Research shows hCaptcha is useless
researchgate.net
researchgate.net
From the guidelines https://news.ycombinator.com/newsguidelines.html
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.
This limits options for the free version they tested, as by design it will not completely prevent all detected automation from passing.
Instead, one of the tools it relies on is frequently changing the classes and types of challenges. However, it also has “anti-drain” protections to avoid leaking these.
Thus, our response to them after looking through the paper was that in fact the anti-drain protections were working as designed, based on the other details reported.
disclosure: work there.
"Not completely prevent all" seems to mean "prevent about 5%", which is cold comfort for users who expected better. If they had paid for the service, would they have gotten better results (i.e. fewer successful bot sign-ups)?
The most amusing part, though, is the gaslighting by the hCAPTCHA team and the denial they live in lol
"We reported our attack and countermeasures to the hCaptcha security team to help them make the system more robust to automated attacks. They responded that their system would have been pretty confident that our traffic was automated based on the techniques we used, and we would never have observed additional countermeasures. However, we did not notice any measures preventing our bot from passing the image CAPTCHA tests during our experiment. "