If everyone would block it the website owners would have no choice other than to move to a different captcha system.
The only way to make that happen is to stop using Chrome and tell others to do the same.
Google took over with shady practices, with the help of tech savvy people.
"It works in Chrome and Edge, which is based on Chrome, so what's your problem, again?"
And before I get accused of shilling, I hate chrome and despise Google with a passion.
It seems pretty clear from the fact that nonsense user agents like "TotallyNotMicrosoft" and "IE6" worked, that there is a blacklist, not a whitelist.
It seems pretty clear from the fact that nonsense user agents like "TotallyNotMicrosoft" and "IE6" worked, that there is a blacklist, not a whitelist.
Then maybe the standards process needs disruption. But if we don't build to standards then we are building roads that only certain cars can drive.
I also love sending him patches to show how easy it is to fix his stuff so it works in Firefox, Chrome, Edge... and of course Safari.
DRINK VERIFICATION CAN
It shouldn't be the case, and I don't want to block people who have a legitimate reason to use Tor. Unfortunately there isn't a "block Tor traffic from assholes" option, so all I can really do to reduce the malicious traffic is block exit nodes.
> Unfortunately there isn't a "block Tor traffic from assholes" option
What exactly is "Tor traffic from assholes"? Bulk DDoS attacks? E-mail spam? SSH login attempts? Please share your valuable experience with everyone here, so that all of us could stay safe by learning from your example.
Most "asshole" traffic I see falls into one of two categories - attempts to exploit vulnerabilities (../../../etc/passwd stuff) and account takeover attacks.
The first I can forgive, I don't frankly care where that traffic comes from and the responsibility is entirely mine as website admin to prevent these types of attacks through good coding practices, WAF, etc.
The second I have less control over because customers / the general public sucks at security. They re-use passwords they've had for 10 years and won't opt-in to 2fa. And as a merchant, my company generally eats the cost of fraud that these attacks generally result in.
If no or little legitimate traffic is coming from Tor, and a significant percentage of malicious traffic is coming from Tor - at great cost to me / my company - why the hell would I allow it to continue?
There are many types of "abuse" (not just trolling) - mass downloading/scanning. (Ex: several types of port scanning can't be done via Tor since it doesn't support UDP)
Now you're just training many Google machine learning algorithms by classifying data. In which they get more useful for the consumer, thus more powerful.
What is the purpose of those choices then?
Not to get all tin-foil-hat, but this is going to sound like it, but if you have a car that has 9+ cameras upon it that drives in areas full of these, then maybe there would be some use for it for Google.
Bear in mind that I'm not saying that they are doing this but to dismiss it unequivocally as something that can't or wouldn't be done entirely ignores the premise that it could prove useful to other areas of their business, which might have a vested interest in such use (say, for example, if Google or it's parent company were trying to break into the self-driving car area[0]).
I would love to see some evidence (a link or something) of this. I see captchas that look like pretty good edge-detection discriminators- street lights in tree limbs, bicycles against brick, and so on.
I kind of wonder if it would be possible to force the issue legally as an accessibility problem, but other people than me would need to do it, and in any case it feels a kind of dirty to me to use blind accessibility as a tool in the fight for privacy.
On the other hand, it also feels dirty to me that being blind would mean you're not allowed to do as much on the web to protect your privacy. Blind people should be able to use Tor.
That'd be very cruel to ignore those with vision, but who don't have anything close to perfect vision or correctable vision through glasses. It would also ignore those who have poorer vision as well as have difficulties in recognizing patterns. There's a whole spectrum of accessibility issues, and trying to "fail people" who seem to have enough vision to click on an audio button would be the definition of being evil.
> I kind of wonder if it would be possible to force the issue legally as an accessibility problem, but other people than me would need to do it, and in any case it feels a kind of dirty to me to use blind accessibility as a tool in the fight for privacy.
Even if this is not possible legally in all jurisdictions, enough publicity and outrage could help. There should certainly be some journalists from major publications/site reading HN (or HN readers with journalist contacts) who can investigate and write about this.
I dislike Google reCAPTCHA, however, it brought down contact form and comment spam to almost zero. (With the price of an unknown number of false positives and some frustrated users.)