The other day when Google was having issues (the same day that a bunch of Android apps were crashing due to a bad map data push), I was unable to log into my bank, unable to pay my electric bill, and a half dozen other things I needed to do that day.
Because Google's servers were down, core service providers were unable to do anything either because they block access to their site without recaptcha approving the entry.
To me, as a technologist, as a builder of software, this is absolutely and entirely unacceptable. Captcha needs to be something you can self host.
I don't understand this habit of handing Google a knife and then telling them where to stab you.
- We started out with self generated and self hosted captcha. It was too easy to beat. Complexity of the image generation turned up until eventually it was easier to just outsource it to someone else. Going to throw out a guess here that reCAPTCHA is far from simple, and likely exceeds what most teams would want to run internally.
- Google has an uptime that's significantly higher than most companies. I'm not defending any of Google's habits or business practices, but I personally wouldn't bet that most companies can run software more reliably than Google.
- As someone else mentioned, fail open is an option in situations like these (depending on the threats you're trying to protect against). For something with a high probability of failure, this could make sense, but I would have a hard time imagining a team allocating time to deal with the case "when Google is down" unless it's truly life or death software (think: surgical robots, autopilots, etc)
I found that generating math questions in a captcha style (curved / with other noise drawing over) and requiring that questions to be answered in a box is unbeatable. The bad actor would require very good OCR and after that also good math parser to answer. Easy for human, very hard for automation. And the script was like 50 lines long that did that.
reCAPTCHA changed to its current model to try to significantly reduce friction in the "hopefully normal" case (down to just a check box if all goes well) because every ounce of friction you add to critical inflection points in your product translates to meaningful lost opportunity.
Even if this wasn't a problem, and it were trivial to create something that's easy for humans and hard for computers, it's just not worth most companies' time. Would they rather spend a few days properly implementing and testing a captcha solution, then whatever unknown time on future bug fixes and support, or setup reCAPTCHA in 30 minutes and move on to things that produce value for their customers?
As for visual impaired ones, I agree this one is harder to crack. Usually you do it by audio, which in itself is more then 50 lines of code, but here is my personal approach. Absolutely none is stopping you to have, for visual impaired ones, a separate step like the one described in OP, where you have mail activated. You see visual impaired users have infinitely more patience then normal "visual" ones. They are used for web to not be friendly, so they won't mind going through extra hoops if they want your service. So a checkbox saying "I am visual impaired and I want registration by e-mail" or something equivalent and you're good to go.
Was this a mistake on the bank's part, or Google's?
Even if it's not Google's reCAPTCHA - is it so hard to make something like this that only Google can provide it? Surely the big players would want this component under their control exactly for reasons like "we don't want to have an outage due to a provider outage". Or at least, fail over to a less-preferred backup. Like if Cloudflare had such a service.
https://blog.cloudflare.com/moving-from-recaptcha-to-hcaptch...
My bank once required me to fill a reCAPTCHA to change my password. Yes, Google's tracking on my bank's website. I asked my financial adviser to reset my password for me to increase the cost of using reCAPTCHA for my bank. I told them it didn't work because of reCAPTCHA not working on my computer, which is actually true because I block it.
Some are using reCAPTCHA to detect bots, but I see many sites that appear to be using it specifically to slow down users. Users are to be respected but customers are to be mined for their money. Sometimes that means making things more difficult than is strictly necessary. If an onerous reCAPTCHA is required to delete an account or qualify for a price discount, so be it.
There is a reason it is so much more difficult find one's way out of a casino than it is to walk in.
This is basically how "e-stamp" system proposals were supposed to work for email; but they never took off because email is an ossified system. The web is not ossified; individual websites are free to implement something like this.
If you're worried about spammers just throwing a GPU farm at the problem: the overlap between spammers and people who own crypto-mining operations is small; and the people who own crypto-mining operations have much-more-profitable things to point them at. So this should mostly stymie spammers—individuals will be okay with sitting around on the page for a couple minutes to complete the action, but it'll throttle spammers' actions way down, to the point where it's mostly not worth it to attack that site any more, vs. some other site (i.e. it'll have the same relative-deterrent effect that putting a club on your car does.)
You could even frontload the work, turning it from a proof-of-work system into a proof-of-stake system. Have the user "buy in" with a large hash workload during user registration; and then trust them from then on. (This is the better approach for a mobile app: direct them to register on the app's website on a PC, and then you can trust that user on the much-lower-powered mobile device, despite that device never generating a token.)
-----
An effectively strictly-equivalent approach is to just charge the user a dollar to complete certain actions.
One famous example of this is the SomethingAwful forums, where registrations cost $10. You can register as many times as you like—i.e. if your account gets banned, there's nothing stopping you from just coming right back again—but you'll need to pay another $10. Seems to work fine, in terms of making it too costly to keep doing anything the site bans people for.
Charging a buck is extremely simple, and fair. The SA example tickles me.
I wonder if the folks who dislike reCAPTCHA would be willing to choose to pay $1 if given the option between the two.
Another commenter said that the market rate for reCAPTCHA solving is 1c each, so $1 is probably more than most would pay.
You may not agree and I respect this, but this is actually my point (and I don't have an answer to this question - I wish I had, though, and you have a point!).
I wish that people stop thinking soon that reCAPTCHA is a solution at all.
Then, it will open people to start thinking hard on this problem and hopefully find good solutions that fits their exact situation. There may not be one size fits all, but many good solution for each situation. We would not know without thinking.
I wonder if you could ask the user to trace a shape/pattern with their mouse? Or you draw a few animating dots with a canvas, and ask them to click the blue ones?
Fundamentally, though, you likely either piss people off by challenging their humanity, or violate their privacy by silently tracking their behavior, or break accessibility by evaluating the way they interact with your site against "normal" (bad for folks with screen readers, lynx, etc I'd assume).
If you want to solve this legal is your best bet. Make the things bots are doing illegal, and then track down the owners. It is hard but the criminal system is the only thing we have.
Absolutely a no-go: let me first try it for free and then I will add the credit card details, if I'm interested
Good friction (verifying emails, asking a question in the signup form, collecting a CC upfront) can result in more paying customers as you’re optimizing your experience towards people who are actually interested in buying your service.
Rather than trying to cast a wide net and wasting resources on poor leads who want zero friction.
So, without that step, you can't say "has nothing to do with hoping people forget to cancel."
But for any business that requires some amount of human support for users, it can be much easier to convert 15 out of 100 signups than out of 1000.
There are other components. Credit card entry acts like a captcha, but it’s actually a useful part of the process (unlike clicking street signs).
And the marginal cost of a free trial is low, but it’s not zero. If I can have less free trial customers but end up with similar paying customers, that’s a win.
There’s not only one reason.
If you really think a captcha is necessary, limit it. For example, require that a captcha is required for two account registrants with a 24h period from the same ip. Don’t require captchas for logins unless a reasonable limit of attempts has been exceeded (5 wrong passwords within 24h by the same ip for example).
If your site is small, a captcha is often overkill. A hidden input can trick pretty much any automated spam bot (if input empty, real user, otherwise bot). Just make sure you do enough research so accessibility readers also work with that field properly.
If a spammer targets you, you can always active a captcha manually, although by the time you realize it, it might be too late.
Keep in mind that a captcha only adds friction to the spammer (and users). Bypassing reCAPTCHA is possible for any motivated spammer for only a few cents/captcha. There are services that have humans in developing countries solve them for you. Coupled with a headless chromium, you can easily build a reputation so that google will let you through. For testing credit cards, this setup is definitely used and most likely worth it. So a captcha will not always save you from bots.
Also keep in mind that hacker news does not have a captcha and the amount of spammers is minimal.
2. Identify a target for some kind of account takeover attack. (Assuming you have other details needed for takeover.)
3. Rent botnet.
4. Perform thousands of signups for the target's email address starting shortly before your attack.
If the account's only security notifications (e.g., password reset, etc.) are in the form of emails, the flood of spam will usually keep the target from seeing them until too late.
These are real attacks, frequently seen in the wild.
In any site that creates a community or has any kind of interaction between its users, spammers and spambots will ruin the site for everyone else.
It's hard for me to take people seriously who rail against recaptcha yet don't seem to realize why we use it nor pitch a real alternative. Or that spammer protection is overrated because their obscure blog doesn't get much spam.
It's easy to enumerate what sucks about something, but you can't just stop there.
Depends on your size and resources. Imagine you're basically scrappy with a very small and tight budget and still trying to validate your idea, and you're using one of those providers that gives you a free quota (like Google App Engine), you don't want 'spammers' to drain your free allotment of resources. I know someone who has a small niche blog in the health sector whose blog was repeatedly targeted by spammers/bots. He repeatedly saw increases in his bills till he had someone audit his blog and try to block the bots
I have found that simply throwing a reCaptcha onto your form forces you to make a bad choice between protecting the user's privacy and creating a mostly-seamless experience: if you don't want most of your users identifying school buses, you need to send all their behavior to Google.
To get around that, I've tried layering a number of different approaches. These include outright throttling/blocking repeated form submissions from the same ip; using a honeypot field; using a third-party email verification/validation service; showing captchas only under certain very restrictive circumstances (heuristics that make a guess/overall traffic patterns); etc. It's more work, and still a bit cat-and-mouse but at least I don't feel like I'm pissing off every potential customer
I have seen spammers signing up just to send short message via welcome email ("Hi firstname," -> "Hi check this foo.com,") to their targets. The worst thing that can happen from that is that your domain/email servers end up in the blacklists.
For the majority of users, they won't see a captcha challenge and it is a seamless experience with no added friction.
Those who have lots of tracking/privacy protections however will more likely be flagged as a potential bot and usually have tougher challenges as a result.
And it achieves that by surveilling all user activity on your site, not just on the signup form.
>reCAPTCHA works best when it has the most context about interactions with your site, which comes from seeing both legitimate and abusive behavior. For this reason, we recommend including reCAPTCHA verification on forms or actions as well as in the background of pages for analytics.
https://developers.google.com/recaptcha/docs/v3
A privacy minded programmer/company might restrict the scripts to the minimal set of pages, but I'd imagine most sites would blindly follow that advice and put it on every page because they think more data = better.
This usually stops simple spam bots that are aimed at that particular off-the-shelf forum software.
Manually approve someone who registers ... then discover they're a spam bot?
I recently had an incident with Chime Bank like this, where someone enrolled every public email address at my company with them. I sent them an abuse report and they told us to block their domains. Real great solution, guys.
I was getting questions where I'm just not sure what the right answer is.
Which pictures have traffic lights? And then some pictures where I can barely make out a traffic light far away in the background. Does this count?
Which pictures have busses? Is the blurry white vehicle a large passenger van or a small bus? I don't know.
Then the most absurd one, I was asked to select tiles containing a bicycle, on a picture like this:
https://www.bikecleveland.org/wp-content/uploads/2015/04/Sha...
Does a representation of a bicycle count? I don't know.
And then when there is just a few pixels of an object going into a tile, am I supposed to select it?
Here's a video (not mine) of the sort of thing I mean: https://www.youtube.com/watch?v=GGBsopLvwwo
Likewise. It's randomly difficult to get through, and if you have third party content blocking it just doesn't show up. I just hit back pretty often just counting the times I knew it was there any was a reason the page wasn't working.