Judge tosses proposed class action accusing Google of CAPTCHA fraud
arstechnica.com
arstechnica.com
> In addition, at oral argument, Plaintiff did not represent that if given leave to amend she could allege that had she known the second reCAPTCHA word was used to assist Google with its other services she would not have completed the reCAPTCHA. To the contrary, counsel represented that he had not asked Plaintiff and he did not know what she would say. (Dkt. No. 60 at 20:23-25.) Such question, of course, should have been asked and answered before this lawsuit was filed and pursued in two states. Regardless, it defies common sense that the answer would be yes.
[1] http://boothsweet.com/wp-content/uploads/2016/02/Google-Orde...
The fact that they didn't cover this important point is ridiculous.
As the company who invented the anti-trust defense "competition is only a click away", Google should equally be capable of acknowledging there in absolutely no burden on Google to create 2 boxes for new users, one identified as CAPTCHA, and the other as a crowd-sourced word to be used for Google's other services.
Most users will just check a "I'm not a robot" box now; and if you do get a test, it will likely be a computer vision / image labeling problem: https://googleonlinesecurity.blogspot.com/2014/12/are-you-ro...
For example, if a computer passes a CAPTCHA in order to use gmail to automate the sending of spam emails, look for users that mass-spam; typical users won't do that. On the other hand, the computer may try to approximate the usage of a typical user to avoid detection. But if you cant distinguish automated use of your service from typical use of your service, then at that point maybe it doesn't matter so much.
Another way is to send the same using email which is a bit more convenient than sending it to cell-phone.
In other words, we need to keep inventing more sophisticated ways of telling the difference between humans and computers (and the great progress in the field of AI is certainly going to push us to do that more frequently)
Looking for atypical use of services is something that we should be already doing, but there are limits to those. The said users you are talking about keep churning new email addresses and hide behind dynamic IP ranges of countries like Mongolia or Kyrgyzstan over which we have no control. We can't tell the difference between good/bad IPs for traffic coming from there, otherwise there is no need for Google to keep re-inventing the CAPTCHA every few years.
I thought this was the entire point of re-captcha, so regardless of the 'time necessary to complete' element, their case doesn't seem very well thought out.
Why? because Google, through their almost-monopoly in some areas (including captchas) has gotten an unfair advantage in computer vision.
I personally would prefer if Google would be forced to publish any training data and parameters for neural networks that were trained with data created by the public.
They work quite well. I tend to get about a 1 out of 5 correct of the squiggly words, whereas the service is more like 4/5
I am not aware of any successful dictionary attack on recaptcha. And the only OCR techniques to bypass recaptcha was by xrumer[0] but that was a few years ago
[0]xrumer: once popular forum spamming software waned in popularity / effectiveness in recent years
> A hybrid system composed of the most advanced OCR system on the market, along with a 24/7 team of CAPTCHA solvers. An average response time of 11 seconds,...
My understanding is that this is mostly humans in third-world countries staring at a screen and working for peanuts (or maybe less than the value of a peanut). I don't see how any system for recognizing humans can succeed against real humans.
But I'd argue that the CAPTCHA itself is a greater benefit to the end user than the cost (not just Gmail or Google Maps). If Google had to stop using OCR CAPTCHA tomorrow, they would have to use an alternative, and frankly most of the alternatives are worse. Further still without the ability to hinder bots services like Gmail couldn't exist.
Arguing that Gmail is a greater benefit than the CAPTCHA costs to complete is fine, but potentially leaves the gate open to sue later because someone finds a service which they claim doesn't benefit the end user (e.g. paying a bill). Arguing that the CAPTCHA method itself has more benefit than cost completely destroys any future lawsuits.
The judge said that.
> > Moreover, users’ transcriptions increase the utility of other free Google services such as Google Maps or Google Books. Plaintiff has failed to allege how these numerous benefits outweigh the few seconds it takes to transcribe one word.
Sometimes I have the feeling like the whole judicial apparatus has gone from solving real life problems to creating absurd problems that allow you to sue somebody.
What ultimately happened was that regime change happened at IEPA and they got serious about enforcing the consent decree. But that still doesn't compensate the townspeople. Good luck getting someone to buy your house in a former superfund site, even if the heavy metals on the school grounds have been cleaned up to a reasonable, cost-effective standard.
[1] This problem is recurring. Agency enforcement is a lot more efficient than lawsuits. But agencies only have the resources to go after the biggest fish for the most egregious violations. And they're far more susceptible to political pressure ("you can't sue XYZ, they have 10,000 jobs in our state!")
One interesting thing I've learned from the court rule though: apparently software delivered online and through downloads does not qualify as a good or service under the California's Consumer Legal Remedies Act, unlike boxed software delivered on physical media (pp.14-16)
- reCaptcha presents 2 words for the end user to solve
- the purpose of the second word has nothing to do with security. The word itself is not known to Google.
- the "fraud" is that Google is deceiving you into helping them decipher the second word for their own financial gain
(paraphrasing from http://digitalcommons.law.scu.edu/cgi/viewcontent.cgi?articl...)
Edit: Please note that I am not in agreement with the premise above...just trying to summarize it.
Are we saying that fraud is not going out of your way to carefully explain exactly what you're doing as you're doing it?
Saying that Captchas are in any way misleading or fraudulent calls into question "free" software paid for by ads, any app that has a ToS contract, pretty much every financial agreement on the planet, most repair shops, and just about anywhere else that you agree to something without 100% ELI5 in your face explanation before you pull the trigger.
My feeling these days is that either you're on the inside or you're a sucker.
(On the level of fairness and justice - I don't know enough to comment on legality - I don't think this particular incident rises to the level of damages. However, Google could just display, In return for our free service, please help our computers read this word! Even Google's computers can't do everything - read more about it <here>. - Why not disclose it if you are doing nothing wrong? If you don't disclose it, you're manipulating people.)
[1] http://toucharcade.com/2015/09/16/we-own-you-confessions-of-...
Suppose Microsoft used a small bit of your unused processing power for some of their own work in order to increase their profits. It's likely few would ever know of this. Is that ok? Somehow I would feel...violated. Like somebody else just took rights to something I thought was under my control.
Note: I don't use gmail, and I view ads on google. The reCaptcha I've seen has been on third-party sites. So their doing this seems to be outside of the 'contract' I have with them. I'm not doing this to pay for a service of theirs that I use- at least not directly.
> reCAPTCHA offers more than just spam protection. Every time our CAPTCHAs are solved, that human effort helps digitize text, annotate images, and build machine learning datasets. This in turn helps preserve books, improve maps, and solve hard AI problems.
That seems like disclosure to me?
Call me a data point to the contrary. I don't use gmail or Google Books at all, and Google Maps rarely. I contribute to OpenStreetMap. It sticks in the craw that whenever I use any Google Captcha-enabled site (even if the site's not owned by Google) I'm helping to increase the quality divide between Google Maps and OSM.
I guess you are in the same category as the plaintiff?
Not for free, that's the point. You get access to Gmail.
That means that the answer to your questions is a resounding no. While on average we're better off, not everybody is, he in particular is worse off.
You contribute and therefore probably benefit OSM, you're using a google captcha enabled site so you're benefiting from something on that site, that site benefited from the captcha service because they didn't have to write one themselves so could spend their time improving the site you're benefiting from.
You're a link through which google captcha is benefiting OSM :)
Are there any CAPTCHA providers out there who OSM could team up with to do the same?
When you think like that, all sorts of interesting things come out. For example, something I don't think anyone has done but could be pretty amazing, put a camera in a store which tracks gazes, set up a set of mannequins with different looks and compare male and female gaze time. Sure it used to be you could change the window display and count sales, this is so much more informative than that.
So are you using their interactions for your own benefit? Sure. Is this a new phenomena? No. I totally think the judge called it on this one.
There are plenty of legit class actions and stuff like this diminishes them.
After google bought them and moved to useless training for their image classification, which helps nobody, i was simply banned from contributing to all sites that demand captcha. Because it simply refuses to work with my phone.
Will all site who used google captcha be affected by the result of this case?