Blocking via an Unsolvable CAPTCHA
google.com
google.com
To add insult to injury, if you do try to make complex and slightly varying queries and exhaust its result pages in an effort to find something you know exists, very often it will think you're a robot and present you with a CAPTCHA, or just ban you completely (solving the CAPTCHA just gives you another, and no matter how many you solve it keeps refusing to search; but they probably benefit from all the AI help you just gave them, what bastards...) for a few hours.
Edit: I wonder if Google is using this as a sort of income source for pages that bring little to no ad revenue.
At work I just recently managed to trip it three times in one day, which I consider a record since in the past I've encountered it at most a few times a week. What's more infuriating is that my queries were far less complex than the ones that tripped it before (trying to find information about some API constants), basically one quoted term and one site: modifier. I can understand if I was querying 24/7 and hogging their servers (in which case a nice "please slow down" message would be much better), but it tripped within a few minutes of, admittedly intense, Googling.
The security device may notify the attacker device that the solution is incorrect regardless of whether the solution is actually correct.
In Google's case, it doesn't do that at all --- solve one CAPTCHA successfully and all you get is another, immediately. If you actually do deliberately give the wrong answers, it does tell you they were incorrect.
I wonder what can be done to stop it from doing that, besides the old tactic of evading IP bans by changing IP --- it's somewhat creepy to think that it's probably capable of detecting that too and banning the entire subnet. On second thought, it might be worth it... if it means I can get thousands of others blocked from Google for a nontrivial amount of time, all the more mouths to complain and maybe force some reconsideration. I am not a robot. I am not a competitor scraping your pages or doing anything else against your ToS. I am just an intelligent human with over two decades of Internet searching experience enthusiastically using your service for the exact purpose it claims to do: to find something on the Internet.
I have experienced Google doing the endless captcha when using Opera's built in VPN.
The first time I went through about 3 captchas and then I "knew" they were messing with me.
So, now, I just change my location in the VPN, and get back the searching...
Which shows how important it is for Internet health that we have search competitors to Google who maintain their own indexes. No one company should become the sole practical gateway to the Net.
Maybe it’s time to stop using Google and use another search engine which actually treat you like a human being, like DuckDuckGo.
Once you realize this it’s way less confusing, and in fact it even clearly states the instructions at the top of the CAPTCHA. But it’s super confusing and definitely a usability nightmare.
The goal, as I see it, is to increase the number of round trips to google required to solve a CAPTCHA, in order to increase the cost for those using CAPTCHA solving services.
These Google CAPTCHA's are deployed all over the internet, but you mostly won't notice them until you use a VPN. When you do, you get them at what seems to be their strictest setting: multiple rounds of 'click the object that is a car/storefront/road/mountain/road sign/bus/river', where all pictures clicked are replaced via a fade-out-fade-in that lasts about five seconds before you can continue evaluating the new picture.
I had trouble with Coinbase account verification which I'm almost certain was akin to the linked patent: it asked me for a picture of my passport, and then a picture of my face, and then told me that the pictures didn't match and I must try again. Every single time. I only managed to regain access to my account by emailing a contact that most people wouldn't have.
Hmm, maybe I should start thinking up annoying things that future software might do for profit, and patent them now to stop companies from doing them for a while.
My favorite in this genre is IBM's patent on patent trolling: https://www.google.com/patents/US20070244837
https://www.google.com/patents/US20030133714
Of course it doesn't actually work, but figuring out why makes an interesting exercise.
http://www.flownet.com/ron/QM.pdf
Or if you prefer, this video:
I've always found that kind of interesting. The US lets you patent just about anything.
But in my home country, Australia, one of the patent requirements is that it actually appears to function in the way you are claiming it does. ("The application must be for something patentable, like a practical adaption, not for an idea or principle.")
I wonder if that has any impact on patent trolling, or if it's just as pervasive.
It's an _incredibly_ frustrating experience for real users caught in this
I see this occasionally, but just change servers. And it's typically just temporary. Affected servers are OK in a day or so.
A challenge-response test may include a type of authentication where one party (e.g., security device 240) presents a question (e.g., a “challenge”) and another party (e.g., attacker device 210) is required to provide a valid solution (e.g., a “response”) to be authenticated. An unsolvable challenge-response test may include a challenge-response test that does not have a correct solution and/or a challenge-response test where attacker device 210 may be incapable of providing the correct solution (e.g., when the correct solution includes a character that may not be typed using a standard keyboard, etc.). In some implementations, security device 240 may generate the unsolvable challenge-response test in the form of an unsolvable CAPTCHA. In some implementations, security device 240 may generate the unsolvable CAPTCHA using one or more construction techniques that are designed to block attacker device 210 from sending a request to server device 230 without making attacker device 210, and/or a user of attacker device 210 (e.g., a hacker), aware that attacker device 210 is being blocked (e.g., by security device 240) from sending the request to server device 230.
Just fabulous. /s
That's criminal deception.
The services were never truly to offer, and you've wasted a persons time and energy.
What if a store kept out undesirable customers by giving them an unsolvable puzzle? There'd be lawsuits.
Basically, they've patented shadow-banning via CAPTCHA. And I'm left also wondering if they've taken the "that's not a bug, it's a feature" meme to a whole new level. I've run into the scenario described by this patent on a few occasions over the last year. I'll be given a CAPTCHA on Google's search results page that has no solution, and they're cleverly frustrating -- not just pictures of roads asking for you to identify lakes, but "click on pictures of street signs", you click, they disappear, new ones appear but there are no street signs left and the submit button yells at you to "make sure you check the new pictures". So you start wondering if it's a trick question; maybe they're using the phrase "street signs" in a manner you weren't previously familiar with?[0] I hate it when my search engine tires to screw with my head.
A hard-refresh resolves it (or I could have probably picked the audio version and been fine, but I have a difficult time understanding those). Running into this bug, the very first thought I had was "this would be a rather novel way of frustrating a bot", followed immediately by "that's got to be what's going on" (and a bit of profanity about how lovely it is to be a false positive)[1]. I mean, combine a freshly loaded PC with an obscure set of search terms and you tend to get a long CAPTCHA. Perform some action that triggers a CAPTCHA while logged in to Google and you'll get a CAPTCHA-less CAPTCHA (check the box to continue). It's only logical they'd have the opposite extreme of "we're going to reject this one because the maliciousness rating indicates that we're being visited by satan coding in brainfuck".
[0] It seems to be occur the most when searching for obscure, specific error messages with commands like "allintext:" (since Google likes to just pretend I didn't actually mean what I asked for) along with portions of the search in quotes. It also doesn't trigger until I hit page 3, or have performed the search a few times with changes only in what I'm including in quotes. It's been happening a lot since I started doing CUDA development. I guess Google really, really, hates bad CUDA developers. Joking aside, since I usually have to get a few pages in, I probably look like a search-engine scraper combining variations of rarely searched terms with no click-through traffic.
[1] I have a funny history with this sort of thing. I was banned from Bing Rewards years ago for ToS violations that I didn't violate. My guess was they assumed my search traffic automated for reward harvesting (because, you know, the rewards would have ever been worth wasting the time developing a bot). And it probably looked that way since obscure searches on Bing, way back when, rarely yielded any relevant results (a half-page of log files, often). Things over there have improved enough that I use it as a fallback when I don't feel like clicking pictures of storefronts, though the banning was a personal insult, so I have to be really cranky about the CAPTCHA interruption to "Ask Chandler".
edit: I felt that neither "satan" nor "brainfuck" deserved title casing.
Original Assignee: Juniper Networks, Inc.