Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While relatable, this is just a low effort post more suited for Twitter or Reddit.

For a fair comparison OP would need to use clean browser profiles on fresh IPs. Like this it is just fan-service for Google Captcha victims (like me).



FWIW I encountered the same problem this weekend. On a fresh Firefox profile (no prior browsing activity), reCAPTCHA just wouldn't let me log in to a website! Out of curiosity, I wanted to see how long they deny me -- well over ten minutes before I gave up in shock and horror.

It felt like staring into the soul of evil.


This is a common problem with FF if you have any privacy settings enabled. ReCAPTCHA does deep fingerprinting. If you block that fingerprinting it punishes you.


If you come up with another way that is as effective in an ever growing world of bots trying to break anything in their way, I would love to use it.

I've had to pay 100x bills on my monthly quota once too often, and as a hobby developer, I just can't afford trying to fight off people abusing my website every day.

Yes, resorting to fingerprinting is not ideal, but what's better, asking everyone to solve that hard captcha, or only some users?


Considering how easy it is to use real chrome with puppeteer, I'm inclined to not give the benefit of doubt on this one to google.

In the end, a custom captcha is probably a better solution, even if it is easier than google's.


Use self-hosted CAPTCHA with simpler solutions. They still keep out the stupid bots that can't get past ReCAPTCHA.


> Use self-hosted CAPTCHA with simpler solutions

My favorite CAPTCHA is the one on the Arch Linux forms but I realize this cant be used many places. > What is the output of "date -u +%V$(uname)|sha1sum|sed 's/\W//g'"?

Easy to do but hard to do with computers. My second favorite are the math problems one.

However if these become popular people will just write bots for them and were back to square 1.


> > Use self-hosted CAPTCHA with simpler solutions

> My favorite CAPTCHA is the one on the Arch Linux forms but I realize this cant be used many places. > What is the output of "date -u +%V$(uname)|sha1sum|sed 's/\W//g'"?

> Easy to do but hard to do with computers. My second favorite are the math problems one.

> However if these become popular people will just write bots for them and were back to square 1.

Interesting...I wonder if they show destructive commands below a certain threshold. It would be funny if a captcha caused a bot to delete itself.


It would not be funny if even just one person ended up with that so I hope not. A bot would not end up in that situation anyways, either the earlier commands were already evaluated or your proposed remote kill would also not work.


Surely the same is true if you block these things in Chrome?


I kept looking for the article. Surprised to see such a low-effort post submitted to HN.


Users have the option to flag submissions


Okay, I will flag it. This submission still received almost 400 comments. That's pretty disappointing.


How can you have a fresh IP which isn't in your control?


Many of us have control of our IP Address within a certain range. In fact I have to specially request a static IP and pay money for it. A dynamic IP that changes when I refresh DHCP on the edge router is free.


> A dynamic IP that changes when I refresh DHCP on the edge router is free.

But you don't know who had it before you, what Google thinks of it ("known Spammer", "legitimate User") etc, so that's not going to help in this case.


Maybe try buying up some unclaimed IPv6 space and test from there?


The slow reloading of images is just intentional harassment. There's no other explanation I can think of.


I disagree about the more appropriate for Twitter/Reddit than HN. But that's because my immediate interpretation, while not spelled out in the "article", was within the context of anti-competitive behavior by Google in making non-Chrome browser perform more poorly with google-created content.


The topic itself is definitely super interesting and relevant. But the submitted post is pretty much a meme.


That's a good idea for a research paper. Not something I'd OP though :-)


being logged into gmail and the status of that account affects captcha as well


Not only that, you need to run multiple trials and average them. The post obviously picks the slowest most painful instance of a reloading captcha, where they got really unlucky. I've had those slow captcha's on Chrome too, they are not inherent to the browser.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: