifically AI agents, to inject slop into HN threads. I worry about the integrity of the discourse here and if the ever growing wave of garbage will overtake staff resources to deal with it. Is it time to implement captcha for HN? If so, should it be out of the box, or a new mechanism more tailored to the security and privacy-centric nature of the HN readership? Are captchas even still effective enough in the age of AI to warrant their use?
- chaps 9mo agoThis wouldn't solve anything. To see what I mean, take a screenshot of a random captcha that needs solving and ask an LLM to solve it for you. It will do it accurately.
- rfw300 9mo ago"Captcha" doesn't refer to any specific type of puzzle, but a class of methods for verifying human users. Some older-style captchas are broken, but some newer ones are not.
- bdcravens 9mo agoSince before LLMs were even an issue, there have been services that use overseas workers to solve them, with the going rate about $0.002 per captcha. (and they solve several different types)
- gilrain 9mo agoThis is both true and misleading. It implies captchas aren’t effective due to these services. In practice, though, a good captcha cuts a ton of garbage traffic even though a motivated opponent can pay for circumvention.
- chaps 9mo agoI'm aware. But I'm also aware that breaking these sorts of systems is quite fun for a lot of nerds. So don't expect anything like that to last for any meaningful amount of time.
- fyrn_ 9mo agoIt _would_ set the bar for a viable bot slightly higher. I'm not sure that's enough to justify it though.
- losvedir 9mo agoI've been thinking the same. I'm actually building a little site that presents a textarea that you can type your comment into and it will track its changes over time (typing, editing, pasting, etc) and provide a little playback widget so someone can see the composition of the comment. The idea being you can include a link to the playback in your comment that you post here and someone can eyeball it and see if it looks like you really spent some time writing it, vs just pasting in LLM slop. Of course, a sophisticated agent could _simulate_ writing the comment, but I think it could still help in general.
- rd 9mo agoI don't know why more school districts don't force this for essays. It's so straightforward with Google doc editing history too. And yeah, sure, you can get around it if you _really_ want quite trivially, but I imagine it would solve for 99% of students, and force them to actually engage with whatever AI-generated stuff they inevitably type by hand more than they were before.
- fyrn_ 9mo agoMoney is more focused on rolling out AI as fast as possible, rather than dealing with the side effects of that.
- deleted 9mo ago[deleted]
- johnisgood 9mo agoI have no problems typing an essay out.
- dizhn 9mo agoA generic playwright script taking agent's output as input could do this easily. Especially if it's just a few sites.
- keyringlight 9mo agoOne caveat, you might want to account for text that the writer deleted staying deleted/hidden. I'm not always the best at proofreading before submitting, but I'll often cut tangents I'm prone to ramble onto. Accidental pastes from other sources that are meant to stay private would be another issue if the history tracker grabs everything that goes into the text box.
- rd 9mo agoI've always wished there was a "block comments from this user" feature that didn't rely on vibe-coding my own Chrome extension (and thus not work on Safari where I spent at least 50% of my HN time). I imagine it could even work like Sponsorblock does, and we could crowdsource people who's comments are inflammatory. I've also noticed that very obviously LLM-generated comments are called out, and the community tends to agree, but those that have any plausible deniability are given far too much leniency, and people will over-index on the guidelines to give them the benefit of the doubt. I don't think a captcha is the solution, as it'll degrade conversation by an OOM though.
- ada0000 9mo ago+1. even blocking keywords could be nice, e.g. i don’t use AI for coding and don’t care much for news about claude code. captcha would make it more of a hassle to post comments.
- elashri 9mo agoI have a userscript that takes a list of keywords, domains and user names on HN. I host the json file containing the list on git instance and I use userscript plugin on iOS safari which would support this userscript. This is the lowest friction solution I found that would work on different devices. I find HN much more tolerable this way.
- SockThief 9mo agoThat kind of feature would be welcome. Blocking domains would be nice too. Like substack or medium. I'm happy to just ignore them, but it sure would be nice to filter them out if possible. I get that it's complicating the system and keeping it simple is perhaps for the best.
- pepperball 9mo ago[flagged]
- orsorna 9mo agoYour inflammatory accusation aside, is there even any indication that OP worked to push such efforts? Believe it or not, I think most HN users are not directly contributing to writing tools that "enshittify" the internet and are collecting a wage writing other kinds of software.
- stuffn 9mo ago[flagged]
- deleted 9mo ago[deleted]
- pamcake 9mo agoHN already enforces ReCAPTCHA for registrations. More CAPTCHAs will not do much if anything to improve.
- 1970-01-01 9mo agoPosts like this should just implement the poll feature. You'll have your answer in 24h. Then go and quibble with your data. https://news.ycombinator.com/newpoll https://news.ycombinator.com/newpoll
- l33tbro 9mo agoA preliminary discussion is more efficacious than polling uniformed users.
- metadope 9mo ago[flagged]
- sgentle 9mo agoAnd "picturing" is just a florid way of saying "imagining", no? The art of language lives in its redundancy; every unforced choice is a venue for self-expression.
- metadope 9mo agoYes, I love the redundancy of English. Language makes a playground of our minds. And yes, "picturing" is another way of saying "imagining", but to me and my mind it carries more of a connotation of visualization. Imagining may have its root in "imaging", but encompasses more imho, describing the entire Reality Construction Kit. "Unforced choice" is an interesting phrase. Perhaps another discussion, another time. End self-expression.
- metadope 9mo agoApologies for my sibling reply here (now flagged and downvoted to oblivion) if it was offensive to you. I thought I knew you irl and was making an overly familiar joke. Typos are nit inherently funny.
- lovich 9mo agoI’ve been here for years and somehow never knew about this feature
- lynndotpy 9mo ago[flagged]
- iammjm 9mo ago> "there is a tremendous amount of attempts by bots, and specifically AI agents, to inject slop into HN threads" Do you have some examples of this? I am on HN almost every day, and I read a lot of comments, and I haven't noticed this
- regnodon 9mo agoYou're right! It's just the flavor of the month (quarter? year?) complaint. Enslopification is coming for everyone, everywhere, at all times. Everything is already slop and will be slop, and will have been being slop.
- khannn 9mo agoNO "Me furiously trying to decide what a EURO thinks a motorcycle is" for 60s
- freeplay 9mo agoCaptcha is only effective at annoying legitimate users. If there is any incentive to do so, bots have no problem bypassing/solving them.
- gilrain 9mo agoIs this your experience as a sysadmin or a user? As a sysadmin, this is an absurd statement in contradiction of my everyday reality.
- properbrew 9mo agoI think it depends on how determined the actor is. I see all the range from your simple scripts to full on mimicking real user behavior that I can only really spot from the honeypots they hit. You'd probably catch most the low hanging fruit for sure, but you would cause friction for real users. I say this as someone who has enabled captcha on some of our more critical endpoints, there's definitely a place for it.
- fragmede 9mo agohttps://2captcha.com/ https://2captcha.com/
- JohnMakin 9mo agoThere are dozens, if not far more, of captcha solver API's for extremely cheap. Captcha is very shallow bot "security" theater, they just deter the cheapest attempts. latest greatest versions of captcha are more resilient to these types of services, but it's a cat and mouse game. I would recommend that you, as a sysadmin, learn at least the most basic things about this stuff.
- otterley 9mo ago> I would recommend that you, as a sysadmin, learn at least the most basic things about this stuff. This sort of language is inappropriate and unnecessarily combative. In any event, no filter screen is perfect. Getting rid of 80% of bot traffic is a good thing, even if you can't rid yourself of 100% of it. You can't let perfect be the enemy of "pretty good." People use CAPTCHAs because they work--even if imperfectly. Of course, you have to stay on top of the latest implementations.
- imiric 9mo agoThat is a losing battle. Even if you manage to make bot usage more expensive, which is all a captcha can do, the content posted by humans in discussions and shared links is increasingly generated by machines. It's ironic having a community of people object to the same technology they helped build. Enjoy the show, and learn to live with it. It's going to get much worse before it gets any better, if at all.
- ThrowawayR2 9mo ago> "they helped build" The overwhelming majority of developers have never worked anywhere close to LLM tech. AI is a very small field requiring specialized expertise.
- iamnothere 9mo agoI agree, having never worked on AI or anything privacy invasive for that matter. HN is not a monolith.
- dewey 9mo agoThis won't work, HN is a high enough value target (Not a random site where bots try to spam some guestbook) that people would adapt to that quickly. Headless browsers, browser extensions, outsourcing captcha solving etc. - there's too many ways to do that if you are determined unless you want to also throw captchas at regular users for every action.
- pogue 9mo agoDo you have some examples of ai slop posts? There are quite a few third party apps for Hacker News, such as Hacki (ios/android). [1] Something like using a third party app that includes forms of spam filtering like checking when the user joined, how many posts they have, amount of 'karma' (or whatever it's called here). You could implement blocking individual users & etc etc. This app does not have that but it could be forked and modified or talk to the dev... That might be a better solution than trying to implement all types of annoying captchas & other extremely annoying checks on HN's side. [1] https://github.com/Livinglist/Hacki https://github.com/Livinglist/Hacki
- deleted 9mo ago[deleted]
- tptacek 9mo agoThe value of an HN post or comment that people actually see is so much higher than the value of a CAPTCHA-solve that there's no point in even talking about this.
- ibejoeb 9mo agoTotally. Captcha should be thought of as rate limiting, not anti-spam.
- SoftTalker 9mo agoAnd HN already has rate-limiting, at least for newer accounts.
- sqrtminusone 9mo agoThis would prevent people from reading HN via a custom RSS, like I do.
- b112 9mo agoI just realised that one day, an AI moderated board will receive such a post from an AI, not a human. And then a captcha only an AI can solve will appear, and the board will be rid of all "human slop"
- regnodon 9mo agoBut would they still let us read the board though, just not post? How dystopic. And you're probably right.
- paganel 9mo agoSeeing "is this a bike?" captchas on a forum like this one would mean that the web is well and truly dead. Bring it on, for all intents and purposes, and 2fa also, while we're at it.
- jmward01 9mo agoThis is evolution in action. An ecosystem is generating with different things populating it. Is there a better method than captcha out there? For instance, hide things in html comments that only bots would see and if they are reacted to then flag that as a bot account and silently hide their comments (so that another account isn't created)? Do this randomly so that it is hard to find but bot code would catch it. Or other things like text with the same background color so only a bot could have seen it. Basically, instead of staying defensive, go on the attack?
- jrh3 9mo agoWhat's wrong with simple categories for comments... Informative, Funny, Flamebait, etc.
- regnodon 9mo agoIs complaining about the rise of AI Slop itself a sub-category of AI Slop?
- chasebank 9mo agoWe've always wanted to build a service which provides authentication through credit score verification. Whether its applied to dating apps, product review sites, HN. I'd sure love to filter by 650+ only. I'm certain it's illegal but it sure would help.
- calgoo 9mo agoThe rest of the world thank you for not including us. Also, this leads to the dystopian way where you loose all your access based on someone stealing your details and you have no way of fighting it off.
- _DeadFred_ 9mo agoHell yes! Not just a social credit score, but one that permanently locks in/enforces a class system. Tech bros even manage to enshittify social credit scores to be even more shitty. Amazing work.
- lovich 9mo agoIf you wait around long enough you’ll also start hearing them complain about China’s Totally Different Credit Score System that is only for social control, unlike the American system which is obviously just good business sense and doesn’t exert any control into seemingly unrelated portions of your life
- chasebank 9mo agoPick your poison, I suppose. All I know what we have now is a race to the bottom. Reviews, comments, dating sites, all a giant fabrication.
- al_borland 9mo agoWhat happens if someone had no debt, and thus no score? Lenders see this as a negative (to drive more business), but is likely a positive sign, as it means they live within their means and can get their bills paid without leaning on debt.
- 9mo ago
- NedF 9mo ago[dead]
- estimator7292 9mo agoI think you should first ask if captchas are at all effective at stopping bots. (They are not and haven't been for a long, long time)
- kevinh456 9mo agoCaptchas are not effective. You can pay 2captcha less than a penny per captcha and humans solve them for you.
- nobody9999 9mo ago>Captchas are not effective. You can pay 2captcha less than a penny per captcha and humans solve them for you. I'd expect that if we took Randall Munroe's advice[0], that price would go up significantly, perhaps prohibitively so. [0] https://xkcd.com/810/ https://xkcd.com/810/
- disambiguation 9mo agoIts too bad Team Blind doesn't support a dev api to their auth service. Work emails are a good candidate for a simple "blue check mark" system for the HN crowd, but with a layer preserving anonymity. Ex. Generate a token, add to profile, browser extension performs verification. Otherwise agreed with the sentiment.
- FloorEgg 9mo agoI explored a startup idea that really didn't make sense unless there was a way to ensure users were unique humans in an anonymous and privacy preserving way. Researched it substantially and realized it's an unsolved problem. Anything that makes a dent is incomplete and comes with ugly tradeoffs. For a time I wondered if I should try and solve it myself, but I could never think any solution that hadn't already been/being tried. Years later I'm left curious if it's even possible to solve the problem. My point is that captcha won't solve this, and solving this problem is a lot harder than it seems at first, and might not even be solvable (which I know is hard to accept). If someone does find an elegant privacy ensuring way to solve it, I think the impact would extend far beyond HN and could make a big difference to the future of civilization as a whole.
- binary132 9mo agoHaving to invite people in person and maintaining a network of trust could work. There would always be people ignoring friends selling accounts to bots, but ultimately I guess it would be mostly too costly.
- baxuz 9mo agoIt is a solved problem with ZKPs
- FloorEgg 9mo agoI studied ZKPs. You and I must have very different understandings of the actual scope of the problem. Like I said, everything that exists or is being worked on that makes a dent (including ZKPs) is incomplete or has ugly trade offs. Maybe you are thinking purely from a math / theoretical perspective, but I'm thinking of a compete solution that's practical to use to solve the problem for sites like HN and many others.
- baxuz 9mo agoThat is true, and I'm also working in the industry. We are currently in dire need of ZKP providers / abstractions that will aggregate both eIDs and tradition IDV (scans). However it's extremely important that the technical capability is there. The next step is to build upon it, and I think that it's a great time for something like this due to all the horrible implementations of identity verifications currently available — that is 3rd party companies collecting scans of documents and biometrics.
- binary132 9mo agoIMO, the old guard are all-in on the glorious slop future. We will eventually need to seek refuge in human-only and invite-only spaces as the infinite slop tide consumes all public spaces.
- deleted 9mo ago[deleted]
- nickphx 9mo agono.
- crazygringo 9mo ago> there is a tremendous amount of attempts by bots, and specifically AI agents, to inject slop into HN threads Is there? I enable showdead and don't see it. There are the occasional spam and vulgar comments, but not that much. Any "AI slop" being posted seems to come from actual HN'ers who think they're being helpful, and is often downvoted. But there's not much. So I'm not sure this is a problem that currently needs any new solutions? I don't see AI bots taking over the discourse at all. Not even a little.
- raw_anon_1111 9mo ago[flagged]
- vivzkestrel 9mo ago- here is an idea for a captcha - write this number in words - 486436546497964136564768756456455824164567575646875812445676854253154782125 - four quadrigintilion eight hundred sixty four trigintillion three hundred sixty five duovigintillion four hundred sixty four unvigintillion nine hundred seventy nine vigintillion six hundred forty one novemdecillion three hundred sixty five octodecillion six hundred forty seven septendecillion six hundred eight seven sexdecillion five hundred sixty four quindecillion five hundred sixty four quatuordecillion five hundred fifty eight tredecillion two hundred forty one duodecillion six hundred forty five undecillion six hundred seventy five decillion seven hundred fifty six nonillion four hundred sixty eight octillion seven hundred fifty eight septillion one hundred twenty four sextillion four hundred fifty six quintillion seven hundred sixty eight quadrillion five hundred forty two trillion five hundred thirty one billion five hundred forty seven million eight two thousand one hundred twenty five
- janez2 9mo agofour point nine times ten to the uh... 74th?
- vivzkestrel 9mo agowell i think you are right, let me think aloud here, 10^63 is one vigintillion so unvigintillion would be 10^66, duo 10^69, tre 10^72 , that makes 400 something as 10^74
- notepad0x90 9mo agoThere is already a captcha when you create accounts. There is no high-volume spam (ai or otherwise) on HN, so captcha won't help, low volume captcha can be farmed out. Humans are the best defense against low-volume spam. So flag these posts!
- erelong 9mo agoInteresting question but my problem is... it sometimes feels like there are almost no users on this site to begin with, real or not! This post only has around 100 comments, and even a top page post around 1500. Reddit's front page posts have thousands of comments and for me they seem pretty readable (and we know there are plenty of bots there... but Reddit does use captchas a bit I guess). I guess I am focused on a different problem though of how to attract more good human content...
- Bluescreenbuddy 9mo agoWhy would we want more users. The more people you add the worse it gets
- gus_massa 9mo agoUpvote good comment to reward people with imaginary points Go to /newest from time to time. You may find an undiscovered gem.
- loveparade 9mo agoCaptcha is a completely useless system trivially solved by many agents and services. The only thing captcha does is annoy humans. I do agree with the problem, but I don't know what a solution would look like outside of government identification.
- sgammon 9mo agoSuggesting this in 2025 is wild
- zz5759 9mo agoI’m not convinced CAPTCHA is the right long-term solution anymore. Most low-effort bots can already bypass basic CAPTCHA, while it mostly adds friction for legitimate users. HN’s strength is the quality of discussion, and that seems better protected by behavior-based signals (account age, posting patterns, community feedback) rather than one-time verification challenges.
- ranger_danger 9mo agoCan you name one "low-effort bot" that can bypass cloudflare captcha?
- MopAmine 9mo ago[flagged]
- vjxhgtiuyy 9mo agoYes really
- andyjohnson0 9mo agoI'm noticing quite of lot of posts to Ask/Show that are basically people using HN as a blogging platform. Sometimes they're tech-flavoured AI slop wrapped around a few links - persumaby an attempt at SEO. Other times they seem to be posted by users who may genuinely think that this is appropriate usage. Or they're cheap rants. Mostly they seem to be posted by new accounts. It's not clear to me that a captcha mechanism would help with this.