A website with captchas is like a retail store with metal detectors; it's not somewhere I feel welcome.
A website with captchas is like a retail store with metal detectors; it's not somewhere I feel welcome.
Imagine how mortified I was when we reached the last steps and I had to explain to her 'and NOW.. after all that... you have to click on all the tiles with traffic lights'.
She looked at me and asked with childlike innocence and wonder "but WHY do I have to click all the tiles that contain a traffic light?"
I could not reasonably answer that question but I came close to saying "dear Kristine, throw this tablet in the garbage, none of this is going to make you happier"
I wonder how much of that was due to the impairment itself, and how much was due to people underestimating her or not being willing to work with her to get her online.
> I could not reasonably answer that question
I can appreciate that it would have been challenging to come up with an explanation on the spot, while trying to talk her through joining the meeting. Having spent several minutes thinking about this from the safe distance of an asynchronous discussion after the fact, the best I can come up with is this:
When you join a Zoom meeting, your tablet makes a call to Zoom over the Internet. But Zoom doesn't know for sure that the call is coming from an actual person trying to join the meeting. Have you ever gotten a phone call from a stranger, only to find out that the call is actually from a computer playing a recording, trying to sell you something? But if you assumed all calls from strangers were like that, you might also miss important calls from real people. It's kind of like that for Zoom as well. There are all sorts of nasty programs out there on the Internet, trying to make calls to Zoom. They might be trying to snoop on people's meetings, bombard people with advertisements, or just overload Zoom. Zoom needs to keep those programs out, so it can focus on serving people like you that are actually attending meetings. Now, when you get a call from a computer, you can tell pretty easily that it's a computer, because so far, computers aren't very good at having a conversation with a person. But Zoom is a computer program, and it's not smart enough to tell whether you're a real person without asking you to do something annoying like clicking all of the tiles with traffic lights.
> I came close to saying "dear Kristine, throw this tablet in the garbage, none of this is going to make you happier"
What actually happened? Did she make it into the meeting? Do you know if she continued to use the tablet for other things? I hope so. I know the Internet can be frustrating, but I think it would have been a mistake to conclude that it wouldn't make her any happier. After all, it has helped us stay connected through the pandemic, right? I hope she got to participate in that.
Perhaps drawing a parallel with social networks could help: when such a huge portion of the population is on facebook properties, it could look crazy to not have a facebook account. Perhaps there wasn’t enough help to explain how it works ? But we understand not dealing with facebook has upsides, and while it creates hurdles, they can be worked around. We wouldn’t push someone to go on facebook if they had no need to.
Obviously we are talking about exceptional cases, but if they were happy as they were, it could be worth keeping it that way if they don’t have an appetite for changing.
But now the pandemic has happened, being online is more important than ever, and there's probably no going back. I find it unacceptable to leave some people behind. I know that pessimism and cynicism about the Internet are fashionable these days. But we're still here, discussing things online. If we're not willing to throw that away ourselves, then maybe we need to give those people more of a chance to decide for themselves if it's worthwhile.
My interest is on what you see as actions related to that. We're a community mostly on the building the web side, bearing at least some responsibility of what "being online" means today.
Your describing them as left behind makes me think you see the current web as the way forward, but I don't know if it's a fair assumption on your position.
Arguably I see their lack of using online tools up to this point as a failure of those tools to provide enough value for the hassle, and the issues would be less to bring this people along than to come up with ways to bridge their world and ours.
We often talk of digital litteracy as if it was an unavoidable skill, but I kind think it's like positing that Amazonia tribes have to learn english. It could be better for them, but we could also have adaptation layers that make it work for them even if they stay in their culture and lifestyle.
Speaking of adaptation layers, my own expertise is in accessibility for blind people. There's some debate in the online blind community about the merits of devices and user interfaces designed specifically for blind people, versus retrofitting a screen reader onto a mainstream GUI. Given the prevalence of proprietary walled gardens, the staggering complexity of even the open web, and the need for blind people to participate in mainstream society, it's inevitable that we have to rely on the latter to some extent. But that doesn't mean that blind people have to live with only the level of accessibility and usability that mainstream platform companies choose to provide, ad least as long as one mainstream platform is open enough to allow for third-party adaptations.
So maybe there's also a need for alternative UIs for people who, for whatever reason, aren't familiar with the conventions of the mainstream Internet, such as email inboxes. It would be important, though, to make sure such attempts at alternative UIs don't come off as condescending (like, say, Microsoft Bob).
Edit: OK, in hindsight, my explanation was incomplete. I should have added something like: The general idea is that Zoom is asking you to do something that a computer program can't reliably do. Unfortunately, as computers get better at performing simple tasks that used to require human intelligence, it becomes more challenging for a computer to determine that you're a person and not another computer. That's why it has gotten to the point of asking you to click on the tiles with traffic lights.
https://www.mainstreetmaterials.com/lighting-and-electrical/...
Captcha bonus level: try solving one of these from a public VPN.
This is a great and wise insight !
Also, i'm assuming, maybe wrongfully so, that Google would make accessible CAPTCHAs harder to pass, with the logic that sound-based CAPTCHAs are much easier to break for a bot.
All in all, reCAPTCHA (and other modern CAPTCHAs like hCaptcha) are a usability/accessibility disaster. It should be a crime to enable that on a service to restrict access to your peers.
Audio reCAPTCHA is super easy. Significantly easier than the visual one.
How is that an excuse? It's like having a café that only lets people wearing t-shirts in. Are you wearing a sweatshirt? "Well i'm sure you can download a t-shirt for free from your cupboard or one of your friends" /s.
It's a fundamental principle of interoperability ("strict about what you offer, lax about what you accept") that an online service should try to serve anyone, whether they have this or that technology or not enabled. In the case of the web, anyone with HTML parsing technology should be able to browse it... minus some stuff that actually doesn't work without additional technology.
> Audio reCAPTCHA is super easy.
I wouldn't know, it never let me through. I have to say, as a sighted person, the only times i've tried audio CAPTCHA were when Google wouldn't let me through using visual CAPTCHA (infinite CAPTCHA loop). Not even once have i been able to pass it.
I guess once you're on Google's no-pass list, whether you fill the CAPTCHA via audio or video doesn't matter, they're just not letting you through? I find it worrying that some people accept to have a private corporation strip-search their guests on the way to the doorbell/mailbox.
Literally everything is a choice of "If you refuse to use X, you will not get Y."
Most of my web browsers, including my phone's web browser, have JavaScript turned off. I can't use reCAPTCHA on the browser I'm using right now. It's not a big deal, and it's not something morally wrong. A piece of technology doesn't work if you're not using pieces of technology that operate with it. This is expected behavior.
If you like larry page and his friends, say so clearly, but please dont shame people based on accessibility that is not there.
The frustrating thing is that this happens even on devices/browsers with fewer privacy measures enabled, like just using a fresh firefox temporary container or private mode (so no browsing history or existing cookies maybe?) with no script blocking is ‘suspicious’ enough that accessibility to the blind is disabled with no recourse.
So yeah, it’s accessible (when they feel like it).
And we dont even have to go down the deaf-blind road. I have excellent hearing, but have failed at solving audio captchas in the past. Also, please remember that there might also be a language barrier. Give an english audio captcha to a german housewive, and learn how discrimination works.
It's how blatantly dishonest and disrespectful it is. Let me explain: google decides if you're human based on the data it has on you, such as your browsing profile and whether you're logged in to your Google account. Therefore it punishes you for trying to have privacy or refusing to use google services, at which point it will:
- Give you longer captchas
- Fade images in slower, something whose purpose can only possible be to annoy you for daring to refuse to submit to google's profiling, since bots don't care about that
- Even falsely claim you failed captchas even if you get them right
Fuck that!
Humans just have to give up and hope that whatever was behind the captcha wasn't actually important.
Reminds me of a bug I found at (with) work last week: typing too quickly (sending auto-completion requests too quickly) locks up the entire page, nothing for it but to refresh. (It's intended to cancel previous requests since only the latest one is needed, but obviously not supposed to freeze.)
I think of this every time now
Do you have a source for this?
If you are especially unlucky, you might even get denied entirely after solving captchas for several minutes.
I mentioned before, but once I got present with hCAPTCHA asking me to select 電車 (lit. electric train, but since all trains in big cities in Japan are electric train, 'train' in English also usually got translated as 電車). There's a picture of diesel train in the choice. Do I select it? idk.
Lately I have been presented with reCAPTCHA asking me to select トラック (lit. truck). Half of the choices are firetruck. Do I choose them? Because in Japanese (and probably most other languages too), we don't considered firetruck as 'truck'.
And the complaint that is more common: parking meter. I have literally never saw one, as it doesn't exist where I live. How do you expect me to chose the correct answers with noisy images?
It seems that they have them in many countries, but they are often underground rather than the pillar type used in the US. https://en.wikipedia.org/wiki/Fire_hydrant
These are standpipes [0] which can be used to move water to parts of the the building from that external fitting. They may contain some static water or be completely dry (like a dry riser [1]) but they are not a source of water like a hydrant is.
The cultural gap is annoying with captcha's, even if you keep your preferred browser language set to English.
It’s pervasive across the entire internet.. we’re all expected to suddenly relearn the names of everything we’ve ever learned in our life because the US has decided the rest of the world is wrong and should learn their distorted version of English or just not take part in the “world wide” web.
What's particularly degrading is when it asks you to do something like "select all the bridges" and you as a human see one that is clearly an overpass, not a bridge. You don't select it because it's not what you'd call a bridge. You're inhuman.
You're asked to select the motorcycles.. Here's a motorised scooter that looks a lot like a motorcycle. You thought that wasn't a motorcycle? Back to the training camps with you until you start to think like a human.
Now select all the mountains. Huh? That raised mound of grass doesn't look like a mountain to you? Guess again, inhuman scum.
At least with the "audio captcha" I feel like I might be contributing to some closed captions for another human :(
We can both look at the same image and have two different opinions about it. An AI simply boils it down to a confidence rating and if they're confident enough that an overpass IS a bridge, then your opinion does not matter to them.
My interpretation of overpass is that it can be a bridge but is not always a bridge.
https://en.wikipedia.org/wiki/Overpass
However, I would totally accept your point of view if you said an overpass is also a bridge.
I was fine with Google's captchas when they were designed to help translate scanned printed material into searchable text (providing a social good). I'm not fine with providing free labor for their self driving car project.
The problem, of course, is that the dataset is exclusive to Google, so while it may benefit society it's not creating a public good. But that's also true for text OCR.
Which will be available any day now, probably as early as 2018 if experts on the field can be believed. Some would even go so far as state that by 2025 private car ownership will be a thing of the past.
> that is not a social good?
Hype, empty promises and constantly moving deadlines. If this goes on we will have commercial fusion reactors before self driving has any positive impact outside of heavily supervised trials.
It's worse than that - if I prove I'm human by choosing pictures the machine doesn't agree with it won't let me in.
I recently found that using IE made for exponentially more tests. Out of pique, I tried doing the opposite of what was requested; for instance, if it wanted me to click on fire hydrants until there were no more, I clicked on pictures without fire hydrants until every square had one.
But it never got tired, or decided it was wrong about what fire hydrants are, or deduced the rule I was following.
It won't even let me differ on, say, 1/4 of them.
That's a problem of literacy, but it is still their fault and their responsibility as owners of the site.
You have probably never been stuck in a loop where it just wont stop throwing captcha at you.
Hilton.com is a big annoyance.
I know why they force me though, I use content blockers on macOS and iOS to block tracking and ads, but that is not a good reason.
I also hate sites that force you to do so... eg. twitter, where it decides it won't let you register without a phone number (making a new twitter account for a project), then won't allow you to use the phone number, because you already used it for your primary account.
The issue is that it may flag your account as more suspicious. After three days I had my account flagged. I couldn't view tweets or use the account in any way. On log in it would redirect me and ask for my phone number for "verification". Funny how they can verify something they never received. It took about ten days for support to correct but my account is active again and they still don't know my phone number.
I mean, maybe I can see/accept an argument for that. But when I have a recent order? When I'm logging in from the link you just emailed me?
In a quite a few instances, I find it flattering, because it implies "we haven't sucked enough data on you already to know if you are a human, so we need to be sure."
If it says "select a sign" and I see there's also a sign far away in the distance only a few pixels in size, I select it because it is a sign. I think most people don't because I frequently get many tests after, because I'm not human enough for them.
My surprise if the sites that do those things turned out to be using humans for free labeling of images would be an exact, unsigned zero.
In all fairness, i usually do that.
The machine doesn't know the answer so it doesn't really matter. You need to emulate the crowd and also realize you are contributing to the crowd. So you can actually pollute it with wrong answers to delay the robot uprising. Or at least cripple it when they keep running into fire hydrants they didn't see.
They do, they just look different. At least that's how it is in France.
Missing link? In NZ, and presumably other countries, personal letterboxes in rural areas can be used to send too, which I'm guessing is the same as what you're referring to.
Honestly, as a driver, when I see a bicycle, I make sure to provide as much room around them as possible. When I see a motorcycle from behind, I have no idea what the thought processes of the rider will be and just continue on in a straight line and allow them to make a decision. A bicycle in my rearview mirror poses no threat as they cannot keep up. A motorcycle can easily overtake in way ordinary cars cannot (between lanes, etc). They are much more difficult to predict. (not even taking into consideration the tendancy of motorcycle drivers being less risk averse).
So, if you want to teach the AI that a bicycle and a motorcycle are the same thing, then yes, you might inadvertantly lead to an AI making the wrong decision leading to a death. I wouldn't necessarily blame you for picking the wrong image in a captcha, but I'd definitely blame the devs for not sanitizing user input.
I fully understand this isn't going to have any effect. Maybe if a million of us were doing it, it would. But it still makes me feel better.
I remember far worse...
It would just be simply people refusing to work on captchas more than a certain amount. Basically, if you make me hunt for bikes and there's more than 3 of them, then I'm not doing it. More akin to a deliberate labor slowdown than a DDoS, or even a strike.
I mentioned DDOS because every time you fail to satisfy captcha criteria website requests a new batch of captcha for you; in that way you would be constantly requesting a new captcha if you would be deliberately failing your current one or as you described imposing a "hunt limit" upon yourself.
Indignity, that's it! I was never able to explain to myself the visceral hate I feel when I encounter captcha. I knew it could not be explained by the little work it requires, I knew there had to be more, I just couldn't put my finger on it. Indignity, and maybe the feeling of being used.
I have to admit, When I encounter captcha, I leave that page and never come back. I stopped using Pocket where I had hundreds of articles because of that. And when I encounter captcha on an especially bad day, I spend a few minutes clicking on incorrect images in an attempt to mess up their data.
Before I want to buy something there login. To prove that it is me owning the account I receive an email with a code I have to type in. Especially when I am on a mobile phone.
After that, when frigging ever I want to checkoutmy cartI am forcedto do these captcha again prove that I am a human.
I just stopped buying from them. Even if I like the cause.
What cause is that? To make IGN more money? Because everything else is only marketing by now.
So if anyone has better solution so I can eliminate the G and is Wordpress happy, I'm all ears (or eyes reading in this case).
Requires the browser to complete a Proof of Work challange.
Not for verifying humanness, but against spam / dos attacks.
"Demo Friendly Captcha in action The form was unable to submit. Please contact the site administrator."
Demo Hell 101. Make sure the demo shows the product working.
Is that what this is actually doing though? Is it PoW for a mining operation, or just causing some electrons to be moved around to prove your not a bot? I didn't read too far into what the PoW actually is since their demo shat the bed.
The problem is spam networks have more computers and more power than your phone does so any proof that you can do, spammers can do 1000x faster. PoW can sort of work when your attack to defend against is a ddos situation where an attacker has to make far more requests than the average user, but most captchas try to defend against bots being able to use the site at all which PoW can not do.
;]
> IP reputation
my ISP has, it seems, all of their addresses in a blacklist. The ips are also dynamic.
For IP reputation, looking for IPs associated with proxies and also data center IPs though blacklisting all the big cloud providers will grab innocent users. EG: US military runs outbound proxies on azure.
This all for new traffic. Users that are known to be non fraudulent have a unique persistent cookie that allows them to bypass all the checks. So they could jump on a VPN and stuff would work.
Stuff we built for an online bank was even more advanced and looked at the incoming packets to detect proxies(tcp fingerprinting to determine OS). And we did shady stuff with fingerprinting internal networks with WebRTC. Our adversaries were 100 times better than simple carders running selenium scripts.
As an aside, I enjoyed the use of the word "anomie" in the article.
Now I'm going to put on some sovietwave...
Well put. I would add that it's even more humiliating that you have to "prove" it to a machine, who has no clue what it even means to be human.
https://github.com/rene-tobner/unity
Egovernment and identity management @ world-wide-wished-for-things.org ?
How do you feel about Apple's face scanner?
This is EXACTLY what a Robot would say...