i'm generally against this type of gating, where the people doing the right thing get punished disproportionately (even small slices of time add up to wasting thousands of human-years over the population) just to combat the tiny number of bad actors. target the bad actors directly.
it's the same for tsa security theater. let's put all those humans to work training dogs of all sorts and filtering them through people at the airport. the money for those privacy invading scanners can be put toward training and housing the dogs. our collective time is not wasted on silliness and standing in line, and we'd probably save a lot of tax dollars that way.
I have also trained myself to wait a few seconds before clicking the box, which seems to help assert my humanity.
I wonder how many different weird rituals are out there for 'beating' CAPTCHA?
For me, I usually make some effort to keep moving my mouse and being "active" after clicking the box, on the idea that an isolated click event looks less human. It's based on a friend's tip and it seems to help, but I have no confidence that it's actually relevant in such a complex system. I sort of suspect Google has created a new generation of meaningless routines fit to rival historical standouts like sports rituals.
On the one hand, fuck Google for wanting another vector with which to track me, on the other hand, why can't it remember that I proved to it that I'm human (allegedly) two days ago?
Maybe to prevent bot operators from manually aquiring a human-cookie then let their bot operate for ever ?
I'm using that captcha on my website, and I can tell you, that one works 100% while the other ones don't.
this is a subtle externality borne from scale combined with zero marginal cost. we need to find a way to make the bad actors bear the cost of that externality rather than the rest of us.
it's a hard problem that resists simple solutions like captchas, certificate signing, delivery fees, taxes, or even just outlawing the practice. as a lowly consumer, one of the few levers i have is curtailing my use of services employing (google) captchas.
Annoying as they are, I don’t really see a better alternative. They’re also pretty easily circumvented with cheap labour like mechanical turk and similar services.
Identifying the lights and cars and bicycles is you training Waymo's self-driving AI.
Personally, I've reached the point where this is the first thing that I do. If a site is presenting a CAPTCHA (especially one run by Google) to me, then 90% of the time, that's a site I'm better off avoiding anyway.
That last 10% can be infuriating, though, and I certainly won't feel positively about it.
I disable most scripts using uBlock, but I have to make an exception for reCaptcha if I want to interact with half the web. I'm pretty sure due to that alone Google is able to track where I go.
How much, and at what odds?
The length of the average Google CATPCHA has been steadily going up for me. I haven't pulled out a stopwatch, but I do count how many image sets I go through. I basically never get through on the checkbox unless I've done one on another site shortly before. I sometimes succeed after one set, but if I don't it's consistently 3+. The worst case I've seen was 10 layers of slow-loading images without success, at which point I gave up and tried on another device. (If it had been a site I didn't need, I'd have given up after 5 - which I do fairly often, so I don't have an average count needed to succeed!)
I'm fully aware that average users don't have this much trouble, or people would be furious. But I also see that captcha ramps up to an extremely long process in the face of even modest privacy-protection efforts like not running Javascript or allowing third party trackers by default. (God forbid you're using a VPN for any reason.) It's not assessing your humanity but your familiarity, using the same fingerprinting tools as any site that wants to track you.
Spam is a real problem, and a hard one to solve, but I admit I'm hostile to Google's captcha. Partly because it really is a significant time sink for me. Partly because it lacks any progress indicator or fallback option so it's an indefinite hurdle to accessing sites I'm already committed to using. But largely because, despite what I really believe are good intentions, it's yet another force pushing people to give up privacy and even security if they want websites to work tolerably.
It's almost definitely not my problem, and it's not even necessarily a problem it's just a way to access pages, made easier by Google in fact because it's a perfectly legitimate way to navigate the internet and Google themselves depend on it. If anyone wants to discourage it just provide an official API to use instead of pages, which are a defacto API for humans.
https://github.com/GoogleChrome/puppeteer
https://www.trustedreviews.com/news/apple-hit-two-factor-law...
Phone calls to GF, to get her to login, similar issue, it was now signed out, and after another attempt, one of them showed the 2FA window, which got me in. At no point was I able to use the phone number also associated with my account, and it was a huge, long, pain in the ass. It's actually a huge part of why I won't buy an iPhone.